Document files and sensitive fields use authenticated encryption.
What stays local, what connects, and what you control
PaperSafeAI is built around a local encrypted vault. This page separates current protections from operational limits so you can decide whether that model fits your documents.
The desktop vault database uses SQLCipher with a 256-bit key.
Password-based key protection uses a memory-hard key derivation function.
OCR, metadata extraction, and search indexing run on the computer.
Documents and local processing
- Imported documents are stored in the encrypted local vault.
- Document OCR, metadata extraction, and semantic search run locally.
- The internet is needed for initial model setup, updates, licensing, and services you explicitly enable.
- Temporary document material is managed by the desktop application during preview and processing.
Access and recovery
- Your master password unlocks the local vault.
- A recovery key is provided so you can reset a forgotten master password.
- PaperSafeAI does not hold a server-side copy of the vault key.
- If both the password and recovery key are lost, the encrypted vault cannot be recovered by PaperSafeAI.
Backup and restore
- Desktop backup exports include the vault database and document files.
- Backups use an encrypted PaperSafeAI backup format.
- Restore verifies the backup manifest and file integrity before applying it.
- Store a backup separately from the computer and keep its passphrase safe.
Diagnostics and limits
- Analytics and crash reporting are controlled through application settings.
- Performance depends on hardware, document length, and whether OCR is required.
- Local-first storage means you are responsible for maintaining a recoverable backup.
- No independent external security audit is claimed on this page.
Network clarity
When PaperSafeAI may connect
| Activity | Connection | Document content |
|---|---|---|
| Local OCR, extraction, and search | Not required after setup | Stays on device |
| AI model and application setup | Required | Not needed |
| Licensing and update checks | Required when used | Not needed |
| Optional diagnostics | Only when enabled | Designed for operational events, not document files |
Try the current desktop beta
No payment details are required. Review the privacy policy before requesting access.