Privacy Policy
Last updated: September 30, 2026
This Privacy Policy explains how SaaS Labs US, Inc. ("DemoPage", "we", "our", or "us") collects, uses, shares, and protects personal information when you use demopage.io, app.demopage.io, the demo pages and embedded demo buttons our customers put on their websites, and the related products and services we offer (collectively, the "Services").
DemoPage is an AI demo agent for software companies. A business (a "Customer") connects its website, its documentation, and, if it chooses, a sandbox account of its product. When a visitor asks for a demo, DemoPage opens the pages the Customer approved in an isolated browser, narrates them for what the visitor said they need, answers questions from those pages, and hands the lead to the Customer's team. DemoPage never saves, sends, or pays anything inside the Customer's product during a demo.
This Privacy Policy is incorporated by reference into our Terms of Service. Capitalized terms that are not defined here have the meanings given to them in the Terms of Service.
1. Key definitions
- "Customer" means a business that uses the Services to demonstrate its own product, including a business invited to create a DemoPage account.
- "User" means an individual who accesses the Services on behalf of a Customer, such as an employee who signs in to the portal or the dashboard.
- "Visitor" means an individual who uses a Customer's demo page, recording, recap link, support page, or training page. Visitors are usually the Customer's prospects or customers.
- "Site Visitor" means an individual who visits our marketing website at demopage.io without signing in.
- "Personal Data" means information that identifies, or could reasonably be linked to, an identified or identifiable natural person, as defined under applicable law.
- "Customer Data" means Personal Data and other content that a Customer, its Users, or its Visitors submit to or generate within the Services, including the Visitor information described in Section 2.2.
2. Information we collect
2.1 Information Customers and Users provide
- Account information: company name, your name, work email address, the website you want to demonstrate, and a password, which we store only as a salted hash.
- Configuration: the pages you approve for demos, your call to action and booking link, the email addresses and Slack channel that receive lead alerts, webhook addresses, coaching settings, and approved answers.
- Product logins: if you connect a sandbox or demo account of your product, its login is stored encrypted on our servers and is never shown in full, even to you.
- Leads you send us: if you use "Demo before the first call" or our account API, the lead's email address and, as you choose, their name, company, what they want to solve, and the tools they use.
- Maps from AI tools you connect: if you connect an AI tool, such as Cursor, Claude Code, Codex, or ChatGPT, with "Sign in with DemoPage", the tool can send us pages it mapped from your product's code or documentation. For each page, that is a title, its web address, a short piece of text visible on the page, a description, and optional keywords or click path. The tool reads your code on your side: DemoPage does not receive your source code, your files, or access to your repository. We also keep the name the tool registered with, when you connected it, and when it last used DemoPage.
- Invite requests and communications: when you ask for an invite, contact support, or write to us, your name, work email, company, what you would use DemoPage for, and what you tell us.
2.2 Information about Visitors, collected for the Customer
When you use a Customer's demo page, we collect the following on behalf of that Customer. The Customer whose demo you used receives it.
- The demo form: your work email address, the tool you use most, and what you want to solve or evaluate.
- Your replies to the guide's questions, and the questions you type or speak during the demo. Voice clips are transcribed and then discarded; we keep the text.
- What happened in the demo: the pages shown, whether you watched to the end, whether you took the screen, and which next step you clicked.
- Live demo recordings: a live demo is recorded as video of the demo browser, which can show what you type into the Customer's sandbox. What you type goes to that sandbox, not into your own accounts.
- A qualification summary for the Customer's team, written only from your own words and plain facts about the demo. Nothing is inferred into words you did not use.
- Recap and recording links: when a link is opened, we record opens, plays, and how far it was watched against a random viewer id. We store your name and email on those links only if you choose to give them.
2.3 Information collected automatically
- Usage limits and counts: to limit abuse and count visits, we use a salted hash of your IP address and browser. The address itself is not stored, and counts are kept per day.
- Server logs: our servers keep standard technical logs, such as request times and errors, for security and troubleshooting.
