Privacy Policy
Draft — under review. Not yet reviewed by legal counsel.
Last updated: 24 August 2026
paperwork is operated by GlueCode ("we", "us"). This policy explains what
personal data we process when you use the paperwork app, why, and the choices
you have. It is written for the Digital Personal Data Protection Act, 2023
(India), which is where paperwork operates.
The short version
You store documents with us — often identity documents. We treat that as the
most sensitive thing a product can hold. Documents are private by default,
never public, encrypted in transit, checked by automated systems only to tell
you whether they are usable, and never sold or used for advertising.
What we collect
- Account data. Your phone number (used to sign you in), and a display
name if you provide one.
- Documents you add. Files you upload or photograph, which may include
government identifiers such as Aadhaar, PAN or passports. You choose what to
add; we do not fetch documents from anywhere without your action.
- Document metadata. Titles, categories, dates such as expiry, and the
results of automated document checks.
- Activity records. An audit trail of significant actions (a document was
added, viewed, shared, deleted), kept so you can see what happened to your
documents. Audit records never contain document contents.
How documents are processed
When you add a document, our backend inspects it to answer three questions:
is it the document that was needed, is it readable, and has it expired.
- Image quality (blur, resolution, lighting) is measured by our own software.
- Document identification uses Google's Gemini API as a processor. The
document image is sent to Google for this analysis. Under the paid API
terms we use, Google does not use this data to train its models.
- Text extraction (OCR) via Google Cloud Vision may be used for the same
purpose when enabled.
Automated checks only ever decide whether a document needs a clearer copy.
They do not make decisions about you.
Where your data lives
- Database and document storage: Supabase, hosted on Amazon Web Services
in Mumbai, India (ap-south-1). Document files live in private storage that
has no public access path; access is through short-lived signed links
created only after permission checks.
- Sign-in: Google Firebase Authentication processes your phone number to
verify it is yours.
- Compute: Vercel runs our backend. Some background-processing state is
currently stored in Vercel's United States region. This means limited
processing metadata crosses borders; document files themselves are stored
in India.
Sharing
- Family sharing is explicit: people you add to your family can see the
family's documents. You control who is in your family.
- If a business requests documents from you through paperwork, the documents
you submit for that request are visible to that business inside paperwork.
- We do not sell personal data. We do not share it for advertising.
Retention and deletion
Removing a document from your lists archives it: the file and its version
history are retained under your account, and you can restore it at any time.
When you want a document gone, permanent deletion is available and removes
the stored file and its derived data. Account deletion removes your documents
and personal data, subject to records we are legally required to keep.
Your rights
Under the DPDP Act you may access, correct and erase your personal data, and
raise a grievance. Contact: privacy@gluecode.in. Grievance officer details
will be published before public launch.
Children
paperwork is not directed at children. A parent or guardian may manage
documents for family members, including minors, as data they control.
Changes
We will update this policy as the product evolves and note the date above.
Material changes will be announced in the app.