Paperwell

Privacy Policy

What Paperwell collects, why, who it is shared with, and how to have it deleted.

Effective 5 October 2026 · Last updated 5 October 2026

AppPaperwell: PDF Scanner & Sign (iPhone)
DeveloperThe Apptor
App Store ID6818315145
Privacy contactcontact@theapptor.com
The short version
  • Your documents stay on your iPhone. Scanning, cleaning up pages, text recognition (OCR), signing and PDF creation all happen on the device. We never receive your scans, their text or your signatures.
  • There is no account. Paperwell never asks you to sign in.
  • No ads, no tracking, no selling. The app contains no advertising or attribution SDKs, does not use the advertising identifier, and we never sell or rent your data.
  • What does leave your device: anonymous usage and crash reports, your purchase status, and anything you choose to send us through Contact support.

What stays on your iPhone

Everything you scan or import, the pages' cleaned-up images, recognised text, your saved signatures, folder names and settings are stored only in Paperwell's private storage on your device. We have no copy and no way to see them. Like other app data, they are included in your iPhone's own backup (iCloud Backup or your computer), which Apple or your computer handles. Deleting the app deletes them from the device.

Optional: copies in iCloud Drive

If you turn on Save copies to iCloud Drive in Settings, Paperwell saves a PDF of each document into your own iCloud Drive (in a folder called Paperwell). Those copies are stored by Apple under your Apple Account and Apple's privacy policy. We cannot access your iCloud Drive. Turning the setting off stops new copies; you can delete existing ones in the Files app.

What leaves your iPhone, and why

1. Usage and crash reports (Google Firebase)

To understand which features are used and to fix crashes, the app sends Google Firebase Analytics and Crashlytics:

These reports never contain your documents, their text, file names, signatures or your name. Paperwell uses the version of Firebase Analytics that does not collect the advertising identifier, and the data is not used for advertising or linked with data from other companies' apps. Google processes it on our behalf. Analytics events are kept for no longer than 14 months; crash reports for 90 days.

2. Purchases (Apple and RevenueCat)

Payments are handled entirely by Apple; we never see your card or payment details. To know whether you have Premium, the app uses RevenueCat, which receives your App Store purchase receipts, a random anonymous ID created by the app, and basic device information (app version, iOS version, country). We keep purchase records for as long as needed to provide what you bought and to meet tax and accounting duties.

3. When you contact support

If you use Contact support in the app or the form on this website, we receive:

No documents or scans are ever attached. The request is sent over an encrypted connection to our server, saved in our database and delivered to our support inbox by email — all run on Cloudflare. To stop abuse, we also keep a one-way hash of your IP address (not the address itself) for 24 hours to limit how many messages can be sent in a short time.

We use these details only to answer you and to fix the problem you report. We keep support messages for up to two years so we can follow up on repeat problems, then delete them. You can ask us to delete yours sooner.

Who receives data

Google (Firebase Analytics, Crashlytics)Usage events and crash reports, as described above
RevenueCatPurchase receipts and an anonymous ID, to manage Premium
ApplePayments, App Store downloads, and iCloud Drive copies if you turn them on
CloudflareHosts this website and our support form, stores support requests and emails them to us

Each of these companies acts as our service provider (processor) and may only use the data to provide its service to us. We do not share data with anyone else unless the law requires it. Some of these providers are based in the United States; where data moves outside the UK or EU, it is protected by the providers' standard contractual clauses or equivalent safeguards.

Why we are allowed to use it

For people in the UK and EU, the legal bases are: performing our contract with you (providing Premium you bought, answering your support request) and our legitimate interest in keeping the app working and improving it (anonymous usage and crash reports), which we have balanced against your privacy by never collecting your documents or identity for these purposes.

Your choices and rights

Depending on where you live (for example under the UK GDPR, EU GDPR or California law), you may have the right to access, correct, delete or object to the use of your personal data, and to complain to your local data-protection authority (in the UK, the Information Commissioner's Office). We reply to requests within one month.

Children

Paperwell is a general-audience productivity app and is not directed at children. We do not knowingly collect personal information from children under 13 (or under 16 in the EU). If you believe a child has sent us their details through the support form, contact us and we will delete them.

Security

Your documents are protected by iOS's own data protection on your device, and by Face ID if you turn on the app lock. Everything Paperwell sends over the internet is encrypted in transit, and support requests are stored in a database that only our server can access.

Changes to this policy

If we change what Paperwell collects, we will update this page and the date at the top before the change reaches the app. Significant changes will also be noted in the App Store release notes.

Contact

Questions about privacy: contact@theapptor.com, or use the support form.