Quick Read
- We collect what we need to run the Service: account info (email, name, org), your job inputs and outputs, and operational telemetry (timings, error codes, IP, browser).
- We do not read your sequences or designs to train foundation models without your explicit, separately-given opt-in.
- We use a small, named list of subprocessors (Supabase, Stripe, Modal, Resend, Vercel, Cloudflare, Sentry) for hosting, payments, compute, email, and observability.
- You have rights to access, correct, delete, port, and (for EU/UK/Brazil/etc.) object to processing. Email privacy@papercrane.bio to exercise them.
- We retain your job data for 7 days (Free), 90 days (Pro), or 365 days (Frontier) unless you delete it sooner or your Order Form sets a different period.
- We use essential cookies and privacy-friendly analytics (Plausible) that does not set cross-site tracking cookies and does not collect PII. See our Cookie Policy.
- We don't sell your personal information. We don't share it with advertisers.
1. Who we are and how to reach us
Controller: Paper Crane, Inc., a Delaware corporation, operating from Atlanta, GA, USA.
- Privacy contact: privacy@papercrane.bio
- Security contact: security@papercrane.bio
- General contact: hello@papercrane.bio
If you are in the EU/EEA or the UK, you can also contact our representative at the same address until we appoint a local Article 27 / UK GDPR representative; we will publish that representative's contact details here when appointed.
2. What we collect
2.1 Information you provide
- Account info. Email, name, organization, password hash (we use bcrypt/argon2 via Supabase Auth and never see your plaintext password), profile picture if you set one.
- Billing info. Plan, billing email, billing address, last 4 digits of card and card brand. Full card numbers are handled by Stripe and never touch our servers.
- Customer Content. Sequences, target structures (PDB IDs and uploaded files), hotspot definitions, parameter sets, design outputs, notes, and any files you attach to a job or design.
- Communications. Support emails, in-app messages, survey responses, scheduling, and anything you send to our team.
2.2 Information generated by your use
- Job logs. Tool name and version, queue time, GPU type, duration, success/failure code, error messages, and resource usage. These power the dashboard and the public benchmark.
- Designs as inputs/outputs. Hashes, paths, metric scores (pLDDT, ipTM, ipSAE, etc.), and links between them. We treat the contents of designs as Customer Content (see §2.1).
- Auth and session events. Sign-ins, sign-outs, password resets, MFA events, API key issuance and revocation.
- Device and connection. IP address, user-agent, approximate region (city-level, derived from IP), referrer URL, time zone.
- Product analytics. Page views, navigation events, feature usage. We use Plausible Analytics, which is privacy-friendly, EU-hosted, cookieless, and does not collect personal information or set cross-site identifiers.
2.3 Information from third parties
- OAuth providers (Google, GitHub, ORCID if you choose them) give us your email, name, avatar, and a stable user ID. We do not get your password.
- Stripe sends us payment status, subscription state, invoice IDs, and the metadata above.
- Email-deliverability vendors (e.g., Resend) tell us whether our messages were delivered, bounced, or marked as spam.
We do not buy data from data brokers and we do not enrich your profile with marketing data.
3. Why we use it (legal bases)
| Purpose | Categories | Lawful basis (GDPR) |
|---|---|---|
| Provide the Service | Account, Customer Content, Job logs | Contract (Art. 6(1)(b)) |
| Bill you and prevent fraud | Billing, IP, device | Contract + legitimate interest (b, f) |
| Secure the Service | IP, device, auth events, job logs | Legitimate interest + legal obligation (c, f) |
| Improve via aggregated telemetry | Aggregated job logs, error patterns | Legitimate interest (f) |
| Transactional email | Email, name, job state | Contract (b) |
| Marketing email | Email, name | Consent (a) — unsubscribe any time |
| Comply with biosecurity / export law | Account, Customer Content metadata | Legal obligation (c) |
| Defend legal claims | As reasonably necessary | Legitimate interest (f) |
4. What we DO NOT do
- We do notsell your personal information. We do not "share" it for cross-context behavioral advertising under the CCPA/CPRA.
- We do not read your sequences, structures, or designs to train foundation models, fine-tune model weights, or build new tools, unless you explicitly opt in through a labeled contributor program with a published data-use agreement.
- We do not make automated decisions that produce legal or similarly significant effects on you.
- We do not use your Customer Content to advertise to you.
- We do notshare Customer Content with other Paper Crane customers, ever, except where you've explicitly chosen to publish or share it.
5. Subprocessors
We rely on a small set of subprocessors. Each is bound by a written data-processing agreement with appropriate safeguards (SCCs for EU transfers, where relevant).
| Subprocessor | Purpose | What it gets | Region |
|---|---|---|---|
| Supabase | Postgres, auth, object storage | Account info, Customer Content, sessions | US (multi-region) |
| Stripe | Payments, subscriptions, invoices | Billing email, name, payment method, plan | US/EU |
| Modal | Serverless GPU compute | Customer Content during job execution, job logs | US |
| Vast.ai (where used) | Spot GPU compute | Customer Content during job execution, job logs | US/EU |
| Resend | Transactional + newsletter email | Email address, name, message content | US/EU |
| Vercel | Web/API hosting, edge runtime | IP, user-agent, request metadata | Global edge |
| Cloudflare | DNS, CDN, DDoS, WAF | IP, user-agent, request metadata | Global edge |
| Sentry | Error + performance monitoring | Error stacks, request URL, pseudonymous user ID | US/EU |
| Plausible | Privacy-friendly site analytics | Aggregated, cookieless event counts; no PII | EU |
If we add or change a subprocessor, we will update this table and, for paid customers, give 30 days' notice via email or in-app banner before the change takes effect, so you can object.
