Privacy Policy

Last updated: July 29, 2026

Introduction

Papera is an AI-assisted content studio: you create and refine content, render it into formats such as slides and social posts, and — when you choose to — publish it and connect social accounts. This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and the rights you have over it. It applies to the Papera web application, its marketing site, and related services (together, the "Service").

Please read this policy alongside our Terms of Service. By using the Service you agree to the practices described here.

Who we are

The Service is operated by Uladzimir Karaleu, a natural person conducting individual activity in the Republic of Lithuania under Individual Activity Certificate No. 1504522 (taxpayer identification number 37105012024) ("we", "us", "our"). For the purposes of applicable data protection law (including the EU/UK GDPR), we are the data controller of the personal data described in this policy. If you have questions or wish to exercise your rights, contact us at papera.dev@proton.me.

Information we collect

We collect information in three ways: information you provide directly, information collected automatically as you use the Service, and information we receive from third parties you connect.

Information you provide

  • Account information — when you create an account we store your name, email address, and (if you sign in with Google) your profile image. Accounts are created via Google sign-in or a passwordless magic-link email.
  • Content you create — the content units, slides, themes, media, and other assets you create, upload, generate, or publish, and the posts you draft, schedule, or publish to connected accounts.
  • Billing information — your plan, subscription status, and billing history. When you subscribe to a paid plan, checkout and payment are handled by our payment processor (Stripe), which collects your billing email, billing address, tax identifiers where required, and your card or bank-account details directly. We do not receive or store full card or bank numbers — only a tokenised customer reference and the subscription details we need to run your plan (customer and subscription identifiers, price/plan, subscription status, and current billing-period end).
  • Support and communications — the contents of any messages you send us (for example, support or feedback emails).

Information collected automatically

  • Session & authentication data — to keep you signed in and to secure your account, we record session tokens and sign-in events (including sign-in timestamps) together with the IP address and browser user-agent associated with each session, and security-relevant events such as new sign-ins.
  • Device & connection data — IP address, browser type and version, operating system, device identifiers, referrer URL, language preference, and the approximate location (country/region) we derive from your IP address.
  • Error & crash reports — PostHog is loaded for every visitor to report unhandled errors in your browser: the error message and type, the stack trace, the page it happened on, and basic device, browser, and operating-system information. This does not depend on analytics consent — we rely on our legitimate interest in keeping the Service working — and without that consent PostHog stores no cookie or other identifier on your device, so the reports are not linked to you or to your other visits.
  • Usage & telemetry — once you accept analytics, PostHog additionally collects page views and routes visited, referrer information, device type, browser and operating system, and approximate country, and links them to a stored device identifier. Independently of analytics consent, our servers keep operational logs of feature and API usage, publishing outcomes (posts created, published, or failed), and error, crash, and performance data needed to run and debug the Service.
  • Interactions with the interface — once you accept analytics, PostHog also records interactions automatically: clicks, form submissions, dropdown selections, and repeated frustrated clicking on the same spot (a "rage click"). For each one it stores what you interacted with rather than what you wrote — the element's type, its styling classes and identifiers, its visible label, and any link it points to. It does not record what you type into text fields, nor the content you write, generate, or paste in the editor.

Information from connected services

  • Google account — if you sign in with Google, we receive your name, email address, and profile picture from Google.
  • Connected social accounts — when you connect a social platform (for example, Bluesky) to publish, we store the OAuth access and refresh tokens the platform issues us and the scopes you granted, along with the account's username or handle and its platform identifier, its display name and profile picture, and the account-level metadata the platform exposes (such as follower or audience counts and, on platforms that use them, page or channel identifiers). These tokens are held server-side, are never exposed to your browser, and are released when you disconnect the account.
  • Content & engagement data — to power your Analytics pages, we fetch and cache the post-level and audience metrics the platform exposes for your account and the posts you publish through us — such as impressions and reach, likes, reposts, and replies, and the engagement rates derived from them.

How we use your information

We use personal data to:

  • Provide, operate, and maintain the Service, including your account and projects;
  • Authenticate you and keep your account and sessions secure;
  • Generate content on your behalf when you use AI features, and publish content and posts to the social accounts you connect;
  • Run scheduled publishing you arm, which executes on our servers even when your device is offline;
  • Bill and collect payment — manage your subscription, issue invoices and receipts, prevent payment fraud, and comply with tax and accounting law;
  • Send you service-related emails, such as magic-link sign-in links, receipts, post-failure notices and scheduled-post confirmations, and other important notices; and, where you have opted in, product and marketing emails you can unsubscribe from at any time;
  • Understand how the Service is used and improve its performance and reliability;
  • Detect, prevent, and address security incidents, fraud, and abuse;
  • Comply with legal obligations and enforce our Terms of Service.