- Cookies and browser storage: see Section 6. We do not use advertising cookies or third-party analytics on our website or in demo pages.
- Free tools: the website address you give one of our free tools (the SaaS Website Grader, Demo Script Generator, Discovery Call Question Generator, Follow-up Email After a Demo, or Buyer FAQ Generator) is read, like any visitor would, to produce your result. The grader keeps its result in memory for up to six hours, so a repeat check is quick; nothing is saved to an account. The writing tools send the text of those public pages, and anything you type, such as call notes, to our AI providers to write the result, and we don't save either. The Speed-to-Lead Test keeps your work email and first name, and the time, sender address, and subject line of each reply to your test address (not the message bodies), for 30 days; we email you the test address and the result. The AI Demo Video of Your Website keeps your work email, first name, website, and request for 30 days, reads your public website, records a demo of it in one of our demo browsers, and emails you the link, which works for 30 days; the product setup made for it is deleted once the recording exists. The Demo No-Show Calculator runs in your browser. The published SaaS website grades are made from each company's public web pages and contain no personal information. A question in a Let Me Google That For You or Let Me ChatGPT That For You link stays in the link; we don't save it. Usage limits for the tools use the salted hash above.
2.4 Information from third parties
- Tools a Customer connects, such as HubSpot, Salesforce, Zapier, a calendar, or Chili Piper, can send us events about the Customer's leads.
- To build a demo, we read the Customer's public website and documentation, and the pages of its product that the Customer lets us open.
- For our own sales and marketing, we may receive business contact information about prospective Customers from public sources and sales-intelligence providers.
3. How we use information
- Provide the Services: read and approve pages, plan and narrate demos, answer questions, record demos, prepare demos for leads before a first call, and send lead alerts, recap links, and weekly summaries.
- Security and abuse prevention: enforce usage limits, review new sign-ups, block actions that would save, send, or pay inside a Customer's product, and investigate misuse.
- Support: respond to questions and fix problems.
- Quality and improvement: check each night that approved pages still load as expected, measure demo quality, and improve the Services, using aggregated or de-identified information where we can.
- Communications: send invites, email confirmations, password resets, alerts, and service notices. We send marketing email only where the law allows, and you can opt out at any time.
- Legal and compliance: comply with law and legal process, and protect our rights and the safety of our users.
Legal bases (EEA, UK, and Switzerland). Where the GDPR or UK GDPR applies, we rely on performance of a contract to provide the Services, our legitimate interests (such as securing and improving the Services), compliance with legal obligations, and consent where required. You may withdraw consent at any time.
4. AI features
- DemoPage uses AI providers to plan demos, write narration, speak it aloud, transcribe spoken questions, answer questions, and decide the next step in a demo. They process the inputs we send to return results to us.
- Answers are limited to the pages the Customer approved. When those pages do not answer a question, the guide says so and hands the question to the Customer's team.
- The guide introduces itself as an AI guide.
- We do not use Customer Data or Visitor information to train AI models.
- The Services do not make decisions that have legal or similarly significant effects on you. Qualification summaries are notes for the Customer's team.
7. Your choices
- Customers and Users can change account settings and alert recipients in the portal or dashboard, turn off the weekly summary, see and disconnect AI tools connected with "Sign in with DemoPage", and ask us to delete their account.
- Visitors: the Customer whose demo you used decides how your information is used. Please send access, correction, and deletion requests to that Customer. You can also write to us, and we will pass your request to the Customer and help them respond.
- Email: transactional emails, such as an invite or a password reset, are part of the Services. Marketing emails include an unsubscribe option.
- Do Not Track: there is no common standard for Do Not Track signals, so we do not respond to them. We honor Global Privacy Control signals where the law requires.
8. Data retention
We keep Personal Data only as long as we need it for the purposes in this Policy, unless the law requires or allows longer. Some records are removed automatically:
- Account data: while the account is active, and deleted when the Customer asks, subject to the backups below.
- Leads and questions: each demo link keeps its latest 200 leads and latest 60 questions.
