Paper Paws Privacy Policy
- Effective date: July 19, 2026
- Last updated: July 19, 2026
- Service provider: Synapse Ent
- Services covered: the Paper Paws Android app (
com.synapseent.paperpaws) and related web and server services
Synapse Ent ("we," "us," or the "Company") respects your privacy. This Privacy Policy explains what information Paper Paws processes, why it is processed, how long it is kept, and the choices and rights available to you.
Key points
- When you learn as a guest, your learning records are generally stored on your device.
- If you choose Google Sign-In, account information and learning backups may be stored on our server.
- We do not store raw speech recordings on our server. Your Android speech recognition provider may process audio when you use speaking exercises.
- In ad-supported versions, the Google Mobile Ads SDK may process device and usage information for advertising, measurement, analytics, and fraud prevention.
- You can request deletion through
Settings > Account & sync > Delete accountin the app or the Paper Paws account deletion page. - Deleting your Paper Paws account does not cancel a Google Play subscription. You must cancel recurring billing separately in Google Play.
1. Data controller and contact
- Data controller: Synapse Ent
- Service: Paper Paws
- Website: https://www.synapseent.com/
- Privacy contact: admin@synapseent.com
2. Information we process, purposes, and retention
We process only the information needed to provide Paper Paws. Google Sign-In, server backup, push notifications, advertising, speaking exercises, and paid subscriptions are processed only when you select or use the relevant feature.
2.1 Google Sign-In and account management
| Category | Information | Purpose | Retention |
|---|---|---|---|
| Google account information | Google account unique identifier, verified email address, display name | Identification, sign-in, account creation and restoration, support | Until account deletion. Deleted from live systems within 7 days after a verified request. Isolated disaster-recovery copies are blocked from restoration and overwritten or deleted within 30 days. |
| Device and session information | Hash of the Paper Paws installation identifier, server user and device IDs, platform, app and content versions, last-seen time, hashes of login/session tokens, expiry and revocation records | Keep you signed in, distinguish devices, prevent token replay and unauthorized access, security | While the account is active. Expired or revoked session records may be retained for up to 90 days for security. Non-mandatory data is deleted when the account is deleted. |
Email addresses are encrypted at rest. Raw authentication tokens are used only as needed during authentication; our database stores token hashes or encrypted values where persistence is required.
2.2 Learning records and backups
| Category | Information | Purpose | Retention |
|---|---|---|---|
| On-device learning data | Words studied and marked as known, answers, correctness, response time, hint use, review schedule, difficulty and stability, repetitions and lapses, results by learning type including listening and speaking, daily history, goals, notification, audio, and performance settings | Offline learning, personalized review, statistics, missions, achievements, and settings | Stored on your device until you reset learning data, clear app storage, or uninstall the app. |
| Server learning backup | The on-device learning data described above, backup time, installation identifier, app/content/schema versions, file size, and integrity hash | Backup, restoration, and device migration through your Google-linked Paper Paws account | Up to the 20 most recent backups per account. Kept until you delete the account; older backups are automatically deleted. |
Guest learning records are not normally uploaded to our server. If you choose to attach existing guest progress to a Google-linked Paper Paws account, a learning backup may be uploaded.
If Android automatic backup is enabled, Android may back up the Paper Paws learning database and app settings to your Google account according to your device and Google backup settings.
2.3 Google Play subscription and membership
We may process the product and base-plan IDs; encrypted and hashed purchase token; order ID; purchase, renewal, and expiry times; auto-renewal status; subscription, acknowledgement, cancellation, refund, and revocation states; test-purchase status; and membership entitlement history. We use this information to verify purchases, provide and restore membership, prevent duplicate or fraudulent purchases, and reflect subscription changes.
Transaction records are retained as required by applicable law. Where Korean e-commerce retention rules apply, contract/withdrawal and payment/supply records are kept for 5 years, and consumer complaint/dispute records for 3 years. After account deletion, legally required records are separated from the account or pseudonymized and deleted when the applicable period ends.
Google Play processes payment instruments such as card and bank-account details. We do not collect or store those payment instrument details.
2.4 Push notifications
We may process the encrypted and hashed Firebase installation identifier; Paper Paws user ID if signed in; platform; package and app version; language; time zone; mission, marketing, and quiet-hours preferences; and registration/unregistration times. This information is used to deliver the notifications you select in the appropriate language and time zone.
We delete our server registration within 7 days after all server notifications are disabled, the installation is unregistered, or the account is deleted. Inactive registrations are automatically deleted after 180 days without activity. After we request Firebase deletion, Google states that related data may take up to 180 days to be removed from live and backup systems.
