| Provider | Purpose | Data involved | Current retention boundary |
|---|---|---|---|
| Stripe | Checkout, payment method, subscription, invoices, taxes, hosted billing portal | Owner and billing identity, payment and subscription data. Kill the CRM stores references, not full card numbers. | Stripe’s legal, accounting, and customer-configured retention rules. |
| Resend | Inbound agent email, private owner receipts, explicitly requested authenticated To/CC thread replies, verification, reminders, export and deletion notices | Selected email content, attachments, authenticated thread recipients, addresses, delivery and authentication metadata. | Provider email data may remain up to 30 days. |
| Anthropic | Structured extraction and grounded or no-evidence answers through the commercial Messages API | Bounded excerpts from selected content, owner questions, and structured outputs. | Anthropic normally deletes API inputs/outputs within 30 days but may retain limited data longer for documented usage-policy, legal, or contractual reasons. Current policy describes up to two years for flagged inputs/outputs and up to seven years for safety scores. No model training by default. |
| Cloudflare | DNS, TLS edge, denial-of-service and security filtering, public web delivery | IP and network request metadata and public web requests. Authenticated API/content caching is disabled. | Cloudflare service and security retention under its contract and configuration. |
MODEL BOUNDARY
Standard messages. No tools.
Initial release does not use Anthropic Files, batch, explicit prompt caching, tools, web search, or feedback submission. The production model is pinned as claude-sonnet-5. A model change that alters data behavior reopens provider review.
OPERATOR
Paper Blueprint.
Paper Blueprint operates the application, database, and encrypted backups on infrastructure it controls in the United States. A material new content processor receives advance policy disclosure and, where required, consent before processing begins.