PaperPict
Home / Resources / Security

SECURITY & DATA

Your manuscript is yours. Here is how we treat it.

What happens to prompts, sketches, PDFs, and figures from upload to deletion.

Not used for training

Uploads and generated figures are never used to train models — ours or a provider's. Inference providers are bound by no-training, delete-after-processing terms.

Isolated processing

Each generation runs in an isolated job. Your files are not visible to other users or other jobs.

Deleted on schedule

Source PDFs and images are deleted 30 days after the related figure is deleted. Closed accounts are purged within 12 months.

Export everything

Every figure can be exported as SVG, PPTX, PNG, or JPG at any time, including for 30 days after cancellation.

Encrypted in transit and at rest

TLS 1.2+ for all connections; AES-256 encryption for stored files and backups; EU-hosted infrastructure.

GDPR by design

France-based controller, CNIL as supervisory authority, data-processing agreements with every processor, and a documented data map.

Unpublished work

Most figures are made before the paper is public. We treat every upload as confidential unpublished research: staff do not open user files except to resolve a support request you have raised, and access is logged.

Lab and institutional requirements

Lab plans can request a signed data-processing agreement, a completed security questionnaire, and invoicing through institutional purchase orders. Contact us for the current documentation.

CONTACT

  • Security questions: security@paperpict.com
  • Data requests: privacy@paperpict.com
  • Responsible disclosure: report vulnerabilities to security@paperpict.com; we acknowledge within two working days

Privacy policy

Questions about data handling?

Write to security@paperpict.com or book a call.