Paperbark

Privacy policy

Last updated 14 September 2026. Paperbark is made by Koda Software, Australia. Privacy enquiries: takamundy@gmail.com.

Your original client records stay in your local vault. Account sync and optional practitioner messaging use cloud services. If you share a case in a message, only the de-identified text copy you review and send is uploaded.

What stays on your device

Client names, dates of birth, contact details, intake answers, treatment notes, body diagrams, signatures and any files you attach are stored only in Paperbark's own database on your device, encrypted with a key derived from your password. Original records are not uploaded to our servers. User-initiated exports and reviewed case messages are separate sharing paths.

A note is sealed when you sign and lock it. At that point Paperbark writes an encrypted archive to your device, and to your own cloud drive if you have connected one. Those copies are yours: they are encrypted with your key, and the storage provider cannot read them either.

What we collect, and why (APP 5)

This is the notice Australian Privacy Principle 5 requires, and you also see it in the app at the moment you are asked for anything.

  • Your email address, so you can sign in and so we can reach you about the software.
  • Your name and practice name, because they appear on the forms your clients fill in and on what you export.
  • Account sync data: your profile, encrypted forms and device roster.
  • Subscription verification data: product and transaction identifiers, account binding and entitlement expiry. Apple or Google Play processes payment; we do not receive your card details.
  • Optional practitioner messages: your display name, invitations, conversation membership, message text, timestamps and reports. This includes reviewed case summaries you explicitly send.

Local client work does not require messaging. Case sharing applies the existing identifying-field filter and additional redaction on your device, then shows the exact text for review. Free text may contain identifying circumstances that automated filtering cannot recognize. Cloud messages are protected in transit and by access rules; they are not end-to-end encrypted.

Giving us this information is voluntary, but without an email address we cannot give you an account. If you would rather not be contacted, email us and we will only write to you about something that affects your data.

What we never hold

  • Your password, or any key derived from it.
  • Your recovery code.
  • Your original local records, diagrams, signatures and attachments. Reviewed case summaries that you send in messages are an explicit exception: the cloud service stores that shared text.
  • The contents of your archives, wherever you keep them.

Where your data is held

Your account uses Google Firebase Authentication. During beta and development, account settings, device rosters, messages and subscription verification run on Paperbark-operated servers in Australia. Cloudflare provides the HTTPS connection to those servers. Firebase Authentication is a separately managed Google service and is not restricted to Australia. Apple or Google Play verifies purchases. A read-only Firestore migration copy remains temporarily available for recovery; current app writes go to the Paperbark account service.

The intake relay, which passes an encrypted intake form between you and a client, runs on hardware we operate in Australia behind Cloudflare. It holds ciphertext it cannot read, and deletes it as soon as your app confirms it has the answers.

Your archives go where you send them: your own device, and your own Google Drive, iCloud Drive, OneDrive or Dropbox account if you connect one. Those are your accounts, under your agreement with that provider, and the files are encrypted before they leave your device.

Service providers

  • Google Firebase Authentication, for sign-in, and a temporary read-only Firestore migration copy.
  • Apple and Google, when you choose to sign in with them.
  • Cloudflare, for network access to this site, the account service and the intake relay.
  • Your own cloud drive, if you connect one, under your own agreement with them.

A subprocessor annex naming each of these, what they hold and where, is available on request: email takamundy@gmail.com.

Keeping and deleting

You control your records entirely. Deleting a client, a record or the app deletes that data from the device, and we cannot recover it because we never had it. Health records carry statutory retention periods in Australia, generally seven years for adults and until a child turns 25, and meeting them is yours to do: keep your archives somewhere safe and lasting.

You can delete your account in Settings. Before anything is purged, Paperbark writes out your key material and an archive, so deleting the account never destroys your ability to open the records you already hold. After that we remove your sign-in and your profile. Conversation history and reports are not automatically removed by that local account action; contact support about those cloud records. Copies already received by another practitioner remain outside your control.

If a client asks you to erase their file, Settings has a path for exactly that: it removes the client, their records and their drafts from the device and records the deletion so your other devices follow.

Your rights

Australian Privacy Principles apply. You can ask what we hold about you, ask for a correction, or complain, by emailing takamundy@gmail.com. If our answer does not satisfy you, the Office of the Australian Information Commissioner takes complaints at oaic.gov.au.

No tracking, no advertising

  • No advertising, ad networks or data brokers.
  • No tracking of you across other companies' apps or websites.
  • No analytics or crash-reporting SDK inside the app.
  • Your information is not sold. Optional messaging shares the information you send with the conversation recipient and the service providers described above.

Children

Paperbark is for practitioners and is not directed at children. Original records about child clients stay on the practitioner's devices; the same deliberate sharing and review controls apply to any case summary the practitioner sends.

Changes

If this policy changes we update this page and the date at the top, and say so in the app's release notes.