Privacy policy
Short version: we keep only what runs your account, your infrastructure data stays in the EU, payment data is handled by Stripe as our merchant of record, and we never sell it.
Who we are
Paperclip.inc OÜ operates the hosted product at Paperclip.inc. For your account, billing, and usage data we are the data controller. For the content you put into the product so your agents can act on it (issues, routines, skills, prompts, approvals, and the context they need), we act as a processor on your behalf: you decide what goes in and why, and our handling is governed by our data processing agreement.
- Entity
- Paperclip.inc OÜ
- Registry code
- 17517227
- Address
- Sepapaja tn 6, 15551 Tallinn, Harju Maakond, Estonia
- Privacy contact
- privacy@paperclip.inc
What we collect
Account information (name, email, billing identifiers from our payments provider). Telemetry tied to the organization (agent runs, costs, errors, login events). The content of issues, routines, skills, and approvals created inside the product.
We collect privacy-friendly, cookieless website analytics (which pages and features are used) without tracking you across sites. With your consent, we also collect heatmaps and session recordings that play back how the site and product are used, with typed input masked. You can decline recordings, and withdraw consent at any time. The "Cookies and analytics" section below explains this in full.
If you choose to sign in with Google or GitHub instead of an email address and password, that provider tells us your name, email address, whether that address is verified, your profile picture, and your account identifier with them. We store those, and the tokens that keep the link working, in the EU. We receive nothing else from them: no contacts, no calendar, no files, no repositories.
We do not collect third-party browsing history, device location, contact lists, microphone or camera input, or any signal from outside the product itself.
Why we process it, and our legal basis
Under the GDPR we rely on a specific legal basis for each purpose:
- Run the account and agents
- Performance of our contract with you.
- Sign-in with Google or GitHub, where you choose it
- Performance of our contract with you, using the sign-in method you selected. Email and password, a magic link, or a passkey involve neither provider.
- Telemetry, error monitoring, security, and service improvement
- Our legitimate interest in keeping the product reliable and safe, balanced against your rights.
- Cookieless website analytics
- Our legitimate interest in understanding usage, with no cookies or cross-site tracking.
- Heatmaps and session recordings
- Your consent, which you can withdraw at any time.
- Billing, tax, and accounting records
- Compliance with our legal obligations, and performance of our contract.
- Product or marketing email, where applicable
- Your consent, which you can withdraw at any time.
When agents process the content you provide, that processing is on your instructions as the controller. You determine the legal basis for the people whose data you put into the product.
What we send to model providers
When an agent runs, the prompt and required context are sent to the model provider you connect for that agent, using your own provider account or API key. You choose the provider for each agent, and you can point an agent at an EU-hosted or self-hosted endpoint if you need requests to stay in the European Union. We do not send billing data, team membership, or unrelated organization content along with the request.
Model provider data handling is governed by the provider that serves the request. Where a provider or route supports zero data retention and no training on inputs, we prefer it and pass that setting through, and we surface what is enabled in the org settings page so an org admin can see it. We do not control, and do not promise on behalf of, how every downstream provider handles a request, which is why those settings are visible to you.
Paperclip provides an AI system. We do not use your personal data to make solely automated decisions that produce legal or similarly significant effects about you. Agents carry out tasks that you configure and start, and you stay in control of what they do.
Subprocessors
We use a small, named set of subprocessors to run the service. We do not sell or rent customer data, and we do not advertise.
Note: Stripe, Google, and GitHub appear below for completeness, but none of the three is a subprocessor under our data processing agreement. Each is an independent controller for the data it handles, governed by its own terms and safeguards.
- Hetzner
- Cloud hosting and managed database, in the European Union.
- Cubbit
- Object storage and backups. A European (Italian) company storing data across the EU.
- Stripe
- Payments, as merchant of record (checkout, billing, VAT, invoicing). Our contracting entity is Stripe Payments Europe, Limited (Ireland). Stripe is its own controller for the payment and tax data it handles.
- Optional "Continue with Google" sign-in. A United States company, and its own controller for your Google account. Involved only if you choose that button.
- GitHub
- Optional "Continue with GitHub" sign-in. A United States company (part of Microsoft), and its own controller for your GitHub account. Involved only if you choose that button.
