Privacy
Pagivise privacy notice
Pagivise is a PDF application and optional document-signing service operated by AeroFrohne. This notice describes its Android app, public website, subscription verification, and signing website.
Effective date: September 25, 2026
PDFs and information on your device
PDF reading, supported editing, and optical character recognition (OCR) run on your device. Opening a PDF does not upload that PDF to AeroFrohne. Google ML Kit performs OCR on the device; PDF images and recognized text are not sent to Google for recognition.
The Android app stores settings such as appearance and language, references to recent documents, and subscription access information on the device. You choose where to open and save files through Android’s document picker. A cloud storage provider you choose through that picker handles files under its own settings and privacy practices.
Deleting the app or clearing its storage does not delete PDF files saved elsewhere, copies held by a file provider, or information already submitted to the signing or subscription service.
Subscriptions and access verification
Google Play processes subscription purchases. Pagivise sends the Google Play purchase token and a randomly generated app installation identifier to AeroFrohne’s verification service to confirm access, restore purchases, and respond to subscription changes. The service stores the purchase token and its digest, subscription status, expiration and verification information, and any linked owner email address. The installation identifier is used to issue access bound to that installation; the billing service does not retain the raw identifier in its purchase records.
If you use the signing service, your verified email address can be linked to your subscription so the service can check your access. AeroFrohne does not receive your payment-card number through this integration. Google handles checkout and payment information under its own privacy practices.
Optional document signing
The signing pilot uploads a document only after you approve the upload. It handles the document title and contents, sender email address, recipient names and email addresses, selected language, and document and request identifiers. The sender separately confirms sending invitations to the listed recipients.
To authenticate users, deliver invitations, and record a signing request, the service handles email verification and session information, delivery status, and request activity. Invitation emails include the document title and a private link; they do not attach the PDF. When a recipient signs, it records the typed name, consent and intent, document digest, and signing date and time. It stores the original document, review pages, and any completed document and evidence record.
The sender and authorized recipients can access information associated with their request. A completed document and evidence record can identify other signing parties and their signatures. Send a document only to intended recipients and only when you are authorized to include its contents and their contact details.
Signing is a limited pilot for approved senders. It is not generally available solely by purchasing a subscription. Email verification establishes access to a mailbox; it does not verify government identity.
Service operation and SDK information
The service processes request and connection information, including IP addresses, to deliver requests, limit abusive traffic, and protect access. It stores IP-derived request-limiting identifiers for security; the app does not collect device location. Hosting providers may also maintain operational and security logs.
The signing website uses necessary session cookies for authentication and browser storage for appearance and language preferences. It does not include advertising or third-party analytics scripts. The public Pagivise website has no advertising or analytics scripts and does not set app-session cookies.
The Android app includes Google Play Billing and Google ML Kit. ML Kit sends device and app information, an SDK installation identifier, performance measurements, image-format and size information, feature events, and error codes to Google for diagnostics, usage analytics, and detecting misuse or abuse. This SDK traffic is separate from local OCR processing. Google describes it in its ML Kit data disclosure. The app contains no advertising SDK.
Isolated app-review workspace
App reviewers can use a separate, isolated test workspace. It handles generated app, device, and session identifiers and any test documents submitted to that workspace. Test signing invitations and verification messages remain in an internal test inbox; the review workspace does not send external email. Records in the test workspace become eligible for automatic daily cleanup after 30 days without modification. The test workspace can also be reset sooner. This cleanup applies to review test data and does not change the retention of production signing or subscription records described below.
Service providers and recipients
Pagivise uses these providers to deliver its features:
- Google: Play purchases, subscription verification and notifications, and ML Kit OCR software and its service metrics.
- Netlify and Neon: hosting, server-side processing, and database infrastructure for the signing and subscription services.
- Resend: delivery of verification codes, signing invitations, and related service emails.
These providers process information needed for their services. A document’s sender and authorized recipients receive information needed to review and complete that signing request. Information you send to support is used to respond to your request. Providers’ own privacy notices describe their separate practices.
How information is protected
Connections to the configured production service use HTTPS, and database connections use TLS. Signing and subscription record contents are encrypted in storage, and access to signing documents requires authorization. The service uses verification codes, expiring sessions, and document digests to help protect requests. The service must process uploaded documents, so this is not end-to-end encryption. No storage or transmission method can guarantee absolute security.
Retention and deletion
AeroFrohne retains stored signing documents, completed records, signing evidence, and associated information until it receives a verified, authorized deletion request, subject to the exceptions below. Stored subscription-verification records likewise have no automatic deletion schedule. Expiration of a verification code, session, invitation, or signing request limits its use; it does not by itself erase the underlying stored records.
You may request deletion through the process on the Pagivise data-deletion page. A request requires identity and authority verification. Deleting a sender’s signing profile can remove documents they own, related review copies, completed documents, signing evidence, pending invitation records, associated access records, and the email-to-subscription association.
Purchase tokens and subscription-status records are retained for subscription verification even if the signing profile and its email association are deleted. Documents owned by another sender in which you are a recipient require separate review because other signing parties have an interest in those records. Some information may also need to be retained for security, a dispute, or applicable recordkeeping requirements. AeroFrohne will explain information it cannot delete and the reason when handling your request.
Deleting information held by AeroFrohne cannot remove copies already downloaded by other signing parties or records independently held by Google or another provider. Provider backups and operational logs follow the provider’s retention and deletion processes, so deletion from active application storage does not promise immediate erasure from every backup. Canceling a Google Play subscription and requesting data deletion are separate actions.
Your choices and requests
You control which files you open, which documents you approve for upload, and which recipients receive a signing invitation. You can clear the recent-document list, change device or browser preferences, and manage your subscription in Google Play.
You can contact AeroFrohne to ask about personal information, request access or correction, or request deletion of all or part of the information associated with you. Applicable rights depend on your location and the circumstances. We may ask for enough information to verify your identity and your relationship to a signing request before disclosing or changing records.
Pagivise is a business and productivity tool intended for adults aged 18 and over. It is not directed to children. If you believe a child has provided personal information to the service, contact us so we can review it.
Contact and changes
For privacy questions and data requests, email AeroFrohne at info@aerofrohne.com. Identify Pagivise in your message. Do not send passwords, verification codes, payment-card details, or a full sensitive document with an initial request.
This notice may be updated when Pagivise’s features or data practices change. The effective date above identifies the version of this notice.