- Demo sessions and recordings: kept while the Customer's account is active, up to the most recent 1,000 sessions across the Services plus each demo link's 20 most recent and the recording it shows, and deleted when the Customer asks.
- Recap and recording links: they stop working when they expire, after 1 to 90 days as the Customer sets (recap links after 30 days).
- Email received by DemoPage demo-login addresses: 14 days.
- Saved sign-ins to Customer sandboxes: 24 hours.
- Visit counts used for limits: 7 days.
- Invite requests: until the invite is used, and at most the latest 500.
- Connected AI tools: a connection ends after 30 days without use. Disconnecting the tool, or resetting your password, ends it at once.
- Backups: hourly database backups are kept for 30 days, and disk snapshots for 14 days.
9. Roles for Customer Data
For Customer Data, including Visitor information, the Customer decides the purposes of processing and is the "data controller" or "business" under applicable law. DemoPage processes that data on the Customer's behalf as a "data processor" or "service provider." Where the GDPR, UK GDPR, or CCPA/CPRA requires it, we sign a Data Processing Addendum with the Customer, available on request from legal@demopage.io.
DemoPage is the controller of account data, invite requests, and information about Site Visitors.
10. Security
We use administrative, technical, and physical safeguards designed to protect Personal Data. These include:
- encryption in transit (TLS);
- salted password hashing;
- storing the sign-in keys of connected AI tools only as hashes;
- encryption of stored product logins (AES-256-GCM);
- keeping secrets in a managed secret store;
- running each demo in its own isolated, sandboxed browser on a separate machine that holds no cloud credentials and is wiped after the demo;
- guards that block saving, sending, and paying inside a Customer's product and mask keys and tokens on screen;
- private backups;
- limited access to production systems.
No method of transmission or storage is completely secure. If a personal-data breach occurs, we will notify affected parties and authorities as the law requires. Report security concerns to legal@demopage.io.
11. International data transfers
We are based in the United States, and our servers are in the United States. When we transfer Personal Data out of the European Economic Area, the United Kingdom, or Switzerland, we use legally recognized transfer mechanisms. These include the European Commission's Standard Contractual Clauses, and the UK Addendum for UK transfers.
12. Your rights
12.1 EEA, UK, and Switzerland
Subject to conditions and exceptions under applicable law, you may have the right to access, correct, or delete your Personal Data; to object to or restrict certain processing; to data portability; and to withdraw consent. You also have the right to complain to your supervisory authority. To exercise these rights, contact legal@demopage.io.
EU Representative. IT Governance Europe Limited has been appointed as our representative in the EU under Article 27 of the GDPR. You can contact our representative at eurep@itgovernance.eu.
12.2 California (CCPA/CPRA)
If you are a California resident, you may have the right to know what Personal Information we collect, use, and disclose; to request deletion or correction; to opt out of the sale or sharing of Personal Information; and not to be discriminated against for exercising these rights. We do not sell or share Personal Information for cross-context behavioral advertising. To make a request, email legal@demopage.io. We will verify your request, and you may use an authorized agent.
12.3 Other U.S. states
Residents of other states with comprehensive privacy laws may have similar rights. Contact legal@demopage.io. If we deny your request, you may appeal by replying to our decision.
13. Children's privacy
The Services are for businesses and are not directed to children under 16. We do not knowingly collect Personal Data from children. If you believe a child has given us Personal Data, contact legal@demopage.io and we will delete it.
14. Third-party websites
Demos show Customers' own websites and products, and the Services may link to other sites. Their privacy practices are their own, so please review their policies.
15. Changes to this Policy
We may update this Policy from time to time. When we do, we will change the date at the top of this page. If a change is material, we will also give notice by email or in the Services. Continuing to use the Services after an update takes effect means you accept the updated Policy.
16. Contact us
Questions about this Policy or our privacy practices: SaaS Labs US, Inc., Attn: Privacy, 355 Bryant Street, #403, San Francisco, CA 94107, United States of America. Email: legal@demopage.io.