Skip to content
PaperFlow
home github

LEGAL / PRIVACY

Privacy at PaperFlow

Effective September 24, 2026

PaperFlow is designed around a simple boundary: your research library belongs to you. There is no PaperFlow document backend and no product analytics or advertising tracker.

01

Data stored on your device

Paper metadata, collections, notes, annotations, conversations, paper memory, settings, and reading progress are stored locally in IndexedDB. Offline PDF files use OPFS.

02

Google Drive sync

Sync is optional and begins only after you connect a Google account. PaperFlow requests the minimum drive.file scope and stores encrypted objects in a visible PaperFlow folder in your Drive. Offline PDF backup is separately controlled and off by default.

03

AI requests

When you submit a question, the text you provide and the bounded paper context shown by the product are sent to the AI provider you selected. PaperFlow does not proxy those requests through a PaperFlow-operated server.

04

Credentials

Google OAuth tokens remain under Chrome Identity management. Optional API keys are stored by the native host in macOS Keychain, Windows Credential Manager, or Linux Secret Service, not in extension storage.

05

Local processing

PDF rendering, search indexing, and OCR run locally. OCR workers, WebAssembly, and language data are bundled with the extension; the extension does not load executable code from a CDN.

06

Control and deletion

You can disconnect Google Drive, remove local records, delete offline PDFs, or delete the PaperFlow folder from your own Drive. Uninstalling the extension removes Chrome-managed local extension data; Drive files remain under your account until you delete them.

07

Support and security

For product support, use GitHub Issues. For a suspected vulnerability, follow the security policy and do not disclose credentials or private papers publicly.

PaperFlow
links product source support

Apache-2.0  ·  2026 PaperFlow AI