This Privacy Policy explains how PaperOrg collects, uses, stores, and protects personal data when you use our services at paperorg.com, app.paperorg.com, and through the PaperOrg mobile applications for iOS (Apple App Store) and Android (Google Play).
PaperOrg is a household document-organisation platform that allows users to upload, store, organise, search, and analyse personal documents. Because documents may contain sensitive personal information — including health records, identity documents, and financial records — we explain our practices in clear and specific terms below.
1. Controller
The controller responsible for the processing of personal data is:
Luxxow S.à r.l.-S
RCS Luxembourg: B311306
12, rue Treeschheck
L-3321 Berchem
Luxembourg
Operating the PaperOrg service.
Privacy contact: privacy@paperorg.com
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us at the address above.
2. What PaperOrg Does
PaperOrg helps users organise personal and household documents.
Users may upload files such as: (i) invoices; (ii) receipts; (iii) contracts; (iv) insurance documents; (v) tax documents; (vi) bank documents; (vii) vehicle records; (viii) property records; (ix) identity documents; (x) medical or health-related documents; and (xi) other personal paperwork.
PaperOrg uses artificial intelligence provided by OpenAI (primary provider) and Anthropic (fallback provider) to classify, organise, extract metadata from, summarise, and retrieve information from uploaded documents. This processing is described further in Section 7 below.
3. Personal Data We Collect
3.1 Account Data.
We collect: (i) name; (ii) email address; (iii) authentication credentials; (iv) passkey credentials; (v) household membership information; (vi) subscription and plan information; and (vii) account settings and preferences.
3.2 Uploaded Documents and Derived Data.
We process documents and files uploaded by users, including: (i) document images, PDFs, and scans; (ii) extracted text and OCR output; (iii) metadata (dates, amounts, senders, deadlines); (iv) AI-generated summaries, tags, and classifications; and (v) document categories assigned by the system or by the user.
3.3 Technical Data.
We collect: (i) IP address; (ii) browser type and version; (iii) device and operating system information; (iv) security and authentication event logs; and (v) error and performance logs.
3.4 Billing Data.
Paid subscriptions are processed through Stripe (web), Apple via the App Store (iOS), and Google via Google Play Billing (Android). PaperOrg receives transaction confirmations, subscription status, and purchase-receipt data from each payment provider. PaperOrg does not receive or store full payment card numbers or payment-method details from any provider.
3.5 Analytics Data.
PaperOrg uses Plausible Analytics, a privacy-first, cookieless analytics service. Plausible does not collect personal data, does not use cookies, and does not track individual users. Aggregate, anonymous usage statistics (page views, referral sources, device types) are collected for service-improvement purposes only.
4. Special-Category Data (Article 9 GDPR)
Documents uploaded to PaperOrg may contain special-category personal data under Article 9 GDPR, including: (i) health information (medical invoices, prescriptions, health-insurance statements, doctors' letters); (ii) disability information; (iii) medical records; (iv) trade-union membership; (v) religious or philosophical beliefs; and (vi) biometric data appearing in uploaded documents.
4.1 Legal basis.
PaperOrg processes special-category data on the basis of explicit consent under Article 9(2)(a) GDPR.
4.2 Consent mechanism.
During the account-creation process, before any documents can be uploaded or processed, each user is presented with a dedicated consent step that: (i) identifies the specific categories of special-category data that may appear in uploaded documents; (ii) explains that document content is sent to PaperOrg's AI providers (OpenAI as the primary provider and Anthropic as a fallback provider) for classification and data extraction; (iii) explains that approved service providers may process data on PaperOrg's behalf, with appropriate safeguards where data is transferred outside the EEA; (iv) directs the user to this Privacy Policy for further detail; and (v) requests the user's explicit, informed consent to this processing. The consent toggle is off by default and must be actively enabled by the user. This consent covers all documents the user subsequently uploads to PaperOrg, including documents uploaded after consent is given.
4.3 Withdrawal of consent.
You may withdraw your consent to special-category data processing at any time through the in-app privacy settings or by contacting privacy@paperorg.com. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. If you withdraw consent for special-category processing, PaperOrg will no longer process new documents that may contain special-category data through AI analysis. You may also delete any previously uploaded documents at any time.
5. Third-Party Information in Uploaded Documents
Documents uploaded to PaperOrg may contain personal data relating to individuals other than the account holder, including: (i) spouses, partners, children, and family members; (ii) employers and colleagues; (iii) healthcare providers; (iv) insurers; (v) landlords and tenants; (vi) accountants and legal representatives; and (vii) other third parties named or referenced in documents.
Users are responsible for ensuring that they have an appropriate lawful basis to upload documents containing other individuals' personal data and to share such documents with household members.
Individuals whose personal data appears in uploaded documents may exercise their privacy rights by contacting us at privacy@paperorg.com.
