Last updated 16 August 2026
Paperomat renders documents. The shortest true summary of this policy is that the documents themselves are the thing we try hardest not to keep.
Paperomat is operated by a sole proprietorship registered in Türkiye. Contact [email protected] for any question about this policy or about data we hold.
| Data | Why | How long |
|---|---|---|
| Email address, name and provider account identifier | To create and sign in to an account. Supplied by Google, GitHub or Microsoft when you sign in, or by you when you use an email link. | Until you delete the account |
| Your templates and sample payloads | They are the product. You author them, we store and render them. | Until you delete them |
| Render request data | The JSON you send to be merged into a template. | Held in memory for the render, not stored |
| Counts of documents rendered | To apply plan limits and to bill correctly. | About 15 months |
| Waitlist address | To send you an invitation. Nothing else is ever sent to it. | Until you ask us to remove it, or the beta closes |
| Product usage events | To see where people get stuck between signing up and publishing. | Per our analytics provider's retention |
On Growth and Enterprise plans, a finished document is written directly into cloud storage you own — your own Amazon S3 bucket or Azure Blob container, encrypted with your own key. We do not retain a copy, and we hold no long-lived credential of yours: access is a role you grant and can revoke, and on Azure no client secret exists at all.
On the Free and Starter plans there is no customer storage to write to, so the finished PDF is returned in the API response and any temporary copy is deleted within one day.
| Processor | What for | Where |
|---|---|---|
| Amazon Web Services | Compute, rendering, queues, operational data | Europe (Frankfurt) and United States |
| Neon | The account database | Europe (Frankfurt) |
| Cloudflare | DNS, this website, inbound email routing | Global edge |
| Resend | Sign-in links, invitations, service notices | United States |
| PostHog | Product analytics inside the signed-in app | European Union |
| Sentry | Error reports | United States |
| Dodo Payments | Payments, invoicing and tax, as merchant of record | Per their own terms |
No customer document passes through the email, analytics or payment providers.
The signed-in application sets one cookie, which keeps you signed in. There are no advertising or third-party tracking cookies anywhere on Paperomat.
We process account and template data to perform our contract with you, usage and error data under legitimate interest in running a reliable service, and billing data to meet legal obligations. Where consent is the basis, you may withdraw it at any time.
You may ask for a copy of your data, ask us to correct or delete it, or object to processing. Templates can be exported at any time from the application without asking us. Write to [email protected] and we will respond within 30 days.
Data is encrypted in transit and at rest. Signing keys are held in a hardware security module and cannot be exported. Paperomat does not hold a SOC 2 or ISO 27001 certification; the architecture is designed so that your documents stay in your own account rather than depending on ours.
If this policy changes in a way that affects you, we will email account holders before it takes effect.