Privacy Policy

Last updated: [06/09/2026]

1. Who we are

Paprly ("we", "us", "our") provides AI-powered invoice parsing and export tools for accountants and bookkeepers, available at paprly.org, operated by Paprly. This policy explains what data we collect, why, and how it's handled. We are based in Ireland; if you are located in the EU/EEA or UK, the GDPR / UK GDPR applies to our processing of your data.

2. What we collect

  • Account information: your email address and a generated API key, when you register.
  • Invoice content: the files you upload (PDFs, images, scans) and the data our AI extracts from them — supplier name, amounts, dates, line items, and similar fields.
  • Payment information: if you subscribe to a paid plan, billing is handled entirely by Stripe. We do not store your card details ourselves.
  • Connected accounting software: if you connect QuickBooks or Xero, we store an access token that lets us create bills/invoices in your account on your instruction. We do not access your accounting data beyond what's needed to complete the export you request.
  • Usage data: how many invoices you've parsed, your plan, and basic account activity, so we can enforce plan limits and provide support.

3. How we use it

  • To parse the invoices you upload and return the extracted data to you.
  • To export that data into QuickBooks or Xero when you choose to.
  • To manage your account, subscription, and usage limits.
  • To send you account-related emails (e.g. your API key on registration).
  • To provide customer support and diagnose technical issues.

Our lawful basis for this processing is performance of a contract with you (providing the service you've signed up for), and in limited cases (e.g. fraud prevention, keeping the service secure) our legitimate interests.

4. AI processing of your invoices

Invoice data you upload is processed by an AI system (via OpenAI) to extract structured fields such as supplier, totals, and line items. This is the core function of the service — the AI is not used to make automated decisions that produce legal or similarly significant effects about you or your clients; every extraction is presented to you for review before you choose to export it.

5. Third parties we share data with

We use a small number of third-party services to operate Paprly. Each only receives the data necessary to perform its function:

  • OpenAI (United States) — processes uploaded invoice files to extract structured data.
  • Supabase — hosts our database (accounts, parsed invoice data, connection tokens).
  • Stripe — processes payments and manages subscriptions.
  • Resend — sends account-related emails.
  • Intuit (QuickBooks) and Xero — only if and when you choose to connect your account, to create bills/invoices on your instruction.

Where a provider is based outside the EEA (such as OpenAI, in the United States), any transfer of your personal data is made subject to appropriate safeguards under GDPR Chapter V — including Standard Contractual Clauses or an equivalent adequacy mechanism offered by that provider. You can request more detail on the specific safeguard in place for any given provider by contacting us (Section 9).

We do not sell your data, and we do not share it with third parties for their own marketing purposes.

6. Data retention

  • While your account is active, we retain your parsed invoice data so you can access your history and organize it (folders, on paid plans).
  • If you delete your account, your invoices, connected-integration tokens, and account record are permanently deleted immediately — this is an irreversible action you can trigger yourself from your dashboard.
  • If your account is inactive (no login) for 24 consecutive months, we delete your stored invoice data automatically, even if you haven't deleted the account itself.

7. Your rights

If the GDPR or UK GDPR applies to you, you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to or restrict certain processing
  • Request a copy of your data in a portable format
  • Lodge a complaint with a supervisory authority (in Ireland, the Data Protection Commission)

8. Cookies

Paprly does not use tracking or advertising cookies. Your login session is handled using browser storage, not cookies, and is used solely to keep you signed in — no non-essential cookies are set. If this changes in future (for example, if we add analytics), we'll update this section and request consent where required under the ePrivacy Regulations.

9. Security

We use industry-standard measures to protect your data, including encrypted connections (HTTPS) and access-controlled databases. No system is perfectly secure, and we encourage you to use a strong, unique password-equivalent (API key) and keep it confidential. Where available, we recommend enabling two-factor authentication on your account.

10. Data Protection Officer

Given the scale and nature of our processing, we are not required to appoint a formal Data Protection Officer under GDPR. For any data protection queries or to exercise your rights, contact us using the details in Section 11 below — as an Ireland-based business, we don't have a separate EU representative distinct from this contact.

11. Contact us

For any questions about this policy or to exercise your data rights, contact us at privacy@paprly.org.

12. Changes to this policy

We may update this policy from time to time. We'll update the "Last updated" date above when we do. Continued use of Paprly after changes means you accept the updated policy.