Legal
Privacy
Effective 2026-09-16
What Dealpages collects, from whom, why, and for how long. Written to match the code.
Who runs this
Dealpages is operated by Kyle Legare, an individual, at dealpages.app. Questions, access requests, and deletion requests go to kylelegare@gmail.com. It's a small product with a human attached; you'll get a reply from that human.
Two kinds of people touch Dealpages: account holders (usually sales reps, whose AI publishes pages) and readers (the people a page is shared with, who never need an account). Each is covered below.
If you have an account
- Email address — used to sign you in (one-time email links) and to contact you about the service. No password is ever stored; sign-in tokens are stored hashed and expire in 15 minutes.
- API keys — stored as a one-way hash; the key itself is shown once and never kept.
- Sessions — a browser cookie keeps you signed in for 30 days.
- Everything your AI publishes — page HTML (every version), titles, stakeholder names, roles and emails you attach to links, and the engagement data those pages generate.
- Service logs — request metadata (timestamps, truncated IP, user agent) kept for operating and securing the service.
You are responsible for the content you publish and for the stakeholder details you attach to links; treat them as you would in your CRM.
If you're reading a page someone shared
Every hosted page carries a visible notice that it uses engagement analytics. Here is exactly what that means.
- Which link you opened and when. Links are minted per person, so the sender knows who they sent each link to.
- Roughly where from. City, country and network provider, as reported by our hosting provider. IP addresses are truncated before storage (last octet dropped for IPv4, network prefix only for IPv6) and never kept whole.
- Your browser's user-agent string and whether it looks like a phone or a laptop.
- Reading behaviour on the page: engaged time (only while the page is visible, focused and you're actually interacting — a background tab counts nothing) and which tagged sections you read and for how long.
- Comments you choose to leave, with the name you type, if any.
- A first-party cookie (
srv_id, random, up to 400 days) so repeat visits across links from the same sender can be recognised. If your browser sends the Global Privacy Control signal, no cookie is set and a daily-rotating hash is used instead, which self-expires within 24 hours. - A per-page cookie if the sender password-protected the page, so you don't retype it (30 days).
What we don't do: no third-party trackers, no ad networks, no cross-site tracking, no selling or sharing of reader data. Dealpages never learns your name or email unless you type it into a comment or a report. Pages are unlisted and marked noindex.
Every hosted page also carries a Report this page link. A report records the link, your reason, anything you type, and a truncated network address, and is emailed to the operator.
What the sender sees: a per-link summary of the above. Signals about someone new opening a link are scored and described as exactly that — "someone new opened this link" — never as a claim about who.
Where the data lives
Hosting, database and edge network: Cloudflare. Sign-in email delivery: Resend. Both process data on our behalf under their own terms. There are no other third parties.
How long we keep it
- Raw request logs: 90 days, then pruned automatically.
- Fine-grained engagement events (opens, reading time, new-viewer signals): 180 days, then pruned automatically.
- Page versions, links and comments: as long as the page exists. Deleting a page (account holders can, from the console) erases all of it, including any engagement history still within the 180 days.
- Abuse reports readers send about a page: kept as an audit record.
- Expired sign-in tokens and sessions: swept nightly.
- Accounts: deleted on request, with everything under them.
Your rights
Whether you're an account holder or a reader, you can ask what we hold about you, ask for it to be corrected, or ask for it to be deleted. Email kylelegare@gmail.com. Readers: tell us the link you opened if you have it; it's the only way we can find your visits.
Changes
When this page changes, the changelog says so, with the date. Material changes for account holders are also emailed.