Policy

Privacy policy

This policy describes the information PaperPMF processes when you create a diagnostic, purchase a report, or contact us.

Effective July 12, 2026

Information we process

  • Product names, descriptions, images, Shopify URLs, target-audience text, and research notes you submit.
  • Synthetic personas, model reactions, semantic scores, report results, and method metadata produced for a diagnostic.
  • Your email address when you request checkout for a full report.
  • Payment identifiers, status, amount, currency, and allowlisted webhook metadata received from Dodo Payments.
  • Page views, referring pages, device and browser information, approximate location, and interaction events collected through Google Analytics.
  • Basic security and operational logs that may include an IP address, request time, route, and user agent.

How we use information

  • To create the requested preview and paid diagnostic report.
  • To prefill hosted checkout and associate verified payment with the correct run.
  • To recover a paid report link, respond to support requests, prevent abuse, and investigate failures.
  • To understand aggregate site usage and improve product workflows.
  • To maintain security, reliability, and an auditable method record.

Service providers

PaperPMF uses Supabase for database and private object storage, OpenRouter and its selected model providers for language and vision processing, Cloudflare Turnstile for bot and abuse detection on diagnostic submissions, Google Analytics for product and site usage measurement, and Dodo Payments as the hosted payment provider and Merchant of Record. These providers process the information required to perform their respective services under their own terms and privacy practices.

Payment-card details are entered on Dodo Payments' hosted checkout and are not stored by PaperPMF.

Browser storage and tracking

PaperPMF stores your selected theme and a bounded report index in browser local storage. The report index contains run and report slugs, display titles, target-audience text, status, and timestamps so links can be reopened from My Reports. It remains on that browser, can be cleared from My Reports, and is not an account or cross-device profile. Google Analytics may use first-party identifiers and cookies to measure page visits and interactions. PaperPMF uses this data for aggregate product analytics, not advertising. Payment and infrastructure providers may use essential cookies or logs on the services they operate.

Retention and security

Staged uploads expire after 24 hours. Preview runs are designed for seven-day access, while purchased report links are permanent. Attached inputs and generated report evidence remain stored until deletion is requested or a documented purge policy applies.

PaperPMF uses private storage, server-only credentials, short-lived signed image URLs, authenticated engine requests, verified payment webhooks, and unguessable public slugs. No internet service can guarantee absolute security.

Your choices

You may request access, correction, or deletion by emailing [email protected]. Include the relevant run or report link. We may need to verify that you control the submitted link or checkout email. Applicable legal rights may vary by location.

Changes and contact

Material changes will be reflected by updating the effective date on this page. Questions about this policy can be sent to [email protected].