PaperMove privacy notice
Version 2026-07-25.2 ยท Last updated 25 July 2026
Chen Liu operates PaperMove and is the controller for personal information processed specifically to provide this invitation-only service. Questions and rights requests can be sent to c.liu.5@research.gla.ac.uk.
Information PaperMove processes
- Account information, including email address, authentication status, and terms-acceptance version.
- Workspace information you enter, including paper records, tasks, handoffs, notes, links, tracked opportunities, and activity history.
- Private files that you deliberately upload.
- Information Board posts, including your chosen display name, category, message, and timestamps.
- Technical and security information generated by authentication, hosting, and storage providers.
- If the calendar feature is enabled after its release checks, the minimum event fields needed for the selected weekly view.
- If you enable GPT Revision, your encrypted OpenAI API key and the text passages you deliberately submit for revision.
Public conference and funding listings are collected from their original publishers. They may contain names of organisers, speakers, or contacts that those publishers have already made public.
Why the information is used
- To authenticate users and provide their private workspace.
- To save, display, export, and restore information at the user's request.
- To secure the service, investigate failures, and prevent unauthorised access.
- To show monitored public opportunities and changes to those listings.
- To provide the shared Information Board and allow the operator to moderate it.
- To show an optional read-only weekly calendar if that feature is enabled.
Account and workspace processing is necessary to provide the service requested by invited users. Security and limited service-administration processing is carried out for the legitimate interest of operating a secure and reliable private service. An optional calendar connection will be activated only at the user's request and can be disconnected.
Calendar information
You may connect a private, read-only Outlook-published ICS link. The link is encrypted separately from your workspace and is used only to retrieve events for your Week view. PaperMove cannot create, edit, delete, accept, or decline calendar events. Disconnecting removes the encrypted link and its cached events from your workspace.
Information Board
Board posts are visible to every signed-in PaperMove user and are not private workspace records. Do not post confidential or sensitive information. Authors may edit or delete their own posts, and the operator may remove content to administer the service.
GPT Revision
GPT Revision is optional and uses the OpenAI API key you provide. The key is encrypted separately for your account, is never included in workspace exports, and is never returned to the browser after setup. You can permanently remove it with Disconnect. For a revision, PaperMove decrypts the key inside the authenticated server function and sends only the passage you submitted, the selected style, and editing instructions to OpenAI. OpenAI processes that request under the terms and settings of your OpenAI API account.
Service providers and transfers
- Supabase provides authentication, database, and private file storage.
- Resend delivers transactional account emails.
- GitHub Pages hosts the PaperMove application files.
- OpenAI processes text only when a user requests a GPT revision using their connected API account.
- Connected calendar providers will process information under their own account terms when that feature is enabled.
Providers may process information outside the UK. Where UK transfer rules apply, PaperMove will rely on an applicable adequacy regulation or contractual safeguard. Contact the operator if you require details about the safeguard used for a particular provider.
Retention and deletion
Account and workspace information is retained while the account is active. You can permanently delete your account from the Account view. Self-service deletion removes your authentication account, private workspace, temporary uploads, and Information Board posts from the active service. A reference to you that another user has independently stored in their isolated private workspace is part of that user's record and is not changed by deleting your account. Provider security logs and backup remnants follow the providers' documented retention cycles. Public opportunity snapshots may be retained to identify changes, but user Track and Dismiss choices are deleted with the workspace. Information Board posts are automatically deleted from the active database 30 days after they are created. Workspace activity records are retained and searchable for 30 days; older activity records are automatically removed.
Your choices and rights
Depending on the circumstances, UK data-protection law may give you rights of access, correction, erasure, restriction, objection, and data portability. You can export your workspace and permanently delete your account in PaperMove. Contact the operator to request correction or to ask about information held independently in another user's record. You may also complain to the Information Commissioner's Office.
Automated ranking
PaperMove may categorise or rank public opportunities to help users review them. This does not make decisions about eligibility, applications, employment, funding, or attendance. The user always decides whether to track, dismiss, or act on an opportunity.
Changes
Material changes will be dated on this page and communicated to active users where reasonably practicable.