Pappery home

Trust and control

Public policies and verifiable controls.

Trust is not built from customer logos or generic promises. Pappery publishes its policies, limits, live status, license notices, and routes for exporting or deleting an account.

01TLS

data in transit

02MFA

administrative protection

037 days

account export link

01

Layered security

Sessions use secure, HttpOnly, host-only, same-site refresh cookies; access tokens stay in memory. Data is encrypted in transit and at rest.

The platform uses request limits, least privilege, administrative audit, MFA, and owner-scoped access.

02

Ownership and portability

Your documents remain yours. Download .ppry files and request an account data export from Settings.

Account deletion stops new writes, verifies subscription cancellation, erases private objects, and removes identity through a recoverable job.

03

Verified billing

Polar processes payments, invoices, taxes, and refunds as merchant of record. Pappery verifies provider state and lets paid privileges expire when evidence is stale or paid time ends.

Cancellation and refund rules are published before purchase.

04

Status and help

The status page makes a live API check; it does not invent uptime history or an SLA. Support explains what evidence to include.

Save, export, and billing incidents should include UTC time and the exact visible message.

Pappery

Review the details before you trust.

Policies and third-party notices are available without signing in.