Papira Privacy Policy
In three lines
Papira keeps your documents and dates only on your phone, encrypted. None of it is sent to us or to anyone else — we have no server where your data could be, and no technical means of accessing it.
This does not mean that none of your data is processed with us. Some is: if you write to us, if you visit our website, or if you buy a subscription. This policy explains exactly what, why, and for how long.
1. Who we are
Papira is developed and made available by Toralle, Lda., a private limited company (sociedade por quotas) incorporated under Portuguese law.
| Registered office | Rua da Cruz da Argola, n.º 742, trás, Mesão Frio, 4810-225 Guimarães, Portugal |
|---|---|
| Legal person identification number (NIPC) | 518102564 |
| Contact | support@papira.app |
For the purposes of the General Data Protection Regulation (GDPR), Toralle is the controller of the data described in section 4 of this policy — and of that data only.
We have not appointed a data protection officer, as we are not required to do so. All privacy matters are handled through the contact above.
2. The core idea: Papira does not collect your data
Papira works with no account, no sign-up and no password of ours. Install it and use it.
Everything you create in the app — documents, photographs and PDFs, dates, counters, family profiles, notes, settings — is created and stored exclusively on your device, in encrypted form.
That data:
- is never transmitted to Toralle servers;
- is never shared with third parties on our initiative;
- is never looked at by us, because we have no technical means of doing so;
- is not used for advertising, profiling, statistics, training artificial intelligence models, or any other purpose. This applies to everything you enter in the app, without exception: what you keep in Papira is never used to show you ads.
This is not a commercial promise. It is a consequence of the way the app was built: there is nowhere on our side where that data could be.
Papira contains no usage analytics and no error reporting — no Google Analytics, no Firebase Analytics, no Crashlytics, no equivalent. The only third-party component that collects information is Google AdMob, present only on the free plan and described in section 7. On any paid plan, that component is not initialised and collects nothing.
3. What stays on your device, and how it is protected
3.1 What the app stores
- Documents: title, category, notes, issue and expiry dates, number (optional), issuing body, website, phone number, address, instructions and the free-text field "where the original is".
- Attachments: photographs and PDF files you attach to documents.
- Bank cards: the details you choose to record — number, expiry date, security code, name on the card and issuer — encrypted on the device. The security code is not included in the backup.
- Dossiers and delivery record: the document lists you assemble and, if you note them, the people or organisations you handed each dossier to — name, company, email, phone, notes and date.
- Profiles: the profiles you create and everything you associate with them.
- Dates and counters, and their respective reminder settings.
- App settings, including theme, language and reminder time.
- Lock configuration: if you enable the PIN, we store a verifier derived from the PIN, never the PIN itself.
3.2 How it is protected
| Layer | Protection |
|---|---|
| Database | Encrypted with SQLCipher. There is no code path that opens the database unencrypted: if the key is not available, the app fails rather than opening a plaintext database. |
| Database key | Stored in the operating system's secure store — Android Keystore or iOS Keychain — hardware-protected on modern devices. |
| Attachments | Encrypted individually, with one key per file. No file of yours is written to disk in plaintext. The temporary camera file is read, encrypted and deleted. |
| Photograph metadata | EXIF metadata, including GPS coordinates, is removed at the moment the image is saved. |
| PIN | Derived with PBKDF2-HMAC-SHA256, 210,000 iterations and its own salt. It encrypts a verifier, and the record is sealed with a key from the system's secure store. |
| System backup (Android) | Disabled (allowBackup="false"), so that your data is not copied into Google's backup. |
| Viewing | On Android, the attachment viewer blocks screenshots. On iOS, the system does not allow blocking them; the app applies a privacy veil when it goes to the background. On both, the content is hidden in the app switcher. |
3.3 About the backup file
If you create a backup, the .papira file is encrypted with AES-256-GCM, from a password that only the user chooses and knows, derived with PBKDF2 and 210,000 iterations. The readable header contains only the format, the schema version, the date, a label and the encryption parameters — it contains no counts and no content.
The file goes wherever the user puts it. We do not receive it, we do not store it and we cannot open it.
Important warning: we neither receive nor store the backup password and we have no means of recovering or bypassing it — that is precisely why the file is secure. If the password is lost, the content of the file becomes permanently inaccessible, to you and to anyone else. The same applies to the PIN, if you forget it without having biometrics set up.
