Last updated: August 31, 2026
This Privacy Policy describes how SecurePaper, operator of the website securepaper.app and the application at app.securepaper.app (together, the "Service"), collects, processes, and uses your data. Privacy is the core of our product, so this policy is written to be read: it says exactly what we store, what we never see, and how to get your data deleted.
The text you encrypt with SecurePaper is processed exclusively on your device, in your browser, using the browser's built-in cryptography. The plaintext you type and the decrypted content you read are never sent to our servers, never logged, and never stored by us in any form. The encrypted output exists where you put it: on your screen, in files you download, and on the paper you print.
Creating an account is optional. If you do create one, we store the following in our database, which is hosted on Supabase and protected by row-level security tied to your login:
We do not sell your personal data, and we do not share it with third parties except for the infrastructure providers necessary to operate the Service (hosting and database), or where the law requires disclosure.
If you use SecurePaper without an account, your encryption keys are stored only in your browser's localStorage on your device. They are not transmitted to us. Clearing your browser data will delete them, so we recommend exporting or printing key backups — the app provides both options.
We use Vercel Analytics and Vercel Speed Insights to understand aggregate site usage and performance. This analytics is cookieless and anonymous: it does not use cookies, does not build cross-site profiles, and does not identify individual visitors. It is loaded only after you give consent for analytics through the cookie consent banner; if you reject analytics, it does not run. You can change your choice at any time via the "Do Not Share My Personal Information" link in the footer. We do not use Google Analytics or any advertising or remarketing trackers.
The marketing site itself sets no tracking cookies. We use browser localStorage for essential functionality: remembering your cookie consent choice and, for guest users of the app, storing your encryption keys locally. The app uses essential session storage to keep you logged in when you have an account. None of this is used for tracking.
Like virtually all web services, our hosting infrastructure keeps standard, short-lived technical logs (such as request timestamps, requested URLs, and truncated technical metadata) for security, abuse prevention, and debugging. These logs are not used to profile users and never contain message content.
Account data is retained for as long as your account exists. You can delete individual keys and document records from within the app at any time. To delete your account and all associated data, or to request a copy of the data we hold about you, email support@securepaper.app from the address associated with your account. We will process deletion requests within 30 days.
You have the right to access, correct, export, and delete your personal data, and to withdraw any consent you have given (such as analytics consent) at any time with effect for the future. To exercise any of these rights, contact support@securepaper.app.
If we change this policy, we will update it on this page together with the "last updated" date above. Material changes affecting account holders will be announced by email.
Questions about this policy or about your data: support@securepaper.app