Policy
Privacy Policy
Last updated 27 September 2026
We collect the minimum needed to run a moderated archive, and we never sell it.
What we collect
- Account data — your name, email address, college, and a hash of your password. We never store the password itself.
- Contributions — the papers you upload, their metadata, your comments, and the reports you file.
- Session data — one record per signed-in device with its browser description, approximate location from the request IP, and last-seen time, so you can spot and revoke a session you do not recognise.
- Audit records — moderation and administrative actions, kept so decisions can be explained and reversed.
There is no third-party advertising or behavioural tracking on PaperVault.
Support tickets and teacher verification
When you open a support ticket we keep what you write, any files you attach, and the replies. Files are stored privately and only you and platform admins can open them. Admins may add internal notes to a ticket that are not shown to you.
If you apply to become a Verified Teacher we collect the details on the form and the documents you upload. Only platform admins can view them, each view is logged, and documents are deleted after the decision as described in the Teacher Verification Policy.
Why we use it
To authenticate you, to attribute and moderate contributions, to send the notifications you have opted into, to enforce rate limits and detect abuse, and to produce the aggregate statistics shown on the statistics page. Aggregates never identify you beyond the public contributor profile that already carries your name.
What is public
Your display name, college and contribution counts appear on your contributor profile and next to papers and comments you post. Your email address, session list and notification preferences are never public.
We send account email — verification, password reset and security notices — regardless of preference, because they protect your account. Moderation decisions, comment replies and the weekly digest are optional and can be switched off in Settings.
Retention
Account data is kept while your account exists. Verification and password-reset tokens are single-use and expire within hours. Removed comments keep a placeholder so threads stay readable, but the original text is no longer served. Deleted papers go to a recycle bin and are purged permanently after thirty days.
Your control
From Settings you can correct your profile, change your password, revoke any session, adjust email preferences, download your data, and erase your account.
- Download your data gives you a JSON file containing your profile, your uploads, your comments, your bookmarks and pinned colleges, the reports and requests you filed, and your sign-in history. Password hashes, two-factor secrets and session tokens are excluded on purpose.
- Erase your account permanently overwrites your name, email address, password, two-factor setup, bookmarks, pinned colleges, reading history, reports and messages, withdraws the text of your comments, and signs out every device. It takes effect immediately and cannot be undone. You will be asked for your password and to type a confirmation word.
Papers you contributed stay in the archive after erasure, under an anonymous author with no link back to you. They are shared study material that other students rely on, and removing them would damage the archive rather than protect you. If a specific paper must come down, use the takedown process.
Security
Passwords are hashed with a slow, salted algorithm. Sessions are server-side records that can be revoked instantly. Uploads are virus-scanned and re-written through a PDF parser that strips embedded scripts. Files are served through an authorising route, never from a public bucket path.
Contact and grievances
PaperVault is operated by Alex. Questions about these terms or your data: papervaultt@gmail.com.
Complaints may be addressed to our Alex at papervaultt@gmail.com. We acknowledge complaints within 24 hours and aim to resolve them within 15 days.
This template covers the common cases for a student-run archive. Have it reviewed by a lawyer in your jurisdiction before you launch publicly.
