The short version
Conversion runs entirely on your device. The app has no account system and no server that sees your documents. It makes no network requests of its own.
We do not run ads and we do not use any SDK that can identify you. The only two third parties involved are the purchase processor for Papyr Pro and an anonymous usage counter you can switch off.
Who is responsible
Papyr is published by TECHNINN SOLUTIONS BİLİŞİM TEKNOLOJİLERİ A.Ş., İnkılap Mah. Sokullu Cad. No:5 Ümraniye / İstanbul, Türkiye ("we", "us"). For the purposes of the EU and UK General Data Protection Regulation and the Turkish Personal Data Protection Law (KVKK), we are the data controller for the limited processing described below.
You can reach us at support@techinn.solutions.
What never leaves your phone
- The PDF, Word file or images you choose to convert, and the file the app produces.
- The text the app extracts or recognises, including recognised text from scanned pages (OCR runs on the device with Apple Vision).
- Passwords you type to open a protected PDF. They are used once, in memory, and are never stored.
- Your conversion history and the results themselves: the converted file, a copy of the source and the quality report are kept in the app's private storage for 7 days so you can reopen them from the Recent list, then removed. Password-protected documents are never kept. Clear history in Settings deletes everything at once.
- Your settings: recognition languages, keep-screen-on, the usage-counter switch.
- The weekly free-export counter.
Files you share or save go where you send them, through the system share sheet or the Files app. Deleting Papyr removes everything the app kept. Because we hold no copy, we cannot restore anything for you.
Purchases
Payments are handled entirely by Apple. We never see your card, billing address or name.
To know whether Papyr Pro was bought, we use RevenueCat, Inc. as a processor. RevenueCat receives a randomly generated, app-specific identifier that is not linked to your name or email, the purchase receipt, your storefront country and basic device and OS information. We use this only to unlock Pro and to restore it on a new phone. RevenueCat's privacy policy is at revenuecat.com/privacy.
Anonymous usage counters
If the switch is on, Papyr sends a handful of anonymous counters to TelemetryDeck GmbH (Germany): a conversion started, finished or failed, its page-count band and duration band, the number of columns, tables and images found, an export happened, the paywall was shown, a purchase happened, and — if you tap 👎 — which of five reasons you chose. Each signal carries the app version, the OS version and the device model.
By construction these signals cannot carry text: the app's telemetry module can only send fixed category values and small numbers. No file names, no document text, no images, no passwords, no location, no advertising ID. The identifier is a random value stored on your phone and hashed before it is sent; it cannot be turned back into you. TelemetryDeck's privacy policy is at telemetrydeck.com/privacy.
You can turn these counters off at any time in Settings › Privacy › Anonymous usage statistics. When the switch is off, nothing is sent.
Permissions the app asks for
- Files, only for the document you pick, through the system picker. Papyr sees that one file, not your library.
- Photos, only when you pick images to turn into a PDF, again through the system picker.
- Notifications, optional, only to tell you a batch conversion finished while the app was in the background.
We never ask for the camera, microphone, location or contacts. The Share extension copies the shared file into the app's private inbox and nothing else.
What we do not do
We do not sell or share personal data. We do not run advertising, and we do not use attribution or crash-reporting SDKs. We do not build profiles and we do not track you across other apps or websites, so we have no reason to ask for App Tracking Transparency permission.
Children
Papyr is a document tool and is not directed at children under 13 (or under 16 where local law sets that age). We do not knowingly process their personal data. If you believe a child has provided us with data, write to us and we will delete it.
Why we are allowed to process this data
Under the GDPR we rely on the performance of our contract with you (Article 6(1)(b)) to verify your purchase and unlock the features you paid for, and on our legitimate interests (Article 6(1)(f)) in understanding aggregate, non-identifying usage and in preventing fraudulent purchases. Under the KVKK the corresponding grounds are Article 5(2)(c) and 5(2)(f).
How long data is kept
Purchase records at RevenueCat are kept for as long as your purchase can be restored. Anonymous counters at TelemetryDeck are aggregated and cannot be attributed to a person; raw signals are discarded by TelemetryDeck after aggregation. Nothing else is kept, because nothing else is collected.
Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to have it deleted, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent where processing is based on consent.
In practice the only data we can act on is the anonymous purchase record at RevenueCat, since everything else is on your device and outside our reach. Write to support@techinn.solutions and we will respond within 30 days.
You also have the right to complain to your local supervisory authority: in Türkiye the Kişisel Verileri Koruma Kurumu, in the EU your national data protection authority, in the UK the ICO.
Changes
When this policy changes we update the date at the top and, for material changes, tell you in the app before they take effect.