Loading
Loading
Compliance & security
PaperLens is built on a simple principle: your documents are none of our business beyond what you explicitly ask us to analyse. This policy explains exactly what we collect, why, and what rights you have over it.
When you create an account we collect your email address and a hashed version of your password. We do not store plaintext passwords.
A display name or phone number added to your profile is optional and can be removed at any time from your settings.
Documents are transmitted to our servers over an encrypted connection. On the Free plan they are processed in memory and never written to storage. If you save a document on a paid plan, it is stored in an encrypted, access-controlled bucket tied to your account.
We do not use your documents for any purpose other than producing the analysis you asked for. We do not sell them, share them, or use them to train models.
The structured output — risk level, summary, action type, deadline, key entities — is stored against your account only when you save the document. It is encrypted at rest.
We collect the minimum technical data needed to operate the service securely: authentication tokens, session cookies, and server-side error logs. We do not place advertising pixels, fingerprint your device, or track you across other websites.
Traffic between your device and our servers uses TLS 1.3. Stored data — analysis results and saved documents alike — is encrypted at rest with AES-256.
Your data is isolated from other accounts by row-level security enforced in the database itself, not only in application code. Only your authenticated session can read your documents.
PaperLens uses third-party services to perform analysis and to store your account. When you submit a document, a copy of it or of its extracted text is sent to the model provider below.
Depending on where you live, you have the rights below. To exercise any of them, write to privacy@paperlens.co.
You can delete your account and everything associated with it from your settings. Deletion is processed within 48 hours, during which you may cancel the request. After that, the data is permanently deleted and residual backup copies are purged within 30 days.
We act as a Data Fiduciary. Indian users have the right to request information, access, correction, erasure and grievance redressal under the DPDP Act 2023.
For privacy questions or to report a concern, write to privacy@paperlens.co.