Legal

Privacy policy

Plainpaper is where your marketing work lives, so it holds real work and real contact details. This page says plainly what we collect, why we hold it, who else touches it, and what you can make us do with it.

Last updated: 2 August 2026.

Who this is about

Plainpaper is a shared workspace for AI-driven marketing. You bring your own AI agent; Plainpaper is the durable place its work lives. This policy covers the Plainpaper app at app.plainpaper.io and this website at plainpaper.io.

The controller of your personal data is colibri.studio, established in the Netherlands and trading as Plainpaper. You can reach us at [email protected] about anything on this page.

Registered in the Dutch Commercial Register (Handelsregister) under 42127858.

Signing in with Google

Signing in with Google is optional — an email address and password work just as well. If you do use it, this is the whole of it.

We request two scopes, email and profile. That means Google sends us your email address, your name and profile picture as you have set them on your Google account, and an opaque Google account identifier. We do not ask for, and cannot see, your Gmail, your Drive, your contacts, your calendar, or your Google password.

We use that data for exactly one thing: creating your Plainpaper account and recognising you when you come back. It is stored in our authentication database alongside any account created with a password. To be explicit about what we do not do with it — we do not sell it, we do not share it with third parties for their own purposes, we do not use it for advertising or profiling, and we do not use it to train machine-learning models.

You can revoke Plainpaper's access at any time from your Google account permissions. Revoking access stops future sign-ins; it does not by itself delete the Plainpaper account, which you can delete separately (see your rights).

What we collect

Your account

An email address, and either a password (stored only as a cryptographic hash, never in readable form) or the Google identity described above. If you accept an invitation to someone else's workspace, we record who invited you and which invitation you used.

What you tell us about yourself

During onboarding we ask, optionally, for your name, job role, company name, industry and team size. Every one of those can be skipped, and skipping does not limit the product. We use them to understand who Plainpaper is for.

Your work

The boards, cards, comments, guidelines and uploaded files you and your agent create. This is your content, not ours. We hold it to show it back to you and to serve it to the agents you have authorised. Uploaded files are stored privately and served only through short-lived signed links — there is no permanent public URL for your assets.

Billing

Subscriptions run through Stripe. Stripe handles the card; we never see or store card numbers. We keep the identifier of your Stripe customer record, your plan, and its status, because that is what tells the app which features to unlock.

Technical records

Server logs covering requests to the service, including IP address, browser user agent and timestamps. These exist to keep the service up and to investigate abuse and faults.

Analytics

On this website we use Google Analytics and DataFast to understand which pages bring people to Plainpaper. Inside the app we deliberately report far less: a single pageview for the signed-out sign-in screen, an opaque account identifier, and two milestone events (an account was created; a first board was made). We do not send your email address, your board contents or your internal navigation to any analytics provider.

Your AI agent, and what leaves Plainpaper

This part matters more here than in most products, so it gets its own section.

Plainpaper is not an AI model and does not contain one. You connect your own agent — Claude, or any MCP-compatible client — using a token you issue and can revoke. When that agent reads your board, the content it reads travels to whichever AI provider you chose, and what that provider does with it is governed by their terms, not ours. Choosing an agent is choosing a second processor for your content. We cannot see or control that relationship, which is why we make the token yours to grant and yours to withdraw.

We do not train models on your content, and we do not share your content with any AI provider on our own initiative.

Plainpaper also never executes anything on an outside platform and never holds your credentials for one. When a campaign finally ships, your agent sends it through that platform's own integration, not through us.

Why we are allowed to hold it

Under the GDPR we rely on: performance of a contract for your account, your content and your billing, because without them there is no product; legitimate interests for security logging and for keeping the service working; and consent for website analytics, which you can withdraw.

Who else processes it

We keep this list short on purpose. Each of these is a processor acting on our instructions, not an independent recipient of your data.

Where a processor operates outside the EEA, transfers are made under the European Commission's Standard Contractual Clauses or an equivalent approved mechanism.

Where your data lives

Your account and your content sit in a Postgres database in Frankfurt, and uploaded files sit in object storage in Amsterdam. Both are in the EU. Traffic to and from the service is encrypted in transit.

Workspaces are isolated from one another in the database itself, not merely in the application: every read and write is filtered by workspace membership at the database layer, so a bug in our code cannot hand one customer another's boards.

How long we keep it

Your content stays for as long as your account exists, because that is the point of the product — Plainpaper is meant to be the place work does not scroll away.

When you delete your account, your content is removed from the live service immediately and from our backups within 90 days, after which it cannot be recovered. If you want a copy, export it before you delete.

Two things outlive the account. Billing records — invoices and the transaction data behind them — are kept for seven years, because Dutch tax law requires it of every business administration (article 52 of the Algemene wet inzake rijksbelastingen). And security logs are kept for 90 days, then discarded.

Your rights

If you are in the EEA or the UK you can ask us to give you a copy of your data, correct it, delete it, hand it over in a portable form, restrict what we do with it, or object to processing we base on legitimate interests. You can also withdraw consent to analytics at any time.

Write to [email protected] and we will answer within one month, as the GDPR requires.

If you think we have got it wrong, you can complain to our supervisory authority, the Dutch Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). You may also complain to the authority in your own EU country if you live elsewhere. We would rather you came to us first, but you are not obliged to.

Security

Passwords are hashed, never stored readably. Agent tokens are scoped to the workspaces you grant and can be revoked from the app at any time. Uploaded files are private by default and reachable only through links that expire. Database-level isolation is described under where your data lives.

No system is perfect. If you find a security problem, please tell us at [email protected] before telling anyone else, and we will work with you.

Children

Plainpaper is a business tool and is not intended for anyone under 16. We do not knowingly collect data from children.

Changes to this policy

When this policy changes materially we will update the date at the top and, for anything that affects how we handle your data, tell account holders by email before it takes effect.

Contact

Anything on this page, including a request about your own data: [email protected].

colibri.studio, trading as Plainpaper