- mailbox.org
- Email mailboxes and inbound (receiving) email. A European (German) company, EU-hosted.
- Scaleway
- Transactional email sending (onboarding, billing, notifications). A European (French) company (Scaleway S.A.S., Paris, Iliad group), hosted in Paris (fr-par).
- PostHog
- Product analytics, heatmaps and session recordings. Hosted in the EU (Frankfurt), with a United States parent company; transfers are covered by standard contractual clauses.
We update this list when it changes. We do not provide data to anyone else except to comply with a valid legal request, in which case the affected org is notified unless we are legally prohibited from doing so.
Where your data is hosted, and transfers
Your data is hosted in the European Union, and every subprocessor stores it there. Two of them have a parent company outside the EEA: PostHog, our analytics provider, which is EU-hosted with a United States parent, and Stripe. Where a parent company could be asked for access, the transfer is covered by standard contractual clauses. Stripe is not a subprocessor but an independent controller for payment data; our contracting entity is Stripe Payments Europe, Limited (Ireland), and Stripe protects any transfers within its group under its own safeguards, including standard contractual clauses. Beyond those, we transfer your data outside the European Economic Area only to Google or GitHub where you choose to sign in with one of them, and to any model endpoint you choose to configure, which is under your control.
On the sign-in exception: Google and GitHub are United States companies and each is its own controller for your account with them, under its own privacy policy. That route exists only if you pick it, and it carries your sign-in identity, never your organization's content, agent runs, or billing data. Email and password, a magic link, or a passkey keep sign-in entirely within our EU infrastructure. Our subprocessors page sets out exactly what each provider tells us.
Retention
Active accounts: kept as long as the account exists. Deleted accounts: 30 days for backups, then purged. Audit logs: 12 months by default, with extended retention up to 7 years available for larger deployments on request for compliance use cases. Session recordings: up to 30 days, then deleted. Product analytics events: up to 12 months. Billing and tax records are kept for as long as the law requires.
Your rights
You can export, delete, or correct stored data at any time from settings, or by emailing privacy@paperclip.inc. Where we rely on your consent, such as for analytics and session recordings, you can withdraw it at any time, which stops future processing without affecting what happened before.
If you are in the EU or UK, you have the right to access your data, to have it corrected or erased, to restrict or object to processing, and to data portability. We respond within one month, and may extend by up to two further months for complex or numerous requests, in which case we tell you within the first month. You also have the right to lodge a complaint with a supervisory authority. Our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee), and you may also contact the authority where you live.
If you are a California resident, you have the right to know, delete, and correct your personal information, and to not be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined under California law. We respond to verifiable requests within 45 days, and may extend once when reasonably necessary.
We confirm your identity against your authenticated account before acting on a request, so that we do not disclose data to the wrong person.
Cookies and analytics
We use PostHog, hosted in the EU, to understand which pages and features are used. Before you choose, it counts page views only: no cookies, nothing stored on your device, and no identifier that follows you between visits or across sites. If you accept, it also sets a cookie so we can recognise a returning visit, and turns on heatmaps and session recordings. If you decline, it stops entirely. You can change your mind at any time, and withdrawing clears what was stored.
Session recordings play back how pages are used, so we can see what is confusing or broken. Typed input is masked everywhere. Inside the product, the areas that show your content are excluded from recording altogether: agent conversations and run output, run logs, files and artifacts, and agent instructions. A recording shows how the interface was used, not what was in it. We do not use recordings to read what you or your users put into agents.
We set no advertising or cross-site tracking cookies, and we do not sell or share data for advertising. Logged-in product sessions also use a first-party session cookie and a CSRF token cookie. Those keep you signed in and protect the session, so they are set without consent as strictly necessary cookies.
Changes to this policy
When this policy changes we post the new version here and update the date above. For changes that materially affect how we handle your data, we give notice in the product or by email before they take effect.
Contact
Privacy questions and rights requests go to privacy@paperclip.inc. Security reports go to security@paperclip.inc.
Entity of record: Paperclip.inc OÜ (registry code 17517227), Sepapaja tn 6, 15551 Tallinn, Harju Maakond, Estonia.