Privacy policy
Last updated 15 September 2026
PaperFlight (“the console”, “we”), at paperflight.app, is a private tool for the people its owner invites. It helps those people write, review and publish social posts, and see how the posts did. This page says what the console stores, why, who can see it, and how it is protected. Contact: the contact page.
What we store, and why
- Your account — a username or email and a salted password hash, so you can sign in. Sign-ins are recorded (when, from which account) in the console’s activity ledger.
- Your workspace — the brand profile and guidelines you write, the posts and drafts made in it, notes saved to its memory, the agents you set up, your conversations with the Assistant, and the activity ledger of what was done. A workspace is visible only to the people the owner adds to it.
- Connected accounts — when you connect a social account (through PostForMe), a Gmail mailbox or Google Analytics, we keep only what is needed to act on your behalf: account identifiers, the account’s email address, and access tokens or keys, stored encrypted. We never store your passwords for those services.
- Post performance — the numbers the social platforms report for your posts (views, likes, comments, shares) and, if you connect Google Analytics, the visits your posts sent to your site.
- Run logs — when an agent or the Assistant works for you, the console keeps a log of the steps it took, with a short excerpt of what each step read or returned, so you can audit what was done. If a step read an email, an excerpt of that email is in the log.
- Model keys — API keys for the AI providers you or the owner add, stored encrypted and used only to run the writing and image tools you ask for.
- Contact and beta requests — what you type into the contact form (name, email, company, site, message), kept until the owner has replied and deletes it.
Google user data
Nothing from Google is accessed unless you choose to connect a Google account. When you do, the console asks only for the scopes the feature needs, and uses the data only for that feature.
What is accessed
- Your Google account email address (scopes
openid,email) — stored so the console can show which Google account is connected. - Google Analytics, read-only (scope
analytics.readonly) — the list of Analytics properties your account can read, so you can pick one; then reports for that property: sessions, engaged sessions, key events, page views, users, sources and landing pages. Nothing is written to your Analytics property. - Gmail (scope
gmail.modify) — messages, threads, attachments and labels in the mailbox you connect. With this scope the console can search and read mail and attachments, create drafts, send and reply, change labels, and move messages to the trash. It cannot permanently delete mail or change your Gmail settings. - Google Calendar (scope
calendar) — events in the calendar you connect, so that events can be read and created on your behalf.
How it is used
- Analytics numbers are used only to show, on your Performance and Your site pages, what your posts brought to your website, and to let the console recommend where to post next.
- Gmail and Calendar are used only by the agents and the Assistant you set up, to do the mail and calendar tasks you give them, within the tool permissions and the review mode you choose. In “human in the loop” mode nothing is sent or created until you approve it.
- Google user data is used only to provide and improve these user-facing features. It is never used for advertising, never sold, never given to data brokers or resellers, and never used to build profiles of you.
- Google Workspace APIs are not used to develop, improve, or train non-personalized AI and/or ML models. The AI models the console uses are the providers’ models as they are; your data is sent to them only to produce the specific reply, draft or report you asked for and is not used to train them.
Who receives it
- The people in your workspace — a draft, reply or report made from Google data is visible to the members of the workspace it was made in, and to no one else.
- The AI provider configured for your workspace (OpenAI, Anthropic or Google, whichever key is set) — when an agent or the Assistant works on an email, a calendar event or your Analytics numbers, that content is sent to the provider to produce the result you asked for, under the provider’s API terms.
- Our hosting providers — Cloudflare (application, encrypted tokens, files) and Neon (database) store the data on our behalf and do not use it.
We do not transfer or disclose Google user data to anyone else, and never for a purpose other than the ones above — except where the law requires it, or to investigate abuse or a security problem.
The console’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How long it is kept
- Access tokens are kept, encrypted, until you disconnect the account or the owner removes the workspace; disconnecting deletes the token at once and revokes the console’s access at Google.
- Analytics numbers are kept alongside the posts they belong to, for as long as those posts are in your workspace. A site overview is held in memory for ten minutes and not stored.
- Email and calendar content is not copied into the console except for the excerpts in run logs and Assistant conversations described above; those are deleted when you delete the run, the agent or the conversation, or when the owner removes the workspace.
You can disconnect at any time from Setup › Connections, and you can also revoke the console’s access from your Google account permissions.
How we protect it
- All traffic to and from the console, and between the console and Google, PostForMe, the AI providers and the database, is encrypted in transit (TLS).
- Google refresh tokens, Analytics keys, model keys and platform secrets are encrypted at rest with a key held outside the database. Passwords are stored only as salted hashes.
- Access is limited to the members of a workspace; every request is authenticated, and the owner can revoke any account at once. Agents get only the tools you grant them, and outward actions can be held for your approval.
- Every outward action and every sign-in is recorded in an append-only ledger.
Who processes the data
The console runs on Cloudflare (application and file storage) and Neon (database). Publishing goes through PostForMe. Writing and image generation go to the AI provider whose key is configured for you (for example OpenAI, Anthropic or Google), and only the text and images you ask it to work on are sent. Each of these providers processes data under its own terms.
Analytics on this website
The public pages of this website (the landing page, About, Contact, Privacy, Terms and the sign-in page) use two counters: Google Analytics, which sets Google’s analytics cookies and sends page views to Google under Google’s own privacy terms, and Umami, a self-hosted, cookie-free page counter. Nothing behind the sign-in — the console and your workspace — is measured either way.
Retention
Your workspace data stays until you delete it or the owner removes the workspace. Rendered graphics and uploads are kept while a post or draft points at them; the owner may set a retention period after which unreferenced files are deleted. The activity ledger is append-only and may be pruned after a retention period the owner sets. Google data is kept as described in the section above.
Your choices
- Edit or delete your brand, drafts, notes, agents, runs and conversations yourself, at any time.
- Disconnect any connected account from Setup › Connections.
- Ask the owner to delete your account and workspace, or write to us; deletion removes every row the workspace owns, including tokens, logs and Google data.
Changes
If this page changes, the date above changes with it. If we change how the console accesses or uses Google user data, signed-in users are told in the console before the change takes effect.