LGPD · Brazilian Law 13,709/2018
Privacy Policy
- Your notes are yours. Personal notes stay in your browser and, if you connect it, in your Google Drive. The Paper server never receives their text.
- Groups are end-to-end encrypted. What you write in a group leaves your device already scrambled; the server stores and relays it, but can't read it.
- Friends and groups are optional. For them, the server keeps a 32-character ID of yours, the name you choose, and who your friends and groups are.
- To sign in, we use your Google account. The server keeps only a scrambled code of your account and when each session was used.
- Statistics are optional and start turned off. If you allow them, we count visits and device types without knowing who you are.
- We don't sell data, don't use ads and don't build profiles of anyone.
Who is responsible
Paper is a project run by an individual, who is the controller of the data described here and also acts as the data protection officer (LGPD art. 41).
- Responsible: Israel de Jesus Silva
- Contact for privacy and to exercise your rights: contato.brennoleon@gmail.com
Your notes
The text, titles, tasks, dates and files you import are kept:
- in your browser (the device's local storage), so you can write even without internet;
- in your Google Drive, in a folder called Paper, if you connect Drive. Uploads go straight from your browser to Google.
This applies to each vault (separate notebooks you can create) and to attachments (images, PDFs and other files), which stay in the browser and, with Drive connected, in an Anexos subfolder. The browser also keeps older versions of pages (history) for up to 90 days.
The Paper server doesn't receive, store or have any way to read this content. That's why we don't treat your personal notes as our personal data: you keep them, on your device and in your Google account. Group notes are explained in Friends and groups.
Password pages
You can lock any page with a password. The content is encrypted on your device (AES-256, with a key derived from the password by PBKDF2 with 600 thousand rounds and a random salt per page). The password never leaves the device and isn't stored anywhere. In the browser, in Drive and in exported files only the scrambled text exists. If you forget the password, nobody can open the page, not even us. Locked pages don't go into the version history.
Account and sign-in
To enter the app, you use the “Continue with Google” button. Google sends us your name, email, photo and an account identifier.
| Data | Where it is | What for | Legal basis |
|---|---|---|---|
| Name, email and photo | Only in the session cookie, in your browser. The server reads the cookie on each request but doesn't store this data. | Showing who is signed in | Performance of contract (art. 7, V) |
| Google account identifier, scrambled with a secret key (hash) | Paper server | Knowing which sessions are yours, so you can sign out everywhere or delete the account | Performance of contract (art. 7, V) |
| Chosen language (Portuguese, English or Spanish) | Paper server | Opening the app in your language on every device and answering messages in it | Performance of contract (art. 7, V) |
| Sessions: creation date, last use and device type (e.g. “computer · Windows · Chrome”) | Paper server | Keeping you signed in safely and showing your connected devices | Performance of contract (art. 7, V) and legitimate interest in security (art. 7, IX) |
Friends, groups and editing together
Friends and groups are optional and can be hidden in Settings → Teams and groups. When off, the app doesn't even connect to the server for them. There's no chat. Nobody finds you by search: only with your ID or with an invite link you created yourself.
| Data | Where it is | Who sees it | Legal basis |
|---|---|---|---|
| 32-character ID (random), the display name you choose and a color | Paper server | Your friends, people in the same groups and anyone with your ID (only if you accept requests by ID) | Performance of contract (art. 7, V) |
| Who can add you (by ID, link only or nobody) and whether you appear online | Paper server | Only you | Performance of contract |
| Friendships, friend requests and blocked people | Paper server | You and the other person (blocks, only you) | Performance of contract |
| Invite links: who created them, what for, deadline, limit and how many times they were used | Paper server | Whoever created them and whoever manages the group | Performance of contract |
| Groups: name, color, who takes part, each person's role and who added them | Paper server | Group members | Performance of contract |
| Public encryption key and its short code | Paper server | Members of your groups (to release the group key to you) | Performance of contract |
| Group content (pages and attachments), end-to-end encrypted | Paper server, without the key | Only members, on their devices. The server sees only the size, time and sender of each package | Performance of contract |
| Presence: whether you're online and, in a group, which page and block you're on | Only in the server's memory while the app is open. Never recorded | Friends (online, if you allow it) and group members (page and block) | Legitimate interest in making editing together work (art. 7, IX) |
How group encryption works
Each account gets a key pair. The public key goes to the server; the private key stays in your browser and in a copy in your Google Drive (the file “Paper · chave dos grupos”), so you can open groups on another device. Each group has its own key, delivered to each member wrapped with that member's public key. When someone leaves or is removed, the group key is changed. Anyone with access to your Google Drive could read that copy: protect your Google account.
