Remember to change myapp-bucket-name to the name of your S3 bucket.
You can grant access to multiple buckets by adding more entries to the "Resource" array in the policy.
To create the custom policy, go to "Policies" within the IAM section of the AWS dashboard. Click "Create Policy" and paste the example policy above into the editor in the "JSON" tab. Alternatively you can use the visual policy builder.
Once the policy is saved, edit the Paperplane AWS user to associate it with the policy, either directly or via a group.