Privacy policy
What we hold, why we hold it, and what you can make us do about it.
You are putting what you owe, what you are owed and who your customers are into someone else's software. This page says plainly what happens to it. For how it is protected, see security.
Last updated 2026-09-30
Who you are dealing with
PaprPlain is run by Parikshith, a sole proprietor based in Bengaluru, India, trading as PaprPlain. Where this page says we, that is who it means. You can reach us at hello@paprpla.in, and a real person answers.
PaprPlain is commercial hosted software. We run it on infrastructure we control, through a cloud infrastructure provider, and you use it in a browser. There is nothing to install and nothing to self-host.
The two kinds of information here
It is worth separating them, because they are treated very differently.
- Your business records. The rows you import or type — customers, stock, orders, payments, photos, documents. This is yours. We hold it so we can show it back to you and to the people you have given access. We do not read it, mine it, sell it, share it, or use it to train anything.
- Account information. The handful of details needed to give you an account, bill you and keep the service secure. That is ours to hold, and it is described below.
What we hold
Because you gave it to us
- Your name, email address and, if you give one, a phone number.
- Your business name, and the names and email addresses of people you invite.
- What you write to us — demo enquiries, support emails, anything you tell us to build.
- Everything you put into your tables, and any files you attach to a row.
Because the service produced it
- A record of what changed in your project and who changed it, so a question about a changed figure has an answer.
- Sign-in and security records — when an account signed in, from what IP address and what browser — kept so that a break-in attempt can be spotted and explained.
- Ordinary server logs, which include IP addresses and timestamps.
Billing
Plans are invoiced and paid by bank transfer or UPI. We hold the invoice details — the business name, the address you want on the invoice, the amount and whether it was paid. We never see or store card numbers, because there is no card payment to make.
Why we hold it
- To run the service you asked for — that is the whole of why your business records exist on our servers.
- To let you in, and keep everyone else out — sign-in, the six-digit code, and the security records behind them.
- To bill you, and to keep the invoices we are required to keep.
- To answer you when you write to us, and to fix what you report.
We do not profile you, run advertising, or make automated decisions about you. There is nothing on this list that exists to sell you something else.
What happens when AI is involved
Three parts of the product use an AI model: working out what your business is when your workspace is built, describing a screen you want, and the Analyst, which answers questions about your data in plain language. They all work within the same limits.
- The model is shown the names of your tables and columns. That is how it works out that "unpaid invoices this month" means the Invoices table, the Status column and the Date column — and, when a workspace is being built, that a sheet of names and phone numbers is your customer list.
- It is also shown facts counted about each column: how many rows are filled, how many different values a column holds and which are most common, the highest, lowest and total of a column of figures, and whether the values in one column also appear in another list. That last one is how a link between two of your lists is found.
- It is shown a small sample of rows, never a whole table. Headings alone cannot say whether "1204" is a quantity, an amount or a code, so a model sees a few examples. The limits are fixed: when a workspace is built, up to three rows and a few values from each column; when the Analyst first reads a project, or reads it again after its tables change, up to fifteen rows from each table; and with each question or screen you describe, up to five rows from each table. Your files are never sent.
- A column marked sensitive is left out. Once a column is marked sensitive, nothing from it is sent. When a file is first read, nothing has been marked yet, so a sample row can include a name or a phone number.
- Anything that looks like a secret is removed first. Passwords, card numbers, access keys and similar values are found in your file and stripped out before anything is sent, and what has been built is checked again before it leaves.
- Nothing a model returns is run as a program, or taken at its word. It is checked against a fixed list of what is allowed and against what was actually measured in your file; anything it invents is dropped before it can reach your workspace. A question can only ever read.
- Nothing is used to train anything. Not your names, not your counts, not your questions.
We reach models through OpenRouter, and which model handles a given request changes as we find ones that do the job better or more cheaply. This means these requests, and the samples in them, may be processed on servers outside India. It also means we do not promise you one named model — we promise you the boundary above, which holds whichever model is used. You do not choose the model and neither does anybody in your workspace; if we cannot run one on terms that meet what is described here, the feature is switched off rather than run on weaker terms.
Our own records of these requests hold how long a job took, what it cost and whether it worked. They do not hold your file's contents, the request that was sent, or what came back.
Who else touches it
We keep this list short on purpose, and this is all of it:
- A cloud infrastructure provider, which hosts the servers the product runs on and stores your data. They hold it on our behalf and have no right to use it.
- OpenRouter and the model provider behind it, which sees table and column names, counts about your columns, and short repeating value sets, exactly as described above — and never your rows.
There is no advertising network, no data broker, no analytics company and no third party we sell anything to. If that list ever changes, this page changes before it does.
We will hand over data if a valid legal order requires it. If that ever happens and we are permitted to tell you, we will.
When you share a link
Somebody in your workspace can share an invoice, a screen or the Dashboard as a link. The link shows a copy taken at that moment, of only what that person could see, with columns marked sensitive left out. Anyone who has the link can open that copy without an account, so you choose who gets it. Nothing else in the workspace is reachable from it.
A link stops working when it expires — after 7, 30 or 90 days, as chosen — or the moment it is turned off. Turning it off deletes the copy; a note that the link existed, who made it and when, stays in the project so it can be accounted for. Shared pages ask search engines not to index them and do not pass the link on to other sites.
Cookies and tracking
This website sets no cookies and runs no analytics. No trackers, no ad pixels, nothing that follows you to the next site. Nobody is counting you.
The product itself sets one thing: a sign-in cookie that keeps you logged in. It is strictly necessary — without it you would be signed out on every click — so there is no banner to click through. Signing out clears it.
How long we keep it
- While you are a customer, we keep your business records for as long as you want them. You can delete any row, table or project yourself at any time.
- If you cancel or stop paying, your project is kept for 90 days. During that time you can sign in and download everything as Excel or CSV, and we will get in touch to ask what you want done with it — kept in case you come back, or cleared. After 90 days it is permanently deleted from our systems, and from backups within a further 30 days.
- If you ask us to delete it sooner, we will, within 30 days of the request.
- Invoices and tax records are kept for as long as Indian law requires us to keep them, whatever else has been deleted.
What you can ask us to do
Under India's Digital Personal Data Protection Act, 2023, and as a matter of how we would want to be treated, you can ask us to:
- Tell you what we hold about you and who it has been shared with.
- Correct anything that is wrong or out of date.
- Delete it, unless we are required by law to keep it.
- Withdraw your consent, which for a hosted product means closing the account.
- Nominate someone to exercise these rights if you die or become incapacitated.
Write to hello@paprpla.in and we will act within 30 days. There is no form and no fee. You never need to ask us for an export — every table downloads as CSV or a real Excel file from inside the product, whenever you want.
If you are a business using PaprPlain to hold records about your own customers, then for those records you decide what is collected and why, and we act on your instructions.
If we get it wrong
Complaints about how your data has been handled go to Parikshith, the proprietor, at hello@paprpla.in. We will acknowledge within 7 days and resolve within 30. If you are not satisfied, you may complain to the Data Protection Board of India.
Changes to this policy
If we change something that matters — a new party touching your data, a shorter or longer retention period, a new use — we will email account holders before it takes effect, and the date at the top of this page will change. Fixing a typo does not get an email.
PaprPlain is not for children. The product is sold to businesses, and accounts are for people aged 18 and over.
Questions about any of this?
Write to hello@paprpla.in, or ask on the demo call — we would rather answer it before you sign up than after.