1. Who we are
Cepe (“we”, “us”) operates Cepe Paper, the member dashboard, website, and related services (collectively, the “Services”). Cepe Paper is developed by Nexaverse Technology. This Privacy Policy explains what personal data we process and your choices.
2. Information we collect
Account information. When you register or sign in (including with Google), we receive your email address, display name, profile photo (if provided by your identity provider), and authentication identifiers through our auth provider (Supabase). Sign in with Google is used only to create and authenticate your Cepe account. It does not grant access to Gmail, Contacts, Calendar, or Google Drive.
Google Drive (optional). If you connect Google Drive from Cepe Paper, we request permission to list files you choose to open and to create or update files you save or export from the editor. Drive access is separate from Sign in with Google, is available on Creator plans and above, and can be disconnected in editor settings. We do not use Drive data for advertising, and we do not sell it.
Content you create. Documents, presentations, spreadsheets, PDFs, templates, and files you upload or sync may be stored in our cloud infrastructure when you use cloud features.
Usage and device data. We may collect log data such as IP address, browser type, app version, license activation events, and general usage to operate, secure, and improve the Services.
Payment information. Subscriptions and billing are processed by our payment provider (e.g. Stripe). We do not store full card numbers on our servers.
Cepe AI (CAI). When you use CAI, the text and context you submit may be sent to third-party AI providers to generate responses. Do not submit sensitive personal data you do not want processed for this purpose. See our AI Disclaimer for additional information about AI features.
Activity Tracker. If your organization enables Activity Tracker on an eligible plan, we process usage metadata about how team members use Cepe Paper — such as sign-in and sign-out events, document opens, edits, exports, and shares. Eligible Enterprise organizations may enable optional productivity or advanced monitoring settings. We do not collect webcam, microphone, or screen recordings through Activity Tracker. Administrators who enable this feature are responsible for providing any notices required by applicable workplace and privacy laws.
3. How we use information
We use personal data to:
- Provide, maintain, and authenticate your account
- Store and sync your files when you enable cloud features
- Process subscriptions, licenses, and support requests
- Send service-related emails (e.g. security, billing, product updates you opt into)
- Detect abuse, fraud, and security incidents
- Improve and develop the Services
- Provide Activity Tracker dashboards and audit logs to authorized team owners and administrators on eligible plans
4. Legal bases (EEA/UK users)
Where applicable, we rely on contract performance (providing the Services), legitimate interests (security, improvement, analytics), consent (marketing emails, optional cookies), and legal obligations. See our Cookie Policy for details on cookies and similar technologies.
5. Sharing with third parties
We share data with service providers that help us run the Services, such as:
- Authentication and database hosting (Supabase)
- Google (Sign in with Google, and optional Google Drive if you connect it)
- Payment processing (Stripe)
- Cloud storage and infrastructure
- AI model providers (when you use CAI)
- Email delivery providers
These providers process data to operate the Services. We do not sell your personal information.
6. Retention
We retain account and content data while your account is active. If you delete your account or request deletion, we will delete or anonymize personal data within a reasonable period, except where we must retain data for legal, security, or backup purposes.
7. Security
Production traffic uses HTTPS/TLS. Member files are scoped to your account with access controls and row-level security on our database where applicable. No method of transmission or storage is 100% secure.
8. Your rights
Depending on your location, you may have rights to access, correct, delete, or export your data, object to or restrict processing, and withdraw consent. Contact us to exercise these rights. You may also lodge a complaint with your local data protection authority.
9. Children
The Services are not directed to children under 16. We do not knowingly collect personal data from children. Contact us if you believe a child has provided us data.
10. International transfers
Your data may be processed in countries other than your own. This Privacy Policy and our processor list describe who receives it.
11. Changes
We may update this policy from time to time. We will post the revised version on this page and update the “Last updated” date. Material changes may be notified by email or in-app notice.
12. Contact
Cepe
Contact form