PaperRows

Privacy policy

This is the plain-language version and the only version. If anything here stops being true, we change the software or we change this page before it goes live, never after.

PaperRows is run by [seller entity name, address]. "We" means that seller. For PaperRows support, email hello@asgardagents.com. Replies come from that shared team mailbox under the sender name Asgard Agents.

The short version

What happens to your statement

When you drop a PDF on the page, code running in your browser tab reads it and builds the table you see. That code does not send the file or its contents anywhere. When you close the tab, it is gone from the page. The CSV you download is built in your browser too.

You can check this yourself: open your browser's developer tools, go to the Network tab and convert a statement. Or load the page, disconnect from the internet, and convert a statement offline. The product page explains both.

What we do collect

Visit counts. Our counter keeps daily totals, nothing finer. For each UTC day, we save an event name (such as "page viewed", "preview finished", "file refused", "checkout started" or "file exported"), sometimes a plan, a file format or a short refusal code such as "scan" or "unknown_layout", and a number: how many times that happened that day. There is no time of day, no IP address and no visitor key in it. Nothing from the document is in it.

To count a visitor once a day instead of once per page, your browser makes a random key each UTC day and keeps it in local storage as paperrows.visit. It sends that key with each page view. Our server stores only a hashed copy of it, so a second page view that day is not counted as a new visit, and that copy is deleted automatically after 2 days. The counter's requests go through Vercel like every other request, so they also show up in the request logs described next.

Request logs. Vercel, which hosts our site, records request details, including IP address, time, requested path, referrer, browser user agent and response status. A requested path may include a query string. [Make this field list exact against Vercel's request logs for the paperrows project, including whether query strings are kept.] After you pay, Stripe sends you back to our page with a Stripe checkout session id after a # in the address. Browsers do not send that part of an address to any server, so the id does not reach these logs. The page reads it, sends it once to our service in the body of a request to confirm your payment, and removes it from the address bar. These logs are separate from the visit counter. Our own service does not log requests; if something fails, it logs which route failed and the type of error. When a call to Stripe fails, it also logs the HTTP status and the error code Stripe returned. The route is the request method and path, without the query string. The service does not write request bodies into these lines. We use these logs only to keep the site running and to deal with abuse. The logs we can see are deleted after [retention period, from Vercel's log retention for our plan, once checked]. Vercel may keep its own records of traffic to the sites it hosts, for example to stop attacks; that is covered by Vercel's privacy policy, not by us.

Statement fingerprint. When you pay for a single statement or download one, your browser sends a SHA-256 fingerprint of the file: a 64-character code worked out from the file's bytes. It is not the file, and neither the file nor anything in it can be rebuilt from it. The free preview does not send it. We use it so a $5 unlock works for that one statement only, and to count Bookkeeper downloads toward the 100 limit. Before we store it, or attach it to a $5 payment at Stripe, our server hashes it again with a secret key, so a stored fingerprint cannot be matched against a copy of the file by anyone who does not have that key.

Bookkeeper download records. On the Bookkeeper plan, each download that counts toward your 100 is saved with a hashed subscription id, the hashed statement fingerprint, the start of the billing period and the time of the download. That record is deleted automatically after 24 hours; it exists so you can download the same statement again in that time without using up another one. Separately, we keep one number per billing period, how many downloads you have used, stored under the hashed subscription id and the period start. That number is deleted automatically 45 days after the billing period ends, so we can still check it if you ask for a refund.

Payment details. When you pay, our server stores the Stripe ids for the checkout session, customer, subscription and payment, which plan you bought, the amount charged, when it happened, whether a subscription is active or cancelled, and any refund decision. It does not store your email address. Stripe keeps that, along with your card details. We use these records to unlock your download, to run the monthly plan and to give refunds. We keep payment records for as long as tax and accounting rules require, [7 years].

Unlock token in your browser. After you pay, we store a small unlock token in your browser so you can download without paying twice. A single-statement token works for 24 hours after payment. A Bookkeeper token is checked with Stripe on every download, so it works only while your plan is active. The token lives in your browser's local storage under paperrows.unlocks. It is not a cookie. It holds Stripe ids and hashed values only (the checkout session id and the hashed fingerprint for a single statement, or the subscription and customer ids for Bookkeeper), signed so it cannot be altered. It is not used to track you across sites and you can clear it at any time; you would then need to unlock again.

Messages you send us. If you email us, we keep your email address and message so we can reply, for [retention period, once a deletion process exists for the mailbox] after the conversation ends. Email can carry attachments, so please do not attach your statement. If one arrives anyway, we delete it without opening it. We will never ask for your statement.

What we do not do

Who else is involved

[Before launch: audit the deployed stack (Vercel and Upstash settings including any Upstash backups, DNS, monitoring and anything else that receives visitor or customer data), add any provider found, note which country each one stores data in, and only then consider saying this list is complete.]

Your choices and rights

You can ask us what we hold about you, ask us to correct it, or ask us to delete it. Write to hello@asgardagents.com from the email address you used at checkout. We will answer within 30 days. [Needs a named owner before launch.] Some payment records we have to keep for tax reasons even if you ask us to delete them; we will tell you if that applies.

Depending on where you live (for example California, the EU or the UK), you may have further rights under local law. We will honour them; just ask.

Children

PaperRows is meant for adults handling their own or their business's records. We do not knowingly collect information from children under 13.

Changes

If we change this policy, we update the date at the top. If a change means we would collect more than we do now, we will say so clearly on the product page before it takes effect.