Last updated 2026-10-02
Privacy Policy
This privacy policy describes how papersync handles your data. It covers three surfaces: papersync.ai, the papersync mobile app, and the papersync plugin for Obsidian. The product is built so that we cannot see most of what would otherwise be interesting to collect, and everything that is collected is described below.
Who is responsible for your data
Papersync is operated by Mohamed Ahmed, an individual developer based in Egypt, who is the controller responsible for the personal data described in this policy. For privacy questions or requests, email contact@papersync.ai. For product support, email support@papersync.ai.
What we never collect or see
We do not operate servers that store or process your scans, your handwriting, your transcriptions, or the API keys you use with AI providers. The papersync mobile app sends scanned images directly from your device to the AI provider whose key you provided (Anthropic, OpenAI, Google, OpenRouter, xAI, Mistral, Groq, Hugging Face, Alibaba, Together AI, or a custom endpoint you configure). The Obsidian plugin reads and writes files directly in your storage (Google Drive, iCloud, or a local folder). Neither the app nor the plugin proxies content through a papersync-owned server, because no such server exists.
This means we have no copy of what you scan, what text gets transcribed, which prompts you send to which provider, or what ends up in your Obsidian vault. We also have no way to recover or hand over this content to anyone, including ourselves or law enforcement.
What we do collect
There are three narrow categories, each described in detail below.
Email address (if you subscribe on papersync.ai)
If you fill in the "Get notified when your tool is supported" form on papersync.ai, your email address and the platform you selected (Notion, OneNote, Evernote, Logseq, or a tool name you type under Other — free-text entries are sanitized on our end and stored in Kit as the platform value) are sent to Kit (formerly ConvertKit), our email service provider. Kit stores your address and uses it only to send you occasional product announcements from papersync.
We never share your email with third parties, sell it, or use it for anything other than sending you updates you signed up for. Every email includes a one-click unsubscribe link.
Kit's own privacy practices are governed by their terms, available at kit.com/privacy.
Anonymous page views on papersync.ai
We use Cloudflare Web Analytics to measure aggregate traffic on this site. Cloudflare Web Analytics is cookieless. It does not store personally identifiable information, does not track you across other sites, and does not build a profile of you. We see rolled-up numbers like "how many people visited the hero section today" and nothing more granular.
Cloudflare's own practices for Web Analytics are described at cloudflare.com/trust-hub/gdpr.
App usage events and crash reports (in the mobile app)
The papersync mobile app uses PostHog to capture aggregate product
analytics. The PostHog instance we connect to is located in the European
Union (eu.i.posthog.com), so event data is stored on EU
infrastructure.
What is collected:
-
App lifecycle events:
Application Opened,Application Backgrounded,Application Became Active,Application Installed, andApplication Updated. These are auto-captured by PostHog's lifecycle integration. - Screen-view events: the name of the in-app screen you navigate to (never its contents).
- A small number of explicit usage events that help us understand which features are used (for example, "settings opened", "AI provider switched"). These are sent only on the corresponding user action and contain no scan content, no transcribed text, no file paths, and no API keys.
-
Structured diagnostic events from the app itself (for example
error_occurredorcompression_failed). Like every usage event, these are sent only if you turned on Share anonymous usage stats. - App crash reports: when the app hits an uncaught internal error, or an error screen catches one, a report containing the error message and stack trace is sent to PostHog. These are assembled by the app, so credential-shaped strings are redacted on the device before anything is sent, and a report that cannot be fully redacted is dropped. They are sent whether or not usage stats are on: see Crash reports are always sent.
- Native crash reports: if the app is terminated by a crash in the native layer, for example an out-of-memory kill or an unresponsive-app termination, the crash is collected and uploaded by PostHog's embedded native SDK. These reports consist of native stack frames and device state rather than text drawn from the app, and because the native SDK builds and sends them directly they do not pass through the on-device redaction described above. Native crash reports are sent whether or not usage stats are on: see Crash reports are always sent.
- Coarse device metadata that PostHog attaches automatically, such as app version and build, operating system version, device model and manufacturer, screen size, and a randomly generated pseudonymous device ID. We do not collect your name, email, advertising identifiers (IDFA / Android Advertising ID), or precise location. No location data is collected; the analytics service discards the IP address at ingestion and derives nothing from it.
What is not present:
- Session replay, tap autocapture, heatmaps, surveys: not integrated.
