Your privacy is non-negotiable. This policy explains exactly what data PaperGenius collects, why, and what you can do about it. It's written in plain language on purpose — if anything is unclear, email legal@papergenius.pk and we'll explain.
1. What we collect
From you, directly
- Account details — name, email, role, institute affiliation.
- Test content — the questions you write, papers you build, templates you save.
- Payment proof — when you upload a bank-transfer receipt to upgrade your plan.
- Support correspondence — emails / WhatsApp messages you send us.
From your device, automatically
- Technical logs — IP address, browser, device type, timestamps of major actions. Used for security and debugging.
- Cookies — a single session cookie to keep you signed in, and an optional theme preference cookie. We do not use advertising trackers.
2. What we do NOT collect
- No biometric data, no facial recognition.
- No location tracking beyond the country-level inference from your IP.
- No microphone, camera, or contacts access.
- No data brokers' enrichment.
- No advertising-network identifiers.
3. How we use it
- To operate the service — show you the right tests, route notifications, enforce role gates.
- To bill you — process bank-transfer payments and generate invoice PDFs.
- To improve the service — anonymous, aggregate analytics (how many tests built, average paper length, never individual users in reports).
- To communicate with you about your account, payments, and important platform changes.
- To comply with Pakistani law — tax records, lawful requests from authorities.
4. Sharing
We do not sell your data. We share it only with:
- Service providers who help us operate (hosting, email sending) under strict contracts that forbid them from using your data for anything else.
- Pakistani authorities if legally compelled (court order, FBR audit), and only the minimum required.
- Your institute administrator — if you're a teacher under an institute account, your admin can see your tests and audit-log entries inside that institute.
5. Storage & security
- Data is stored in encrypted databases hosted on servers physically located in Pakistan or trusted regional providers.
- Passwords are hashed with bcrypt — even we can't see them.
- Payment screenshots are stored privately with access restricted to super-admins only.
- HTTPS everywhere; HTTP requests are redirected to HTTPS.
- Daily encrypted database backups are kept for 30 days.
6. Retention
- Active accounts: data is kept while your account exists.
- Deleted accounts: removed within 30 days of deletion request, except records we must keep for tax / audit purposes (typically 6 years per Pakistani tax law).
- Logs: 90 days, then automatically purged.
7. Your rights
You can, at any time:
- Access — see your profile, download your tests as PDFs.
- Correct — edit your profile information from Profile → Settings.
- Delete — delete your account from Profile → Delete account. This removes your personal data within 30 days.
- Export — request a copy of your data by emailing legal@papergenius.pk — we'll respond within 30 days.
- Object — opt out of optional communications via the unsubscribe link in any email we send.
8. Children's privacy
PaperGenius is built for teachers and institutes — accounts are for users 18+. We do not knowingly collect data from children under 13. If a teacher inputs student names into a private question bank, that data is bound by the same privacy commitments as everything else and is never used outside the institute.
9. International users
The service is operated from Pakistan. If you access it from outside Pakistan, your data may be transferred to and stored in Pakistan. By using the service you consent to this transfer.
10. Cookies (short version)
| Cookie | Purpose | Duration |
|---|---|---|
laravel_session | Keeps you signed in | 2 hours of inactivity |
XSRF-TOKEN | Prevents cross-site request forgery | 2 hours |
theme | Remembers light / dark mode | 1 year, optional |
11. Changes to this policy
If we make material changes, we'll show a banner in the app and update the "Last updated" date at the top of this page. We won't reduce your existing rights without your consent.
12. Contact & complaints
Email legal@papergenius.pk for any privacy question, complaint, or correction request. We respond within 7 working days.
You may also lodge a complaint with the Pakistan Telecommunication Authority (PTA) or any other competent data-protection authority in your jurisdiction.