Last updated 2026-07-18

Privacy Policy

This privacy policy describes how papersync handles your data. It covers three surfaces: papersync.ai, the papersync mobile app, and the papersync plugin for Obsidian. The product is built so that we cannot see most of what would otherwise be interesting to collect, and everything that is collected is described below.

What we never collect or see

We do not operate servers that store or process your scans, your handwriting, your transcriptions, or the API keys you use with AI providers. The papersync mobile app sends scanned images directly from your device to the AI provider whose key you provided (Anthropic, OpenAI, Google, OpenRouter, xAI, Mistral, Groq, Hugging Face, Alibaba, Together AI, or a custom endpoint you configure). The Obsidian plugin reads and writes files directly in your storage (Google Drive, iCloud, or a local folder). Neither the app nor the plugin proxies content through a papersync-owned server, because no such server exists.

This means we have no copy of what you scan, what text gets transcribed, which prompts you send to which provider, or what ends up in your Obsidian vault. We also have no way to recover or hand over this content to anyone, including ourselves or law enforcement.

What we do collect

There are three narrow categories, each described in detail below.

Email address (if you subscribe on papersync.ai)

If you fill in the "Get notified when your tool is supported" form on papersync.ai, your email address and the platform you selected (Notion, OneNote, Evernote, Logseq, or a tool name you type under Other — free-text entries are sanitized on our end and stored in Kit as the platform value) are sent to Kit (formerly ConvertKit), our email service provider. Kit stores your address and uses it only to send you occasional product announcements from papersync.

We never share your email with third parties, sell it, or use it for anything other than sending you updates you signed up for. Every email includes a one-click unsubscribe link.

Kit's own privacy practices are governed by their terms, available at kit.com/privacy.

Anonymous page views on papersync.ai

We use Cloudflare Web Analytics to measure aggregate traffic on this site. Cloudflare Web Analytics is cookieless. It does not store personally identifiable information, does not track you across other sites, and does not build a profile of you. We see rolled-up numbers like "how many people visited the hero section today" and nothing more granular.

Cloudflare's own practices for Web Analytics are described at cloudflare.com/trust-hub/gdpr.

App usage events and crash reports (in the mobile app)

The papersync mobile app uses PostHog to capture aggregate product analytics. The PostHog instance we connect to is located in the European Union (eu.i.posthog.com), so event data is stored on EU infrastructure.

What is collected:

What is not present:

Analytics is enabled by default for new installs. You can opt out at any time in Settings → Anonymous Usage inside the app. Opting out flushes the local PostHog queue and stops all future event emission for the install, with the single exception described immediately below.

Crash reports are not covered by the opt-out

Native crash reports are sent even when Anonymous Usage is switched off. They are the only category that behaves this way, and this is deliberate. We treat them as operational reliability data rather than analytics: a crash that terminates the app leaves no other signal we can act on, and without these reports a defect that only affects certain devices can survive unnoticed through many releases.

When Anonymous Usage is switched off, a native crash report is the only thing the app sends. No product analytics, no screen views, no app lifecycle events, and none of the app's own error or diagnostic events are emitted. A native crash report carries the anonymous device ID and the coarse device metadata listed above. It carries no scan content, no transcribed text, no prompts, and no API keys. One caveat we would rather state than gloss over: a native crash message is written by the operating system or by a library rather than by us, so it can name a file path when the failure involves one, such as a file that could not be read.

PostHog's own privacy practices are described at posthog.com/privacy.

AI provider privacy

When the app transcribes a scan, your image is sent directly from your device to the AI provider you configured in the app, using your own API key. We do not see, log, or proxy this traffic. What each provider does with that image is governed by their own privacy policy, not ours. We strongly recommend reviewing the privacy terms of whichever provider you choose before scanning sensitive material:

If you configure a custom endpoint, your images go to whatever URL you enter, including self-hosted servers on your own network, governed by that operator's terms.

