Papaya Privacy Policy
Last updated: 12 July 2026
Papaya is a web-based image editor. This policy explains what we collect, why, and what we do with it.
Editing happens in your browser. Your images are not uploaded to our servers unless you save a document to the cloud. Papaya has paid plans, but we do not sell your personal data, we show no ads, and we embed no third-party trackers or analytics services.
Papaya has no AI features today. Nothing you make in Papaya has ever been sent to an AI company, and we have never used your work to train a model. We are building AI features, and they will change what happens to your data. Rather than this coming as a surprise on shipping, we describe them now, in AI features below.
What we collect
Your account
If you create an account, we store:
- Your email address. Used to sign you in, to send verification and password-reset codes, and to contact you about your account.
- A display name
- Your password, stored only as a hash. We never hold the password itself, and cannot recover it — we can only reset it.
- Some activity data. Account creation time, last active time, and the creation, modification, and last-opened times of your documents.
Your documents
If you save a document to the cloud, we store the document's name, its structure, and its images.
We store these files so we can give them back to you. We do not sell your images. If you share a document, we also record who you shared it with and what access you granted.
Documents you have not saved to the cloud never leave your browser. They are held in your browser's own on-device storage, where we cannot see them, and clearing your browser's site data will erase them.
Billing
If you subscribe, Polar is the merchant of record — it sells you the subscription and handles the billing and tax on our behalf — and Stripe is the payment processor that handles the card transaction. Card numbers never reach our servers. We keep a copy of your subscription status, billing period, and customer ID so we know whether your subscription is active. The privacy policies of Polar and Stripe govern the data they each hold.
Usage analytics
We record page views and some in-editor actions to understand how Papaya is used. Each event stores the time it happened, the page path, the site that linked you here, the kind of action, your browser, operating system and device type, and your timezone, language, and country. We keep only the origin and path of a referring link, never its query string, so a token or an address sitting in the URL you arrived from is discarded rather than stored.
Each event is written as a standalone row carrying nothing that identifies you:
- No IP address. Your country is determined at the network edge, and only the two-letter country code is passed to us. Your IP address is never part of the event, and never reaches our database.
- No cookies, and no other tracking technology.
- No visitor ID, device ID, or fingerprint. We never assign you a number.
- No link to your account, even when you are signed in.
- No raw browser identification string. We keep only the broad categories we derive from it, such as "Chrome", "macOS", "desktop".
Because nothing identifies the event, we cannot tell that two events came from the same person, cannot reconstruct one visitor's path through the site, and cannot connect any event back to you — not across pages, not across sessions, and not across sites. What this gives us is counts, and nothing more.
Analytics are recorded by our own server and stored in our own database. There is no third-party analytics service: nothing about your visit is sent to anyone else, sold, or used for advertising. This collection happens for all visitors, including those who are not signed in.
Feedback
If you send feedback, we store your message and, if you choose to provide it, your email address so we can reply.
Sessions and security
When you log in we store a hashed session token and your browser's user-agent string, so we can recognize your session and detect token theft. Your session token itself is kept in your browser's local storage, along with the name and version of any document you have open. Logging out clears them.
We use IP addresses to rate-limit requests. Our application holds them in memory only and never writes them to disk.
AI features (not yet launched)
None of what follows is happening yet. Papaya ships no AI features today: there is no assistant to type into, no AI-powered tool in the editor, and no model of ours that has been trained on anything. No image of yours has ever reached an AI company, because there is no code in Papaya that could send one.
We are building the three things below, and each of them changes what happens to your data. We are telling you before we ship them rather than after, so you can decide how you feel about it while it is still hypothetical.
Built-in AI tools
Some tools we want to build — background removal, for instance — need more computing power than a browser has. When those ship, using one will send the image you are working on to a GPU server we run, to be processed there and sent back to you.
We intend to run these models ourselves. Your image would not go to any outside AI company, and would not be kept once the job is done. If you never use the tools, no image is ever sent to them.
