← Back to home

Privacy Policy

Last updated: August 20, 2026

Columbia Software Works, LLC ("we," "us") operates PatientPapers (the "Service"). This policy explains what we collect, what we do not, and your choices. It applies to the PatientPapers website and application.

Rollout status (18 August 2026): Paddle is the chosen merchant of record, but paid checkout is not live and the Paddle integration is not yet built. The current preview accepts no payments and sends no buyer or payment information to Paddle. The Paddle statements below describe what will happen if paid sales launch.

Anonymous problem reporting is built but its receiving endpoint is not live yet. Until the shared Worker and its D1 database are deployed, the report page says nothing was sent and the report remains queued on your device. The reporting statements below describe what will happen when that endpoint is enabled.

1. The most important point: nothing you enter reaches us

PatientPapers is built so that the patient records, form answers, signatures, and completed forms you create are stored only on your device, and nothing you enter is sent to us. We do not store that data on our servers, and we cannot see the patients you document or the contents of the forms you complete. If you lose or reset your device, that local data is gone and we cannot recover it — use the in-app export to keep your own backup.

There are no exceptions to that boundary. The app asks our servers for the blank forms and field help it needs, and sends nothing back. No feature sends a note, an image, or a completed form anywhere, and no vendor receives patient information of any kind.

What you print, save, or hand to a patient is of course yours to control once it leaves the application — that is the product working, and it is your responsibility rather than ours. You remain responsible for your own HIPAA and privacy obligations. PatientPapers is a documentation tool built to support those obligations, not to assume them.

2. What we do collect

We collect only what we need to run the Service:

Your provider profile — name, NPI, licence number, practice details, signature — is entered in the application and stays there. We never receive it. There is no account to create and no sign-in: the application unlocks locally with a passcode you set, and a paid licence is a token you paste in, checked on your device without contacting us.

3. What we do not collect

4. Service providers (subprocessors)

We use a small number of vendors to operate the Service. None of them receives patient data, because none of it ever leaves the application:

5. Cookies and tracking

The site sets no cookies and runs no analytics. The application stores your data in your browser's own storage, not in cookies. We do not use advertising or cross-site tracking cookies.

6. Email and marketing

If you join our mailing list or opt in to product updates, we will email you and you can unsubscribe at any time via the link in every message. We comply with applicable anti-spam laws, including CAN-SPAM; our mailing address is included in every marketing email we send.

Email about your licence is not marketing and is not covered by that opt-out. Your licence link, any renewal notice, and our replies to you at support are part of the Service you bought, and we send them for as long as your licence is live. They go out through Cloudflare rather than MailerLite, so unsubscribing from the mailing list does not stop them and does not affect your licence.

7. Your rights and choices

Depending on where you live (including under the CCPA/CPRA), you may have the right to access, correct, or delete the personal data we hold, and to opt out of marketing. In practice what we hold is your email address, any support correspondence, anonymous problem reports if that endpoint is enabled, and — if you have bought a licence — that licence record, and you can have data linked to you removed by asking. A problem report has no name, email address, account, or other identifier, so we cannot find one by who sent it; it deletes automatically instead. When paid sales launch, your billing record will sit with Paddle as merchant of record, so a request that reaches only us will not reach it; tell us and we will point you at the right place. To exercise these rights, contact us at privacy@patientpapers.app. Note: we cannot access or delete patient or form data stored locally on your device, because we never hold it — you control that directly on your device.

8. Data retention and security

We retain your email address for as long as you want to hear from us, and support correspondence for as long as needed for legal and accounting purposes, then delete or anonymize it. Anonymous problem reports delete automatically 90 days after we receive them. Licence and purchase records — the email address, the state of the licence, and the record of licensing emails sent to it — are kept while the licence is live and afterwards for as long as tax and accounting law requires. When paid sales launch, Paddle will keep its own record of each sale under its own policy, as the merchant of record. We use reasonable administrative and technical safeguards to protect the limited data we hold. No method of transmission or storage is perfectly secure.

9. Children

The Service is intended for licensed professionals and is not directed to children. We do not knowingly collect personal information from children.

10. Changes and contact

We may update this policy and will post the new effective date. Material changes will be communicated as required by law.

Columbia Software Works, LLC · privacy@patientpapers.app

Read the Terms of Service →