100% On-Device Privacy Architecture

Privacy Policy & Data Principles

Effective Date: August 2026 • Official Privacy Policy for Papryx Desktop Software & Website

Core Privacy Invariant: Papryx Desktop processes all documents strictly on your local computer. Zero bytes of document text, images, tables, or filenames are ever uploaded or transmitted to external cloud servers.

1Zero Document Transmission & Local Execution

Unlike web-based PDF converters that require uploading confidential files to remote cloud queues, Papryx Desktop is installed locally on your desktop computer (Windows & macOS). All document operations execute entirely on your local device.

  • Zero Cloud Uploads: Files opened in the editor or processed via conversion tools never leave your machine.
  • Zero File Storage on Servers: We do not operate remote document databases, cloud caches, or intermediary file queues.
  • Offline Capable: All 24+ tools function without an active internet connection (in airplane mode or air-gapped environments).

2Information We Collect & Purpose

We collect only the minimum information required to manage beta registrations, deliver product updates, and enforce digital license limits:

A. Early Access & Support Registration

When you submit our Early Access request form or contact support, we collect your Full Name, Email Address, Profession/Role, and optional feedback. This is strictly used to dispatch your installer download link (Windows & macOS), 90-day Pro license key, and software updates.

B. Digital License Activation & Seat Management

To prevent software piracy and enforce authorized seat limits, the desktop application performs a minimal HTTPS handshake during initial license activation and periodic validation. This transmits only a one-way key hash, pseudonymous SHA-256 hardware identifier hashes, machine hostname, and application version. Your IP address is processed temporarily by our cloud endpoint to establish the secure HTTPS connection and enforce rate limiting. Under global regulations like EU GDPR (Article 4(5)), hardware hashes are classified as pseudonymous personal data. Zero bytes of document text, filenames, or user files are ever transmitted.

C. Website Log Data

Standard HTTP access server logs (ephemeral IP address, browser type, referral URLs) are maintained strictly for website reliability, security, and abuse prevention. We do not sell, rent, or monetize your personal information.

D. Zero Document Telemetry & No Vendor Crash Reporting

Papryx contains zero telemetry SDKs, zero behavioral analytics trackers, and no remote crash reporting daemons. Diagnostic logs remain strictly on your physical machine with automatic masking of license tokens and local file paths.

Named Infrastructure Service Providers (Operational Lifecycle Only)

Papryx engages zero sub-processors for document content. The following third-party infrastructure providers are engaged strictly for software lifecycle services (seat licensing, update delivery, and website hosting):

Provider EntityService & RoleData CategoryTransfer Mechanism
Supabase Pte. Ltd. (Singapore) / Supabase, Inc. (USA)Seat licensing database & cryptographic verificationPseudonymous device hashes, key hashes, IP addressEU Standard Contractual Clauses (SCCs, Module 2)
GitHub, Inc. (Microsoft Corp., USA)Release package hosting & update manifestsEphemeral client IP address in download logsEU-US Data Privacy Framework (DPF) / SCCs
Fastly, Inc. (USA)Global edge CDN for binary delta updatesEphemeral client IP address in edge server logsEU-US Data Privacy Framework (DPF) / SCCs
Hostinger International Ltd. (Cyprus / EU)Web portal hosting & early access registrationsVisitor web logs & lead forms (Name, Email)Intra-EEA Processing / GDPR Compliant

3Regulatory Alignment & Data Sovereignty

Because Papryx Desktop never accesses, transmits, or stores document contents on external infrastructure, your organization maintains sovereign data custody:

  • Client Non-Disclosure Agreements (NDAs): Processing contracts, intellectual property, or financial audits locally does not constitute third-party data disclosure.
  • EU GDPR Alignment: Supports Data Protection by Design (Art. 25). Zero cloud document transmission eliminates document processor sub-contracts (Art. 28). Licensing metadata is managed under an Independent Data Controller model (Art. 6(1)(f) legitimate interests for anti-piracy), with downstream cloud processing protected by EU Standard Contractual Clauses (SCCs).
  • India DPDPA 2023 Alignment: Architected to support digital personal data protection principles through strict local data residency. Zero personal document contents are processed externally; operational seat metadata is bounded to statutory contract fulfillment.
  • US HIPAA Alignment: Supports HIPAA compliance by keeping electronic protected health information (e-PHI) strictly within the covered entity's physical device perimeter.

4Data Security & Local Persistence

All modified PDF documents, exported spreadsheets (.xlsx), converted Word files (.docx), and extracted text are saved directly to your local computer storage under your operating system user account. Temporary processing artifacts generated during batch operations are stored in your operating system's local temporary folder and automatically scrubbed upon task completion. License credentials stored on your device are encrypted using OS-native safeStorage (Windows DPAPI / macOS Keychain Services) hardware-bound encryption.

5User Rights, Data Removal & Grievance Redressal

You have the right to request deletion of your registration details from our beta cohort at any time. For questions regarding our privacy practices, exercise of data subject rights, or grievance redressal under applicable regulations, please contact our Data Protection & Support lead at admin@papryx.app or visit our Support page.