Privacy Policy – Papyr
Effective date: 25.06.2026
This Privacy Policy applies to the Papyr iOS app and the related website https://usepapyr.app. It is written for users in the United States and addresses, among others, the California Consumer Privacy Act as amended by the CPRA, and comparable state laws.
1. Who we are
Marcel Rückert
Schillerring 20
65795 Hattersheim am Main, Germany
Email: privacy@usepapyr.app
If you are an EU/EEA/UK user, the GDPR-based notice (German version) applies to you instead.
2. Our approach: on-device by design
Papyr is built to process your information on your device. Scanned documents, the text extracted from them via on-device OCR, and your categories are processed and stored locally. This content only leaves your device if you enable iCloud sync, and then only into your own Apple-encrypted iCloud storage. We never receive or have access to the contents of your documents.
The only information that reaches our service providers is the limited technical usage and diagnostic data described in Sections 3 and 4.
3. Information we process
3.1 On-device data (not collected by us)
Document scans (images/PDF), OCR text, metadata (category, date, tags), and app settings are stored locally on your device. We do not collect, receive, or have access to this content.
3.2 iCloud sync (optional)
If you enable sync, your documents are stored in the private CloudKit database of your own iCloud account. Apple provides and operates this storage under Apple’s privacy terms and encryption. We have no access to it. See Apple’s Privacy Policy at https://www.apple.com/legal/privacy/.
3.3 Analytics and crash reporting (PostHog)
To improve the app and fix bugs, we use PostHog for:
- Crash analytics – crash reports, stack traces, error messages.
- Feature analytics – pseudonymous usage events (which features/screens are used).
Categories collected: a pseudonymous installation/device identifier; app version; OS version; device type; language; approximate region derived from IP (the IP itself is not stored long-term); event/interaction data (e.g., “scan started,” “category changed”); crash data.
Not collected: your document contents, OCR text, images, or file names.
PostHog data is hosted in the European Union (Frankfurt, Germany). Analytics is opt-in; you can enable or disable it in the app settings at any time, and the app remains fully usable either way.
3.4 Website
- Server logs: the website is hosted and served via Cloudflare Pages (Cloudflare, Inc., USA), which processes IP address, timestamp, requested resource, referrer, and user agent for delivery and security. This involves a transfer to the United States, safeguarded by Standard Contractual Clauses and Cloudflare’s certification under the EU-U.S. Data Privacy Framework.
- PostHog (cookieless): the website uses PostHog in a cookie-free configuration (memory-only). No cookies are set and no information is stored on or read from your device. We process pseudonymous event data (pages viewed, approximate region, browser/device type) without storing your full IP long-term. PostHog data is hosted in the EU.
4. How we use information
We use the limited data above to operate, secure, maintain, and improve Papyr and the website, diagnose crashes, understand feature usage in aggregate, and comply with legal obligations.
5. Disclosure of information; no sale or sharing
We disclose limited data only to service providers who process it on our behalf under contract and only for the purposes above:
- PostHog – analytics and crash reporting (hosted in the EU).
- Apple – iCloud storage (only if you enable sync).
- Cloudflare, Inc. – website hosting and delivery (United States; safeguarded by Standard Contractual Clauses and the EU-U.S. Data Privacy Framework).
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CPRA. Our analytics provider acts as a service provider/processor and is contractually prohibited from using your data for its own purposes.
6. Data retention
On-device and iCloud data persist until you delete them or uninstall the app. Analytics/diagnostic data is retained for 12 months, then deleted or anonymized. Server logs are kept for up to 30 days.
7. Your California privacy rights (CCPA/CPRA)
California residents have the right to:
- Know/Access the categories and specific pieces of personal information collected.
- Delete personal information we hold about you.
- Correct inaccurate personal information.
- Opt out of sale/sharing — note: we do not sell or share, but you may still submit a request.
- Limit the use of sensitive personal information — we do not use sensitive personal information for purposes requiring a limitation right; document contents stay on your device and are not collected by us.
- Non-discrimination for exercising your rights.
Categories collected (last 12 months): identifiers (pseudonymous IDs, IP); internet/electronic activity (usage and crash data); coarse geolocation (region from IP). We do not collect government IDs, financial account numbers, biometric identifiers, or document contents on our servers.
How to exercise: email privacy@usepapyr.app. We will verify your request as required by law. You may use an authorized agent.
Global Privacy Control (GPC): we honor the GPC browser signal as a valid opt-out of sale/sharing.
8. Other U.S. state rights
Residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others) have comparable rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, sale, and certain profiling. To exercise these rights, contact privacy@usepapyr.app.
9. Children’s privacy
Papyr is not directed to children under 13, and we do not knowingly collect personal information from children under 13 (COPPA). We do not knowingly sell or share the personal information of consumers under 16 (CCPA). If you believe a child has provided information, contact us and we will delete it.
10. Data location and international transfers
Analytics data is hosted in the European Union. Website hosting and server logs are processed by Cloudflare in the United States, safeguarded by Standard Contractual Clauses and the EU-U.S. Data Privacy Framework. iCloud data is stored within Apple’s infrastructure under Apple’s terms.
11. Security
We use technical and organizational measures appropriate to the limited data we process, including encryption in transit and minimization (no document content leaves your device to us). No method of transmission or storage is completely secure.
12. Changes and contact
We may update this Policy. The current version governs and is dated above. Questions or requests: privacy@usepapyr.app.