Privacy policy
Last updated 11 August 2026
PageTruth is a service for asking questions of your own documents. This policy explains what we collect, what happens to the files you upload, who else touches them, and what you can ask us to do about it.
Who we are
PageTruth is operated by Infonex Pty Ltd, an Australian company. In this policy “we” and “us” mean Infonex Pty Ltd, and “you” means the person or organisation using the service.
We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth). If you want to reach us about anything here, write to admin@infonex.com.au.
What we collect
Your account. You sign in with Google. We receive your email address, your name and your profile picture from Google, and nothing else. We never see your Google password.
Your documents. The files you upload, the text extracted from them, and the page numbers that text came from.
Your conversations. The questions you ask, the answers returned, and the passages cited in support of them. Any rating or written feedback you leave on an answer.
Your knowledge bases. Their names, settings, branding, any custom domain you connect, and who you have invited to them.
Billing. Your plan and subscription status. Payment card details go directly to Stripe and are never sent to or stored on our servers.
Operational logs. Ordinary server logs — request paths, timestamps, error traces — kept to run and debug the service.
What we do with it
We use it to run the service you asked for: storing your files, making them searchable, answering your questions from them, letting your colleagues in, sending you the emails the service needs to send, and taking payment.
We do not use your documents or conversations to train AI models — not our own, and not anyone else’s. We do not sell your data, and we do not share it for advertising.
Staff at Infonex Pty Ltd do not read your documents or conversations as a matter of course. Access happens only where it is needed to investigate a fault you have reported, to respond to a security incident, or where the law requires it.
Who else processes it
Running the service means passing data to a small number of providers. Each one is used for the purpose named below and no other.
| Provider | What it handles | Where |
|---|---|---|
| Vercel | Hosting and serving the application | Japan |
| Supabase | Database and sign-in — accounts, knowledge bases, conversations | United States |
| Amazon Web Services (S3) | The document files themselves | United States |
| Amazon Web Services (S3 Vectors) | The search index and the extracted passages | United States |
| Amazon Web Services (Textract) | Reading text out of scanned pages | United States |
| OpenAI | Turning passages and your questions into the numeric form used for search. Document text is sent here. | United States |
| Anthropic | Composing answers. Your question and the passages retrieved for it are sent here. | United States |
| Stripe | Payments and subscriptions | United States |
| Resend | Transactional email — invitations, welcome and billing notices | United States |
| Sign-in | United States |
Our AI providers process what we send under their API terms, which do not permit them to train models on it. They may hold it briefly for abuse monitoring before deleting it.
Your data leaves Australia
As the table above shows, it does — mainly to the United States, and to Japan for the application servers. This is a cross-border disclosure under Australian Privacy Principle 8. By using PageTruth you consent to it. We choose providers that commit contractually to protecting the data they hold for us, but we cannot guarantee that an overseas provider will be subject to a privacy law equivalent to Australia’s.
Analytics
We use Google Analytics on the marketing pages only — the home page, the sign-in page and the plan page. It is not loaded inside a knowledge base, so the pages where your documents and conversations appear are never measured and their addresses are never sent to Google.
We also collect anonymous page-speed measurements through Vercel Speed Insights. These carry no identifiers and no page content.
We do not use advertising cookies. The only cookies we set are the ones that keep you signed in and remember whether your sidebar is open.
How long we keep it
While you use the service. Your files, extracted text and conversations stay until you delete them or close your account.
When you delete a document, we delete the stored file and remove its passages from the search index.
When you delete a knowledge base, its documents, conversations and entire search index go with it.
When you close your account, we delete your knowledge bases and their contents. We keep billing records for as long as Australian tax and corporations law requires, which is generally seven years.
Deleted data may persist in encrypted backups for a short period before those backups expire.
Security
Access to a knowledge base is enforced in the database itself, not only in the application, so a member can only reach the knowledge bases they have been invited to. Each knowledge base has its own search index, which is what makes it impossible for one customer’s question to retrieve another customer’s passage.
Documents are stored privately and are never publicly addressable. A link to open one is minted only when you click it, expires within minutes, and is checked against your current membership every time.
Data is encrypted in transit and at rest. No system is perfectly secure, but if a data breach occurs that is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.
If you were invited by someone else
Where your employer or a client created the knowledge base, they control it — including which documents are in it, who else can see it, and whether your access continues. They can see the conversations held in it. For that knowledge base they are responsible for the content, and we handle it on their instructions. Questions about why a document is there, or why you have access, belong to them rather than to us.
Your rights
You can ask us to:
- give you a copy of the personal information we hold about you;
- correct anything that is wrong;
- delete your account and its contents;
- explain how a particular piece of information is handled.
Write to admin@infonex.com.au and we will respond within 30 days. If you are unhappy with how we handle a privacy complaint, you can take it to the Office of the Australian Information Commissioner at oaic.gov.au.
Children
PageTruth is a tool for work and is not intended for anyone under 16. We do not knowingly collect information from children.
Changes
If we change this policy we will update the date at the top. Where a change materially affects how we handle your information, we will email account holders before it takes effect.
Contact us at admin@infonex.com.au, or through infonex.com.au/contact.
Infonex Pty Ltd · ABN registered in Australia · infonex.com.au
Questions about this document: admin@infonex.com.au