Usage analytics is off by default on every install, in every region. Nothing in the list above except crash reports (and the device metadata they carry) is sent until you turn on Share anonymous usage stats, either during setup or in Settings. You can turn it off again at any time in Settings; turning it off stops all future usage events for the install and sends the events already queued, with the single exception described immediately below.
Crash reports are always sent
Crash reports are sent whether or not usage stats are on. They are the only category that behaves this way, and this is deliberate. We treat them as operational reliability data rather than analytics: a crash leaves no other signal we can act on, and without these reports a defect that only affects certain devices can survive unnoticed through many releases. The app says so next to the usage-stats switch.
When usage stats are off, crash reports are the only thing the app sends to PostHog. No product analytics, no screen views, no app lifecycle events, and none of the app's diagnostic events are emitted. App crash reports travel on a separate crash-only channel that sends nothing but error reports, builds no user profile, and uses a temporary ID that is discarded when the app closes, so they cannot be tied to your usage stats. A native crash report carries the pseudonymous device ID and the coarse device metadata listed above. No crash report carries scan content, transcribed text, prompts, or API keys. One caveat we would rather state than gloss over: a native crash message is written by the operating system or by a library rather than by us, so it can name a file path when the failure involves one, such as a file that could not be read.
PostHog's own privacy practices are described at posthog.com/privacy.
AI provider privacy
The first time you save an AI provider, the app shows a one-time notice explaining that each page you scan is sent to the AI provider you connect, and asks you to agree before saving it. No page is sent to any AI provider until you have agreed. The notice covers every provider you add later; to stop pages being sent, remove your providers.
When the app transcribes a scan, your image is sent directly from your device to the AI provider you configured in the app, using your own API key. Only the photo of the page (with the transcription instructions) is sent. The AI processors that can receive your pages are exactly the providers listed below, and only the one you choose receives them. We do not see, log, or proxy this traffic. What each provider does with that image is governed by their own privacy policy, not ours. We strongly recommend reviewing the privacy terms of whichever provider you choose before scanning sensitive material:
- Anthropic (Claude): anthropic.com/legal/privacy
- OpenAI (ChatGPT): openai.com/policies/privacy-policy
- Google (Gemini): policies.google.com/privacy
- OpenRouter: openrouter.ai/privacy
- xAI (Grok): x.ai/legal/privacy-policy
- Mistral: mistral.ai/terms#privacy-policy
- Groq: groq.com/privacy-policy
- Hugging Face: huggingface.co/privacy
- Alibaba (Qwen): alibabacloud.com privacy policy
- Together AI: together.ai/privacy
If you configure a custom endpoint, your images go to whatever URL you enter, including self-hosted servers on your own network, governed by that operator's terms.
OpenRouter is a routing layer rather than a model provider on its own: when you select OpenRouter as your provider, your image is first sent to OpenRouter and then forwarded by OpenRouter to whichever upstream model you (or OpenRouter's default routing) picked, for example a Claude, GPT-4o, or open-weight Llama model hosted by an inference partner. Two privacy policies apply to that request: OpenRouter's, and the upstream provider's. Review both before scanning sensitive material via OpenRouter, and choose an upstream that matches the privacy posture you want. Hugging Face works the same way: its router forwards your request to the inference provider that hosts the model you choose.
Permissions the app requests
The papersync mobile app requests only the system permissions it needs to function. Each is requested with a system dialog at first use and can be revoked at any time in the operating system settings.
- Camera (iOS and Android): used to capture an image of the handwritten page you are scanning. Frames are processed entirely on-device until you trigger a capture. Only the captured image leaves your device: to the AI provider you configured, and to the storage you chose (for example your own Google Drive) when you save.
- Storage (Android 12 and older only): required for the legacy scoped-storage compatibility path on Android API 32 and below. On Android 13+ the app uses the Storage Access Framework (SAF) and does not request broad storage access.
Where your data lives on your device
- API keys are stored in the operating system's secure
keystore (iOS Keychain on iOS, Android Keystore on Android) via
expo-secure-store. They are never written to plain disk and never leave the device except as an authentication header (Authorization, or the provider's equivalent such asx-api-keyfor Anthropic orx-goog-api-keyfor Google) on direct requests to the AI provider you chose. - App settings and preferences (selected AI provider,
your usage-stats choice, the date you agreed to the AI notice, UI
preferences) are stored in the app's
private storage area via
AsyncStorage. This area is sandboxed by the operating system and inaccessible to other apps. - Your captured notes and transcriptions are written directly to the storage backend you configured: a local folder on your device, your iCloud Drive, or your Google Drive. They are not written to any papersync-controlled location.
