This policy explains what PageHawk does with your information: what it does on your device, what travels when you use sync, sharing and PageHawk AI, who helps us run those features, and the choices you have.
Who we are
PageHawk is made by Epiphani Studios LLC, a Georgia limited liability company (“Epiphani Studios”, “we”, “us”). This policy covers the PageHawk apps for Mac, iPhone and iPad, the PageHawk web app at app.pagehawk.com, shared document pages at share.pagehawk.com, and this website, pagehawk.com. Questions go to hello@pagehawk.com.
What PageHawk does on your device
On the Mac, reading, searching, comparing, recognizing text in scans, redacting, Bates numbering and organizing all run on your Mac, using the frameworks built into macOS; your saved signatures are kept in the Mac’s Keychain, and the counts behind the app’s own usage view are kept in a file on the Mac. On iPhone and iPad, reading, searching and recognizing text in scans run on the device. The web app at app.pagehawk.com runs in your browser and uses the account, library sync and sharing features described below. On the Mac, Ask and Translate run on Apple’s on-device models unless you choose an AI provider of your own, described below.
When information leaves your device
Some features work by sending information to a server. Each is listed here with what it sends and when.
Your account. When you sign in, your Epiphani account (account.epiphani.com) receives your email address and the sign-in exchange. PageHawk then keeps a sign-in token on your device (on the Mac, in the Keychain) to check which plan you have. When you are signed in on iPhone or iPad, the app also tells your account a few milestones, such as its first open, reaching a free limit, or seeing an upgrade screen.
Library sync. On the Mac, PageHawk syncs your library across your devices from the first launch, whether or not you are signed in. In PageHawk for Mac 0.87.32 and later, you can turn this off in Settings, Devices & Sync. Each document you open (up to 30 MB), its cover, its title, your reading position, your collections and your markup are sent to our sync service. Documents, covers, titles, collection names and markup are encrypted on your device before they are sent. Reading positions, page counts and each document’s content fingerprint are sent without that encryption, so your other devices can place you on the right page. On iPhone and iPad, sync starts when the device joins your library: by a code you type or scan, by signing in, or on its own when a Mac signed in to the same iCloud account already has a PageHawk library. Unpair this device, in the app’s sync sheet, stops sync on that iPhone or iPad and keeps it from rejoining on its own.
Your library on a new device. When you are signed in, we keep your library’s key with your account, encrypted on our servers, so your library can follow you to a new device without a code. Because we hold that key, we can decrypt a signed-in library. PageHawk also saves the library code in your iCloud Keychain, so your other Apple devices on the same iCloud account can join the library without a code.
Sharing. When you share a document as an online link, the document (up to 50 MB), a page preview, its title, the first 200 characters of its text and its page count are uploaded so the people you share it with can open it. On the Mac, the shared link updates automatically when you change the file; on iPhone and iPad it updates when you choose Update. Anyone who has the link can open it, unless you add a password. We count views and downloads on each share. When someone comments, annotates or signs, we keep what they add (the name they enter, their comment or markup, a signature image and where it sits on the page, and the time) so it appears on the share. Deleting a share removes it from our servers; copies people already downloaded stay with them. A redline shared from the web compare tool is uploaded as page images and change details, and its link expires after 30 days.
PageHawk AI. When you are signed in on the Mac and open the Signature Assistant, the text and position of each page’s words are sent to PageHawk AI, which uses a model from OpenAI to find the places to sign. The Signature Assistant says when this check is running online. We keep a count of checks per account per month. PageHawk AI does not keep the page text; OpenAI processes it under its API terms.
An AI provider you choose. If you add your own key for OpenAI or Anthropic (and, on the Mac, Google) in Settings, or pick one of them in Ask, the features you use send that provider what they need: a short excerpt and the file name for Smart Rename and Organize, and your question with the document text it needs for Ask and Translate. On the Mac your key is kept in a settings file on your device; on iPhone and iPad it is kept only while the app is open. That provider’s own terms govern what it does with the request.
The free scan allowance. When you are signed in and the Mac reads text in a scanned document under the free allowance, it sends that document’s fingerprint (a hash of its contents) and size to your account, so the count follows you to every Mac you sign in on. This request does not include the document; library sync, described above, may upload it separately.
Dropbox and Google Drive. If you connect either on iPhone or iPad, PageHawk signs in to it with your permission, lists your files and downloads the ones you open. The sign-in stays on your device.
SealHawk. If you connect SealHawk, the connection code, your device name and any PDF you choose to archive are sent to sealhawk.com.
Claude Desktop. If you connect PageHawk to Claude Desktop, search results and passages go to Claude Desktop when you ask Claude for them, and Claude Desktop handles them under your own Claude account. By default, PageHawk masks common patterns of email addresses, phone numbers, payment card and bank account numbers, and API keys in those passages before they go; pattern matching can miss an unusual format.
Feedback and diagnostics. When you send feedback, we receive your message, the email address if you add one, the app version, the device model and system version, and the device’s thermal state. On iPhone and iPad, a screenshot of the screen you were on, which may show the document you had open, is attached unless you switch it off before sending, and a diagnostics report you choose to send adds the network type, free memory and storage, a recent app log and an identifier for that install.
