Privacy Policy

Last updated: August 31, 2026

This Privacy Policy describes how SecurePaper, operator of the website securepaper.app and the application at app.securepaper.app (together, the "Service"), collects, processes, and uses your data. Privacy is the core of our product, so this policy is written to be read: it says exactly what we store, what we never see, and how to get your data deleted.

01. The Short Version

  • Your message content is never transmitted to us or stored by us. Encryption and decryption happen entirely in your browser.
  • If you create an account, we store your email address, your encryption keys, and your documents' titles and creation dates in our database (hosted on Supabase).
  • If you use SecurePaper as a guest, your encryption keys are stored only in your own browser's localStorage. Nothing reaches our servers.
  • Analytics is Vercel Analytics — cookieless and anonymous — and it only runs after you consent via the cookie banner.

02. Message Content

The text you encrypt with SecurePaper is processed exclusively on your device, in your browser, using the browser's built-in cryptography. The plaintext you type and the decrypted content you read are never sent to our servers, never logged, and never stored by us in any form. The encrypted output exists where you put it: on your screen, in files you download, and on the paper you print.

03. Data We Store for Account Holders

Creating an account is optional. If you do create one, we store the following in our database, which is hosted on Supabase and protected by row-level security tied to your login:

  • Your email address — used for login, password resets, and essential service messages.
  • Your encryption keys — stored so you can access them from any device. Note that this means you are trusting our infrastructure with your keys; see our Security page for the full trade-off and for alternatives (guest mode and passphrase mode) where we store no keys at all.
  • Document titles and creation dates — the title is optional and is the only document metadata we keep. We never store the document content itself.

We do not sell your personal data, and we do not share it with third parties except for the infrastructure providers necessary to operate the Service (hosting and database), or where the law requires disclosure.

04. Data for Guest Users

If you use SecurePaper without an account, your encryption keys are stored only in your browser's localStorage on your device. They are not transmitted to us. Clearing your browser data will delete them, so we recommend exporting or printing key backups — the app provides both options.

05. Analytics

We use Vercel Analytics and Vercel Speed Insights to understand aggregate site usage and performance. This analytics is cookieless and anonymous: it does not use cookies, does not build cross-site profiles, and does not identify individual visitors. It is loaded only after you give consent for analytics through the cookie consent banner; if you reject analytics, it does not run. You can change your choice at any time via the "Do Not Share My Personal Information" link in the footer. We do not use Google Analytics or any advertising or remarketing trackers.

06. Cookies and Local Storage

The marketing site itself sets no tracking cookies. We use browser localStorage for essential functionality: remembering your cookie consent choice and, for guest users of the app, storing your encryption keys locally. The app uses essential session storage to keep you logged in when you have an account. None of this is used for tracking.

07. Server Logs

Like virtually all web services, our hosting infrastructure keeps standard, short-lived technical logs (such as request timestamps, requested URLs, and truncated technical metadata) for security, abuse prevention, and debugging. These logs are not used to profile users and never contain message content.

08. Data Retention and Deletion

Account data is retained for as long as your account exists. You can delete individual keys and document records from within the app at any time. To delete your account and all associated data, or to request a copy of the data we hold about you, email support@securepaper.app from the address associated with your account. We will process deletion requests within 30 days.

09. Your Rights

You have the right to access, correct, export, and delete your personal data, and to withdraw any consent you have given (such as analytics consent) at any time with effect for the future. To exercise any of these rights, contact support@securepaper.app.

10. Changes to This Policy

If we change this policy, we will update it on this page together with the "last updated" date above. Material changes affecting account holders will be announced by email.

11. Contact

Questions about this policy or about your data: support@securepaper.app