The AI assistant
We plan to let you type instructions into an assistant chat box. Unlike the tools above, this will not run on our servers. To answer you, it will send your request to a third-party AI service. Depending on what you ask for, that can include the text of your instruction and the rest of your conversation with the assistant, and the image content of the document you are working on, when the assistant needs to see it or change it.
Two consequences, stated plainly:
- Your prompt and your image will leave Papaya. Once they reach the AI company, its privacy policy and terms govern them, not ours. What it keeps, for how long, and whether it uses your data to improve its own models, is its decision, not ours.
- We will not be able to get them back for you. Deleting your Papaya account will not delete anything the AI company has already received; that would be a matter between you and them.
We have not chosen a provider. We may route requests through a service that gives us access to several models, or we may let you connect an AI account you already have — an existing ChatGPT subscription, for example — in which case your requests go to that company under the agreement you already have with it, and are billed to you rather than us. Handling your words and generating your images may be done by two different models, possibly at two different companies.
We will name the provider or providers here before the assistant launches. Using it will always be your choice: if you never type into the assistant, nothing is ever sent to anyone.
Training our models
In the future, we reserve the right to use documents saved to the cloud from free accounts to train our own AI models. We have not started. No model of ours has been trained on anyone's work.
To be precise about what that will and will not cover:
- It will apply only to documents saved to the cloud from a free account.
- Documents on a paid plan will not be used for training.
- Documents you never save to the cloud never leave your browser, so they can never be used for training, on any plan.
- We will use your images only to train our models. We will not sell them, and we will not use them to train anyone else's models.
Deleting a document, or your whole account, takes it out of any future training. Once a model has been trained on an image, deleting the image cannot remove it from that model.
Who we share it with
We do not sell your personal data, and we do not share it for advertising. We rely on these service providers:
| Provider | What they handle |
|---|---|
| Cloudflare | Serves the site, stores cloud documents, and delivers account emails. Cloudflare sees your IP address as traffic passes through it. |
| Hetzner | Hosts the server that runs our API and database, in Finland. |
| Polar | The merchant of record for subscriptions: it sells you the plan and handles billing and tax. |
| Stripe | The payment processor Polar uses to handle the card transaction. |
That is the whole list. No AI company is on it, because no part of Papaya sends anything to one; when the assistant launches, its provider will be added here first. Beyond these, we may disclose data if the law requires it.
How long we keep it
- Deleted documents are kept for 30 days, then permanently erased along with their image files.
- Unconfirmed signups — an email address and password hash from an account you started but never verified — are deleted within 24 hours of the code's expiration.
- Analytics events are kept indefinitely. They contain nothing that identifies you.
- Feedback is kept indefinitely, including the email address you optionally attach to it.
Deleting your account
You can delete your account from the settings page. Doing this deletes your documents and their image files, your sessions, your sharing permissions, your assistant conversations, and your subscription records. We also cancel any subscription you hold at Polar, so you stop being charged. (Analytics events are not tied to your account in the first place, so there is nothing there to delete.)
Things survive that deletion:
- The billing records Polar holds as the merchant of record, which include your email address, are retained by Polar for accounting and tax purposes under its own privacy policy.
- Feedback you submitted is not linked to your account, so it is not deleted automatically.
Once the AI features described above are live, two more things will survive it: images already used to train a model, which deleting cannot pull back out of that model, and anything you sent to the AI assistant, which is held by the company that received it and which you would need to take up with them.
Your rights
You can delete your account yourself at any time. If you want a copy of your data, want something corrected that you cannot change yourself, email us and we will take care of it.
Depending on where you live, you may have additional rights over your personal data, including the right to object to how we use it. Contact us and we will honor them.
Children
Papaya is not directed at children under 13, and we do not knowingly collect their personal data.
Changes
If we change this policy in a way that materially affects you, we will update the date above and let you know.
Contact
Questions, requests, or complaints: mail@papaya.io