Papyrus · Privacy Policy Home Download
Privacy Policy

Your library stays yours.

Papyrus is local-first. Your PDFs, notes, annotations, evidence, search index, and library database stay on your Mac or iPad unless you choose to export, share, look up metadata, turn on iCloud Sync, or configure WebDAV sync.

Last updated: October 3, 2026

Summary

  • No Papyrus account is required.
  • Apple and Google sign-in are optional. Your default device library stays independent of sign-in.
  • Papyrus does not run developer-operated advertising, tracking, or analytics services. Optional Google sign-in uses Google's SDK and the data practices described below.
  • Your library is stored locally by default.
  • Network requests happen only for features you choose, such as metadata lookup, iCloud Sync, or WebDAV sync.
  • The optional Safari extension runs only when you invoke it and hands captured papers to the app on your device.

Local Data

Papyrus stores research data on your device, including the library database, imported PDFs, linked-file bookmarks, annotations, Markdown notes, project evidence, reading progress, local search indexes, preferences, and rolling local backups.

Credentials that should not be stored in plain text, such as WebDAV passwords, are stored through the system keychain where supported by the platform. iCloud Sync uses the Apple ID and iCloud account already configured on your device; Papyrus does not ask for or store your iCloud password.

Sign-In and Account Deletion

If you choose Sign in with Apple, Apple provides an app-scoped identifier and, when you consent, a name and email address, which may be an Apple private relay address. Papyrus stores this profile in the device-only Keychain, not on a Papyrus server. Your default device library and its own sync configuration are preserved. If you have a separate Apple library, signing in may reopen it according to your saved choice or when the current device library is empty, or offer it through recovery. This does not change the system's iCloud account; iCloud sync uses that system account independently of this optional profile.

If you choose Sign in with Google, Google's official SDK authenticates your Google Account. Papyrus stores the provider-specific user identifier, name, and email in the device-only Keychain; the SDK manages its authorization session and credentials through the system Keychain. Email addresses do not merge identities. Google sign-in keeps your independent device library and iCloud sync settings unchanged. It requests basic sign-in/profile access, not Google Drive access.

If you have a separate Apple library, it retains its own data and sync settings. You can open it explicitly using its Apple identity; libraries are not automatically merged.

To request deletion, open Settings → Account → Sign-In → Delete Papyrus Account. You can cancel the destructive confirmation before deletion starts. For Apple sign-in, deletion removes your Papyrus sign-in profile and any separate library owned by that Apple identity, including its managed files, database, app-managed backups, library preferences, credentials, and associated account-scoped iCloud and configured WebDAV data. Your independent default device library and its sync configuration are kept. Linked original files outside Papyrus are not deleted. If deletion cannot finish, Papyrus keeps the request pending and offers a retry; completion is shown only after the required steps succeed. Deleting the currently open separate Apple library requires reopening Papyrus to use your independent device library.

To prevent another device from recreating a deleted account library through sync, Papyrus retains minimal deletion controls in the associated private iCloud and configured WebDAV storage. These include deletion markers, otherwise empty iCloud record zones with a lifecycle guard in each zone, and a WebDAV marker. They identify the opaque library namespace and its deleted status; they contain no name, email address, authorization token, or library content. These controls remain after account data is removed for the purpose of preventing that library from being synced again.

Deleting Apple sign-in account data does not automatically revoke Apple authorization. After completion, open your Apple Account, choose Sign-In & Security → Sign in with Apple, select Papyrus, and stop using Sign in with Apple. See Apple's revocation instructions for the device and website steps. Signing out is not account deletion or authorization revocation.

For Google sign-in, deletion removes your Papyrus Google profile and uses the official SDK's disconnect operation to revoke Papyrus's Google authorization. A failed disconnect remains pending for retry and is not shown as complete; if the session is missing, sign in with the same Google Account to finish. Your independent device library, Google Account, and Google Drive files are not deleted. Ordinary Sign Out clears this device's session without claiming to revoke access. Google may retain authentication and service records under its own policies.

Network Use

Papyrus does not upload your library to a Papyrus cloud. The app may contact outside services only when a feature needs a network request.

Metadata lookup

When you ask Papyrus to enrich metadata, it may send public identifiers or search terms, such as DOI, arXiv ID, ISBN, PMID, title, or author names, to services including Crossref, arXiv, Semantic Scholar, OpenAlex, OpenLibrary, NCBI / PubMed / PMC identifier services, Zenodo, and doi.org.

Safari extension

The optional Papyrus Import extension for Safari runs only when you invoke it — from the toolbar button, the Save Link to Papyrus context-menu item, or its keyboard shortcut. It reads the page or link you chose in order to extract citation details (title, authors, year, venue, DOI or arXiv ID) and locate a PDF, then hands that capture to the Papyrus app on your device. Papyrus may then download the paper's PDF from its source when you ask for one. The extension does not run on pages you have not invoked it on, does not collect browsing history, and sends nothing to any Papyrus server — there are none.

Apple services

Downloads, App Store account records, iCloud storage, CloudKit sync, and push delivery are handled by Apple. Apple may process data according to Apple's own policies and the Apple ID you use.

Optional Google sign-in

Google Sign-In uses Google's authentication service, not a Papyrus account server. Google documents collection of a user identifier to record authorized OAuth grants and an IP address that may estimate general location for fraud prevention. Its SDK also sends platform/version information for service operation. The SDK's privacy manifest lists name, email, phone number, coarse location, user and device identifiers, usage data, and other data categories for app functionality and/or analytics; it marks these categories as linked to the user and not used for tracking. These are SDK-level declarations, not a claim that Papyrus receives every category or that the SDK is free of analytics. Google controls its authentication, security, service diagnostics, and retention. See Google's Apple-platform SDK privacy explanation, its SDK privacy manifest, and Google's Privacy Policy.

System language models

On supported systems, Papyrus may use Apple-provided on-device Foundation Models for metadata synthesis when enrichment results are ambiguous or incomplete. Papyrus does not run its own hosted AI backend.

Sync

Sync is optional. If you turn on iCloud Sync, Papyrus uses Apple's CloudKit service under your iCloud account to sync library records, PDFs, notes, annotations, evidence, folders, tags, projects, and sync state across devices where you enable the feature. Papyrus does not operate its own cloud backend for this data.

If you configure WebDAV sync, Papyrus connects to the WebDAV destination you provide. WebDAV sync may include the library database, PDFs, notes, evidence, sync manifests, restore points, your server URL, and your username. The WebDAV server's storage, retention, security, and access controls are governed by that server.

Your Choices

  • Use Papyrus offline.
  • Use the default library without signing in, or delete your optional Papyrus account through Settings.
  • Skip metadata enrichment when you do not want identifier lookups.
  • Leave iCloud Sync and WebDAV sync disabled.
  • Use Copy Into Library when you want Papyrus to manage PDFs, or Keep PDFs In Place when you want files to remain where they are.
  • Delete exports or shared files from their destination when you no longer need them.

Deleting items removes them from active use, but older local backups, iCloud records, or WebDAV restore points may contain historical copies until they rotate or are removed according to your settings and provider retention.

Account deletion removes app-managed backups and the associated account-scoped iCloud and configured WebDAV library. It cannot automatically remove previously exported backups, copies on other devices, provider backups, or historical unscoped sync copies outside that account's current library namespace. Remove those copies separately through their storage or provider controls.

Contact

For privacy questions, email zdfu189@gmail.com, visit Support, or open an issue on GitHub.