Skip to content

Privacy and data protection

We know an unpublished manuscript is sensitive material. This page explains, without hedging, what happens to it from the moment you upload it until you get the diagnosis.

What happens to your manuscript, step by step

  1. You upload a .docx or .txt file. We extract the text and delete the original file as soon as the extraction finishes — the document as you uploaded it is never stored, only the text.
  2. The extracted text is stored encrypted, both in transit (TLS) and at rest (AES-256) — this is the standard infrastructure of Supabase, our database provider.
  3. That text is sent to the OpenAI API to generate the diagnosis. We only call the standard chat completions endpoint — with no additional tools that persist data on their own, and without asking for the call to be stored.
  4. The diagnosis produced is stored against your project, protected by the same access controls: only you and the members of your group can see it.

What OpenAI guarantees about what it processes

The diagnosis is generated by an OpenAI model. What follows does not depend on any special agreement we negotiated — these are the default terms of their API:

  • No model is trained on your data. This has been the API default since 1 March 2023: what is sent «is not used to train or improve OpenAI models», unless the customer expressly asks to share it — and we have not asked (OpenAI documentation).
  • The call leaves no stored copy. On the endpoint we use, and without asking for storage, OpenAI does not retain the request or the response as application state. The text only remains in their abuse monitoring logs, which are deleted within 30 days at most.
  • Encrypted in transit and at rest (TLS 1.2+ and AES-256), with strict access controls (security and privacy at OpenAI).
  • International transfer. OpenAI's servers are in the United States. Their Data Processing Addendum establishes OpenAI as the data processor and covers transfers from the EEA under Standard Contractual Clauses.

What we keep, and for how long

The diagnosis (report, findings) stays in your account for as long as you use it — it is the product you are paying for and using. The text extracted from the original manuscript is deleted automatically 30 days after upload, whether or not the diagnosis ever completed — you do not have to ask. If you want it deleted sooner, write to us at [email protected] and we will remove it by hand.

Other providers we use

The «your diagnosis is ready» notice is sent by email through Resend. That email carries your project name and your email address — never the content of the manuscript or of the report.

What you should not upload

Upload the manuscript only. If your study includes raw participant data (names, identifiers, transcripts with personal information), leave it out of the file — the diagnosis does not need it, and this keeps third parties' personal data out of the system.

Analytics

We use Google Analytics to understand how the app is used — but only if you accept it explicitly in the notice you see the first time you visit the site. Without your acceptance, no Google script is loaded and no analytics cookie is set. You can change your mind at any time by deleting the ga-consent cookie from your browser, which makes the notice appear again.

Group invitations

If a principal investigator invites you to their group, we process your email to send you the invitation and, if you accept it, to manage your access to the group's projects — these are pre-contractual measures at the data subject's request (Art. 6(1)(b) GDPR). If you do not accept the invitation, we keep nothing beyond the record of the invitation itself, which expires after 14 days.

Contact

You can delete your account and all associated data yourself, at any time, from Account inside the app. For anything else, or to exercise your other rights (access, rectification, objection), write to [email protected].