Marketing notifications are off by default and are sent only after you enable them. You can withdraw permission in the app or Android notification settings at any time.
2.5 Advertising and online activity information
Ad-supported versions may use the Google Mobile Ads SDK and User Messaging Platform. Depending on your choices and region, they may process:
- approximate location derived from IP address;
- product interactions such as app launches, taps, and ad video views;
- diagnostic information such as app/SDK launch time, hangs, and energy use;
- Android advertising ID, App Set ID, and other device or account identifiers; and
- advertising consent and privacy-choice status.
This information is used for ad delivery and frequency control, personalized or non-personalized ad selection, measurement, analytics, and fraud prevention. Retention is governed by your consent choices, advertising settings, and the policies of Google and participating ad technology providers.
We do not create or sell a separate user profile from this advertising information. You can manage choices through Settings > Privacy options in Paper Paws and the advertising privacy/advertising ID controls in Android. Refusing personalized advertising does not block basic learning features, but non-personalized or limited ads may still appear.
2.6 Speaking exercises and microphone access
When you choose a speaking exercise, Paper Paws requests microphone permission and invokes the Android speech recognition service. We do not send raw audio to our own server or store it as a recording. Recognized text is processed temporarily to show feedback and the resulting learning outcome may be recorded on your device.
Depending on your device and speech provider settings, audio and recognition results may be sent to Google or a device-manufacturer speech provider. That provider's privacy policy applies. You can deny microphone permission and continue using learning features other than speaking exercises.
2.7 Automatically generated service records
IP address, access time, requested URL, response status, user agent, error/security events, and request IDs may be generated when you use our web or API services. We use these records for stability, incident response, security, and fraud/abuse prevention.
- General access logs: up to 3 months
- Security and abuse-prevention audit records: up to 1 year, or until an active dispute or legal process ends
The privacy-policy page itself does not include advertising or analytics scripts. Cloudflare may temporarily process connection information such as IP addresses to provide transport security and DDoS protection.
2.8 Support and privacy requests
We may process your email address, request details, the minimum information needed to identify the account, and the request/response history to answer support requests, verify identity, process access/correction/deletion/restriction requests, and resolve disputes.
General support records are kept for 3 years after completion. Identity-verification material for account deletion is kept for 30 days after completion unless a longer period is legally required.
Do not send a national ID number, full identity document, payment card number, Google password, or raw purchase token by email or through a support form. We do not normally require these items.
3. Legal bases
Depending on the feature and applicable law, we process information to perform the service contract you request; on the basis of your consent for optional advertising personalization or marketing notifications; to comply with legal obligations; and for legitimate interests in service security, fraud prevention, and protection of rights, where those interests do not override your rights.
4. Disclosure to third parties
We do not sell personal information and do not disclose it to third parties except when you have consented, disclosure is required by law, or communication with an external provider is necessary to deliver a feature you requested. The external providers and international transfers below apply in those cases.
5. Service providers and international transfers
| Provider/recipient | Destination | Information | Purpose and transfer method | Retention |
|---|---|---|---|---|
| Google LLC and affiliates | United States and countries where Google operates services | Google account identifier, verified email, display name, app/OAuth identifiers | Google Sign-In and identity verification; encrypted network transfer when you sign in | Under Google policies; information received by our server follows our account retention above |
| Google LLC and affiliates | United States and countries where Google operates services | Product/base-plan ID, purchase token, order/subscription status, randomized app-account identifier | Google Play payment, purchase verification, and subscription synchronization; encrypted network transfer during purchase/restore/status checks | Under Google Play policies and applicable transaction-retention law |
| Google LLC (Firebase Cloud Messaging) | United States and countries where Google operates services | Firebase installation ID, app instance information, notification payload | Push delivery; encrypted network transfer during registration and delivery | Google states removal from live and backup systems may take up to 180 days after deletion is requested |
| Google LLC and Google ad technology providers | United States and countries where each provider operates | Approximate location, interactions, diagnostics, advertising/App Set IDs, consent status | Advertising, measurement, analytics, fraud prevention; encrypted SDK communication when ads are used | Under your choices, ad settings, and provider policies |
| Google LLC or device-manufacturer speech provider | Countries where the selected provider operates | Audio spoken during an exercise and device/language information needed for recognition | Speech-to-text; transferred by the Android speech service when you activate the microphone, unless processed on-device | Under the selected provider's policy and device settings |
| Google LLC (Android Backup) | United States and countries where Google operates services | Learning database and app settings | Android automatic backup and device transfer; encrypted network transfer when Android performs backup | Under your Google account backup settings and Google policy |
| Cloudflare, Inc. | United States and Cloudflare global network locations | IP address, request/response metadata, security events | TLS, CDN, DDoS and malicious-traffic protection; encrypted transfer when web/API services are accessed | As necessary for security/service delivery and under Cloudflare policy |
You may refuse optional transfers by not using a feature or withdrawing permission/consent in the app or device settings. Refusal prevents the relevant Google Sign-In, Play payment, push, advertising, or network speech-recognition feature from working, but guest offline learning remains available.