Anonymous statistics (optional)
Statistics start turned off. They only work if you click “Allow statistics” in the site notice or turn them on in Settings → Privacy. You can turn them off anytime, and when you do we delete what had already been counted from your device.
What they're for
To know how many people use Paper, on what kind of device, how they reached the site and which features are used most. This guides what to improve and helps the site be found in search. They're never used to know who you are, what you do outside Paper or what you write.
What we count
- A random device identifier, created in your browser when you allow it. It's just a random number: it doesn't come from your hardware, isn't linked to your account and disappears if you clear the site's data or turn statistics off. It's what lets us count “unique devices” without identifying anyone.
- Site pages and app screens opened, without ids or titles (for example “/app/p/:id”, never the page name).
- Names of features used, like “import” or “export:pdf”.
- The site you came from (domain only) and campaign parameters (utm), if any.
- Device type, system and browser, worked out on the server. The full text the browser sends is discarded right away.
- Screen size range (e.g. “laptop”), language and time zone.
What we don't count
- Content, titles or names of notes.
- Name, email, photo or anything from your account.
- IP address (not stored with the statistics).
- Browser fingerprint (fonts, graphics card, canvas and the like).
Legal basis: consent (art. 7, I and art. 8). We keep your choice (allowed or declined), with the date and the version of this policy, to be able to demonstrate consent.
Technical server logs
Like any site, the server logs requests for security and to fix problems: date, requested address, response and browser. The IP address is stored with its last part erased (e.g. 179.199.143.0). These logs are deleted automatically after 14 days. Legal basis: legitimate interest in keeping the service secure (art. 7, IX).
Language and region
Paper speaks Portuguese, English and Spanish. To choose the language and how to show dates, times and numbers, we use, in this order: the language you chose (stored in your account and in the paper-lang cookie), the languages set in your browser and the country you're accessing from.
The country comes from the IP address, looked up on the spot in a database that lives on our own server (IP Geolocation by DB-IP, CC BY 4.0 license). For this, the IP isn't stored or sent to anyone. The result, just the country code, stays in your browser so the app doesn't ask again. Legal basis: legitimate interest in showing the service in your language (art. 7, IX).
In other languages, you can use your browser's automatic translation, which follows the policy of whoever made the browser. Paper marks your notes so the translator leaves them out.
Google Drive and Google Calendar
You connect Google once per device. Google hands over a permanent permission (a “refresh key”). The Paper server seals it with encryption and returns it to your browser, which keeps the sealed package. Every hour, the app sends the package, the server asks Google for fresh access and returns it to the browser, without storing anything. The access itself lives only in the tab's memory. That's how sync keeps going on its own, without asking for a click. Disconnecting (Settings → Integrations) revokes the permission at Google.
The only exception is developer mode: with it on, you authorize the server to keep the sealed package so the API can act on your Drive when one of your tokens is used.
- Drive (
drive.file): Paper only sees the files it created itself in the Paper folder. - Calendar (
calendar.app.created): Paper only touches the “Paper” calendar it created. Your other calendars stay out of reach.
The use of this information follows the Google API Services User Data Policy, including the Limited Use requirements.
Pages published by link
When you publish a page, the server keeps a copy in plain text of that page only (title, text and structure, without attachments), to show it to whoever has the link, as a page, plain text (.md) or JSON. We count visits without knowing who visited. With “keep it updated”, the app sends the page again when you change it. Taking it down deletes the copy right away; links with a deadline are deleted when they expire. Legal basis: performance of contract (art. 7, V), at your choice. Password-protected pages can't be published.
