Skip to main content
Papaya
Composer
  • Consent Checker
  • got cipa?
History Teams
  • API
  • MCP
Methodology Privacy Policy Terms of Service
Papaya
-- min
Account Log in / Sign up
  • English EN
  • Français FR
Composer
  • Consent Checker
  • got cipa?
History Teams
  • API
  • MCP
Legal

Privacy Policy

Privacy Policy for Papaya Consent Checker

Last Updated: 15th July 2026

Papaya Privacy Co ("we," "our," or "us") respects your privacy. This Privacy Policy describes how we collect, use, disclose, and retain information when you use the Papaya Consent Checker platform, including:

  • our hosted web application (including the got cipa? assessment workspace),
  • our command-line interface (CLI) for local or self-hosted use,
  • our HTTP API (/api/v1),
  • our Model Context Protocol (MCP) server, and
  • any related documentation, support, or account features

(collectively, the "Service").

1. Information We Collect

We collect information you provide directly, information generated when you use the Service, and limited technical data needed to operate the Service.

A. Information You Provide

  • Account Information: When you create an account or sign in, we collect your email address and account identifiers through our authentication provider (Supabase). You must be signed in to start privacy tests in the hosted web application.
  • Payment Information: If you subscribe to a paid plan, our payment processor (Stripe) collects and processes your payment details. We do not store full credit card numbers on our servers. We may receive subscription status, customer identifiers, and billing metadata from Stripe.
  • Test Configuration and Input Data: We collect the information you submit to run analyses, including:
    • target website URLs,
    • consent flow selections (for example, accept all, reject all, GPC, or granular/custom prompts),
    • geographic or regional simulation settings (for example, US state or international region codes),
    • post-consent journey settings (such as reload, navigation, or workflow prompts),
    • assessment mode selections (for example, default compliance analysis or got cipa? / CIPA-oriented analysis),
    • language preferences, and
    • any free-text prompts you provide for granular testing or Composer workflows.
  • Composer Data: If you use Composer, we collect and store workflow definitions, run plans, chat messages, saved workflows, and related metadata associated with your account.
  • Scheduled Test Configuration: If you create scheduled or recurring tests, we store the URL, flow, region, schedule type, status, and timing details needed to run them.
  • Chat Queries: If you use AI chat features to ask questions about a report or to build workflows in Composer, we collect and store your message history for that session or draft so the feature can maintain context.
  • API Keys: If you create API keys for programmatic access, we store a hashed version of each key (not the plaintext key), along with metadata such as key prefix, environment, creation time, revocation time, last-used time, and usage count.

B. Information Generated by the Service

  • Analysis Results and Artifacts: When you run a test, we generate and may store artifacts such as:
    • screenshots and visual captures of the target website,
    • network traffic logs (requests, responses, cookies, and tracker-related data),
    • markdown and JSON analysis reports,
    • PDF exports derived from those reports,
    • compliance or CIPA-oriented AI summaries,
    • session JSON containing run metadata and evidence, and
    • live-session/debug URLs when browser sessions are active.
  • Shared Report Copies: If you create a public share link for a completed run, we copy the relevant report artifacts into a separate shared storage location and store a share record linking that content to a share token.
  • Usage and Operational Metrics: We record service usage for monitoring, account visibility, and—on certain plans—billing, including:
    • browser session duration,
    • AI token usage and estimated model cost for direct OpenAI calls we make (such as summaries and chat),
    • timestamps and status of runs,
    • API key usage counts, and
    • server, queue, and application logs needed to operate and secure the Service.
  • Temporary Processing Data: We use Redis and similar in-memory/cache infrastructure for task queues, short-lived session state, chat history caches, and other operational data. Some cached data expires automatically; other cached data may persist until overwritten or deleted.

2. How We Use Your Information

We use the information we collect to:

  • Provide the Service: authenticate users, run privacy and consent analyses, generate reports, provide live views, export results, operate Composer and scheduled tests, and maintain your run history.
  • Provide Programmatic Access: issue, validate, and revoke API keys; serve API and MCP requests tied to your account.
  • Process Payments and Access Controls: manage subscriptions, free-test allowances, and feature access.
  • Operate AI Features: generate summaries, chat responses, and Composer assistance using OpenAI. This may include sending report content, screenshots or screenshot URLs, your prompts, workflow definitions, and related context to OpenAI. Some AI features may also use OpenAI's web search capability to retrieve publicly available information about laws, enforcement actions, or tracking technologies relevant to your question.
  • Monitor and Bill Usage: measure browser time and AI usage so we can display account usage summaries and, for certain plans, calculate charges. On the self-serve Starter plan (currently $99.99/month), usage metering is for monitoring and visibility only and does not affect your bill beyond the flat subscription fee. If you are on a different subscription or custom/enterprise plan, usage metering may also be used for billing, quotas, or overage charges according to the pricing terms or written agreement that applies to your account.
  • Improve and Secure the Service: debug failures, prevent abuse, maintain reliability, and improve detection accuracy and product performance.
  • Communicate with You: respond to support requests and send service-related notices when appropriate.

