Privacy Policy

Last updated: January 19, 2026

Introduction

PaperLab ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our mobile application and services. PaperLab is intended for users aged 13 and above.

Camera and Photo Library Usage

PaperLab requires access to your device's camera and/or photo library to photograph exam papers for AI-powered marking. This is the core functionality of our service. We only access photos that you explicitly select or capture within the app.

  • Camera access is used solely to photograph exam papers
  • Photo library access allows you to select existing images of exam work
  • We do not access or scan photos outside of your explicit selections
  • We do not access your camera or photo library in the background

Third-Party AI Processing

Important: Your exam paper images are sent to third-party AI services for processing. To provide automated marking, PaperLab uses AI services from OpenAI, Anthropic, and Google (Gemini).

  • Your images are transmitted to these providers for analysis and marking
  • This processing is essential for the app to function
  • By uploading images, you consent to this data sharing

Data retention by AI providers:

  • OpenAI: Retained up to 30 days for abuse monitoring, then deleted
  • Anthropic: Retained 7-30 days for trust and safety, then deleted
  • Google (Gemini): Retained temporarily for processing, then deleted

None of these providers use your API data for model training.

Image Storage

Images of exam papers you submit are securely stored on Cloudflare R2, a cloud storage service. These images are used to process your marking requests and provide feedback.

  • Images are transmitted using secure, encrypted connections (HTTPS/TLS)
  • Images are retained until you delete them or delete your account
  • Data is stored in the United States

Authentication and Account Data

We use Supabase for authentication services. When you create an account, we collect and store:

  • Your email address
  • Encrypted password (for email/password accounts)
  • Authentication tokens for secure access

Sign-In with Apple and Google

If you choose to sign in using Apple Sign-In or Google Sign-In, authentication data is processed by those respective services. We receive limited information:

  • Your email address (or a relay email for Apple Hide My Email)
  • A unique identifier for your account
  • Your name (if you choose to share it)

We do not receive or store your passwords from these services.

Data Retention

We retain your data according to the following policies:

  • Uploaded images: Retained until you delete them or your account
  • Account data: Retained while your account is active
  • Marking results: Stored to provide you with history and progress tracking

Analytics and Tracking

PaperLab does not track you. We do not use advertising trackers, behavioral tracking tools, or share data with advertising networks. We may collect basic technical metrics (error logs, crash reports) to improve the app.

Third-Party Services

We use the following third-party services to operate PaperLab:

  • Supabase: Authentication and account management
  • Cloudflare: Image storage (R2) and web app hosting (Pages)
  • Railway: Backend application hosting
  • OpenAI, Anthropic, Google Gemini: AI-powered marking
  • Google, Apple: OAuth sign-in services

Account Deletion

You can delete your account and all associated data at any time using the "Delete Account" button in the app settings. This action is immediate and cannot be undone.

Alternatively, you can contact us to request manual deletion:

[email protected]

When your account is deleted, your data is removed immediately. Backups may retain data for up to 90 days for disaster recovery, after which it is permanently purged.

Your Rights

You have the right to:

  • Access a copy of your personal data
  • Request correction of inaccurate data
  • Request deletion of your account and data
  • Request your data in a portable format

If you are in the EEA or California, you may have additional rights under GDPR/CCPA. Contact us to exercise these rights.

Contact Us

If you have any questions about this Privacy Policy, please contact us at:

[email protected]