ShinyPapers has no accounts, so there is very little to say here — but what there is, is worth stating precisely.
Last updated July 2026
When you save a paper, mark one done, or add one to your revision queue, that is written to your browser’s local storage under a single key. It holds:
This is not a cookie and it is not an account. Local storage is never transmitted with requests, so the server cannot read it. It stays on that one device, in that one browser, until you clear it.
Two consequences follow, and neither is hidden: your history will not appear on another device or browser, and clearing your browsing data will erase it. You can export a backup file at any time from settings. Note also that local storage is not private from anyone else using the same browser profile on the same device.
ShinyPapers sets no cookies for visitors. There is no tracking cookie, no advertising cookie, and no session cookie, because there is no session to keep.
One cookie exists in the codebase, for the password-protected admin console used to run the data ingest. It is never set for normal visitors.
Loading a page necessarily reveals some technical information to the server and hosting provider — your IP address, which page you asked for, and your browser and operating system, in the ordinary way that any website works. This is used to serve the page and keep the site running.
When the dashboard needs to display your saved papers, it sends the paper id numbers from your browser to the server and gets those papers back. The request carries no identifier of any kind, so it cannot be linked to you, to a session, or to any earlier request.
The site uses Vercel Analytics to count page views. It is configured to work without cookies and does not build a profile of individual visitors or follow them across sites. It records aggregate information such as which pages are viewed and roughly where traffic comes from.
Question papers and mark schemes are hosted by PapaCambridge, not by ShinyPapers. Opening a paper takes you to their servers, where their own privacy practices apply. ShinyPapers has no control over and no visibility into what they collect.
ShinyPapers is intended for school students, so many visitors will be under 18. The protection offered is structural rather than procedural: no account can be created, no email or name is requested, and no personal information is collected from anyone, whatever their age. There is therefore no children’s data held, and none to request or delete.
Rights of access, correction, deletion and portability all normally require the operator to hold data about you. ShinyPapers holds none, so there is nothing to request.
The practice data that exists is entirely under your control: view it in the dashboard, export it to a file, restore it from one, or delete all of it in one action from settings. You can also clear it through your browser’s own site-data controls, without involving ShinyPapers at all.
This page will change only if what ShinyPapers collects changes. Adding accounts or any form of personal data collection would mean rewriting it, and would be announced rather than done quietly. The date at the top reflects the current version.