3.4 How you delete your data
You do not need to ask us for anything, because we have nothing of yours. Deleting an item in the app deletes it. Uninstalling Papira permanently removes the entire encrypted database and all attachments from the device. Any backups you have created stay where you saved them, and it is the user who controls them.
4. What Toralle actually processes
Outside the device, and only in these three situations, personal data does in fact reach us. The free plan's advertising involves data collected by Google, which never reaches us: it is described in section 7.
4.1 Messages you send us
What data: the email address and everything you write in the message.
Purpose: to reply and resolve the matter.
Legal basis: Article 6(1)(b) GDPR (performance of the contract and steps prior to entering into a contract) for matters relating to the app; point (f) (legitimate interests in replying to those who contact us) in all other cases.
Retention: 24 months after the matter is closed.
Recipients: the email service provider we use, acting as a processor.
Please do not send us documents or document numbers by email. We never need them to resolve a support matter, and email is not a secure medium. If you do send us any, we delete them.
4.2 Access logs for the papira.app website
Like any web server, ours logs the requests it receives.
What data: IP address, date and time, page requested, response code and browser identification (user agent).
Purpose: to keep the website running, diagnose faults and detect abuse and attacks.
Legal basis: Article 6(1)(f) GDPR — legitimate interests in ensuring the security and continuity of the service (recital 49).
Retention: 30 days, with automatic deletion. Beyond that period, we keep only aggregate statistics from which no one can be identified.
Recipients: the hosting provider, acting as a processor.
4.3 Information from the app stores
Apple and Google make reports on downloads, sales and subscriptions available to us. These are aggregate reports: they do not identify who bought. We do not receive anyone's name, email address, postal address or payment details from the stores.
Purpose: to run the business and comply with accounting and tax obligations.
Legal basis: point (f) (legitimate interests) and point (c) (legal obligation), as the case may be.
The purchase itself is made from Apple Distribution International Ltd. or Google Commerce Limited, and the processing of your payment data is governed by those companies' privacy policies, not by this one.
5. The papira.app website
The website was built deliberately so as to collect nothing:
- no cookies and no storage of any kind in the browser — no localStorage, no sessionStorage, no IndexedDB;
- no analytics systems, no tracking pixels and no social media widgets;
- no third-party fonts or resources — everything is served from our own server, precisely so that your IP address is not exposed to anyone else;
- no forms and no waiting list; the only contact is an email link.
It is because we neither write to nor read anything on your equipment that the website shows no cookie consent request. What remains are the technical logs described in 4.2, which we inform you about here.
6. When the app connects to the internet
Papira works offline. Everything you enter — documents, photos, PDFs, names, dates and notes — stays on your device, encrypted, and is never sent to us or to third parties. The app has no account, no sign-up and no servers of ours. Working offline is not the same as never communicating. These are the only situations in which the app uses the network:
| Situation | What happens |
|---|---|
| App stores | Downloads, updates, purchases and subscriptions, handled by Apple and Google under their respective terms. |
| Links the user opens | When you tap the website, phone number or address of an issuing body, the phone opens the browser, the phone app or the map you already use. From that point on, the terms of those services apply. |
| Backup the user creates | The encrypted file goes wherever the user puts it. It does not pass through us. |
| Sharing the user starts | A document leaves through the system share sheet, to the app the user chooses, and only when the user asks for it. Never automatically. |
| Advertising (free plan only) | The app requests ads from Google AdMob. See section 7, Advertising. |
The library of document templates by country is included in the app and requires no internet connection.
7. Advertising
On the free plan, Papira shows advertising. There is no advertising on any paid plan — subscribing to any plan, including the No ads plan, removes it immediately.
Where, and how much
There is a single ad position in the whole app: the end of the Today panel. The ad is always labelled as advertising. There are no interstitial ads, no pop-up ads, and no ads during the first seven days of use.
Who supplies them
Ads are supplied by Google AdMob, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. To serve them, Google’s SDK collects data on your device. According to Google’s own documentation, that includes:
- Identifiers and device information — the system advertising identifier, the IP address, the model, the operating system version and the language.
- Approximate region — derived from the IP address. It is not your precise location: Papira neither requests nor holds location permission.
- App interactions — launches, taps and ad views. This is what allows impressions to be counted and how often you see the same ad to be capped.
