Legal · Plain language

Privacy Policy

We tried to write this the way we’d want to read it — short, honest, no legal mystery. If anything is unclear, ask your deployment operator.

Last updated · 22 August 2026Applies to this PAPI deployment & the PAPI MCP serverSee also: Trust & Security & Terms

The short version

  • You own your project data. Tasks, decisions, plans, and notes belong to you. We store them so the dashboard works.
  • We don’t sell your data. Ever.
  • We don’t train AI models on your content. When PAPI calls Claude on your behalf, that goes through Anthropic’s commercial API, which doesn’t train on customer content.
  • We collect what we need to make PAPI work — account info, project content you create, light usage telemetry, and standard web logs.
  • You can leave at any time. Ask your deployment operator to delete your account and everything attached to it.

Who we are

PAPI is built and operated by Cathal O’Sullivan, an independent developer based in the EU. PAPI is the “data controller” for the purposes of GDPR. You can reach us at cathal@getpapi.ai or through the contact form.

This page describes the configured services used by this independent PAPI deployment. Its operator is responsible for the deployment-specific privacy terms and contact details.

What we collect

Account information

When you sign up, we collect your email address and a password (or your GitHub / Google identity if you use OAuth). If you sign in with GitHub, we also receive your public profile (display name, avatar, GitHub username) and a token that lets us list your public repositories when you ask us to.

Project content

This is the bulk of what PAPI stores. When you run cycles, plans, builds, decisions, reviews, and briefs — through the dashboard or the MCP server — the contents of those artefacts are saved to our database against your account. That includes:

  • Task titles, descriptions, scope, status, and free-text notes
  • Active decisions, briefs, planning logs, build handoffs
  • Build reports, including commit hashes and the list of files changed
  • Strategy reviews and reviewer comments
  • Project metadata (name, repo URL if you set one)

What we don’t store: we don’t clone your repository or copy your source code into our database. Build reports reference file paths and commits; the actual file contents stay in your repo.

Files you upload

If you upload a brief during onboarding (markdown, text, PDF, or Word, up to 1 MB), we parse it server-side and send the parsed text to Anthropic’s API to extract structured information. The original file isn’t kept — only the extracted result.

Usage telemetry

Light, scoped to your account: which PAPI tools you call, how long they take, milestone events (e.g. “setup completed”). You can disable MCP-server telemetry by setting PAPI_TELEMETRY=off in your local config.

Technical logs

Standard web request logs (IP address, user agent, URL, timestamp) are kept by the configured application and database infrastructure. We use these to keep the service running and investigate problems.

When you contact us

Your deployment operator controls how support and privacy enquiries are received and retained.

Where it lives

Project, account, and application data is stored and served by infrastructure selected by this deployment’s operator. Optional external AI and email services process only the data sent to them for the requested operation.

Who can access it

Inside this deployment: only you and administrators authorised by the deployment operator. That operator controls administrator access and support procedures.

Outside PAPI: only the sub-processors listed below, and only the data each of them needs to do their job. We don’t share your data with anyone else.

Note: when you sign up, we add your email to an internal contact list so we can reach out with product updates if needed. Any outbound email we send will include a clear way to opt out.

Cookies & storage

We use a small number of cookies and browser-storage keys, all functional — no advertising trackers.

NamePurposeLifetime
sb-<ref>-auth-tokenSupabase session (sign-in)Session / refresh-managed
papi-authLegacy operator session (HMAC)7 days
papi-dashboard-install-idAnonymous browser ID for pre-auth telemetry and visit countingPersistent (localStorage)
papi_vidSame anonymous browser ID, in a server-readable form, so a visit can be linked to the account it leads to. First-party only — never shared, never used across other sites.400 days
papi-visit-recordedMarks this browser as already counted, so we stop sending the pingPersistent (localStorage)
papi_ftHow you first found us — campaign tags and the referring site’s domain (never the full address), plus the section you landed on. Written once and never overwritten.90 days
papi-ui-theme + UI preferencesTheme, sidebar, view preferencesPersistent (localStorage)

Sub-processors

These are the third parties that process your data on our behalf:

ServiceWhat they receivePrivacy policy
ResendRecipient email address + the contents of transactional emails (signup, reset, magic link).Link
Anthropic (Claude API)Brief contents during import; project context for AI-assisted intelligence calls. Anthropic’s commercial API doesn’t train on customer content.Link
GitHubOAuth identity if you sign in with GitHub; public-repo access if you grant it.Link
GoogleOAuth identity if you sign in with Google (email + profile).Link
StripeBilling for Pro subscriptions. Card details go directly to Stripe; we only receive subscription status.Link
NetcupEU VPS infrastructure hosting the dashboard, MCP server, database, authentication, and storage.Link

We’re not currently using PostHog, Mixpanel, Sentry, Datadog, or any advertising network.

How long we keep it

Account & project data: for as long as you have an account. When you ask us to delete your account, we hard-delete your account and all attached project rows within 30 days.

Telemetry: for as long as you have an account; deleted with your account.

Provider logs: Your deployment operator controls application and database log retention; configured email providers retain metadata under their own policies. We don’t control third-party retention windows.

AI providers and your content

The only place our servers call an AI provider is brief extraction: if you upload a brief file during onboarding, its parsed text is sent to Anthropic’s Claude once to extract structure, then discarded. Anthropic’s commercial API is contractually committed not to train on customer content. Everything else — planning, strategy reviews, dashboard intelligence — runs inside your own AI session, on your own subscription; our servers make no AI calls for those.

When you run plan or strategy_review from the MCP server, those calls go directly from your machine to the AI provider you configured — your key, your subscription. We don’t see or store those prompts.

Your rights

You have the right to:

  • Access a copy of your data
  • Correct data that’s wrong
  • Delete your account and everything attached to it
  • Export your project data in a portable format
  • Object to specific processing or withdraw consent
  • Complain to your local data protection authority

Send access, deletion, and export requests to your deployment operator using the contact details supplied by that organisation.

You can already do these yourself today: delete an individual project from Settings, revoke or rotate API keys and OAuth tokens, and disconnect GitHub.

Security

Everything in transit is encrypted with TLS. Passwords are hashed by the deployment’s Supabase Auth service; plaintext passwords are not exposed to the application. API keys and OAuth access/refresh tokens are stored as SHA-256 hashes — the raw value is shown once at generation and cannot be recovered. Admin routes and service-role database access are restricted to authorised deployment processes, with application-layer tenant checks and row-level security as defence in depth.

Report security issues to your deployment operator using its published security contact.

Age requirement

PAPI is intended for users aged 16 and over. We don’t knowingly collect data from anyone younger. If you believe a child has signed up, contact your deployment operator to remove the account.

Changes to this policy

We’ll update the “last updated” date at the top whenever this policy changes. For meaningful changes (new sub-processors, new categories of data) we’ll also email registered users.

Contact us

Questions, requests, complaints — all welcome.

Use the privacy or security contact published by your deployment operator.

PAPIv1.0 · 22 August 2026