6. Cookies, analytics, and tracking
We use a minimal set of cookies and similar technologies. The full list and purpose is in our Cookie Policy. In summary:
- Strictly necessary cookies — auth/session, CSRF, load balancing. Required to use the Service.
- Privacy-friendly analytics — Plausible. Cookieless, no cross-site tracking, no PII. Aggregated only.
- Preferences — your dashboard layout, theme, accepted cookie banner state. Stored in
localStorage, not transmitted.
We do not use Google Analytics, Meta Pixel, TikTok Pixel, or any third-party advertising cookies.
You can manage your preferences any time at /privacy-choices or via the cookie banner that appears on your first visit.
7. International transfers
Our primary infrastructure is in the United States. If you access the Service from outside the U.S., your information will be transferred to and processed in the U.S. and other countries where our subprocessors operate. We rely on:
- EU Standard Contractual Clauses (2021/914) with each subprocessor receiving personal data from those regions.
- The EU-U.S. Data Privacy Framework for subprocessors that have certified to it.
- Supplementary measures where appropriate (encryption in transit, encryption at rest, access controls).
You can request a copy of the relevant SCCs by emailing privacy@papercrane.bio.
8. Retention
| Data | Retention |
|---|---|
| Account info | Active account + 30 days after deletion |
| Customer Content (Free tier) | 7 days rolling, then auto-deleted |
| Customer Content (Pro tier) | 90 days rolling |
| Customer Content (Frontier tier) | 365 days rolling, or per Order Form |
| Job logs (operational) | 90 days |
| Aggregated, anonymized benchmark data | Retained indefinitely (no PII) |
| Billing and invoice records | 7 years (tax/audit) |
| Support tickets | 2 years after closure |
| Security/audit logs | 1 year |
| Backup snapshots | 30 days, then overwritten |
Deletion requests under §9 will accelerate these timelines, subject to legal-hold exceptions.
9. Your rights
Depending on where you live, you have some or all of the following rights. We honor all of them globally as a baseline.
- Access — get a copy of the personal information we hold about you.
- Correction — fix anything inaccurate.
- Deletion — ask us to delete your account and Customer Content. We will, except where retention is required by law (e.g., tax records).
- Portability — get a machine-readable export (JSON or CSV) of your account info, designs, and job history.
- Restriction / objection — ask us to stop or limit certain processing, particularly direct marketing and profiling.
- Withdraw consent — for any processing based on consent, withdraw it at any time without affecting prior lawful processing.
- Non-discrimination(CCPA/CPRA) — we won't discriminate against you for exercising your rights.
- Lodge a complaint— you can complain to your local data-protection authority. We'd appreciate a chance to fix it first.
To exercise any of these, email privacy@papercrane.bio from the email address on your Account, or use the in-app Privacy choices page. We respond within 30 days (extendable by 60 days for complex requests under GDPR Art. 12(3)).
10. Security
- Encryption in transit (TLS 1.2+) for all traffic.
- Encryption at rest for our database and object storage (AES-256 via Supabase / Vercel KV / S3-compatible storage).
- Access controls — least-privilege IAM, MFA for engineering staff, audit logs.
- Network isolation — production traffic is firewalled; engineering access goes through a bastion or short-lived credentials.
- Vulnerability management — dependency scanning, periodic external penetration tests, a public security contact, and a coordinated-disclosure policy.
- Incident response — we will notify affected users and regulators within the timelines required by GDPR Art. 33–34 and applicable U.S. state laws.
We are not yet SOC 2 attested as of the Effective Date. We are working toward it. For our current security questionnaire, email security@papercrane.bio.
11. Children
The Service is not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, email privacy@papercrane.bio and we will delete it.
12. Changes to this Policy
We may update this Policy. The Effective Date at the top reflects the most recent version. For material changes, we will notify Account holders by email and post a banner in-app at least 30 days before the change takes effect. Continued use after that date is acceptance of the updated Policy.
13. Region-specific addenda
13.1 California (CCPA/CPRA)
The categories of personal information we have collected, the purposes for which they are used, and the categories of recipients are described in §§2, 3, and 5. We do not sell or share personal information. California residents have the rights listed in §9. To exercise rights, email privacy@papercrane.bio. Authorized agents may submit requests on your behalf with written authorization.
13.2 European Economic Area / United Kingdom / Switzerland
The data controller is Paper Crane, Inc. The legal bases for processing are listed in §3. Transfers outside the EEA are governed by the safeguards in §7. You have the right to lodge a complaint with your supervisory authority (e.g., the Irish DPC, the UK ICO, the Swiss FDPIC).
13.3 Brazil (LGPD)
Our processing of personal data of individuals located in Brazil follows the LGPD's requirements. Data-subject rights mirror §9.
14. Contact
- Privacy: privacy@papercrane.bio
- Security: security@papercrane.bio
- General: hello@papercrane.bio
- Mail: Paper Crane, Inc., Atlanta, GA, USA
Thanks for trusting us with your science.