Privacy Policy
Last updated: September 24, 2026
Columbia Software Works, LLC ("we," "us") operates PatientPapers (the "Service"). This policy explains what we collect, what we do not, and your choices. It applies to the PatientPapers website and application.
Rollout status (12 September 2026): Paddle is the merchant of record and paid checkout is live. Buying a license sends buyer and payment information to Paddle, as §§2 and 4 describe; the application itself still sends nothing.
Anonymous problem reporting is live. When you press Send this report on the report page, the report is sent to us and handled as the statements below describe. Nothing is sent until you press it, and the app itself never sends a report.
The first-form check-in is live. After your first completed form for a real patient, the app offers three optional questions once. If you answer them, the check-in stays on your device until you open the report page, and it is sent to us only when you press Send this check-in there. The app itself never sends a check-in.
1. The most important point: nothing you enter reaches us
PatientPapers is built so that the patient records, form answers, signatures, and completed forms you create are stored only on your device, and nothing you enter is sent to us. We do not store that data on our servers, and we cannot see the patients you document or the contents of the forms you complete. If you lose or reset your device, that local data is gone and we cannot recover it — use the in-app export to keep your own backup. The backup opens with the same passcode or recovery code, so losing both means losing access to the backup too.
There are no exceptions to that boundary. The app asks our servers for the blank forms and field help it needs, and sends nothing back. No feature sends a note, an image, or a completed form anywhere, and no vendor receives patient information of any kind.
What you print, save, or hand to a patient is of course yours to control once it leaves the application — that is the product working, and it is your responsibility rather than ours. You remain responsible for your own HIPAA and privacy obligations. PatientPapers is a documentation tool built to support those obligations, not to assume them.
2. What we do collect
We collect only what we need to run the Service:
- Your email address — if you join our mailing list, write to support, or buy a license. This is the only identifier we hold about you.
- Support communications — whatever you choose to send us when you contact support. You never need to send us a patient record to get help, and you should not.
- An anonymous problem report — if you choose to send one: the form id, form edition, app version, the screen where it happened, and the problem categories you checked. It contains no name, email address, free text, patient detail, form answer, file, or screenshot.
- An anonymous first-form check-in — if you choose to send one: the form id, form edition, app version, and your answers to three multiple-choice questions (whether the finished form came out right, how it compared with filling it in by hand, and how likely you are to use PatientPapers again). We ask once, after your first completed form, and you can ignore it. It contains no name, email address, free text, patient detail, form answer, file, or screenshot.
- Your license record — if you buy a license: your email address, whether the license is currently active, the plan you are on, and a record of the licensing emails we sent you, which is the address, the subject line and whether delivery succeeded. We keep this so we can answer "did her license actually go out?" It contains no payment details and no patient information.
- Billing information — held by Paddle, our merchant of record, and not by us. Paddle takes your name, email address, billing address and payment details when you buy, and passes us only the email address, the transaction reference and the state of your subscription. See §4.
Your provider profile — name, NPI, license number, practice details, signature — is entered in the application and stays there. We never receive it. There is no account to create and no sign-in: the application unlocks locally with a passcode you set. A paid license is a signed token. Getting that token to your device may involve us — you either paste it in, or you open a one-time link we email you — but checking it never does: the check happens on your device, against a key built into the application, and makes no request to us.
3. What we do not collect
- Patient identities, conditions, or form contents. None of it, ever.
- Usage analytics. We run none — no analytics service, no product telemetry, no beacons of any kind.
- Payment card numbers. We never receive them.
- Location tracking, advertising identifiers, or data sold to third parties — we do not sell your data.
4. Service providers (subprocessors)
We use a small number of vendors to operate the Service. None of them receives patient data, because none of it ever leaves the application:
- Cloudflare — hosting and content delivery for the website and the application, and the sending of the emails that come with a license: your license link and any renewal notice, sent from
license@mail.patientpapers.app. Cloudflare receives the recipient's address, the subject and text of that message, and the delivery result. Cloudflare also receives and stores an anonymous problem report's five enumerated fields in D1, with automatic deletion after 90 days, and the first-form check-in's six enumerated fields on the same terms. - MailerLite — our marketing mailing list: the product news and updates you asked us for. It does not carry license or billing mail.
- Paddle — our merchant of record for paid licenses. That is a different relationship from the two above: Paddle sells the license to you in its own right rather than only processing a payment on our behalf, so it is a seller as well as a vendor. It receives your name, email address, billing address and payment details, and holds the transaction record and your receipt. We never receive your card number — see §3.
5. Cookies and tracking
The site sets no cookies and runs no analytics. The application stores your data in your browser's own storage, not in cookies. We do not use advertising or cross-site tracking cookies. On the purchase page only, Paddle's checkout script also loads a script from ProfitWell, Paddle's subscription-retention service. We do not pass it your name, email address or any other detail about you.
6. Email and marketing
If you join our mailing list or opt in to product updates, we will email you and you can unsubscribe at any time via the link in every message. We comply with applicable anti-spam laws, including CAN-SPAM; our mailing address is included in every marketing email we send.
Email about your license is not marketing and is not covered by that opt-out. Your license link, any renewal notice, and our replies to you at support are part of the Service you bought, and we send them for as long as your license is live. They go out through Cloudflare rather than MailerLite, so unsubscribing from the mailing list does not stop them and does not affect your license.
7. Your rights and choices
Depending on where you live (including under the CCPA/CPRA), you may have the right to access, correct, or delete the personal data we hold, and to opt out of marketing. In practice what we hold is your email address, any support correspondence, anonymous problem reports, first-form check-ins, and — if you have bought a license — that license record, and you can have data linked to you removed by asking. A problem report and a check-in have no name, email address, account, or other identifier, so we cannot find one by who sent it; they delete automatically instead. Your billing record sits with Paddle as merchant of record, so a request that reaches only us will not reach it; tell us and we will point you at the right place. To exercise these rights, contact us at privacy@patientpapers.app. Note: we cannot access or delete patient or form data stored locally on your device, because we never hold it — you control that directly on your device.
8. Data retention and security
We retain your email address for as long as you want to hear from us, and support correspondence for as long as needed for legal and accounting purposes, then delete or anonymize it. Anonymous problem reports and first-form check-ins delete automatically 90 days after we receive them. License and purchase records — the email address, the state of the license, and the record of licensing emails sent to it — are kept while the license is live and afterwards for as long as tax and accounting law requires. Paddle keeps its own record of each sale under its own policy, as the merchant of record. We use reasonable administrative and technical safeguards to protect the limited data we hold. No method of transmission or storage is perfectly secure.
9. Children
The Service is intended for licensed professionals and is not directed to children. We do not knowingly collect personal information from children.
10. Changes and contact
We may update this policy and will post the new effective date. Material changes will be communicated as required by law.
Columbia Software Works, LLC · privacy@patientpapers.app