Privacy Policy

Pantherahive Cloud · Notion public connection · Last updated 2026-08-19

This Privacy Policy describes how PantheraHive Cloud ("we") handles data when you connect a Notion workspace to our Service via the Notion OAuth API. It applies only to the Notion public connection hosted at notion-oauth.hotwodi4.workers.dev.

1. Data we collect

When you authorize the connection, Notion provides us with:

We do not collect your name, email address, payment information, or any other personal data through the OAuth flow itself. Any such data you provide separately (e.g., by emailing support) is handled under our general privacy practices.

2. How we use the data

3. Data we do not collect

4. Where data is stored

Installation records and credit balances are stored in a Cloudflare D1 (SQLite) database located in Cloudflare's global network. Access tokens are stored in the same database. All transport between the Service, Notion, and your browser uses HTTPS.

5. Data retention

We retain installation records for as long as your Notion workspace is connected to the Service. When you disconnect via Notion's settings or request deletion via support, we remove the installation row within 7 days. We may retain aggregated, non-identifying logs (e.g., error counts) for up to 90 days for service reliability purposes.

6. Your rights

7. Security

OAuth client secrets are stored as Cloudflare Worker secrets and are never committed to source control or logged. State parameters are validated on every callback to prevent CSRF. Access tokens are stored only in the D1 database described above and are not exposed in logs or API responses.

8. Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date above reflects the most recent revision. Continued use of the Service after a change constitutes acceptance of the new policy.