6. How We Use Personal Data
We process personal data for the following purposes: (i) providing and operating the PaperOrg service; (ii) storing, encrypting, organising, and classifying uploaded documents; (iii) authenticating users and managing sessions; (iv) maintaining household access controls and sharing permissions; (v) processing subscriptions and billing through Stripe, Apple (App Store), and Google (Google Play Billing); (vi) providing document search, retrieval, and AI-powered analysis; (vii) generating document summaries, extracting metadata, and answering user questions about uploaded documents; (viii) maintaining security, detecting fraud, and preventing abuse; (ix) complying with legal obligations; and (x) responding to support requests.
We do not sell personal data. We do not use uploaded documents for advertising purposes.
7. Artificial Intelligence and Automated Processing
7.1 What the AI does.
PaperOrg uses artificial-intelligence systems provided by OpenAI (primary provider) and Anthropic (fallback provider) to: (i) classify documents by type (invoice, contract, medical record, etc.); (ii) extract structured metadata (dates, amounts, senders, deadlines); (iii) generate document titles and summaries; and (iv) answer user questions about uploaded document content.
7.2 How it works.
When a document is uploaded, its content is sent to PaperOrg's AI providers for analysis. Under normal operation, document content is processed through OpenAI's API. Where OpenAI is unavailable or an alternative is required, Anthropic's API is used as a fallback. Each provider returns structured data (classifications, extracted fields, summaries) which is stored in your PaperOrg account. Neither provider uses your content to train its AI models. OpenAI retains API content for a limited period (up to 30 days) for abuse monitoring before deletion, unless a stricter arrangement applies. Anthropic operates under a zero-data-retention configuration, meaning no document content is retained by Anthropic after processing is complete. Further details are set out in Section 9 below.
7.3 Automated decision-making disclosure (Article 13(2)(f) GDPR).
The AI processing described above constitutes automated processing of your personal data. The logic involved is document analysis using large language models: the AI reads the text and visual content of your documents and produces structured outputs (type, category, dates, amounts, summaries). These outputs are used to organise and display your documents within the service. The AI processing is not intended to produce decisions that have legal effects or similarly significantly affect you. All AI-generated outputs are organisational tools only — they do not constitute legal, tax, accounting, medical, insurance, or financial advice. AI-generated outputs may occasionally be inaccurate, incomplete, or misleading. You remain responsible for reviewing original documents and verifying important information before relying on it.
7.4 Human oversight.
You can review, correct, or override any AI-generated classification, tag, or summary at any time within the application.
8. Legal Bases for Processing
PaperOrg relies on the following legal bases under GDPR:
8.1 Contract (Article 6(1)(b) GDPR).
Processing necessary to perform the contract between you and PaperOrg — including document storage, organisation, AI analysis, search, household sharing, and account management.
8.2 Legitimate Interests (Article 6(1)(f) GDPR).
Processing necessary for our legitimate interests, specifically: (i) maintaining the security, integrity, and availability of the service; (ii) fraud prevention and abuse detection; (iii) system administration and infrastructure monitoring; and (iv) service improvement based on anonymous, aggregate analytics (Plausible). Our legitimate interests do not override your fundamental rights and freedoms, particularly given the technical and organisational safeguards described in this Policy.
8.3 Consent (Article 6(1)(a) and Article 9(2)(a) GDPR).
Where explicit consent is required — specifically, for AI processing of special-category personal data (see Section 4). Consent may be withdrawn at any time through the in-app privacy settings or by emailing privacy@paperorg.com. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
8.4 Legal Obligation (Article 6(1)(c) GDPR).
Processing necessary to comply with legal obligations to which PaperOrg is subject, including retention of billing and accounting records under Luxembourg commercial law.
9. Sub-Processors and Service Providers
PaperOrg uses the following sub-processors and service providers:
9.1 OpenAI
Primary AI document analysis. Document content, extracted text, and user queries are processed through OpenAI's API. OpenAI operates under: (i) its Data Processing Addendum, which incorporates EU Standard Contractual Clauses (SCCs) for international data transfers; and (ii) a commitment not to use content submitted through its API to train its AI models. OpenAI may retain API content for a limited period (up to 30 days) for abuse and misuse monitoring, after which it is deleted, unless a stricter retention arrangement applies or retention is required by law. OpenAI is a US-based provider. Document data may be processed on OpenAI's infrastructure, which may include servers located outside the EEA. The DPA and SCCs provide the applicable transfer safeguards.
9.2 Anthropic
Fallback AI document analysis. Where OpenAI is unavailable or an alternative is required, document content, extracted text, and user queries may be processed through Anthropic's API. Anthropic operates under: (i) its Data Processing Agreement, which incorporates EU Standard Contractual Clauses (SCCs) for international data transfers; (ii) a commitment not to use content submitted through its API to train its AI models; and (iii) a zero-data-retention configuration, meaning no document content is retained by Anthropic after processing is complete. Anthropic is a US-based provider. Document data may be processed on Anthropic's infrastructure, which may include servers located outside the EEA. The DPA, SCCs, and zero-data-retention commitment provide the applicable transfer safeguards.