- Performance diagnostic information — start-up time, crashes and energy consumption relating to the SDK’s own operation.
This data is collected by Google on your device and goes to Google — not to us. We do not see it, we do not store it and we have no technical means of accessing it. See Google’s policy at policies.google.com/technologies/ads.
This does not contradict section 2. Toralle still has no usage analytics and no crash reporting — no Google Analytics, no Firebase Analytics, no Crashlytics, no equivalent. This collection serves ad delivery and measurement, not analysis of how you use Papira, and all of it goes to Google.
Where the law requires consent, none of this is collected before you answer the request: the advertising SDK is not even initialised.
The advertising SDK includes Google measurement components, which are part of the same package and are installed with it on every plan. They are only initialised after consent, where consent is required, and they serve advertising — not analysis of how Papira is used, which does not exist.
What Google does not receive
Nothing you keep in Papira. Your documents, photos, PDFs, names, dates, categories and notes are not sent to AdMob or to any other recipient. The advertising has no way of knowing what you have stored.
Who is responsible
We are the ones who decided to include advertising, where it appears and on which plan. It is Google that determines what data it collects and what it does with it afterwards. For that reason, as regards the collection and transmission of that data from your device, we consider that Toralle and Google Ireland Limited act as joint controllers within the meaning of Article 26 GDPR. As regards what Google does with the data afterwards, the controller is Google. In practice: you can approach either of us. If you write to us about advertising data, we forward your request and follow it up — but it is Google that has the technical means to access it and answer you.
Where we ask for your consent
In the European Union, the United Kingdom, Switzerland and the US states covered, we ask for your consent before the first ad. Until you answer, nothing is read from your phone for advertising — the advertising SDK is not initialised. They are two distinct choices, and you can answer each of them differently:
- Access your device — read the advertising identifier and technical information about the handset. Without that it is not possible to limit how often you see the same ad, or to prevent fraud.
- Personalise the ads — use that information to choose what you are shown.
If you decline personalisation, you will still see advertising, chosen without your profile. If you decline everything, you carry on using Papira exactly as before — declining does not close, limit or degrade the app.
In other countries
Ads are shown without a prior request, on Toralle’s legitimate interest in sustaining the free plan. The consent platform we use does not offer that request outside the regions above, and we would rather say so than promise you a choice we do not give.
Changing your mind, or objecting
Where the consent request exists, you can review or withdraw your choice at any time in Settings → Ad privacy inside the app. Where there is no request, that section does not appear.
You can object at any time, in three ways: write to support@papira.app; reset or delete the advertising identifier in your phone’s settings, under Settings → Google → Ads; or subscribe to any paid plan, which removes advertising immediately. Objecting does not limit your use of Papira.
Legal basis
Where we ask for your consent, access to the information stored on your device rests on that consent, required by Article 5 of Portuguese Law 41/2004, which transposes Directive 2002/58/EC. The processing of the data so obtained, including to personalise ads, likewise rests on your consent — Article 6(1)(a) GDPR. Both are collected in the request described above and can be withdrawn at any time, as easily as they were given. In other countries, the processing rests on Toralle’s legitimate interest in sustaining the free plan. In Brazil, that basis is Article 7, item IX, read with Article 10 of the LGPD.
System advertising profiles
Papira has deliberately removed the Android permissions that allow advertising profiles to be built from your usage (Topics and Attribution). We do not need them and we do not want them.
8. Reminders and notifications
Papira's reminders are local notifications: they are scheduled by the phone itself and do not pass through any server of ours.
There is a difference between the platforms, and we would rather state it than hide it:
- On Android, no document title leaves the encrypted database. The notification is rebuilt at the moment of delivery, by reading the encrypted database.
- On iOS, the system does not allow that design: the notification text has to be handed to the device's notification system when the reminder is scheduled. It stays on your device, but outside our encrypted database.
In Papira's Settings you can enable the "Hide details" option, which makes notifications not show the document title.