OpenRouter is a routing layer rather than a model provider on its own: when you select OpenRouter as your provider, your image is first sent to OpenRouter and then forwarded by OpenRouter to whichever upstream model you (or OpenRouter's default routing) picked — for example a Claude, GPT-4o, or open-weight Llama model hosted by an inference partner. Two privacy policies apply to that request: OpenRouter's, and the upstream provider's. Review both before scanning sensitive material via OpenRouter, and choose an upstream that matches the privacy posture you want.

Permissions the app requests

The papersync mobile app requests only the system permissions it needs to function. Each is requested with a system dialog at first use and can be revoked at any time in the operating system settings.

Where your data lives on your device

App updates and connectivity

At launch, the app checks Expo's EAS Update service (u.expo.dev) for JavaScript updates. That request carries the app and runtime version, the platform, and a per-install update client ID; it carries none of your content, settings, or keys. Updates are cryptographically signed and the app rejects unsigned code.

To detect connectivity, the app may send a contentless probe request. From the next app release this probe goes to a papersync-operated endpoint (papersync.ai/generate_204) that returns an empty response and stores nothing.

How your data is secured in transit

Network requests originated by the papersync app and plugin — to the AI provider you configured, to the storage backend you chose (for example Google Drive), to PostHog, and to Expo's update service — are sent over TLS. One deliberate exception: self-hosted models on your own local network (for example Ollama at http://192.168.x.x) may use plain HTTP; that traffic stays on your LAN, and public hosts require HTTPS. The papersync.ai website is served by Cloudflare Pages over HTTPS.

We do not run any backend that touches your notes, scans, or keys. The only server-side code we operate is the papersync.ai email-subscribe endpoint, which relays your address to our email provider (Kit) and stores nothing itself.

Children's privacy

papersync is not directed to children under 13 (or under 16 where required by local law, such as in the European Economic Area). We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, please email [email protected] and we will delete it.

Your rights

Because the only personal data we hold about you (outside of your own device) is your email address if you subscribed, and pseudonymous PostHog event data tied to a random device ID, the practical scope of most rights is narrow. You still have them:

Under the EU General Data Protection Regulation (GDPR), if you are in the European Economic Area, the UK, or Switzerland, you have the right to access, rectify, erase, restrict processing of, and receive a portable copy of any personal data we hold about you. You may also object to processing and lodge a complaint with your local supervisory authority.

Under the California Consumer Privacy Act (CCPA / CPRA), if you are a California resident, you have the right to know what personal information we hold, to delete it, to correct it, and to opt out of sale or sharing of personal information. We do not sell or share personal information.

To exercise any of these rights, email [email protected]. If you are an email subscriber and only want to unsubscribe, the one-click link at the bottom of any email is the fastest path.

Deleting your data

There is no papersync account, so there is no account to delete. To remove the small set of locally stored items the app controls — your API keys (in the OS keystore), your app settings, and your analytics opt-out preference — uninstall the app. Uninstalling clears the app's sandbox on both iOS and Android.

Your captured notes and transcriptions live in your storage (local folder, iCloud Drive, or Google Drive). They are not deleted by uninstalling the app and are not ours to delete. Manage them in the storage provider you chose.

To remove your email address from our list, use the unsubscribe link in any email, or email [email protected]. Deletion requests can also be sent to [email protected].

Cookies

papersync.ai does not set any cookies. The mobile app and Obsidian plugin do not set cookies (they are not web applications). Your browser may still receive standard HTTP-level caching headers from our hosting provider (Cloudflare Pages), but no cookies are stored.

Source code

The Obsidian plugin source will be made public when the plugin is accepted into the Obsidian Community Plugins directory. The mobile app source is closed but follows the same no-backend architecture described above. If you have specific questions about how either product handles your data before the plugin is published, email [email protected].

Changes to this policy

If this policy changes in a material way, we will update the "last updated" date at the top of this page and announce the change to subscribers on the email list. The previous version of any clause we materially change can be requested by emailing [email protected].

Contact

Questions about this policy or how we handle data go to [email protected].