Privacy Policy
Effective July 18, 2026
This Privacy Policy explains how Papapyrus (“Papapyrus,” “we,” “us”) collects, uses, and protects your personal information when you use our collaborative skill-library service. By using Papapyrus, you agree to the practices described here.
1.Information we collect
We collect only what we need to run the service:
- Account information. Your name and email address, and — if you sign up with a password — a securely hashed version of that password. We never store your password in plain text.
- Single sign-on data.If you sign in with Google, we receive your Google account identifier, email address, and name from Google's OpenID Connect service. We request only the
openid,email, andprofilescopes. - Organization and content data. The organizations, folders, skills (documents), versions, comments, and access grants you and your teammates create. Skill content is encrypted at rest.
- Billing information. For paid plans we store limited payment-method metadata — card brand, last four digits, expiration month and year, and cardholder name — along with invoices. We do not store full card numbers.
- Activity and audit data. Security-relevant actions (sign-ins, invites, role and access changes, deletions) are recorded in an audit log so administrators can review activity in their organization.
- Technical data. Standard server logs and the cookies described below, used to operate and secure the service.
2.How we use your information
We use the information we collect to:
- Provide, maintain, and secure Papapyrus;
- Authenticate you and keep you signed in;
- Send transactional email — invitations, email verification, sign-in-related messages, and notifications you have opted into;
- Process payments and send billing communications for paid plans;
- Detect, investigate, and prevent abuse, fraud, and security incidents;
- Comply with legal obligations.
We do not sell your personal information, and we do not use it for third-party advertising. Papapyrus contains no advertising or cross-site tracking technology.
3.Cookies
We use a small number of first-party cookies. We do not use advertising or analytics tracking cookies.
- Session cookie (
session) — a strictly necessary, HTTP-only cookie that keeps you signed in. Without it you cannot use your account. - Remembered organizations (
recent_orgs) — a functional, HTTP-only cookie that remembers which organizations you have signed into on this device so the login page can offer them as suggestions. It is stored only on your device and never used to track you across sites.
4.How we share information
Your content is visible to other members of your organization according to the access controls you configure. Beyond that, we share personal information only with service providers who process data on our behalf under contract:
- Google — sign-in (SSO) for accounts that choose it.
- Resend — delivery of transactional email.
- Neon — managed PostgreSQL database hosting.
- Vercel — application hosting and content delivery.
We may also disclose information if required by law, or in connection with a merger, acquisition, or sale of assets — in which case we will notify you before your information becomes subject to a different privacy policy.
5.Data retention
We retain your information for as long as your account and organization are active. When an organization is deleted, its data — including users, folders, skills, versions, comments, invoices, and audit logs — is removed. Note that where a name has been recorded as the author of a comment, document version, or audit entry, that name may be retained on those historical records after the individual account is deleted, so the history remains intelligible. We may retain limited information longer where necessary to comply with legal obligations or resolve disputes.
6.Security
We protect your data with industry-standard measures: passwords are stored only as salted hashes, API tokens are stored only as hashes, skill content is encrypted at rest, and session and functional cookies are HTTP-only and served over HTTPS in production. No method of transmission or storage is perfectly secure, but we work to protect your information and to promptly address any vulnerabilities we discover.
7.Your rights and choices
Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can:
- Update your name, email, and password from your account settings;
- Manage notifications and access grants from within the app;
- Ask your organization administrator, or us, to delete your account.
To exercise any of these rights, contact us at [email protected]. Because Papapyrusis an organization-based product, some requests may need to be routed through your organization administrator, who is the controller of your organization's content.
8.Children's privacy
Papapyrus is a workplace product intended for use by businesses and is not directed to children under 16. We do not knowingly collect personal information from children.
9.International data transfers
We and our service providers may process and store your information in countries other than your own. Where we transfer personal information across borders, we rely on appropriate safeguards as required by applicable law.
10.Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, notify you within the app or by email. Your continued use ofPapapyrus after an update means you accept the revised policy.
11.Contact us
If you have questions about this Privacy Policy or how we handle your information, email us at [email protected].