When you sign in with email/password or with Google, Papiano stores your name, email address, and profile photo (if provided) to create your player identity. Password sign-in is handled by Amazon Cognito, which stores your credentials in hashed form — Papiano itself never sees your plaintext password.
Display name, user ID, bio, country, role, avatar, recorded play time, friend list entries, blocked users, and submitted reports are stored so profile, friends, and moderation features work. Your display name, bio, avatar, and play time are visible to other players by design.
Chat messages, message edits, deletion state (whether a message was removed), and images you send in chat are stored so conversations sync across your devices and so moderators can review reported abuse. Public room chat is visible to other players in that room; avoid putting sensitive personal information in messages, names, or bios.
Room names, player lists, room status, room-level chat, access settings, and moderation actions (mutes, kicks, bans) are processed in real time through AWS AppSync and Lambda so players can join, leave, and play together.
Piano settings, visual preferences, sound options, presets, and your session sign-in token are saved in your browser's local storage, not in a third-party cookie. Clearing your browser's site data removes this locally stored information and signs you out.
Standard connection and device information — such as browser type, approximate connection quality, and authentication events — is processed by Amazon Web Services to deliver the app, detect abuse, and keep accounts secure. Papiano does not run independent ad-tracking or analytics scripts.
Where applicable law requires a stated legal basis, Papiano processes data under: performance of a contract (running the account and features you sign up for), consent (where you actively opt in, such as choosing Google sign-in), and legitimate interest (keeping the service secure and moderating abuse).
These providers act as data processors for Papiano and are contractually and technically restricted from using your data for their own purposes.
Papiano's infrastructure runs in AWS's ap-southeast-1 (Singapore) region. If you use Papiano from outside that region, your data is transferred to and processed in Singapore. By using Papiano, you consent to this transfer.
Moderators may review reported content, remove abusive material, restrict accounts, disable rooms, or remove unsafe images to protect players. Actions taken and the reports that triggered them may be retained for safety records even after the related content is removed.
Papiano requires account holders to be at least 13 years old, consistent with the Terms of Service. We do not knowingly collect personal data from children under 13. If we learn an account belongs to a child under 13, we disable it and delete the associated data, subject to Section 13.
Account and profile data is retained for as long as your account is active. After a verified account-deletion request, we aim to delete or irreversibly anonymize your account data within 30 days, except copies kept where required by law, to resolve disputes, to enforce our agreements, or in routine backups until they naturally expire.
You can edit profile details, remove optional profile information, leave rooms, block users, and clear supported chat history directly in the app. To request access to, correction of, or deletion of your account data, email legal@papiano.app from your account's registered address. We respond to verified requests within a reasonable time, generally within 30 days.
Papiano uses industry-standard safeguards available through its infrastructure providers — including encryption in transit, hashed credential storage through Amazon Cognito, and access-controlled backend services — but no online service can guarantee absolute security. If a breach affecting your personal data occurs, we will notify affected users and relevant authorities as required by applicable law.
This policy may be updated as Papiano grows. Material changes will be reflected on this page and, where practical, announced through the app or official community channels.
Data access, correction, or deletion requests: legal@papiano.app. General account or app issues: support@papiano.app.
No. Papiano does not sell personal information to third parties or ad networks. Data is used only to operate accounts, multiplayer rooms, chat, and moderation.
Papiano runs on Amazon Web Services: Cognito for sign-in, S3 for file storage, and AppSync with Lambda for the realtime backend, all in the ap-southeast-1 (Singapore) region. If you sign in with Google, Google processes your authentication.
Email legal@papiano.app from your account's registered address requesting deletion. We aim to delete or anonymize account data within 30 days, except copies kept where required by law or to resolve disputes.
Papiano does not use third-party advertising or tracking cookies. It uses browser local storage to keep you signed in and to remember piano settings on your device.