9. Permissions the app asks for
Papira was designed to ask for the minimum. On first launch we ask for absolutely nothing.
| Permission | When | If you refuse |
|---|---|---|
| Camera | On Android, never — we use the system camera, which means the permission is not needed. On iOS, at the moment you take the photograph. | You cannot photograph documents; everything else works. |
| Photographs and files | None on Android — the system picker returns the chosen file without giving access to the gallery. | You cannot import files; everything else works. |
| Notifications | Only at the moment you create the first reminder. Never at launch. | You do not receive reminders; everything else works. |
| Biometrics | Only if you enable biometric unlocking. | You use the PIN. |
| Internet | Declared by the app. Used only for the free plan's advertising and for what the store handles. | On paid plans there is no advertising traffic. |
| Advertising identifier | Only on the free plan, and only after the consent request where applicable. | You can reset or delete it in your phone's settings. See section 7. |
10. Information about other people
Papira lets you create profiles to organise information about people in your household — spouse, children, parents.
That information stays encrypted on your device, under the same conditions as everything else. There are no invitations, no accounts for family members and no sharing between phones: it is you organising information on your own device, for personal and family use.
10.1 Contacts of the people who receive your dossiers
When you prepare a dossier, the app lets you note who you gave it to: name, company, email, phone, notes and date. It exists so that, months later, you know which documents you handed over and to whom.
Those contacts are information about other people and are subject to exactly the same regime as everything else: they are encrypted on your device and never reach us. We do not use them, we do not send them to anyone and we have no technical means of accessing them. If you create a backup, they go into the .papira file, encrypted with the password only you know.
Noting a contact in Papira does not send anything to that person. Sharing the dossier is done through your own phone’s share sheet, using whichever app you choose.
10.2 Personal use and professional use
It is you who decides what information you record, and about whom. We have no access to that information and no technical means of obtaining it, so we cannot verify it or intervene in it.
As long as your use stays within your personal and family life, the processing is covered by the household exemption in Article 2(2)(c) GDPR, and to that extent the Regulation does not impose controller obligations on you.
That exemption no longer applies to anyone using Papira in a professional or economic context — for example, organising the documents of a company or organisation on the Professional plan. In that case you are the controller in relation to the people concerned, and it falls to you to comply with the GDPR: to inform them, to have a lawful basis for the processing and to answer their requests. We still receive nothing, but that responsibility belongs to whoever uses the app.
The Professional plan is for organising documents of companies or organisations — licences, insurance, certificates, contracts. Papira was not designed to manage information about clients, patients, service users or employees, and it does not have the features such processing would require.
11. Minimum age
Papira is intended for people aged 18 and over, and that is how it is declared in the app stores. We do not collect any information about the age of those who use it, because we do not collect any information.
12. International transfers
The data described in section 4 is processed in the European Union. If any of our providers processes data outside the European Economic Area, it will do so under a transfer mechanism valid under Chapter V GDPR, in particular standard contractual clauses approved by the European Commission.
As for the free plan's advertising, any transfer outside the European Economic Area is carried out by Google Ireland Limited under the mechanisms provided in Chapter V of the GDPR; the conditions are set out in the Google policy referred to in section 7. Toralle does not transfer that data and has no means of transferring it — but it is a joint controller for its collection, as explained in that section.
The data on your device is not transferred anywhere, because it does not leave the device.
13. Your rights
Under Articles 15 to 22 GDPR, you have the right to ask us for access to your data, its rectification, its erasure, the restriction of processing and data portability, as well as the right to object to processing based on our legitimate interests.
These rights apply to the data described in section 4 — your support messages and the access logs. That is the only data of yours that we hold. As for advertising data, you can exercise your rights with either of us — Toralle or Google. In practice it is Google that has the technical means to access that data and answer you; if you write to us, we forward your request and follow it up. Where consent is asked for, it can be withdrawn at any time; in other countries, you can object to the processing. Both routes are described in section 7.
As for the content in the app, there is no request to address to us: access is immediate and complete on your device, and deletion is done by deleting the item or uninstalling the app. We cannot hand over, correct or delete what we never received.
To exercise any of these rights, write to support@papira.app. We reply within one month, extendable under Article 12(3) GDPR.
Complaints. If you consider that we have processed your data improperly, you may lodge a complaint with the supervisory authority. In Portugal, this is the Comissão Nacional de Proteção de Dados (CNPD) (the Portuguese data protection authority) — www.cnpd.pt. If you live in another Member State, you may go to the authority in your country.
14. Users in Brazil
If you are in Brazil, the LGPD, the Brazilian General Data Protection Law (Lei no. 13.709/2018), also applies to you.
