1. Overview
PaperBox is an offline-first document scanner and vault. It is designed around one idea: the documents you scan or import are yours, and the app's job is to store and organize them locally, not to move them anywhere. This policy explains what data the app touches, where it lives, and what — if anything — ever leaves your device.
We don't require an account, we don't operate servers that store your files, and we don't collect analytics by default. If any of that changes in a future version, this page will change with it.
2. What we don't collect
- No accounts. PaperBox doesn't ask for an email address, phone number, or password, and it doesn't create a profile for you anywhere.
- No analytics by default. The app doesn't send usage events, crash telemetry, or behavioral data to a third party out of the box.
- No ad tracking. There's no advertising SDK bundled with the app, and your document activity isn't used to build a profile for ads.
- No document content read by us. We — the developers — don't have a channel to see what you scan, import, name, or tag. There's no server in the loop to see it on.
3. What's stored on your device
Everything you add to your vault — scanned pages, imported files, folders, tags, favorites, and pins — is written to your device's local app storage. This includes:
- Files and folders. Each file's name, type, size, folder membership, tags, and favorite or pinned status.
- Settings. Your theme choice, whether previews are hidden, and whether App Lock is turned on.
This data stays in the app's private, sandboxed storage area on iOS or Android. Other apps can't read it, and it isn't synced to a cloud service by PaperBox itself.
4. Camera and photo access
PaperBox asks for camera access so its built-in scanner can capture pages and turn them into images or PDFs. The camera is only opened when you tap Take Picture or Create PDF — it isn't accessed in the background. Photos you import from your library are copied into your vault the same way a manually scanned page would be; the original stays wherever it already lived.
Captured and imported images are processed and stored locally. They aren't uploaded anywhere as part of scanning, cropping, or PDF creation.
5. Face ID and device authentication
App Lock is optional. When you turn it on, PaperBox asks your device's operating system to confirm your identity with Face ID, Touch ID, or your passcode before the vault opens. That authentication happens entirely inside your device's secure hardware — PaperBox asks the OS a yes-or-no question ("was this the owner of the device?") and never receives, stores, or has access to your biometric data itself.
If your device doesn't support secure local authentication, App Lock is automatically disabled rather than falling back to a weaker method.
7. Import and the handshake link
You can bring files into PaperBox in two ways: by picking a previously exported file, or by using a QR "handshake" to move a vault from one device to another. The handshake is generated on the sending device and read directly by the receiving device's camera — it's a transfer between two devices you control, not a hop through a hosted service run by us.
8. Permissions this app requests
For transparency, here are the exact permission descriptionsPaperBox declares to iOS and Android, and nothing more:
PaperBox does not request access to your location, contacts, microphone, or health data.
9. Retention and deletion
Your files stay in your vault for as long as you keep them. Deleting a file or folder inside the app removes it from local storage. Uninstalling PaperBox removes the app's entire local storage, including your vault, following your device's normal app-data rules — so it's worth exporting anything you want to keep before you uninstall.
10. Children's privacy
PaperBox is not directed at children, does not knowingly collect personal information from children, and — since the app doesn't collect information off-device in the first place — has no server-side data to worry about from any user, including children.
11. Changes to this policy
If PaperBox ever changes what it collects or how it handles your data — for example, by adding an optional cloud backup — this page will be updated first, with a new "last updated" date at the top, before that change ships.
12. Contact
Questions about this policy or how PaperBox handles data can be sent through the Contact option in the app's Settings tab.
Back to security overviewThis page describes PaperBox's data-handling practices in plain language. It isn't a substitute for legal advice, and if you're operating this app for a business or in a regulated context, it's worth having it reviewed against the specific laws that apply to you (such as GDPR or CCPA).