Legal bases for processing

Where the GDPR or similar laws apply, we rely on the following legal bases: performance of our contract with you (to provide the Service and the features you request); legitimate interests (to secure, maintain, and improve the Service); your consent (for optional analytics and, where required, marketing); and compliance with legal obligations. You may withdraw consent at any time where processing is based on consent.

AI processing of your content

When you invoke an AI feature, the content and prompts involved are sent to our server-side AI providers (currently OpenAI and/or Anthropic, depending on configuration) and, for research, to a web-search provider (Tavily) to gather source material. We do not use your content to train our own models. Our AI providers process the content under their own terms and, per their policies, do not train their foundation models on data submitted through their APIs. AI features run only when you invoke them; if you never use them, your content is never sent to these providers.

AI outputs are generated probabilistically and may be inaccurate, incomplete, or unsuitable for your purpose. You remain responsible for reviewing them before you rely on or publish them.

How we share your information

We do not sell your personal data. We share it only with the service providers ("subprocessors") that help us operate the Service, and only as needed for the purposes below. Each processes data on our behalf under contractual confidentiality and security obligations.

  • Google (Sign in with Google) Authentication when you choose to sign in with a Google account.
  • Resend Sending email — transactional and magic-link sign-in messages, and, where you have opted in, product and marketing emails.
  • Stripe Payment processing and subscription billing as merchant of record — Stripe collects and stores your card or bank details directly and handles tax; we only receive a tokenised customer reference and your subscription status.
  • OpenAI Server-side AI generation (research, outlining, drafting) when you use AI features.
  • Anthropic Server-side AI generation, used interchangeably with OpenAI depending on configuration.
  • Tavily Web search used by the AI research step to gather source material for your topic.
  • Amazon Web Services (S3) Object storage for media and assets attached to content you publish.
  • PostHog (EU) Error tracking — crash and error reports from your browser, collected for everyone so we can keep the Service working — and, only if you accept analytics, product analytics such as page views, interface interactions, and basic device/browser information; both are processed in the EU (Frankfurt).

When you publish a post to a connected platform, the post's content and media are sent to that platform and become subject to its own terms and privacy policy. We may also disclose information where required by law, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets (in which case we will notify you).

Cookies, local storage, and tracking

We use cookies and browser storage (localStorage) that fall into the following categories. You can manage non-essential categories through the in-page consent banner or your browser settings; disabling strictly-necessary storage will break parts of the Service.

  • Strictly necessary — required to run the Service, most importantly a session cookie that keeps you signed in after you authenticate, and local storage we use to hold your session and preferences. These cannot be switched off without breaking core functionality.
  • Analytics — set only after you accept analytics. PostHog sets a cookie holding a random device identifier so we can recognise returning visits and measure retention. It is not used for cross-site tracking and never for advertising. Until you accept, PostHog runs entirely in memory: its error reporting sets no cookie and writes nothing to browser storage. If you withdraw consent later, analytics collection stops and the stored identifier is deleted from your browser — see your rights below.
  • Functional and marketing — we do not currently set functional or marketing cookies, pixels, or advertising SDKs. If we introduce any, we will add them to the consent banner and update this policy first.

Data retention

We keep personal data only as long as needed for the purposes described here. Account data is retained for as long as your account is active and then deleted within 30 days after you close it. Published projects and posts are retained until you unpublish or delete the project, after which they are removed within 30 days. Session and log data are rotated on a rolling basis. Social-account tokens are deleted when you disconnect the account or close your account. Billing and transaction records are retained for as long as legally required — invoices and transaction records are kept for the period tax and accounting law demands, typically several years, even after you close your account. When you delete your account, we delete or anonymize the associated personal data, except where we must retain it to comply with a legal obligation or resolve disputes.

International data transfers

We and our subprocessors may process your data in countries other than your own, including the United States. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. Usage analytics are an exception: they are processed by PostHog in its EU region and stay in the EU. Details of the safeguards we use are available on request at papera.dev@proton.me.

Security

We take reasonable technical and organizational measures to protect your data. API keys and platform credentials are held server-side and never exposed to your browser; social authorization tokens are scoped to the minimum permissions publishing needs. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.

Your rights

Depending on where you live (for example, under the GDPR or the CCPA), you may have the right to:

  • Access — request a copy of the personal data we hold about you;
  • Rectify — correct inaccurate or incomplete data;
  • Delete — request deletion of your account and associated data;
  • Port — receive your data in a portable format;
  • Object or restrict — object to or restrict certain processing;
  • Withdraw consent — including opting out of analytics at any time.

You can here at any time(currently: declined). To exercise any other right, contact us at papera.dev@proton.me. You also have the right to lodge a complaint with your local data protection authority.

Children's privacy

The Service is not directed to children under 18, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.

Changes to this policy

We may update this policy from time to time. When we make material changes we will update the "Last updated" date above and, where appropriate, notify you. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.

Contact

For any privacy question or to exercise your rights, reach us at papera.dev@proton.me. The Service is governed by the laws of the Republic of Lithuania.