← Back to overview Security and recovery

What stays local, what connects, and what you control

PaperSafeAI is built around a local encrypted vault. This page separates current protections from operational limits so you can decide whether that model fits your documents.

encryptedAES-256-GCM

Document files and sensitive fields use authenticated encryption.

databaseEncrypted database

The desktop vault database uses SQLCipher with a 256-bit key.

passwordArgon2id

Password-based key protection uses a memory-hard key derivation function.

memoryLocal document AI

OCR, metadata extraction, and search indexing run on the computer.

01

Documents and local processing

  • Imported documents are stored in the encrypted local vault.
  • Document OCR, metadata extraction, and semantic search run locally.
  • The internet is needed for initial model setup, updates, licensing, and services you explicitly enable.
  • Temporary document material is managed by the desktop application during preview and processing.
02

Access and recovery

  • Your master password unlocks the local vault.
  • A recovery key is provided so you can reset a forgotten master password.
  • PaperSafeAI does not hold a server-side copy of the vault key.
  • If both the password and recovery key are lost, the encrypted vault cannot be recovered by PaperSafeAI.
03

Backup and restore

  • Desktop backup exports include the vault database and document files.
  • Backups use an encrypted PaperSafeAI backup format.
  • Restore verifies the backup manifest and file integrity before applying it.
  • Store a backup separately from the computer and keep its passphrase safe.
04

Diagnostics and limits

  • Analytics and crash reporting are controlled through application settings.
  • Performance depends on hardware, document length, and whether OCR is required.
  • Local-first storage means you are responsible for maintaining a recoverable backup.
  • No independent external security audit is claimed on this page.
Network clarity

When PaperSafeAI may connect

ActivityConnectionDocument content
Local OCR, extraction, and searchNot required after setupStays on device
AI model and application setupRequiredNot needed
Licensing and update checksRequired when usedNot needed
Optional diagnosticsOnly when enabledDesigned for operational events, not document files

Try the current desktop beta

No payment details are required. Review the privacy policy before requesting access.

Read privacy policy