Last updated: July 23, 2026

Privacy Policy

This policy explains how ClientPaper ("we", "us") collects, uses, discloses, and protects information when you use the service. It is written to meet the baseline expectations of the EU/UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), Canada's PIPEDA, and India's Digital Personal Data Protection Act, 2023. If your local law grants rights beyond what is described here, that law controls.

1. Who we are

ClientPaper is operated by Siddharth G("the operator", "data controller"). For all privacy questions, requests, or complaints, contact Siddharthgundavarapu@gmail.com.

2. Information we collect

Account information. When you sign up, our authentication provider (Clerk) collects your name, email address, and basic profile information from that provider if you use Google sign-in. We also store the answers you give during onboarding (why you joined, how you heard about us).

Content you create. Invoices, agreements, proposals, NDAs, and other documents you generate, along with any client details (names, emails, addresses, payment terms) you enter to populate them.

What we do not collect.We do not run analytics, advertising trackers, or third-party cookies. The only cookie the service sets is Clerk's strictly-necessary session cookie, required to keep you signed in. Because we use no non-essential cookies, no cookie-consent banner is required under the ePrivacy Directive or similar laws.

3. How we use information

  • To provide and operate the document-generation service you signed up for
  • To authenticate you and keep your account secure
  • To respond to support requests you send us
  • To meet legal obligations (e.g. responding to a lawful request from an authority)

We do not sell, rent, or trade personal information, and we never will.

4. Legal basis for processing (GDPR/UK GDPR)

Where GDPR or UK GDPR applies, we process your data under these legal bases: performance of a contract (to provide the service you signed up for), legitimate interests (keeping the service secure and functioning), and consent (where you have explicitly given it, e.g. marketing communications, which we do not currently send).

5. Who we share information with

We use two subprocessors to run the service. Neither is permitted to use your data for its own purposes:

  • Clerk (clerk.com): authentication and account management, hosted in the United States.
  • Supabase (supabase.com): database hosting for your documents and client data, hosted in Australia (Sydney region).

We do not share your data with advertisers, data brokers, or any other third party, except where required by law or to protect the rights, property, or safety of the operator, our users, or the public.

6. International data transfers

Because our subprocessors are located outside your country, your data may be transferred internationally (for example, from the EU/UK/India to the United States or Australia). Where required, such transfers rely on the receiving provider's Standard Contractual Clauses or an equivalent lawful transfer mechanism.

7. Data retention

We retain your account and content for as long as your account is active. If you delete your account, all associated data is permanently deleted from our database within 30 days, except where retention is required to comply with a legal obligation.

8. Your rights

Depending on where you live, you have some or all of the following rights:

  • EU/UK GDPR: access, rectification, erasure, restriction of processing, data portability, objection to processing, and the right to lodge a complaint with your local supervisory authority.
  • California (CCPA/CPRA): right to know what personal information is collected, right to delete, right to correct, right to opt out of sale/sharing (we do not sell or share data, so there is nothing to opt out of), and the right to non-discrimination for exercising these rights. You may designate an authorized agent to exercise these rights on your behalf.
  • India (DPDP Act, 2023): right to access, correction, and erasure of your personal data, and the right to grievance redressal via the contact details above.
  • Canada (PIPEDA): right to access and request correction of your personal information.

In-app, you can export all of your data at any time from Settings, and delete your account and all associated data permanently from the same page. For any other request, email Siddharthgundavarapu@gmail.com.

9. Data security

All traffic to the service is encrypted in transit (HTTPS/TLS). Your documents and client data are stored in a database with row-level access controls scoped to your account, so no other user can query your data. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

10. Children's privacy

ClientPaper is not directed at children and is not intended for use by anyone under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

11. Data breach notification

If a breach affecting your personal data occurs, we will notify affected users and, where legally required, relevant supervisory authorities, without undue delay.

12. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above. Continued use of the service after changes take effect constitutes acceptance of the revised policy.

13. Contact

Questions, requests, or complaints about this policy or your data: Siddharthgundavarapu@gmail.com