Privacy Policy
Last Updated: January 31, 2026
At PaperGym, we take your privacy seriously. This Privacy Policy explains how we collect, use, share, and protect your personal information when you use our service. We comply with the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
1. Information We Collect
Account Information
When you create an account through our authentication provider Clerk, we collect:
- Email address
- Name (if provided)
- Profile information you choose to provide
Code Submissions and Progress Data
To provide the learning experience, we store:
- Your code submissions for each drill
- Drill completion status and progress
- Points earned and achievements
- Quiz responses and answers
Usage Data
We collect analytics data through Vercel Analytics to improve our service:
- Pages visited and time spent on the platform
- Device type, browser, and operating system
- General location data (country/region only, not precise location)
- Referral sources and navigation patterns
Payment Information
Payment processing is handled securely by Stripe. We do not store your credit card numbers or complete payment details. We only receive:
- Subscription status (active, cancelled, etc.)
- Last four digits of payment method (for display purposes)
- Billing email address
- Transaction history
Cookies and Tracking Technologies
We use cookies and similar technologies for:
- Essential Cookies: Required for authentication, security, and core functionality
- Analytics Cookies: Help us understand how users interact with our platform (optional, requires consent)
- Preference Cookies: Remember your settings like theme preference
2. How We Use Your Information
We use the collected information to:
- Provide the Service: Enable you to access drills, track progress, and learn from research papers
- Process Payments: Manage subscriptions and billing through Stripe
- Improve Features: Analyze usage patterns to enhance the learning experience and develop new features
- AI-Powered Hints: Your code submissions may be sent to Google Gemini to generate personalized hints and feedback
- Send Important Updates: Notify you about changes to your account, service updates, or security alerts (we do not send marketing emails without explicit consent)
- Security and Fraud Prevention: Protect against unauthorized access and abuse of the platform
3. Data Sharing and Third Parties
We only share your data with trusted third-party service providers who help us operate PaperGym:
Clerk (Authentication)
Manages user authentication and account security. Processes email addresses and profile information.
Stripe (Payment Processing)
Handles all payment transactions securely. We never see or store your full payment card details.
Google Gemini (AI Services)
Provides AI-powered hints and feedback. Your code submissions may be sent to Gemini for analysis (without identifying information).
Vercel (Hosting and Analytics)
Hosts our platform and provides privacy-friendly analytics to help us understand usage patterns.
We do not sell, rent, or trade your personal information to third parties for marketing purposes. We may share aggregated, anonymized data that cannot identify you personally.
4. Data Retention
- Active Accounts: We retain your data indefinitely while your account is active
- Deleted Accounts: When you delete your account, we permanently remove your personal data within 30 days, except where we are required by law to retain certain information
- Backup Systems: Data may persist in backup systems for up to 90 days after deletion from production systems
5. Your Rights (GDPR & CCPA)
Depending on your location, you have the following rights:
All Users
- Access: Request a copy of all personal data we hold about you
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your account and personal data
- Data Portability: Export your code submissions and progress data in a machine-readable format
EU Users (GDPR Rights)
- Right to Object: Object to processing of your personal data for certain purposes
- Right to Restrict Processing: Request limitation of how we process your data
- Right to Withdraw Consent: Withdraw consent for optional data processing at any time
California Users (CCPA Rights)
- Right to Know: Know what personal information we collect and how it's used
- Right to Delete: Request deletion of personal information
- Right to Opt-Out: Opt-out of the sale of personal information (note: we do not sell personal information)
- Non-Discrimination: We will not discriminate against you for exercising your privacy rights
To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days.
6. Cookies and Tracking
You can control cookie preferences through our cookie consent banner or your browser settings:
- Essential Cookies: Cannot be disabled as they are necessary for the platform to function (authentication, security)
- Analytics Cookies: Can be disabled through the cookie banner. This will not affect your ability to use PaperGym
- Browser Settings: Most browsers allow you to refuse cookies or alert you when cookies are being sent
Note that disabling essential cookies may prevent you from using certain features of PaperGym.
7. Security
We implement industry-standard security measures to protect your data:
- All data transmission is encrypted using HTTPS/TLS
- Authentication is managed by Clerk with industry-leading security practices
- Payment processing uses Stripe's PCI-compliant infrastructure
- Regular security audits and updates
- Access controls and monitoring to prevent unauthorized access
While we strive to protect your data, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security but continuously work to maintain the highest standards.
8. Children's Privacy
PaperGym is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately at [email protected], and we will delete it promptly.
9. International Data Transfers
PaperGym is hosted on Vercel's global infrastructure. Your data may be transferred to and processed in countries outside of your residence, including the United States. We ensure that appropriate safeguards are in place to protect your data in accordance with this Privacy Policy and applicable laws.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make significant changes, we will:
- Update the "Last Updated" date at the top of this page
- Notify you via email if you have an active account
- Display a prominent notice on the platform
Your continued use of PaperGym after changes become effective constitutes acceptance of the updated Privacy Policy.
11. Contact Us
If you have questions about this Privacy Policy or want to exercise your privacy rights, please contact us:
Email: [email protected]
Response Time: We aim to respond to all privacy requests within 30 days
By using PaperGym, you acknowledge that you have read and understood this Privacy Policy.