1. Introduction
This Privacy Policy describes how Unpaged (“we”,
“us”, “our”) collects, uses, and
protects your information when you use our service at unpaged.io
(“Service”). We are committed to protecting your
privacy and handling your data transparently.
The Service is operated by
Graph Knowledge S.R.L., a company registered in
Romania (registered office: București, Sectorul 6, Drumul
Taberei, Nr. 92, Bl. C7, Scara F, Etaj 1, Ap. 203; trade
registry no. J2026051167004; CUI 55471021), which acts as the
data controller for the personal data described in this policy.
By using the Service, you agree to the practices described in
this policy. Please also review our
Terms of Service.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address
-
Password (stored as a secure hash — we never see or
store your plaintext password)
- Display name (optional)
-
Profile photo or avatar (if a provider supplies one or you
upload one)
Google may provide your name, email address, and profile photo.
Apple may provide your email address and, on first
authorization, the name you choose to share; Apple does not
provide a profile photo. You can upload an avatar separately.
We do not receive your password from these providers.
2.2 Content Data
When you use the Service, we store the documents, nodes, visual
elements, and other content you create. This data is yours and
is stored solely to provide the Service to you.
2.3 Payment Information
When you subscribe to a premium plan, payment is processed by
Stripe, our payments partner and merchant of record. We do
not store your full credit card number, bank
account details, or other sensitive financial information on our
servers. We store only:
- A customer identifier from Stripe
- Your subscription status and plan type
- Subscription expiry date
2.4 Usage and Analytics Data
If you allow optional analytics, we collect pseudonymous usage
data through Google Analytics for Firebase to understand how the
Service is used and to improve it. The browser sends reviewed
product events with limited parameters. Google Analytics also
derives standard session and engagement events, such as
first_visit, session_start, and
user_engagement. The data may include:
- Selected feature and tool types used
-
Aggregate counts, such as node or sharing-recipient counts
- Device type and browser information
- General geographic region (country-level)
- Language, screen resolution, and session statistics
Analytics is disabled until you choose to allow it. We do not
use analytics for advertising, and declining analytics does not
affect access to the Service. We do not send document titles,
document content, document or template identifiers, page routes,
query strings, join tokens, authorization codes, or referrers to
Google Analytics.
When analytics is allowed, Google Analytics may use a
first-party client identifier and a pseudonymous Firebase
installation identifier to distinguish browser sessions. We do
not set a Google Analytics user ID or send account profile
properties.
When you authorize an MCP client, the authorization screen
offers a separate, unchecked choice to share one
mcp_connected event. If you choose it, the MCP
server sends a pseudonymous identifier derived from your account
identifier. It does not send document content, tool inputs,
email addresses, or tokens. MCP authorization works without this
choice, and the choice is offered again for each new
authorization.
2.5 Error and Performance Monitoring Data
In production, we use Sentry for error reporting, performance
monitoring, and sampled session replay. Sentry may receive:
- Error details and stack traces
- Browser and device information
-
Your account identifier and email address, plus route and
document identifiers used to diagnose the affected session
-
Sampled session replay data, including some sessions where
no error occurred
Form inputs are masked in replay. Known sharing capabilities,
authentication codes, email fields, and token-bearing URLs are
scrubbed from structured Sentry events and breadcrumbs. That
structured-field scrubbing does not mask rendered replay text:
document text and media, and account or collaborator details
displayed on screen (including email addresses), may appear in a
sampled replay.
3. How We Use Your Information
We use your information to:
- Provide, maintain, and improve the Service
- Process payments and manage subscriptions
-
Send important service notifications (account verification,
security alerts, subscription changes)
- Monitor and fix errors and performance issues
-
Understand usage patterns to improve the user experience
- Enforce our Terms of Service and protect against misuse
We do not sell your personal information. We do
not use your content data for advertising or
marketing purposes.
4. Legal Basis for Processing (EEA/UK)
If you are in the European Economic Area or the United Kingdom,
we process your personal data under the following legal bases:
-
Contract — processing necessary to
provide the Service you requested (account management,
content storage, payment processing)
-
Legitimate interest — processing
necessary for our legitimate interests (error tracking,
security, and service reliability), balanced against your
rights
-
Consent — optional analytics and
optional communications where you have made an explicit
choice
-
Legal obligation — where required to
comply with applicable law
5. Information Sharing
We share your information only in the following circumstances:
Service Providers
We use third-party services to operate the Service:
-
Google Cloud / Firebase — hosting,
authentication, database storage, and analytics
-
Google Fonts — web-font delivery;
receives ordinary network-request metadata when pages load
-
Google and Apple — optional identity
providers; receive authentication request data when you
choose that sign-in method
-
Payment provider — payment processing
and subscription management
-
Sentry — error tracking and session
replay for reliability
-
Resend — transactional email delivery
for account verification, document-sharing invitations, and
account-deletion confirmations. Depending on the message,
Resend receives the recipient address, sender or display
name, document title, and the verification or access link
needed to deliver the email
Connected Integrations
When you authorize an MCP or AI client, Unpaged returns the
account and document data that client requests within your
access and accepts actions it submits within your permissions,
including content changes, document deletion,
visibility/sharing changes, and collaborator invitations. The
client and its provider are independent third parties; their
terms and privacy policy govern data after they receive it.
