Privacy Policy
Last updated 18 September 2026
1. Who is responsible for your data
NoPapers is operated by a sole trader (enkeltmandsvirksomhed) based in Denmark, acting as data controller for the personal data described below. [Business name / CVR number / registered address to be confirmed before public launch.] Contact for anything privacy-related: zero_zx_3@yahoo.dk.
2. What we collect
Directly from you:
- Account details — name, email address, password (stored hashed, never in plain text), and any passkey you register.
- The documents you upload — the files themselves, plus everything extracted from them (vendor/issuer, dates, amounts, categories, and any free text the document contains).
- Anything you type into search or "Ask AI".
Automatically:
- Basic technical logs (IP address, browser user agent, timestamps) for security and to diagnose problems.
- An audit trail of actions taken in your workspace (who changed what, and when) — visible to your workspace's admins under Settings → Audit log.
3. How your documents are actually processed
This is the part most services don't spell out, so here it is plainly. When you upload a document:
- The file itself is stored on our hosting provider's object storage (Zerops, an S3-compatible service) in the EU. It is not shared with anyone outside your workspace unless you explicitly create a share link.
- The page images and extracted text are sent to Google's Gemini AI models to identify the document type and extract fields (vendor, dates, amounts, and so on), and — when you use "Ask AI" or "Explain this to me" — to answer your question or explain the document in plain language. We use a paid-tier API, which under Google's terms means your content is not used to train their models.
- If you use email-in (forwarding mail to your workspace's dedicated address), the inbound email and its attachments are received and relayed by our email provider, Resend, before being processed the same way as a manual upload.
- Outbound email (notifications, password resets, workspace invitations) is also sent through Resend.
- If you connect a calendar (Google or Microsoft), we create one dedicated calendar in that account and write your documents' dates to it — deadlines, expiry dates, and reminders you've scheduled. We never read your existing events, and we never touch any other calendar in your account. Disconnecting deletes that calendar and the access tokens immediately. An Apple Calendar (or other app) subscription instead uses a private link unique to you; anyone with that link can see the titles and dates it contains, so treat it like a share link.
4. Who we share data with
We don't sell your data, and we don't share it with advertisers. Data is shared only with the service providers who help us run the app (our "sub-processors"), under their own data-protection terms:
- Google (Gemini API) — document content, for extraction and question-answering.
- Google (Calendar API) — document titles and dates, only if you connect Google Calendar, and only to the one calendar we create for that purpose.
- Microsoft (Graph API) — document titles and dates, only if you connect Microsoft Calendar, and only to the one calendar we create for that purpose.
- Zerops — application hosting and file storage.
- Resend — inbound and outbound email.
- Sentry — error monitoring (technical error details only, not document content, and only if enabled for this deployment).
Beyond these, your documents are visible only to the members of your workspace, and to anyone you explicitly send a share link to (which can be password-protected and set to expire).
5. How long we keep it
Documents are kept until you delete them. Deleting a document moves it to Trash first, where it's permanently removed after 30 days (or immediately if you empty Trash yourself). Deleting your account permanently deletes any workspace only you belong to, along with everything in it; a workspace you share with others is left intact for its remaining members. Share links you create expire automatically (30 days by default) unless you set a different expiry or revoke them sooner.
6. Your rights (GDPR)
As a data subject under EU/Danish law, you can:
- Access and export your data yourself, at any time, from Settings → Account → "Download all your data" — every document's original file plus a structured file listing titles, dates, amounts, and categories.
- Correct anything the AI got wrong by editing the document's fields directly.
- Erase your data by deleting individual documents or your entire account (Settings → Account).
- Object or restrict processing, or ask a question about your data, by emailing us at the address below.
- Complain to the Danish Data Protection Agency (Datatilsynet, datatilsynet.dk) if you believe we've mishandled your data.
7. Cookies
We use only strictly necessary cookies: one to keep you signed in (session), and one to keep you signed in across visits if you choose "remember me". We don't use advertising or analytics cookies, and this site doesn't need a cookie-consent banner as a result.
8. Security
Passwords are hashed, never stored in plain text. You can additionally protect your account with a passkey (device biometrics/PIN instead of a password). All traffic to the service is encrypted (HTTPS). Access to a workspace's documents requires being an invited member of that workspace.
9. Changes to this policy
If we make a material change to how we handle your data, we'll make reasonable efforts to notify active users before it takes effect.
10. Contact
Questions, requests, or complaints about your data: zero_zx_3@yahoo.dk. See also our Terms of Service.