Skip to content

Commit c9bd6ad

Browse files
authored
Create PRIVACY_POLICY.md
1 parent ac44c4e commit c9bd6ad

File tree

1 file changed

+104
-0
lines changed

1 file changed

+104
-0
lines changed

PRIVACY_POLICY.md

+104
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,104 @@
1+
# Privacy Policy for Paperless-AI Chat Extension
2+
3+
Last updated: 16.01.2025
4+
5+
## 1. General Information
6+
7+
The Paperless-AI Chat Extension ("the Extension") is a browser extension designed to enhance document interaction in Paperless-ngx through AI-powered chat functionality. We are committed to protecting your privacy and personal data.
8+
9+
## 2. Data Controller
10+
11+
Email: clusterz[at]protonmail.com
12+
13+
## 3. Data Collection and Processing
14+
15+
### 3.1 Stored Data
16+
The Extension stores the following data locally in your browser:
17+
- URL of your Paperless-ngx installation
18+
- URL of your Paperless-AI server
19+
- API key for the Paperless-AI service
20+
21+
This data is stored exclusively in the Chrome Storage Sync API and is only accessible by the Extension.
22+
23+
### 3.2 Document Content Processing
24+
- The Extension only accesses document content when you actively use the chat function for a specific document
25+
- Document contents are transmitted exclusively to your configured Paperless-AI server
26+
- No document content is transmitted to third parties
27+
28+
### 3.3 Chat History
29+
- Chat histories are only temporarily held in browser memory
30+
- This data is deleted when closing the chat window
31+
- No permanent storage of chat histories occurs in the Extension
32+
33+
## 4. Data Transmission
34+
35+
The Extension transmits data exclusively to:
36+
- Your self-hosted Paperless-ngx installation
37+
- Your self-configured Paperless-AI server
38+
39+
No data is transmitted to the Extension developers or other third parties.
40+
41+
## 5. Permissions
42+
43+
The Extension requires the following browser permissions:
44+
- "storage": For saving your configuration settings
45+
- "activeTab": For integrating chat functionality into the Paperless-ngx interface
46+
- "host_permissions": For communication with your Paperless-ngx and Paperless-AI servers
47+
48+
## 6. Data Security
49+
50+
- All communication with your servers is encrypted via HTTPS
51+
- The API key is securely stored in the Chrome Storage system
52+
- The Extension implements best practices for handling sensitive data
53+
54+
## 7. Your Rights
55+
56+
You have the right to:
57+
- Uninstall the Extension at any time
58+
- Delete your stored settings
59+
- Cease using the Extension at any time
60+
61+
Under GDPR, you also have the following rights:
62+
- Right to access your personal data
63+
- Right to rectification
64+
- Right to erasure ("right to be forgotten")
65+
- Right to restrict processing
66+
- Right to data portability
67+
- Right to object
68+
69+
## 8. Changes to Privacy Policy
70+
71+
We reserve the right to modify this privacy policy when necessary, in compliance with applicable data protection regulations. The current version can always be found at [Link to Privacy Policy].
72+
73+
## 9. Contact
74+
75+
If you have any questions about data protection, you can contact us at any time:
76+
clusterz[at]protonmail.com
77+
78+
## 10. Consent
79+
80+
By installing and using the Extension, you agree to this privacy policy. You can withdraw your consent at any time by uninstalling the Extension.
81+
82+
## 11. Technical Details
83+
84+
### 11.1 Data Storage Location
85+
All configuration data is stored locally in your browser using Chrome's secure storage APIs. No data is stored on our servers.
86+
87+
### 11.2 Data Processing
88+
- Document content is processed only when explicitly requested through the chat interface
89+
- Processing occurs on your configured Paperless-AI server
90+
- No content caching or storage occurs within the Extension
91+
92+
### 11.3 Security Measures
93+
- All API communications use HTTPS encryption
94+
- API keys are stored using Chrome's secure storage system
95+
- No logging or tracking of user activities
96+
- No analytics or tracking code is included in the Extension
97+
98+
## 12. Children's Privacy
99+
100+
The Extension is not intended for use by children under the age of 13. We do not knowingly collect or process data from children under 13 years of age.
101+
102+
## 13. International Data Transfers
103+
104+
As the Extension operates entirely within your browser and communicates only with servers you configure, no international data transfers occur through our services.

0 commit comments

Comments
 (0)