Privacy Policy

Last updated: April 12, 2026

1. Information We Collect

Account Information: When you sign up, we collect your firm name, owner name, email address, and password (securely hashed). We also collect billing information through Stripe (we do not store credit card numbers directly).

Client Data: When you add clients, we store their name and email address. When clients upload documents, we store those files securely.

Uploaded Documents: Client documents are stored encrypted at rest in secure cloud storage. Only the firm that owns the data can access it.

Usage Data: We collect standard web analytics data such as pages visited, features used, and error logs to improve the service.

2. How We Use Your Information

  • To provide and maintain the PaperNudge service
  • To send automated follow-up emails to your clients on your behalf
  • To classify uploaded documents using AI
  • To process payments through Stripe
  • To send you service-related notifications (trial reminders, payment failures)
  • To improve our product and fix bugs

3. How We Store Your Data

All data is stored in a secure PostgreSQL database with row-level security on enterprise-grade cloud infrastructure. Files are encrypted at rest and all data transmission uses TLS encryption. Each firm's data is isolated at the database level. No other firm can access your data.

4. Who Can Access Your Data

  • You: Full access to all your firm's data through the dashboard
  • Your clients: Can only upload documents and fill out intake forms via their unique, time-limited link
  • PaperNudge admin: May access data for support purposes only, with your permission
  • Sub-processors: We share documents with our AI classification service for the limited purpose described in Section 5 below. We do not sell your data, and we do not share it for any other purpose.

5. AI Document Processing

Uploaded documents are sent to a US-based AI service provider that we use as a sub-processor for the sole purpose of identifying the document type (e.g., W-2, bank statement). The current provider is Anthropic, PBC. Documents are transmitted over encrypted connections and are not used to train AI models, per the provider's commercial API terms. Documents are not retained by the provider beyond the brief processing window. We may change AI providers; if we do, this policy will be updated accordingly. We do not use your documents for any purpose other than classification.

6. Data Retention and Deletion

Your data is retained as long as your subscription is active. You can delete your account at any time from Settings, which permanently deletes all your data including all client records, uploaded documents, and your firm profile. This action cannot be undone.

7. Your Rights (CCPA/GDPR)

You have the right to: access your data, correct inaccurate data, delete your data, export your data, and opt out of any non-essential data processing. To exercise these rights, contact us at hello@papernudge.com or use the account deletion feature in Settings.

8. Contact

For privacy-related questions, contact us at hello@papernudge.com.