Privacy Policy

Last updated: February 2026

1. Who We Are

PaperLM is operated by Grigory Sapunov. This privacy policy explains how we collect, use, and protect your personal information when you use our website and services at paperlm.ai.

Contact: [email protected]

2. What Data We Collect

2.1 Waitlist Signup

When you join our waitlist, we collect:

  • Email address — to notify you about product updates and launch
  • Consent timestamp — to prove you agreed to receive communications (GDPR requirement)
  • Referral code (if applicable) — to track referrals for waitlist position
  • IP address hash — a one-way hash (not the actual IP) used only for rate limiting and fraud prevention

2.2 What We Do NOT Collect

  • We do not store raw IP addresses
  • We do not use tracking cookies
  • We do not sell or share your data with third parties for marketing
  • We do not use your data for advertising

3. How We Use Your Data

We use your email address to:

  • Notify you when PaperLM launches
  • Send occasional product updates (no more than once per week)
  • Respond to your inquiries if you contact us

Legal basis (GDPR): Your explicit consent, given when you check the consent box on the waitlist form.

4. Data Storage & Security

Your data is stored in Google Firebase/Firestore, which is:

  • SOC 2 Type II certified
  • GDPR compliant
  • Encrypted at rest and in transit
  • Hosted in the EU region (europe-west1)

We implement security headers (HSTS, XSS protection, etc.) and rate limiting to protect against abuse.

5. Your Rights (GDPR)

If you are in the European Economic Area (EEA), you have the right to:

  • Access — Request a copy of your data
  • Rectification — Correct any inaccurate data
  • Erasure — Request deletion of your data ("right to be forgotten")
  • Portability — Receive your data in a machine-readable format
  • Withdraw consent — Unsubscribe at any time

To exercise these rights, email [email protected]. We will respond within 30 days.

6. Data Retention

We retain your waitlist data until:

  • You request deletion, or
  • You unsubscribe from communications, or
  • 24 months after signup if you haven't converted to a user

7. Cookies & Tracking

Our waitlist page does not use cookies or third-party tracking scripts. We may use essential cookies for the full product (e.g., authentication) — this policy will be updated before launch.

8. Third-Party Services

We use the following third-party services:

9. Changes to This Policy

We may update this policy from time to time. Significant changes will be communicated via email to waitlist subscribers. The "last updated" date at the top indicates when the policy was last revised.

10. Contact Us

For any privacy-related questions or requests, contact:

Email: [email protected]