Data Paper uses
- Account: email address, verification status and sign-in sessions.
- Content: notebooks, pages, strokes, page settings and images you upload.
- Subscription: Stripe identifiers and Pro entitlement status. Paper does not receive your full card details.
Services that make Paper work
Vercel hosts the app and stores private images with Blob; Neon stores accounts and notebooks; Resend delivers sign-in codes; Stripe handles payments and subscriptions.
Essential analytics
Vercel Web Analytics receives page views with sanitised URLs only: no queries, emails, notebook names, content, images, or real notebook and page identifiers. Paper does not use session replay or advertising events.
Cookies, installation and offline use
Paper uses essential cookies for your session and language. The PWA stores only the public shell, fonts, icons and static files; sign-in, account, admin, API and notebook routes always use the network and are never added to the offline cache.
Retention and controls
Sign-in codes are valid for 10 minutes and one use; sessions expire after 30 days or when you sign out. Accounts and content remain until you delete them. Notebooks in the trash are permanently deleted after 30 days.
From Notebooks you can export your Paper data as JSON and permanently delete your account, notebooks and images. If a Stripe customer is linked, Paper deletes it before the local account, ending its subscriptions. Stripe may retain its own records under its privacy policy.
Last updated: 10 August 2026.