Privacy policy

How PapSee collects, uses, stores, shares and deletes account and PAP therapy data.

Effective date: 10 August 2026

This policy applies when you visit PapSee, create an account, import PAP device files, use the therapy screens, or contact us. PapSee determines how the personal data described here is processed. You can send privacy requests through the contact page.

Data we process

  • Account data: name, email address, authentication records and, if you choose Google sign-in, identifiers supplied by Google.
  • Profile data: optional date of birth, height, weight, diagnosis date, diagnosis AHI and device guide selection.
  • Health and device data: files imported from your PAP device, device information, therapy settings, sessions, respiratory events, signal samples, derived indices, charts and statistics. This may be health data and special category personal data.
  • Sharing data: when you create a link to show your therapy data to someone else, we store a one-way hash of that link, the moment it stops working and the moment you created it. The link itself is never stored, so it cannot be shown to you again or recovered by us.
  • Contact data: your name, email address, selected topic, message and our correspondence with you.
  • Technical data: session and security records, IP address, request metadata, device and browser information, and service error records needed to operate and protect the service.

We obtain this data from you, your browser, your chosen authentication provider and the PAP device files you decide to import. We do not obtain clinical records from healthcare providers.

Purposes and legal grounds

  • We process account and authentication data to create and secure your account and provide the service you request. The legal ground is performance of the service contract.
  • We process imported PAP therapy data to parse, store and present your nights, history and reports. Because this can reveal health information, we rely on your explicit consent where required by the GDPR. Consent is voluntary and may be withdrawn at any time. Withdrawal does not affect processing already carried out lawfully.
  • We process a share link so that whoever holds it can read the nights of the account that created it, on screen and without changing anything, for as long as that link works. Profile details such as name, date of birth, height, weight and diagnosis are not shown to them, and the link cannot download the history. The legal ground is performing the service you asked for, on your explicit instruction. You decide who receives the link and how long it lasts, and you can stop it at any time.
  • We process technical and security data to prevent abuse, investigate faults and protect accounts and systems. The legal ground is our legitimate interest in operating a secure service, except where your rights and interests override that interest, and compliance with legal obligations where applicable.
  • We process contact messages to answer your request. The legal ground is taking steps at your request, performing the service contract, or our legitimate interest in responding, depending on the subject.
  • We process a small set of usage events to count how the service is used and to see where it fails. The legal ground is our legitimate interest in maintaining and improving the service, except where your rights and interests override that interest. Imported therapy data is never part of these events.
  • We may retain or disclose limited data when necessary to comply with a binding legal duty, establish or defend legal claims, or protect a person's vital interests.

We do not use your PAP therapy data for advertising, sell personal data, or make decisions that produce legal or similarly significant effects solely by automated processing.

Service providers and disclosures

Only providers that need data to perform a service for PapSee receive it. They process it under their own applicable terms and data protection obligations.

  • Vercel hosts and runs the application in Frankfurt, Germany.
  • Neon hosts the primary PostgreSQL database in Frankfurt, Germany.
  • Google receives authentication requests only if you choose Google sign-in.
  • PostHog processes product usage events on servers in the European Union.
  • Cloudflare processes the contact form challenge used to prevent automated abuse, and routes the usage events described above to PostHog.
  • The configured email provider processes contact messages sent through the contact form.
  • Public authorities or other recipients may receive data only when disclosure is legally required or necessary to establish, exercise or defend legal claims.

We do not make imported PAP files or therapy results public. A share link you create is the one way another person can read your nights, it discloses them to whoever holds the link, and choosing to send it is yours alone.

International transfers

The application and primary database are hosted in the European Union. Some providers may process limited account, security, authentication or contact data in other countries. When a transfer is subject to the GDPR, it must rely on a valid transfer mechanism, such as an adequacy decision, appropriate contractual safeguards, or explicit consent where that ground is legally available. You may ask for information about the safeguard relevant to your data through the contact page.

Retention and deletion

  • Account, profile and imported therapy data are kept while your account remains open, unless you delete an import or request account deletion earlier.
  • Contact correspondence may be kept for up to two years after the request is closed so we can follow up and document the response.
  • A share link record is kept until you stop it or it stops working, and expired records are removed the next time you create a link. Deleting your account removes them with everything else.
  • Security and service logs are normally kept for up to 90 days unless a specific incident requires longer investigation.
  • Data required by law or needed for a legal claim may be kept for the applicable statutory period.
  • Deleted data may remain in encrypted, access-restricted backups until the backup rotation completes. It is not restored for ordinary use.

When a retention period ends, data is deleted or irreversibly anonymised.

Cookies and local storage

PapSee uses storage necessary for sign-in, security, language, theme, panel preferences, demo mode and shared views. These features are needed to provide the service or remember a choice you made. Opening a share link sets a cookie in the reader's browser that holds the link and nothing else; it is not readable by scripts and it expires with the link.

PapSee also sets a product analytics cookie, provided by PostHog, that counts pages opened and a short list of named actions: creating an account, signing in, finishing an import, opening the example patient and sending a contact message. Web addresses are stripped of their query and fragment before they leave your browser, so the date of a night you were reading is never sent. Clicks, form contents, keystrokes and screen recordings are not collected, and imported therapy data is never sent. PapSee does not use advertising cookies and does not build advertising or profiling audiences.

Security

We use access controls, encrypted network connections, account separation, restricted infrastructure locations and other technical and organisational measures appropriate to the data handled by the service. No internet service can guarantee absolute security. Keep your account credentials confidential and tell us promptly if you suspect unauthorised access.

Your rights

Depending on the law that applies to you, you may have the right to:

  • learn whether your personal data is processed and obtain access to it;
  • ask about the purpose, use, source, recipients and transfers of your data;
  • correct inaccurate or incomplete data;
  • request deletion, destruction, anonymisation or restriction of processing;
  • receive eligible data in a portable format;
  • object to processing based on legitimate interests or to an adverse result produced solely by automated analysis;
  • withdraw consent at any time without affecting earlier lawful processing;
  • request compensation where unlawful processing caused damage; and
  • complain to the competent data protection authority in the European Economic Area.

Submit a request through the contact page. We may ask for information necessary to confirm your identity and protect the account. We aim to respond within one month under the GDPR, subject to any lawful extension. Requests are normally free, but the law may permit a reasonable fee or refusal for manifestly unfounded or excessive requests.

You can also export or delete eligible account data through features made available in the service.

Children

PapSee is intended for adults. Do not create an account or import another person's health data unless you are legally authorised to do so.

Changes to this policy

We may update this policy when the service, providers or legal requirements change. The current version and effective date appear on this page. If a change materially affects how existing health data is processed, we will provide appropriate notice and obtain new consent when the law requires it.