Privacy notice
How research data, account information and temporary documents are handled.
Draft for pre-launch review. Operator organization: [TO COMPLETE]. Privacy and security contact: [TO COMPLETE BEFORE PUBLIC LAUNCH]. This is not a finalized legal notice.
What this service processes
Supabase processes account sign-in and session information. The application stores a local identity, account plan/status, and operational usage records. Research questions, paper metadata, abstracts and uploaded document content may be processed to provide research assistance. Supplied analysis content may be sent to the configured AI provider; requests ask the provider not to store model responses, but this is not a promise of zero provider retention.
Saved work and temporary documents
Projects, thesis plans, selected paper metadata, derived evidence and reports are saved when you use their save or planning actions. Standalone structured analyses are persisted when you explicitly save them. Raw uploaded files/full text are not saved as a document library. Extraction uses temporary files, normally removed when processing finishes, including handled failures. Abrupt worker termination can delay cleanup until ephemeral storage is removed.
Essential storage and operations
The browser uses essential Supabase session storage and application preferences/state. No tracking analytics or advertising cookies have been added. Approximate daily signed-in-user counts use date-scoped hashed internal identifiers in short-lived operational Redis state; no new browser tracking identifier is introduced. Operational logs and model-use accounting record categories, timing, counts and token usage rather than research content. Literature caches contain public bibliographic information. The full-text resolver also caches machine-accessible article text and source/access metadata for up to 24 hours, and unsuccessful lookups for up to five minutes. User-uploaded documents are excluded from this shared resolver cache. Hosting, authentication and AI providers have their own processing/retention terms.
Deletion and retention
You can delete owned projects and planning content using the application controls. Account deletion currently requires an operator request through the contact above, once completed. Local deletion removes linked projects, analyses, plans, reports and user usage records. A hashed identity marker prevents accidental reprovisioning; privileged audit records and non-user-linked aggregate model accounting remain. External Supabase identity deletion is a separate administrator step and will be reported as pending until completed. Backup copies age out under the operator's configured backup policy; deletion is not a promise of instant erasure from backups.
Before launch, the operator must publish applicable retention periods, contact details, provider disclosures and jurisdiction-specific rights/processes. Do not upload patient-identifiable or other sensitive personal information without a separately approved processing arrangement.