Developer mode and API
Optional and off by default. When you turn it on (Settings → Developer), you accept the API Terms and can create access tokens. We keep:
- Tokens: name, permissions, dates and how many times they were used. Of the token itself, only a scrambled code (hash); not even we can see the token after it's created.
- Daily use of each token (number of requests and uploads), for 90 days, to apply the limits.
- The sealed Google connection, if you allow it, so regular tokens can read and write in your Drive. The server only uses this connection when one of your tokens makes a request. At that moment, the text of the pages the token asks for passes through the server, without being stored.
- Copies for AI (secure tokens): a plain text copy of the pages of the vault you choose (without the protected ones), kept until you revoke the token. That's where the AI works; your vault only changes if you approve.
Turning developer mode off revokes all tokens and deletes the copies and the stored connection. No token opens password-protected pages or reads groups.
Support, appeals and moderation
Support messages and appeals keep the contact you leave, the text and the account ID (if you're signed in or provide it), for up to 1 year after they're resolved. To enforce the Terms, we may ban accounts: the server keeps the date and the reason. A ban cuts off access to Paper, but doesn't delete the notes on your device and in your Drive. Legal basis: performance of contract and legitimate interest in keeping the service secure (art. 7, V and IX).
Who we share with
- Google, for sign-in, Drive and Calendar, when you use those features. The data lives on Google's servers, including outside Brazil, under Google's policy (international transfer under art. 33).
- The hosting provider of the server (VPS), which physically stores the database described above.
- Other Paper users, only what you choose to show: your display name to friends and members of your groups, and what you write in a group to its members.
We don't sell, rent or hand over data to anyone. We only give data to authorities when there's a legal obligation or a court order.
How long we keep it
| Data | Period |
|---|---|
| Login session | Up to 30 days, or 14 days without use. Signing out ends it right away. |
| Anonymous statistics | 13 months, or until you turn statistics off |
| Record of your choice about statistics | 5 years, to demonstrate consent |
| Technical server logs | 14 days |
| Profile, language, friendships, blocks and public key | Until you delete the account |
| Unanswered friend requests | 90 days |
| Invite links | Up to 30 days after they expire or are canceled |
| Encrypted group content | While the group exists. Deleting the group deletes everything in it |
| Online presence | Not stored |
| Pages published by link | Until you take them down or the link's deadline expires |
| Tokens, stored Google connection and copies for AI | Until you revoke the token or turn developer mode off |
| Daily token usage | 90 days |
| Support and appeals | Up to 1 year after they're resolved |
| Your notes | They stay with you: in the browser until you delete them, and in your Drive until you delete the folder |
Your rights (art. 18)
You can, at any time:
- know and access what we keep: Settings → Account and security → Download my data;
- correct your display name: Settings → Profile;
- take your notes to another service (portability): Settings → Import and export;
- withdraw consent for statistics: Settings → Account and security, or the “Cookie preferences” link at the bottom of the site;
- delete your account: Settings → Account and security → Delete account. Profile, friendships, invites and keys leave the server. Groups you created pass to another member (or are deleted, if you were alone). What you wrote in groups stays with the group, without your name;
- ask for correction, information about sharing or a review of any processing, through the contact above;
- complain to the ANPD, Brazil's National Data Protection Authority (gov.br/anpd).
We answer requests within 15 days.
Security
- Connection always encrypted (HTTPS with HSTS).
- Session cookie protected from being read by scripts (httpOnly, Secure, SameSite).
- Content security policy (CSP) and rate limits on the server.
- End-to-end encrypted groups and password pages encrypted on the device, with the browser's standard algorithms (Web Crypto), no home-made cryptography.
- The server keeps as little as possible: if it were breached, there would be no personal notes or emails to take, and group content would be scrambled.
Children and teenagers
Paper isn't aimed at children under 12. Teenagers should use it with the knowledge of their parents or guardians.
Changes to this policy
When we change something important, the date at the top changes and the cookie notice shows up again so you can choose again. Wire Cloud, paid storage still to be launched, will have its rules described here before it opens.