← PaperMind

Privacy Notice

Who is responsible

PaperMind is operated by Huseyn Huseynov, an individual based in Azerbaijan. Contact: hhuseynov0707@gmail.com.

What we collect

We do not collect payment card data. Payments go through Paddle, which acts as Merchant of Record. Card details are entered on Paddle's systems and never reach ours.

We use no advertising trackers and no third-party analytics. The only cookie we set is the session cookie that keeps you signed in. It is httpOnly, so scripts on the page cannot read it.

Who else processes your data

We do not sell your data, and we do not share it with anyone else.

Training

We do not use your questions, notes or saved papers to train machine learning models.

Legal basis

Where the GDPR applies: we process account and library data to perform our contract with you; usage and session records under our legitimate interest in operating the Service securely and within its limits; and billing data to meet legal obligations.

Your rights

You can ask us for a copy of your data, correct it, or delete it. Write to hhuseynov0707@gmail.com and we will respond within 30 days.

Deleting your account

You can delete your account yourself: open the account panel and choose Delete account. We ask for your password again, because a stolen session should not be enough to erase everything you saved.

Deletion is not immediate. Your account is marked and removed permanently 30 days later, so an accidental click can be undone. During that window the same panel offers Cancel deletion.

If you have an active subscription, cancel it first. We block deletion in that case on purpose — otherwise the account would disappear while billing continued, and you would have no way left to stop it.

What is removed

What we keep, and why

If you are in the EU or UK and are unhappy with how we handled your data, you may complain to your national data protection authority.

Security

Traffic is encrypted with HTTPS. Passwords are hashed with argon2id. Session tokens are stored only as SHA-256 hashes, so a copy of our database would not let anyone sign in as you. The database and cache are not exposed to the internet.

No system is perfectly secure. If we discover a breach affecting your data, we will tell affected users without undue delay.

Changes

If we change this notice in a way that materially affects you, we will email account holders before it takes effect.