Not used for training
Uploads and generated figures are never used to train models — ours or a provider's. Inference providers are bound by no-training, delete-after-processing terms.
Isolated processing
Each generation runs in an isolated job. Your files are not visible to other users or other jobs.
Deleted on schedule
Source PDFs and images are deleted 30 days after the related figure is deleted. Closed accounts are purged within 12 months.
Export everything
Every figure can be exported as SVG, PPTX, PNG, or JPG at any time, including for 30 days after cancellation.
Encrypted in transit and at rest
TLS 1.2+ for all connections; AES-256 encryption for stored files and backups; EU-hosted infrastructure.
GDPR by design
France-based controller, CNIL as supervisory authority, data-processing agreements with every processor, and a documented data map.
Unpublished work
Most figures are made before the paper is public. We treat every upload as confidential unpublished research: staff do not open user files except to resolve a support request you have raised, and access is logged.
Lab and institutional requirements
Lab plans can request a signed data-processing agreement, a completed security questionnaire, and invoicing through institutional purchase orders. Contact us for the current documentation.
CONTACT
- Security questions: security@paperpict.com
- Data requests: privacy@paperpict.com
- Responsible disclosure: report vulnerabilities to security@paperpict.com; we acknowledge within two working days