Privacy Policy
Last updated: March 2026
1. Overview
At PaperHero (operated by blaumedia GmbH), we take your privacy seriously. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our document management platform. We are committed to full compliance with the European General Data Protection Regulation (GDPR).
2. Data We Collect
We collect the following types of data to provide and improve our service:
- •Account information: Name, email address, and password (hashed) when you create an account
- •Documents: Files you upload are encrypted and stored securely. We process document text to enable search and AI features
- •Usage data: How you interact with PaperHero (pages visited, features used) to improve our service
- •Payment data: Processed securely by Stripe. We do not store your credit card details
3. How We Use Your Data
We use your data for the following purposes:
- •To provide the PaperHero service - document storage, search, AI features, and sharing
- •To improve and develop our platform based on aggregated, anonymized usage patterns
- •To communicate with you about your account, service updates, and support requests
- •To comply with legal obligations and enforce our terms of service
4. Data Storage & Location
All your data is stored on servers in Germany, hosted by Hetzner. We do not transfer your data outside the European Union. Our infrastructure is designed to meet the highest standards of data protection and availability.
5. Encryption & Security
All documents are end-to-end encrypted. Your encryption keys are stored on our servers but encrypted with your password, meaning even we cannot read your documents. You can optionally choose to store your keys only on your own devices for additional security. We use industry-standard TLS encryption for all data in transit, and support two-factor authentication (2FA) for additional account security.
6. Your Rights Under GDPR
As a user in the European Union, you have the following rights:
- •Right of access: Request a copy of all personal data we hold about you
- •Right to rectification: Request correction of inaccurate personal data
- •Right to erasure: Request deletion of your personal data ('right to be forgotten')
- •Right to data portability: Receive your data in a structured, machine-readable format
- •Right to object: Object to the processing of your personal data for certain purposes
7. Cookies
We use essential cookies required for the functioning of our platform (authentication, preferences). We use Google Analytics for anonymized usage statistics. You can control cookie settings in your browser.
8. Third-Party Services
We use Stripe for payment processing and Google Analytics for anonymized usage statistics. These services have their own privacy policies. We do not sell or share your personal data with any other third parties.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or through our platform. The date at the top of this page indicates when the policy was last updated.
10. Contact
If you have questions about this Privacy Policy or wish to exercise your GDPR rights, please contact us at:
privacy@paperhero.io
blaumedia GmbH
Friedrich-Ebert-Hof 6
22763 Hamburg
Germany