01
Scope and roles.
For account, billing-reference, security, website, support, and product-operations information, Paper Blueprint acts as the business/controller. For business communications and other third-party information a customer deliberately submits, the customer generally determines the purpose and means of processing and Paper Blueprint processes the content to provide the service. Applicable law can assign roles differently in a particular situation.
02
Information collected.
- Account and consent. Owner email, chosen agent address, consent versions and timestamps, authentication state, retention choice, work lens, external-thread-reply setting, and other settings.
- Deliberately submitted content. Selected email headers and bodies, forwarded, BCC, CC, and To threads, authenticated thread-recipient and RFC threading metadata, supported attachments, extracted text, questions, corrections, source-linked memory, and answers.
- Billing references. Stripe customer, Checkout, subscription, invoice, price, status, last-four/card-brand display fields, tax, and portal references. We do not store full card numbers.
- Operations and security. Event and request ids, IP-derived security evidence where necessary, user agent, timestamps, delivery/authentication results, hashes, rate-limit counters, safe trace ids, and redacted logs.
- Attribution and first-party analytics. Allowlisted campaign parameters, page/section events, viewport class, and coarse performance data. Analytics must not contain email addresses, agent names, message content, filenames, questions, answers, customer-visible source ids, RFC email identifiers, database record ids, or any raw source/message/provider record identifier, including Stripe, Resend, Anthropic, Cloudflare, webhook, delivery, request, event, object, trace, or idempotency ids.
- Support. Data you choose to provide.
Initial release does not receive access to your entire mailbox, contacts, calendar, device, or CRM. Unknown or unauthorized inbound delivery is not retrieved for content processing after the routing check fails.
03
Sources.
Information comes from you, your verified owner inbox, Stripe Checkout and Billing, signed Resend delivery events, providers operating the service, and security/analytics generated when you use the site.
04
Uses.
We use information to create and authenticate the account; provision and protect the agent address; receive selected work; extract source-linked memory; answer the verified owner privately and, only after an explicit authenticated request, reply to authenticated participants already on a selected To or CC thread; record corrections; operate billing and reminders; provide retention, export, cancellation, and deletion; troubleshoot; prevent fraud and abuse; measure campaign and product function without content; comply with law; and enforce the Terms.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use customer content to train Paper Blueprint models without a separate explicit opt-in. We do not submit provider feedback containing customer content.
05
Disclosures and subprocessors.
We disclose only what is needed to providers listed on the Subprocessors page, including Stripe for payments, Resend for product email, Anthropic for bounded commercial API inference, and Cloudflare for network delivery and protection. We may also disclose information to professional advisers under confidentiality, authorities when legally required, or a successor in a merger or acquisition subject to this policy and applicable notice.
Anthropic currently states that commercial API inputs and outputs are not used to train its models by default. Anthropic normally deletes API inputs/outputs within 30 days but may retain limited data longer for documented usage-policy, legal, or contractual reasons. Its current policy describes up to two years for flagged inputs/outputs and up to seven years for safety scores.
06
Retention.
Active source and derived data follow the retention choice selected in Account: until deletion, rolling 24 months, rolling 12 months, or rolling 90 days. A shorter change has a 24-hour cancelable period and cannot restore already purged data.
After cancellation and entitlement end, read/export access remains for 30 days, then deletion begins. Direct deletion uses a 24-hour cooling-off period before local processing. Local product data is then removed. Resend email copies and content backups use 30-day standard windows. Anthropic normally deletes API inputs/outputs within 30 days but may retain limited data longer for documented usage-policy, legal, or contractual reasons. Its current policy describes up to two years for flagged inputs/outputs and up to seven years for safety scores. A deleted tenant is not restored from backup.
Incomplete/unverified accounts expire after 7 days. Unknown/unauthenticated inbound keeps only minimal hashed delivery metadata for 7 days. Export downloads expire after 24 hours or first successful download. Redacted application logs expire after 30 days. Content-free billing, consent, security, fraud, and deletion records remain only as reasonably required for accounting, disputes, legal obligations, and abuse prevention.
Complete schedules appear at /retention/.
07
Security.
We use verified-owner access, single-use hashed magic links, secure host-only sessions, CSRF controls, signed provider webhooks, exact address binding, tenant-scoped queries, content limits, malware controls, encryption in transit, restricted local storage, encrypted backups, redacted logs, rate limits, and monitored recovery. No method is perfectly secure. Report a concern to [email protected]; that operational address is reserved and never offered as an agent name.
08
Choices and rights.
Account provides self-serve access to account state, source records, corrections, the external-thread-reply control, billing portal, retention, export, cancellation, address rotation, owner-email change, and deletion.
Depending on location and context, you may have rights to know or access, correct, delete, obtain a portable copy, restrict or object, withdraw consent, or appeal a denial. Submit a request through Account or [email protected]. We verify identity and respond within the period required by applicable law. We may decline or limit a request where an exception applies and will explain available appeal options.
If you are included in business material submitted by a customer, the customer may be the appropriate controller. We will route a verified request to that customer when legally appropriate without exposing another tenant.
You can disable future external thread replies in Account. You can opt out of nonessential marketing email using the unsubscribe control. Transactional owner, billing, security, export, and deletion notices are part of the service.
09
Cookies and analytics.
We use essential session, CSRF, and preference storage needed to operate the service. We may use self-hosted, first-party analytics with recursively closed schemas configured without message content, identity fields, source ids, or raw source/message/provider record identifiers. Hashing or encoding a prohibited record identifier does not make it analytics-safe. We do not use third-party advertising cookies at launch.
10
Children and regulated data.
The service is for business users age 18 or older and is not directed to children. Do not submit children’s information, medical/PHI records, complete card data, government identifiers, credentials/secrets, or other prohibited regulated content.
11
International use.
The initial service is operated from the United States. Providers may process information in other countries as stated in their policies. Do not use the service where these transfers or the Terms are unlawful for your organization.
12
Changes and contact.
Material changes receive notice and, where required, new consent. The current effective date remains visible. Contact [email protected] for privacy questions or requests.