In essence: what the user records stays on their device, encrypted, under their exclusive control, and never reaches us. When a user records information about themselves and their family for exclusively private, non-economic purposes, that processing falls outside the scope of the LGPD, under its Article 4, item I. The only exception is the free plan's advertising, described below.
If you use Papira in a professional or economic context, that exclusion no longer applies and you become the controller of that processing, with the obligations the LGPD places on you.
As for the data described in section 4 — support messages and access logs — Toralle acts as controller and you are entitled to exercise the rights set out in Article 18 LGPD: confirmation that processing exists, access, correction, anonymisation or deletion, portability, information about sharing, and withdrawal of consent where applicable.
Channel for communication with the data subject: support@papira.app. This is where you exercise your rights and raise questions about the processing.
Advertising. On the free plan, Papira shows advertising supplied by Google AdMob. The processing rests on Toralle’s legitimate interest in sustaining the free plan, under Article 7, item IX, and Article 10 of the LGPD. You are not asked for prior consent: the consent platform we use does not offer it in this region. You can object at any time by the three routes set out in the advertising section. Objecting does not limit your use of Papira, and any paid plan removes advertising immediately.
The competent authority is the Autoridade Nacional de Proteção de Dados (ANPD) (the Brazilian data protection authority) — www.gov.br/anpd.
15. Security
We maintain appropriate technical and organisational measures to protect the data described in section 4, including restricted access, strong authentication and automatic deletion within the periods indicated.
As for the data on your device, the protection is described in section 3. There are two things that depend on the user and that we cannot make up for: keeping the operating system updated and enabling the device lock — and, if you want an additional layer, Papira's own PIN.
If a personal data breach occurs that may involve a high risk to your rights, we will notify you, and we will notify the supervisory authority under Articles 33 and 34 GDPR.
16. Changes to this policy
If we change this policy, we publish the new version on this page with a new date. If the change is substantial — for example, if we ever start processing data that we do not process today — we will give prominent notice in the app and on the website, with reasonable advance warning.
Previous versions remain available on request.
Version 1.1, of 25 August 2026. The app now includes advertising on the free plan, supplied by Google AdMob, and declares the internet access permission. Section 7, Advertising, was added, and sections 2, 4, 6, 9, 12 and 13 were made more precise. Nothing you keep in the app has started leaving your device.
Version 1.2, of 25 August 2026. Legal review of v1.1: the allocation of responsibility for the collection of advertising data now describes joint controllership with Google (sections 7, 12 and 13); consent is now described as two distinct choices, with both legal bases (section 7); section 14 now addresses advertising; and references to platforms the app does not yet support were removed.
Version 1.3, of 26 August 2026. Section 10 now describes the third-party contacts you can note in the dossier delivery record — name, company, email and phone — which stay encrypted on your device and never reach us, and distinguishes personal from professional use, with the household exemption in Article 2(2)(c) GDPR. Section 3.1 now lists dossiers and the delivery record, and section 14 adds the equivalent note on Article 4(I) LGPD. Section 7 now lists the four categories the AdMob SDK collects, including app interactions and performance diagnostic information, which were missing and which the Play Data safety form requires to be declared.
Version 1.4, of 29 August 2026. Legal review. Section 7 now distinguishes where we ask for your consent — the European Union, the United Kingdom, Switzerland and the US states covered — from other countries, where ads are shown without a prior request, on Toralle’s legitimate interest in sustaining the free plan, with three routes to object. Section 14 no longer asserts a consent that is not asked for in Brazil, and names the basis in Article 7, item IX, and Article 10 of the LGPD. The two missing SDK collections are added — app interactions and diagnostic information — along with the note on measurement components. Section 2 now names Firebase Analytics and Crashlytics instead of “Firebase”.
Version 1.5, of 2 September 2026. Section 3.1 now lists the bank card details you may choose to record — number, expiry date, security code, name on the card and issuer — encrypted on the device, and states that the security code is not included in the backup. No other section changes: the card details do not leave the device, and there is no new purpose and no third party involved.
17. Contact
support@papira.app Toralle, Lda. — Rua da Cruz da Argola, n.º 742, trás, Mesão Frio, 4810-225 Guimarães, Portugal
The European Portuguese version of this policy is the reference version. The other translations are made available to make reading easier.