- Google sign-in details: when you connect Google Drive, your Google profile (email address, name, and photo) and your sign-in session are stored on-device by Google's sign-in SDK and never sent to papersync. The Obsidian plugin stores its Drive token in your operating system's keychain.
App updates and connectivity
At launch, the app checks Expo's EAS Update service
(u.expo.dev) for JavaScript updates. That request carries
the app and runtime version, the platform, and a per-install update
client ID; it carries none of your content, settings, or keys. Updates
are downloaded over HTTPS from Expo's update service.
To detect connectivity, the app may send a contentless probe request.
From the next app release this probe goes to a papersync-operated
endpoint (papersync.ai/generate_204) that returns an
empty response and stores nothing.
How your data is secured in transit
Network requests originated by the papersync app and plugin — to the
AI provider you configured, to the storage backend you chose (for
example Google Drive), to PostHog, and to Expo's update
service — are sent over TLS. One deliberate exception: self-hosted
models on your own local network (for example Ollama at
http://192.168.x.x) may use plain HTTP; that traffic
stays on your LAN, and public hosts require HTTPS. The papersync.ai
website is served by Cloudflare Pages over HTTPS.
We do not run any backend that touches your notes, scans, or keys. The only server-side code we operate is the papersync.ai email-subscribe endpoint, which relays your address to our email provider (Kit) and stores nothing itself.
Children's privacy
papersync is not directed to children under 13 (or under 16 where required by local law, such as in the European Economic Area). We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, please email contact@papersync.ai and we will delete it.
Your rights
Because the only personal data we hold about you (outside of your own device) is your email address if you subscribed, and pseudonymous PostHog data tied to a random device ID (usage events only if you turned usage stats on, plus crash reports), the practical scope of most rights is narrow. You still have them:
Under the EU General Data Protection Regulation (GDPR), if you are in the European Economic Area, the UK, or Switzerland, you have the right to access, rectify, erase, restrict processing of, and receive a portable copy of any personal data we hold about you. You may also object to processing and lodge a complaint with your local supervisory authority.
Under the California Consumer Privacy Act (CCPA / CPRA), if you are a California resident, you have the right to know what personal information we hold, to delete it, to correct it, and to opt out of sale or sharing of personal information. We do not sell or share personal information.
To exercise any of these rights, email contact@papersync.ai. If you are an email subscriber and only want to unsubscribe, the one-click link at the bottom of any email is the fastest path.
Objecting to crash-report processing
We rely on legitimate interests to process crash diagnostics for finding and fixing app failures. Where applicable data-protection law gives you a right to object, you can object on grounds relating to your situation by emailing contact@papersync.ai. You can also send the request to support@papersync.ai. No special legal wording or Papersync account is required. Do not send your notes, photos, prompts or API keys.
We will assess your request and respond without undue delay, normally within one month. We may ask for only the information reasonably needed to assess the request or locate relevant records. If your objection is upheld, we must stop the relevant processing unless an applicable legal exception permits it. The usage-stats switch does not stop crash reports, and sending an email does not automatically change the app's settings.
Deleting your data
There is no papersync account, so there is no account to delete. To remove the small set of locally stored items the app controls (your API keys in the OS keystore, your app settings, your usage-stats choice, and your AI consent record), uninstall the app. Uninstalling clears the app's sandbox on both iOS and Android.
Your captured notes and transcriptions live in your storage (local folder, iCloud Drive, or Google Drive). They are not deleted by uninstalling the app and are not ours to delete. Manage them in the storage provider you chose.
To remove your email address from our list, use the unsubscribe link in any email, or email contact@papersync.ai. Deletion requests can also be sent to support@papersync.ai.
Cookies
papersync.ai does not set any cookies. The mobile app and Obsidian plugin do not set cookies (they are not web applications). Your browser may still receive standard HTTP-level caching headers from our hosting provider (Cloudflare Pages), but no cookies are stored.
Source code
The Obsidian plugin source will be made public when the plugin is accepted into the Obsidian Community Plugins directory. The mobile app source is closed but follows the same no-backend architecture described above. If you have specific questions about how either product handles your data before the plugin is published, email contact@papersync.ai.
Changes to this policy
If this policy changes in a material way, we will update the "last updated" date at the top of this page and announce the change to subscribers on the email list. The previous version of any clause we materially change can be requested by emailing contact@papersync.ai.
Contact
Questions about this policy or how we handle data go to contact@papersync.ai.