Crash reports. If the iPhone or iPad app stops unexpectedly, the next launch sends us a crash report: the error and where in the app it happened, the app and device details, the network type, free memory and storage, a recent app log and an identifier for that install.
Feedback rewards message. Each time the iPhone or iPad app opens, it asks feedback.epiphanistudios.com for the current feedback rewards message. The request names the app and carries no document information.
Updates. The Mac app checks updates.belstone.com for a new version once a day and downloads it when there is one. The check carries no document information.
Fonts. The Mac app’s welcome window loads a font from Google Fonts, so Google receives that request.
Epiphani Master Key. If you redeem an Epiphani Master Key, the app records the redemption with Epiphani Studios: the key holder’s name, the product and the computer’s name.
Connection details. Whenever your device contacts one of the services above, that service receives your IP address and ordinary request details, such as the time and the app version, as any internet service does.
Who helps us run PageHawk
These service providers run parts of PageHawk for us: Cloudflare (hosting, storage for sync and shares, and the PageHawk AI service), OpenAI (the model behind the PageHawk AI check), Resend (email, such as your license key), PostHog (website analytics, only after you accept them) and the payment processor that handles a purchase. Apple (iCloud Keychain, App Store purchases and app distribution) and Google (the welcome window’s font) also receive the requests described above, and so do Dropbox, Google Drive, an AI provider, SealHawk or Claude Desktop when you connect one. We do not sell your information, and we do not share it for advertising.
When we disclose information
We use a signed-in library’s key to bring your library to the devices you sign in on, and we do not use it to read your documents except when the law requires it. We disclose information about you only in these cases: to the service providers and the services you connect, described above; to the people who open a document you share, as described under Sharing; when the law requires it, for example under a valid court order; to protect the safety, rights or property of people or of Epiphani Studios; or as part of a merger, acquisition or sale of the business, in which case this policy continues to apply to the information transferred.
Payments
On iPhone and iPad, purchases go through Apple’s App Store: Apple handles your payment details and tells the app what you bought. On the Mac and the web, a payment processor handles your payment details, and we receive your email address, what you bought and its status, so we can send your license key and keep your plan active.
This website (pagehawk.com)
To learn what helps visitors decide, we run our own first-party analytics alongside PostHog, which also records sessions, with your typing and the page’s text masked, so we can see where the page confuses people. Both are off until you choose Accept on the banner. If you choose Essential only, no website analytics run and no session is recorded. In session recordings, everything you type is masked before it leaves your browser and all on-screen text is hidden. We honor your browser’s Do Not Track setting.
When you accept, we record how the page is used: which pages are viewed and which features you try, a coarse country and platform (for example “US, Mac”), and a visit identifier, plus the cookie PostHog sets to recognize a returning visit. Our own analytics derive the country and discard your IP address; PostHog uses your IP address to work out an approximate location and to keep its service secure. We do not use any of it to advertise to you.
The PageHawk list
If you join the PageHawk list on this site, we store the email address you enter, and, if you check the box, that you want a Windows version. We use it to tell you about PageHawk and to answer you, and we delete it when you ask.
How long we keep information
Your account, and your synced library whether or not you signed in: until you ask us to delete them or close your account.
Shared document links, and the comments, markup and signatures added to them: until you delete the share. Redline links from the web compare tool: 30 days.
PageHawk AI usage counts: about 40 days.
The record of which scanned documents your account has read for free: for the life of your account.
Feedback, diagnostics reports, crash reports and list sign-ups: until you ask us to delete them.
Your choices
In PageHawk for Mac 0.87.32 and later, Settings, Devices & Sync turns library sync off for that Mac. On iPhone and iPad, Unpair this device does the same. Either one stops new uploads; what is already stored stays until you ask us to delete it.
Signing out stops account features: the library link, sharing and the PageHawk AI check. Library sync stays as you set it.
You can delete a shared link at any time from the share list.
Choose “Essential only” on the banner to keep website analytics off. If you accepted and change your mind, use this control on this page: and the banner asks again on your next visit. To delete what was recorded before, write to us.
To get a copy of what we hold about you, to correct it, to have it deleted (including a synced library you never signed in to), or to close your account, write to hello@pagehawk.com.
Security
Information travels to our servers over encrypted connections. Synced documents, covers, titles, collection names and markup are encrypted on your device before upload. Reading positions, page counts and content fingerprints are not encrypted on your device before upload. For a signed-in account we keep your library key, stored encrypted, which means we can decrypt that library. Shared documents are not encrypted on your device before upload: they are stored on our servers in a form we can read, so the people you share them with can open them.
Children
PageHawk is meant for adults and is not directed to children under 13. If you believe a child has given us personal information, write to us and we will delete it.
Changes
When this policy changes, we update the date below. For a material change, we also say so in the app or on this site.
STAGED PREVIEW · pagehawk.com/privacy/ PROPOSED: the privacy policy rewritten to match the app (audit I56). AWAITING Jason and counsel. · nothing is live until you approveSTAGED PREVIEW · nothing is live