Data Use Policy.
Effective June 26, 2026
This Data Use Policy explains how Paper Compute Company ("Paper Compute", "we", "us", or "our") collects, uses, shares, and protects data when you use the Paper Compute website at papercompute.com (the "Site") and the paper console hosted product (together, the "Services"). It works alongside ourTerms of Use.
Our stance in one paragraph. The paper consolecaptures traces from your agents and displays them for inspection and debugging. For enterprise customers, we do not train models on, and do not access, your customer data, except as required to deliver the contracted Services or as you direct. For non-enterprise users, we may use the data we capture — including agent traces and content shown in your console — to operate, secure, develop, train, and improve our products and models. We do not train our models on the actual prompt text or on sensitive data (such as credentials, secrets, or personal information). To opt out of development and training use, move to an enterprise plan. We do not sell your personal information.
1. Data we collect
Site visitors
When you browse the Site, we collect standard web and product analytics, such as pages viewed, referring URLs, approximate location derived from IP address, device and browser type, and interaction events. This helps us understand how the Site is used and improve it.
paper console users (non-enterprise plans)
- Account data — name, email, and authentication details needed to create and secure your account.
- Agent traces and content — execution traces captured from your agents (such as tool calls, responses, outputs, and logs), along with configurations and other content you submit, which the console records and displays.
- Usage and telemetry — feature usage, configuration, performance metrics, diagnostic logs, and error reports generated while you use the product.
- Billing data — limited records needed to administer paid plans (payment processing is handled by our payment provider; we do not store full card numbers).
Enterprise customers
We do not train on or access your customer data. We process enterprise data only as necessary to provide the contracted Services, under the terms of your order form or data processing agreement, and as directed by you.
2. How we use data
- to provide, operate, maintain, and secure the Services;
- to improve and develop our products, including diagnosing issues and analyzing usage trends;
- for non-enterprise plans, to develop, train, and improve our products and models — excluding the actual prompt text and sensitive data (such as credentials, secrets, or personal information), which we do not use to train our models;
- to communicate with you about your account, updates, and support;
- to detect, prevent, and respond to fraud, abuse, and security incidents;
- to comply with legal obligations and enforce our Terms of Use.
3. Legal bases (EEA/UK)
Where the GDPR or UK GDPR applies, we process personal data on the bases of: performance of a contract (providing the Services); our legitimate interests (securing and improving the Services); your consent (where required, such as certain analytics cookies); and compliance with legal obligations. You may withdraw consent at any time where processing is based on consent.
4. How we share data
We do not sell your personal information. We share data only with:
- Service providers (subprocessors) that process data on our behalf under contract. This includes PostHog for product and web analytics, as well as hosting and infrastructure providers required to run the Services.
- Legal and safety recipients when required by law, legal process, or to protect the rights, property, or safety of Paper Compute, our users, or the public.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.
5. Data retention
We retain paper console telemetry and usage data on a rolling twelve-month basis, after which it is deleted or aggregated into a non-identifiable form. Account data is retained while your account is active and for a reasonable period afterward to meet legal, accounting, and security obligations. Enterprise data retention is governed by the applicable order form or data processing agreement.
6. Your rights
Depending on where you live, you may have the following rights over your personal information:
California (CCPA/CPRA)
- the right to know what personal information we collect and how we use it;
- the right to request deletion or correction of your personal information;
- the right to opt out of "sale" or "sharing" of personal information — note that we do not sell personal information;
- the right not to be discriminated against for exercising these rights.
EEA/UK (GDPR)
- access to, and a copy of, your personal data (portability);
- rectification of inaccurate data and erasure of data;
- restriction of, or objection to, certain processing;
- the right to lodge a complaint with your local supervisory authority.
To exercise any of these rights, email[email protected]. We will verify your request and respond within the timeframe required by applicable law.
7. Cookies and similar technologies
We use cookies and similar technologies for essential site functionality and for analytics. You can control non-essential cookies through your browser settings and, where required, through consent controls presented on the Site.
8. Data security
We use technical and organizational measures designed to protect data, including encryption in transit, access controls, and least-privilege practices. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. International data transfers
We may process and store data in the United States and other countries. Where we transfer personal data internationally, we rely on appropriate safeguards, such as standard contractual clauses, where required by applicable law.
10. Children's data
The Services are not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has provided us personal information, contact us and we will delete it.
11. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, provide additional notice.
12. Contact
Questions or requests about your data? Email[email protected].