PaperPaper
FeaturesReviewsHelpAbout
Log inGet Paper free

Privacy Policy

Last updated: July 2026

1. Information We Collect

We collect the following types of information:

  • Account information: Name, email address, and profile photo when you create an account
  • Content: Pages, documents, video files, audio recordings, and other materials you create or upload
  • Usage data: How you interact with the Service, including pages visited and features used
  • Device information: Browser type, operating system, and IP address

2. How We Use Your Information

We use collected information to:

  • Provide, maintain, and improve the Service
  • Send you notifications related to your account and workspace activity
  • Analyze usage patterns to improve user experience
  • Ensure the security and integrity of the Service

3. Data Storage and Security

Your data is stored securely using industry-standard encryption. Access is enforced per-user at the database level, so other users can't reach your content. Sensitive integration tokens are encrypted at rest. We implement appropriate technical and organizational measures to protect your data.

4. Where Your Data Is Stored

Your account data, content, and uploaded files are stored in Australia, in Amazon Web Services' Sydney region (ap-southeast-2), via our database and storage provider Supabase. Our application servers also run in Sydney.

Some of the third-party services listed below process data in other regions. In particular, our product analytics provider (PostHog) processes data in the United States, and certain AI providers may process requests on infrastructure located outside Australia. Where data is transferred internationally, it is handled under the relevant provider's data protection terms.

5. Data Retention and Deletion

We retain your content for as long as your account is active or as needed to provide the Service. When you delete content, the related data is removed along with it:

  • Deleting a source, document, or chat removes its associated data, including the search index (embeddings) generated from it.
  • Deleted dashboards are moved to trash and permanently purged after 30 days.
  • You can request deletion of your account and all associated data at any time by contacting us.

6. AI and Model Training

Paper uses third-party AI providers (OpenAI, xAI, and Google) to power features such as chat, search, transcription, and document processing. When you use these features, the relevant content is sent to the applicable provider to generate a response.

We do not use your content to train our own models, and we do not permit our AI providers to use your content to train theirs. Under these providers' standard API terms, request data may be retained by the provider for a limited period (typically up to 30 days) for abuse monitoring and then deleted.

7. Chrome Extension

The Paper Video Import Chrome extension detects videos on web pages you visit and allows you to import them into Paper for transcription and study. The extension:

  • Only activates when you click the extension icon - it does not run automatically in the background
  • Detects video elements on the current page to show you available videos for import
  • Downloads video content using your existing authenticated session on the page
  • Uploads imported videos to your Paper account for transcription
  • Does not collect, store, or transmit your browsing history, passwords, or personal data
  • Does not track which pages you visit or inject ads

The extension requires permissions to access web pages (activeTab, scripting) to detect videos, and network request monitoring (webRequest) to identify video stream URLs on supported platforms like Echo360. These permissions are used solely for video detection and import functionality.

8. Third-Party Services

We use the following third-party services that may process your data:

  • Supabase: Database, authentication, and file storage
  • OpenAI: Audio transcription and an optional chat model
  • xAI: Chat model and internal retrieval steps
  • Google: OAuth authentication, calendar integration (optional), and an optional chat model (Gemini)
  • Microsoft: Outlook calendar integration (optional)
  • LiveKit: Real-time audio and video for live sessions
  • PostHog: Product analytics and feature flags
  • Stripe: Payment processing
  • Resend: Transactional email delivery

When you import a video, the audio is transcribed via OpenAI's API - you don't need an API key; Paper handles it. Transcription data is stored in your Paper account and is not shared with other users unless you explicitly share the dashboard.

9. Data Sharing

We do not sell your personal information. We share data only as necessary to provide the Service, comply with legal obligations, or protect our rights. Content you create within a workspace is visible to other members of that workspace.

10. Your Rights

You have the right to:

  • Access and download your data
  • Correct inaccurate information
  • Request deletion of your account and data
  • Opt out of non-essential communications

11. Cookies

We use essential cookies for authentication and session management. We also use cookies set by our product analytics provider (PostHog) to understand how the Service is used and to improve it. We do not use advertising or cross-site tracking cookies.

12. Children's Privacy

The Service is designed for use by educational institutions and their students. If you are under 13, you should only use the Service under the supervision of your school or parent.

13. Changes to This Policy

We may update this policy from time to time. We will notify you of significant changes via email or through the Service.

14. Contact

For privacy-related questions, contact us at hello@paper.ac.

Paper

A study workspace for students and professionals who work with large documents, lectures, and research.

Product

vs Notionvs NotebookLMRoadmapChangelogFeature requests

Resources

Help centerHow it worksSecurityFAQ

Company

AboutContact

Legal

PrivacyTerms

Made in Sydney, Australia 🇦🇺 · © 2026 Paper