Connect only clients you trust.
Shared Documents
If you share a document or make it public, other users can view
the content you choose to share. You control whether a document
is public and can revoke active access, but recipients can
forward links or retain content they have already viewed. Use
sharing links only with people you trust.
Legal Requirements
We may disclose information if required by law, regulation, or
legal process, or to protect our rights, property, or safety.
We do not sell, rent, or trade your personal
information to third parties.
6. Data Storage & Security
Our primary Firestore database, Realtime Database, and Cloud
Functions are configured in European regions. Authentication,
monitoring, email, font-delivery, and connected-client providers
may process data elsewhere as described above. We
implement appropriate technical and organizational measures to
protect your data, including:
- Encryption in transit (TLS/HTTPS)
- Encryption at rest (Google Cloud default encryption)
-
Firestore security rules that enforce per-user access
control
- Secure authentication through Firebase Auth
While we strive to protect your data, no method of electronic
storage or transmission is 100% secure. We cannot guarantee
absolute security.
7. Data Retention
We retain your data for as long as your account is active,
subject to the purpose and legal requirements described here. If
you successfully request account deletion, we remove your
sign-in and start asynchronous cleanup that deletes:
- Your profile and avatar
- Your stored MCP refresh tokens and session records
- Your own notification mailbox
- Your documents and the content stored inside them
- Your sharing access and active invitations
Content you contributed to documents owned by other people, and
activity excerpts already placed in other users’
notification mailboxes, may remain as part of those users’
records. Payment-provider records are retained where required
for financial and legal obligations. Contact us to
request access, review, deletion, or anonymization where
applicable; legal exceptions may apply.
Thumbnail previews cached in IndexedDB on a browser you used may
remain after account deletion until you clear Unpaged site data
in that browser.
Pseudonymous analytics event data is retained for up to 14
months. Withdrawing consent stops future analytics collection in
your browser but does not retroactively remove aggregated
reports created from data collected while analytics was allowed.
8. Your Rights
Depending on your location, you may have the following rights
regarding your personal data:
-
Access — request a copy of the
personal data we hold about you
-
Rectification — request correction of
inaccurate personal data
-
Erasure — request deletion of your
personal data
-
Portability — request your data in a
structured, machine-readable format
-
Restriction — request that we
restrict processing of your data
-
Objection — object to processing
based on legitimate interest
-
Withdraw consent — where processing
is based on consent, withdraw it at any time
Account holders other than anonymous invite viewers can request
a self-serve JSON snapshot from the account page by choosing
Download my data. It includes the account
profile, avatar, notification mailbox, documents you own
(including their nodes, comments, version
metadata, and sharing settings), and your access and invitation
records. It does not include documents owned by other people or
comments you posted in those documents, and very large exports
require support. Anonymous invite viewers, or anyone seeking a
broader access request, can contact us at
contact@unpaged.io.
We will respond within 30 days.
9. Cookies & Browser Storage
The Service uses:
-
Essential identifiers — used by
Firebase Auth and App Check for sign-in, session management,
and app-integrity checks
-
Local and session storage — used for
preferences such as theme and analytics choice, registration
and reauthentication state, and pending invitation or share
navigation. Pending state can contain a document identifier,
invited email address, or short-lived access capability
-
IndexedDB — used by Firebase Auth for
sign-in persistence and by Unpaged for document thumbnails
and unsynced-edit crash recovery
-
Optional analytics cookies — if you
allow analytics, Google Analytics may set first-party
_ga and
_ga_<container-id> cookies to distinguish
browser sessions and calculate usage statistics. These
cookies can last for up to two years from the latest
consented use, although browsers may shorten that period
The Service is online-only and does not maintain an offline
static-asset application cache. Your browser may still use its
ordinary HTTP cache.
We do not use advertising cookies. Analytics
cookies are not set unless you allow browser analytics. If you
later decline, the Service disables collection and removes
accessible Google Analytics cookies for this site. The separate
MCP connection choice does not set a browser cookie. You can
change your browser choice at any time.
10. International Data Transfers
Your data is primarily stored in the European Union (Google
Cloud, Europe region). Some third-party services (e.g., Sentry)
may process data outside the EU. Where data is transferred
outside the EU/EEA, we ensure appropriate safeguards are in
place, such as Standard Contractual Clauses or adequacy
decisions.
11. Children’s Privacy
The Service is not directed at children under 16. We do not
knowingly collect personal information from children under 16.
If we discover that we have collected data from a child under
16, we will promptly delete it. If you believe a child has
provided us personal information, please contact us.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will
notify you of material changes by posting the updated policy on
this page and updating the “Last updated” date. Your
continued use of the Service after changes constitutes
acceptance of the updated policy.