Operator and contact
PageNerve is operated by IVRIS Tech during the public Beta. Privacy questions can be sent to [email protected].
Desktop app and local project data
PageNerve stores audit projects, crawl evidence, recommendations, and exports on your Windows computer. By default, audit files and backups are under the Windows Documents known folder in PageNerve\Audits and PageNerve\Backups. Runtime settings, logs, protected secrets, and supporting local state can be stored under %LOCALAPPDATA%\PageNerve. Your Windows configuration can redirect or back up Documents through OneDrive or another provider; PageNerve does not itself upload those project files to IVRIS Tech.
The desktop interface uses a private on-device service and normally displays only inside the PageNerve Windows app window. If the native window cannot start safely, PageNerve shows a repair message and stops. The interface traffic remains on your computer. PageNerve has no product telemetry, does not upload audit projects, recommendations, or exports to IVRIS Tech, and does not publish changes to a CMS.
When you crawl an authorised website, PageNerve sends ordinary HTTP or HTTPS requests to that website. The website and its infrastructure can log information such as the requested URL, time, IP address, user agent, response, and rate. You are responsible for having permission to crawl the target and for choosing an appropriate rate and scope.
Optional connections
If you activate Private Beta, the PageNerve licence service handles limited account, entitlement, installation, device, lease, and security metadata. Normal server logs can include time, IP address, request route, and success or failure state. Licence and connector secrets stored by the app are protected with Windows Data Protection API (DPAPI) for the current Windows user.
If you connect Google Search Console, Google handles the OAuth sign-in and PageNerve requests read-only Search Console data that you choose to use as local audit evidence. If you validate a WordPress connection, PageNerve sends an HTTPS request to the site you specify; an app password is used for validation, kept in process memory only for that operation, and cleared afterwards. PageNerve does not publish to WordPress.
Website, account, and download information
The website can receive the name, work email, website URL, page range, service interest, and optional context submitted through the enquiry form. Basic security and delivery records may include a submission identifier, time, service category, IP address, and success or failure state. Do not submit passwords, customer records, analytics credentials, or sensitive personal information. The website does not use advertising analytics or marketing cookies.
An account can handle an email address, verification state, account identifier and status, one-way password representation, essential session and CSRF controls, installer-delivery controls, masked licence identifiers, beta state, assigned-user and device metadata, expiry or lease state, and security-event identifiers. Passwords are not stored in readable form. The essential pn_session cookie is host-only, Secure, HttpOnly, SameSite=Lax, and limited to a 12-hour session. A direct-download request can use a Secure, HttpOnly, SameSite=Strict pn_download_grant cookie that expires after 10 minutes.
For protected Direct Beta installer delivery, PageNerve records a random grant identifier, its account link and expiry, and the exact installer version, release sequence, SHA-256, and size. When an authenticated GET or HEAD request passes the grant, artifact-integrity, and Range checks, PageNerve records another random identifier, the method, 200 or 206 response, whether Range was requested, the canonical response byte bounds, authorized byte count, and time. This means only that PageNerve authorized a stream response; it is not proof that a browser completed or saved the download. This installer ledger does not store the raw grant cookie, raw IP address, user-agent, raw Range header, email address, licence key, password representation, or private file path. Microsoft handles Microsoft Store acquisition; that path does not use PageNerve’s account or direct-download grant ledger.
A person with an explicitly granted IVRIS operator role can open the restricted owner console for support, security, and aggregate reporting. Each owner-console session requires fresh confirmation of a current password and authenticator code. Each owner security event records a pseudonymous actor identifier, operation, outcome, timestamp, and limited security metadata in an append-only ledger. A reason is included only where that operation records one; offline lifecycle reasons are represented by a fingerprint. The event does not contain passwords, full licence keys, authenticator secrets, session or download tokens, raw filters, IP addresses, user agents, or local audit-project content. The console itself is limited to necessary account, masked licence, device, and authorized body-bearing installer GET fields.
Service providers and Microsoft Store
Cloudflare supports DNS, security, and anti-automation checks. Hostinger serves the website and its enquiry and account services. Zoho carries enquiry and account emails to or from the IVRIS Tech inbox. Google processes optional Search Console authorisation and API requests when you connect it. Target websites process the crawl requests you authorise.
For a Microsoft Store installation, Microsoft processes Store account, device, installation, certification, diagnostic, and update information under Microsoft’s terms and privacy statement. Microsoft Store manages installation and updates for the Store build; that build does not use PageNerve’s in-app updater. IVRIS Tech does not receive your Microsoft account password or the contents of your local PageNerve projects from the Store.
Retention
You control how long local audit files, backups, exports, and logs remain on your computer or in any Windows-configured backup location. Unsuccessful enquiry content is not intentionally logged. Enquiry records are targeted for deletion within 90 days unless the conversation becomes a required commercial record. Unverified accounts still pending verification are deleted 30 days after account creation. Verified account and licence metadata are retained while the account or beta access remains active and then through deletion plus limited operational, security, or legal retention. User-linked installer grant and authorized-request records are retained for up to 365 days and are removed when completed account deletion removes the linked account. PageNerve reports only the retained window and does not claim a lifetime or completed-download total. Owner-console security records are retained for at least 365 days from each event’s occurrence. After 365 days, they become eligible for removal by a dedicated offline retention operator in bounded batches after a verified backup; legal holds, outages, or safety pauses may extend retention. The web runtime and owner console cannot update or delete them. Each applied batch records its operator, reason, cutoff, and count in a separate append-only maintenance ledger. Verification and reset controls expire under the security policy and are invalidated after use. Microsoft, Google, network providers, and target websites apply their own retention policies to data they process.
Your choices
You can delete local projects, backups, exports, and logs; disconnect optional integrations; use the Account page to request an account-data export, remove an assigned device, or request account deletion after re-authentication; and control Store updates through Microsoft Store and Windows settings. You can also contact PageNerve to ask about an enquiry or request correction or deletion where applicable. See Data Handling for the service-project boundary.