Paper documentation
User guide

Privacy and security

Where notes are kept, what the server sees and how to lock a page.

Where each thing is kept

WhatWhereDoes the Paper server read it?
Personal notesOn the device and in your Google DriveNo
Password-protected pagesEncrypted, on the device and in DriveNo, not even with the wrong password
GroupsEncrypted on the serverNo, it only relays them
Published linksOn the server, in plain textYes, to show them to whoever opens the link
Copies for AI (secure token)On the server, in plain textYes, while the copy exists
Account, language, friendships, sessionsOn the serverYes

Protected pages

The lock at the top of a page locks the content with a password of yours. The page is encrypted on the device with a key derived from the password and a random salt, so:

  • Not even Paper can open it without the password. Keep it safe: there's no recovery.
  • No access token opens protected pages. The API answers 423.
  • Protected pages can't be published by link.

Access tokens

A token only does what you checked when creating it: which vaults, read or edit, calendar and attachments. You revoke it in Settings → Developer, and it stops right away. Details in Tokens.

Sessions

In Settings → Account and security you see the connected devices and end the ones you don't recognize.

Automatic translation

If you use your browser's automatic translation (for languages Paper doesn't speak natively), Paper marks your notes and page titles so the translator leaves them out. Only the app's buttons and menus get translated.

More

On this page