9.3 Stripe
Payment processing and subscription management (web). Stripe acts in two capacities: (i) as an independent controller for its own fraud-prevention, anti-money-laundering, and regulatory-compliance obligations; and (ii) as a processor for subscription management, invoicing, and payment execution on PaperOrg's behalf. Stripe is certified under the EU–US Data Privacy Framework. Stripe's privacy policy and DPA govern its processing. PaperOrg does not receive or store full payment card numbers.
9.4 Apple
Payment processing and subscription management (iOS). When users subscribe or make purchases through the App Store, Apple acts as the merchant of record and processes all payment transactions. Apple operates as an independent controller for payment processing, fraud prevention, and its own regulatory-compliance obligations. PaperOrg receives transaction confirmations, purchase receipts, and subscription-status data from Apple. PaperOrg does not receive or store payment-method details through Apple. Apple's processing is governed by Apple's Developer Program License Agreement and Apple's privacy policy. Apple is a US-headquartered provider. Transaction and subscription data may be processed on Apple's infrastructure outside the EEA. Apple's contractual commitments and privacy framework provide the applicable transfer safeguards.
9.5 Google (Google Play Billing)
Payment processing and subscription management (Android). When users subscribe or make purchases through Google Play, Google acts as the merchant of record and processes all payment transactions. Google operates as an independent controller for payment processing, fraud prevention, and its own regulatory-compliance obligations. PaperOrg receives transaction confirmations, purchase tokens, and subscription-status data from Google. PaperOrg does not receive or store payment-method details through Google. Google's processing is governed by the Google Play Developer Distribution Agreement and the Google Payments Privacy Notice. Google is certified under the EU–US Data Privacy Framework. Transaction and subscription data may be processed on Google's infrastructure outside the EEA. The EU–US Data Privacy Framework certification and Google's contractual commitments provide the applicable transfer safeguards.
9.6 Hostinger
Application hosting, database infrastructure, and transactional email delivery. PaperOrg's application server, database, and transactional email services (account verification, notifications, support correspondence) are provided by Hostinger on infrastructure located in Germany (EU). Hostinger operates under a Data Processing Agreement incorporating EU Standard Contractual Clauses. No international transfer of application, database, or email data occurs where processing remains within Hostinger's EU infrastructure.
9.7 Cloudflare (R2)
Encrypted document storage. Uploaded documents are stored encrypted (XChaCha20-Poly1305) on Cloudflare R2 object storage configured to European (EU) jurisdictional restrictions. Cloudflare operates under: (i) its standard Data Processing Addendum, which forms part of the Self-Serve Subscription Agreement; (ii) EU Standard Contractual Clauses (Commission Implementing Decision 2021/914) for international data transfers; and (iii) R2 Jurisdictional Restrictions, which ensure stored objects remain within the designated EU jurisdiction. Cloudflare is a US-headquartered provider. While document data is stored within the EU, Cloudflare's corporate structure means that access from outside the EEA cannot be categorically excluded. The SCCs, jurisdictional restrictions, and encryption at rest provide the applicable transfer safeguards.
PaperOrg maintains a sub-processor register. We will notify users of material changes to our sub-processors through the service or by email. Details of applicable safeguards for any sub-processor may be requested by contacting privacy@paperorg.com.
10. International Transfers
PaperOrg's application server, database, and document storage are located within the European Economic Area (Germany/EU).
The following sub-processors may process personal data outside the EEA or are headquartered outside the EEA:
| Provider | Data processed | Storage location | Transfer mechanism |
|---|---|---|---|
| OpenAI | Document content, extracted text, queries | United States | Standard Contractual Clauses (via OpenAI's Data Processing Addendum) + limited-retention deletion |
| Anthropic | Document content, extracted text, queries (fallback) | United States | Standard Contractual Clauses (via Anthropic's Data Processing Agreement) + zero-data-retention |
| Stripe | Billing and payment data (web) | United States | EU–US Data Privacy Framework |
| Apple | Transaction and subscription data (iOS) | United States | Apple's contractual commitments and privacy framework |
| Transaction and subscription data (Android) | United States | EU–US Data Privacy Framework | |
| Cloudflare (R2) | Encrypted uploaded documents | EU (jurisdictional restriction) | Standard Contractual Clauses + EU jurisdictional restriction + encryption at rest |
All other processing occurs within the EEA.
You may request a copy of the applicable transfer safeguards by contacting privacy@paperorg.com.
