We take your privacy seriously. Learn how we collect, use, and protect your data.
Last updated: March 26, 2026
We collect information you provide directly to us and information we collect automatically when you use our services:
We use the information we collect for the following purposes:
We implement industry-standard security measures to protect your personal information:
All traffic uses TLS 1.2+; stored data is encrypted at rest by our infrastructure providers (Supabase / AWS).
Strict access controls and authentication for all system access.
Automated daily backups with geographic redundancy.
Continuous monitoring for security threats and anomalies.
We never sell your personal data to third parties.
We may share your information only in the following limited circumstances:
We use the following sub-processors to deliver the service. Each is contractually bound to handle data in line with applicable data protection law.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Authentication, database, file storage | EU / US |
| OpenAI | AI model that generates chatbot responses (zero data retention configured) | US |
| Qdrant | Vector storage for knowledge-base embeddings | EU |
| Lemon Squeezy | Payment processing, merchant of record, tax compliance | US |
| Google (Sign-In) | Optional OAuth login | Global |
We will notify customers in advance before adding or replacing a sub-processor that materially affects how their data is processed.
Your uploaded content, chat transcripts, and customer data are never used to train PaperBrainz machine-learning models or any general-purpose foundation model.
Chat content is sent to OpenAI only to generate the response shown to your visitor. We use OpenAI's API with zero-retention / no-training terms in effect, meaning OpenAI does not retain content beyond what is needed to return the response and does not use it to train their models.
Your knowledge-base content stays in your dedicated workspace and is only used to answer questions for your chatbot.
You have the following rights regarding your personal data:
Request access to your personal data
Update or correct your information
Request deletion of your account and data
Export your data in a portable format
We retain your personal data for as long as your account is active or as needed to provide services. After account deletion, we securely delete personal data within 30 days, except where required by law.
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for international transfers, including compliance with GDPR requirements for transfers outside the EEA.
We may update this Privacy Policy from time to time. We will notify you of any material changes via email or through our service. Continued use of the service after changes constitutes acceptance of the updated policy.
If you have questions about this privacy policy or our data practices, please contact us:
We respond to privacy inquiries within 30 days
We use essential cookies
We use cookies only to keep you signed in and remember your preferences (theme, this dialog). We do not use tracking or advertising cookies. See our Cookie Policy.