Provider policies:
- Google Privacy Policy: https://policies.google.com/privacy
- Google privacy requests and help: https://support.google.com/policies/answer/9581826
- Google Play Terms: https://play.google.com/about/play-terms/
- Firebase Privacy and Security: https://firebase.google.com/support/privacy
- Google ad technology providers: https://support.google.com/admob/answer/9012903
- Cloudflare Privacy Policy: https://www.cloudflare.com/privacypolicy/
- Cloudflare privacy contact: privacyquestions@cloudflare.com
If you use a device-manufacturer speech service, the specific recipient and contact details are shown in the speech-service and privacy settings selected on your device.
6. Deletion and disposal
We delete personal information when its purpose or retention period ends. Legally required records are isolated with restricted access and used only for the required purpose. Electronic records are securely deleted, overwritten, or rendered inaccessible through cryptographic key destruction. Backup files and their database references are removed; disaster-recovery copies are added to a do-not-restore list and deleted on the stated rotation schedule.
7. Your rights and how to exercise them
Subject to applicable law, you may request access, portability, correction, deletion, restriction/cessation of processing, withdrawal of consent, and account deletion. An authorized guardian or representative may exercise rights where legally permitted.
Request methods:
- In the app:
Settings > Account & sync > Delete account - On the web: https://www.synapseent.com/paperpaws/delete-account/en/
- By email: admin@synapseent.com
We may verify ownership using information already associated with the account or Google Sign-In. We do not ask for your Google password or a full copy of an identity document. We respond within the period required by applicable law. Verified account-deletion requests are normally completed within 7 days. If some information must be retained, we explain the reason and scope.
Account deletion removes the Google link and Paper Paws profile, active sessions/devices, server learning backups, push registration/preferences, account-linked membership entitlement, and non-mandatory account support/operations data. Legally required payment, dispute, security, or fraud-prevention records are separated or pseudonymized and kept only for the stated period.
Important:
- Deleting Paper Paws does not delete your Google account.
- Deleting the account or uninstalling the app does not automatically cancel Google Play recurring billing. Cancel Paper Paws in Google Play under
Payments & subscriptions > Subscriptionsfirst if you want to stop renewal. - Local guest progress may remain on the device after server account deletion. Use the in-app reset or Android clear-storage function if you also want to erase local data.
- Android backups and data independently held by advertising, payment, or speech providers may require their own settings or deletion procedures.
8. Children under 14
Paper Paws online accounts, server backup, personalized advertising, and marketing-notification features are not offered to children under 14. Until a legally valid guardian-consent process is implemented, users under 14 must not use Google Sign-In or those online features.
If we learn that a child's personal information was processed without valid guardian consent, we will promptly delete it or apply legally required safeguards. A guardian may contact admin@synapseent.com.
9. Security measures
Our safeguards include HTTPS/TLS; encryption or one-way hashing of email, purchase tokens, and installation identifiers; separate secret storage; least-privilege access controls; non-public operations tools and audit trails; session expiry, revocation, and token-replay protections; backups, integrity checks, restore testing, security updates, and monitoring; and limiting personnel access to what is necessary.
10. Automated decisions
We do not make decisions solely by automated processing that produce legal or similarly significant effects. Automated rules may schedule reviews, stage content updates, or select ads, but these do not create legal effects. Ad personalization depends on your choices and Google advertising settings.
11. Privacy contact
- Privacy officer/team: Synapse Ent Privacy Team
- Email: admin@synapseent.com
- Website: https://www.synapseent.com/
12. Complaints
You may contact the following Korean privacy authorities if applicable:
- Personal Information Dispute Mediation Committee: +82-1833-6972, https://www.kopico.go.kr/
- Privacy Infringement Report Center: 118 in Korea, https://privacy.kisa.or.kr/
- Korean Privacy Portal: https://www.privacy.go.kr/
- Korean National Police Cyber Bureau: 182 in Korea, https://ecrm.police.go.kr/
13. Changes to this Policy
We may update this Policy when laws, app features, or providers change. Material changes will be announced through the app, Google Play listing, or this page before they take effect. We generally provide at least 7 days' notice for changes that materially affect user rights.
Change history:
- July 19, 2026: Initial publication