Security
Promises you can check.
A privacy policy is only words. These are the parts of Paperwren's design that make the words true, and all of them are in the public source code.
- 01
No permissions, enforced at build time
The Android build script removes every permission the app template adds, including internet access, and fails the build if one is left. The app's system info page shows none.
- 02
No way to reach the network
Besides having no internet permission, the app's content security policy only allows connections to itself. There is no analytics, ads, crash or update SDK among its dependencies: just document engines (pdf.js, docx-preview, SheetJS) and small helpers.
- 03
Read-only file access
The app can read documents but has no permission to write, delete or run anything. On Android, reading is limited to files you picked or shared and the app's own private copies.
- 04
Documents are treated as untrusted
Markdown is sanitised with DOMPurify before display. Scripts can only come from the app itself, and plugins and form submissions are blocked outright. Spreadsheets and older Office formats are parsed off the main thread.
- 05
Private copies stay private
Files are copied into storage only Paperwren can read, named by a hash of their content, and every path is validated so nothing is read or written outside that folder.
- 06
Nothing rides along in backups
Android cloud backup is disabled. PDF passwords live in memory only and are never stored.
How builds are made
Releases are built by GitHub Actions from the public repository after lint, type checks, unit tests and Rust tests pass. Download them only from GitHub Releases. While the app is in testing, Android builds are signed with a test key.
Report a vulnerability
Please report security issues privately through a GitHub security advisory rather than a public issue.