3. How We Share Information

We do not sell your personal data.

We share information only with service providers and subprocessors that help us operate the Service, including:

  • Supabase: authentication, database hosting, and object storage.
  • Stripe: payment processing and subscription management.
  • OpenAI: AI summaries, chat, Composer assistance, and related model features (including web search where enabled).
  • Browserbase and Stagehand: cloud browser automation used to load target websites, interact with consent interfaces, and capture evidence. Stagehand may also use model providers configured for browser automation.
  • Cloud and Infrastructure Providers: hosting, background workers, queues, and caching infrastructure (for example, Heroku and Redis) used to run the Service.

We may also disclose information:

  • when you intentionally create a public share link, to anyone who has that link;
  • when required by law, legal process, or governmental request;
  • to protect the rights, property, or safety of Papaya Privacy Co, our users, or others; or
  • in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality protections.

The Service analyzes third-party websites at your direction. We do not control those websites' privacy practices.

4. Public Share Links

If you choose to create a share link for a completed run, we generate a tokenized URL that allows anyone with the link to view a read-only copy of the shared report materials (which may include screenshots, summaries, tracker evidence, and related analysis).

You are responsible for deciding whether sharing is appropriate and for controlling who receives the link. Share links remain available until you ask us to remove them or we delete them as part of account or data deletion. At this time, shared links do not automatically expire on a fixed schedule.

5. Data Retention

  • Account and Run History: We retain test results, reports, screenshots, and related artifacts associated with your account so you can access your history, unless and until you request deletion or we delete them under our retention practices.
  • Shared Reports: Shared copies remain available while the share record exists.
  • Composer and Scheduled Test Data: We retain Composer runs, saved workflows, and scheduled test configurations while your account remains active or until deleted.
  • API Key Metadata: We retain API key records (hashed keys and metadata) until revoked or deleted.
  • Usage Events: We retain usage metering records in our database for monitoring, account reporting, and—where applicable—billing under your plan.
  • Chat History Caches: Some chat history is stored temporarily in Redis. Composer chat caches are retained for a limited period (currently up to seven days) unless cleared earlier.
  • Logs and Backups: We may retain server logs and provider backups for a limited period for security, troubleshooting, and disaster recovery.

You may request deletion of your account and associated data by emailing ram@papayacomply.ai. We may retain certain information where required by law or for legitimate business purposes such as billing records, security logs, or dispute resolution.

6. Security

We implement reasonable technical and organizational measures designed to protect your information, including HTTPS for data in transit, hashed API key storage, access controls tied to authenticated accounts, and use of reputable cloud providers for storage and authentication. No method of transmission or storage over the Internet is completely secure, and we cannot guarantee absolute security.

7. Your Rights and Choices

Depending on your location, you may have rights regarding your personal data, such as the right to access, correct, delete, or export your data, or to object to or restrict certain processing.

You can:

  • manage your subscription through your account and Stripe customer flows,
  • revoke API keys from your account page,
  • clear certain chat histories using in-product controls where available, and
  • contact us to request access to or deletion of your data.

To exercise privacy rights, contact us at ram@papayacomply.ai.

8. International Users

The Service can simulate visits from multiple US states and international regions. The hosted application UI may be available in more than one language (currently including English and French). If you use the Service from outside the United States, you understand that your information may be processed in the United States and other countries where our service providers operate.

9. Children

The Service is not directed to children under 16, and we do not knowingly collect personal information from children under 16.

10. Changes to this Policy

We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the "Last Updated" date. If we make material changes, we may provide additional notice where appropriate.

11. Contact Us

If you have questions about this Privacy Policy, contact us at:

ram@papayacomply.ai

Papaya

AI agents that audit your site for privacy and accessibility, continuously, against every law that matters.

© 2026 Papaya Privacy Co.

Made with Love in San Francisco, Chicago & Chapel Hill, NC

Methodology Privacy Policy Terms of Service