Security

You are about to let a chatbot speak to your customers using your own content. Here is exactly how that content is handled — including the things we cannot yet promise.

Where your data lives

Your account, widget settings and conversation history are stored in Supabase, a managed PostgreSQL platform. The content you upload for training is processed into vector embeddings and stored in Qdrant, a vector database.

Traffic between your browser, your website widget and our servers is served over HTTPS.

What the chatbot is allowed to answer from

Your chatbot answers from the sources you add: uploaded files, pasted text, manual question-and-answer pairs, and pages scraped from a website URL you provide. It is not trained on other customers' content, and one customer's chatbot cannot read another's sources.

When the chatbot cannot find relevant information in your sources, it says so rather than inventing an answer, and can point the visitor to your support contact. You can edit that fallback message. We do not claim the model is incapable of error — no honest provider can.

Accounts and access

Passwords are hashed with bcrypt before storage. We never store them in a form we can read, which also means we cannot tell you your password — only help you reset it.

Dashboard requests are authenticated with short-lived access tokens. You can see your active sessions and revoke any of them from your dashboard, which signs that device out.

The API sits behind rate limiting and standard HTTP security headers, including a content security policy.

Payments

Billing is handled by Lemon Squeezy, acting as merchant of record. Card details are entered on their checkout and never reach PaperBrainz servers — we store only the resulting subscription status, plan and billing period.

Deleting your data

You can delete any knowledge source from your dashboard at any time. Deleting a source removes it from the chatbot's available knowledge.

Account closure is not yet self-service. Email support@paperbrainz.com from your account address and we will delete your account and its associated data.

Subprocessors

We rely on a small number of third-party providers to run the service. If you need a current list for a vendor review, email support@paperbrainz.com and we will provide it in writing.

Reporting a security problem

If you believe you have found a vulnerability, email support@paperbrainz.com with the subject line "Security". Please include enough detail to reproduce the issue. We will confirm receipt and keep you updated while we investigate, and we will not pursue action against good-faith research that avoids privacy violations, data destruction and service disruption.

What we do not claim

PaperBrainz is a small product and we would rather be straight with you than impressive. We do not hold SOC 2, ISO 27001 or HIPAA certification, and we do not offer a contractual uptime guarantee. If your organisation requires any of those, we are probably not the right fit yet — and we would rather tell you now than after you have paid.

See also our Privacy Policy, Terms of Service and Refund Policy. Questions about any of this? Email support@paperbrainz.com.