11. Security
PaperOrg implements the following technical and organisational measures to protect personal data:
- Encryption in transit: all data transmitted between your device and PaperOrg is protected by TLS encryption;
- Encryption at rest: uploaded documents are encrypted at rest using XChaCha20-Poly1305 (libsodium) before storage;
- Authentication controls: secure password hashing, passkey support, and session management;
- Role-based access controls: household sharing with granular, per-document privacy permissions;
- Infrastructure security: European hosting with access controls, logging, and monitoring;
- Backup procedures: encrypted backups with automatic expiry;
- Security review processes: periodic review of security measures and sub-processor commitments.
No method of transmission, storage, or processing can be guaranteed to be completely secure. PaperOrg does not claim end-to-end encryption and does not claim that it cannot access file contents — server-side AI processing necessarily requires access to document content in order to analyse it.
12. Data Retention
PaperOrg retains personal data only for as long as necessary for the purposes described in this Policy or as required by law. The following retention periods apply:
| Data category | Retention period | Basis |
|---|---|---|
| Uploaded documents | Until deleted by the user or on account closure | Contract performance |
| Deleted documents (Trash) | 14 days after deletion, then permanently purged | User convenience / recovery |
| Documents deleted after downgrade grace period | Permanently removed at end of the 30-day grace period (see Terms of Service, Section 10.4) | End of contract scope |
| Account data after account deletion | Purged within 30 days of account closure | No further purpose |
| Encrypted backups | Automatically expire within 90 days | Operational continuity |
| Billing and accounting records | 10 years from the date of the transaction | Luxembourg Code de Commerce, Art. 16 |
| Security and fraud-prevention logs | 12 months | Legitimate interest (security) |
| Consent and data-subject request records | 6 years | Luxembourg civil statute of limitations |
12.1 Account Deletion.
When you delete your account, PaperOrg removes or anonymises personal data associated with your account within 30 days, except where retention is required by law (billing records) or for the limited periods stated above (backups, compliance records). Certain data may remain temporarily in encrypted backups until those backups expire through normal retention cycles (maximum 90 days). Where third-party sub-processors are involved, deletion is subject to their documented retention and deletion commitments (e.g., OpenAI's limited-retention deletion, Anthropic's zero-data-retention policy, Stripe's data-retention policy, and Apple's and Google's respective data-retention policies).
13. Household Sharing
PaperOrg supports shared household workspaces. Users who create or join a household can share selected documents with other authorised household members while keeping other documents private.
13.1 Shared documents.
Documents uploaded to a shared household space may remain available to other authorised household members even if the uploading member later leaves that household. This reflects the shared nature of household document management.
13.2 Responsibility.
The user who uploads a document containing third-party personal data is responsible for ensuring they have a lawful basis to share that document with household members. Household owners and administrators are responsible for managing access to shared documents and for removing members who should no longer have access.
14. Your Rights
Subject to applicable law, you have the right to:
- Access your personal data (Article 15 GDPR);
- Rectification — correct inaccurate personal data (Article 16 GDPR);
- Erasure — request deletion of your personal data (Article 17 GDPR);
- Restriction — restrict processing in certain circumstances (Article 18 GDPR);
- Data portability — receive your personal data in a structured, commonly used format (Article 20 GDPR) — available in-app via the data-export feature (ZIP download);
- Object to processing based on legitimate interests (Article 21 GDPR);
- Withdraw consent at any time through the in-app privacy settings or by emailing privacy@paperorg.com (Article 7(3) GDPR);
- Lodge a complaint with a supervisory authority.
In Luxembourg, the supervisory authority is:
Commission nationale pour la protection des données (CNPD)
15, Boulevard du Jazz
L-4370 Belvaux
Luxembourg
https://cnpd.public.lu
To exercise your rights, contact: privacy@paperorg.com. We will respond within one month of receiving your request, as required by Article 12(3) GDPR. This period may be extended by two further months where necessary, taking into account the complexity and number of requests.
15. Cookies
PaperOrg uses only essential cookies necessary for: (i) authentication; (ii) security; (iii) session management; and (iv) user preferences.
PaperOrg does not use advertising cookies, third-party tracking cookies, or analytics cookies. Web analytics are provided by Plausible Analytics, which is cookieless and does not process personal data.
See our Cookie Policy at paperorg.com/cookies for full details.
16. Children
PaperOrg is not intended for use by children under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16 without appropriate parental consent, we will take steps to delete that data.
17. Changes to This Policy
We may update this Privacy Policy from time to time. Where changes are material, we will notify users through the service or by email at least 30 days before the changes take effect. The updated version will always display the latest revision date at the top of this page.
18. Contact
Privacy questions, rights requests, and complaints:
General inquiries:
Controller:
Luxxow S.à r.l.-S
RCS Luxembourg: B311306
12, rue Treeschheck
L-3321 Berchem
Luxembourg