Legal
Privacy Policy
Last updated 5 October 2026
This policy explains what Research Monitor collects when you use it, why, who processes it on our behalf, how long we keep it, and how you can have it corrected or deleted. It describes the service as it actually works today.
Who we are
Research Monitor (“we”, “us”) is an AI literature-monitoring service for life-science researchers. We are responsible for the personal data described in this policy. You can reach us about anything in it at theonlytoufic@gmail.com.
What we collect
Your account
- Email address and password. We store your password only as a bcrypt hash, never in readable form.
- Google sign-in. If you sign in with Google, Google confirms your email address to us and we keep only that address. We never receive your Google password.
- Account details: your plan, subscription status, whether you have finished onboarding, and a display name if you set one.
- Research profile and settings: the field, career stage, methods focus and years in the field you give us during onboarding, plus your email preferences.
What you tell us about your research
- The collections you follow.
- Your research interview answers for each collection (your aim, your context, what matters and less noise), including earlier versions. We also store numerical representations (embeddings) of your aim, context and less-noise answers, which we use for matching.
- Projects: their names, descriptions and linked collections.
- Custom topics you create: their names, descriptions, scope and search terms.
- Research missions and positions, if you use those features.
- If you used our earlier Research Lens interview, the answers you gave there, which may include your name, role and institution.
What you do in the app
- Papers you open, save, dismiss, rate or share, and collections of papers with any notes you add.
- Questions you ask with Ask and the answers, kept as conversations in your account, plus a monthly count for plan limits.
- Deep Find searches and their results.
- Watchlists and the alerts they produce.
- Feedback and ratings you give, and a reading-preference profile we generate from them, which you can edit.
- Papers you import by PMID, DOI, BibTeX or PDF. For a PDF we extract the text and keep it in your account; we don't keep the file itself. An imported paper's public bibliographic details, such as its DOI and title, may be added to our shared paper catalogue, with no link to you.
- The daily AI briefs and other summaries we generate for you.
- A record of language-model use on your behalf: the feature, model, token counts and cost, but not the text that was sent.
Agent keys
Agent (MCP) keys are stored as SHA-256 hashes, so we cannot read a key back after creating it. We keep its first 12 characters so you can recognise it, along with its label, the collections it covers, its expiry, when it was last used and, if revoked, when. We count your agents' tool calls by day, key or connected app, and tool name, to apply the daily limit and the Free allowance, to show you your usage and to spot abuse. We don't log what your agent asks for or what it receives, though results may be cached for a few minutes to speed up repeat requests. Upload tokens for our bookmarklet are also stored only as hashes.
Billing
If you subscribe, Stripe runs the checkout and stores your payment details. We store your Stripe customer ID, subscription ID and subscription status. We never see or store your full card number.
Usage analytics
Our own analytics records events such as visiting the landing or pricing page, starting sign-up, completing onboarding steps, following a collection and opening your Today page. Each event carries a random session ID from a cookie, your browser's user-agent string, and a one-way hash of your IP address combined with the date, so the hash changes every day. We don't store your IP address with these events. Events from a signed-in browser are linked to your account, so we can tell whether the service is working for you, for example how often people return in their first week.
We also record where you first arrived from before you signed up: the referring website, any campaign tags in the link you followed (such as utm_source) and the page you landed on. It is stored with your account, and we look at it only in aggregate, to see which channels bring people who find the service useful. We don't use third-party analytics, advertising or tracking services.
Server logs
Like most web services, our hosting records server logs, which can include IP addresses, the pages and API endpoints requested, and error details. We use them to keep the service running and secure.
Services you choose to connect
If you connect GitHub to sync notes to Obsidian, we store your GitHub username and user ID, the app installation ID and the repository name, and we write topic notes into an app/ folder of a repository in your GitHub account. Depending on your plan, that repository may be public; the setup page says which before you connect.
How we use it
- To provide the service: running your account, matching new papers to your aim, building your Today page and briefs, answering your questions, and sending the emails described below.
- To bill you, through Stripe, if you subscribe.
- To keep the service secure and fair: rate limits, plan allowances, and investigating abuse or faults.
- To support you: a small number of authorised staff can see an account's activity to answer questions and fix problems.
- To improve the service: mainly through aggregate usage analytics, such as how many people finish onboarding.
- To meet legal obligations, such as keeping tax and accounting records.
We do not sell personal data, we do not share it for advertising, and we do not use your content to train machine learning models.
If you are in the European Economic Area or the UK, our legal bases are: performing our contract with you (running the service you signed up for); our legitimate interests in securing, supporting and improving the service; and complying with legal obligations.
Language models and your content
Some features send text from your account to the language-model providers listed below, so that they can produce a result for you:
- Interview answers. Your aim, context and less-noise answers are turned into embeddings by Google's Gemini API for matching. On paid plans, your answers are also included in the prompts that write your daily AI brief and answer your Ask questions, which go to OpenAI.
- Ask. Your question and the conversation so far go to OpenAI to write the answer, and the question is embedded by Google to find relevant papers.
- Search. Search queries, including those your agent sends, are embedded by Google.
- Custom topics. The name, description and scope you write go to OpenAI to design searches. The resulting search terms are sent to public literature databases.
- Imports. The titles and abstracts of papers you import go to OpenAI to extract findings.
- Your feed. The names of the collections you follow go to Google to explain why papers appear.
- Deep Find. Your search goes to OpenAI, to Exa for web search, and to public literature databases.
We don't attach your account details, such as your email address, to these requests. The providers process the text to return results to us under their API terms, and may keep it for a limited time under those terms, for example to monitor abuse. We do not use your content to train models.
Service providers
These companies process personal data on our behalf, only to provide the service:
| Provider | What they do for us | Data involved |
|---|---|---|
| Render | Hosts our API, background jobs, PostgreSQL database and Redis cache. | All account and service data described in this policy. |
| Vercel | Hosts the website and handles sign-in requests. | Website requests, and sign-in details as they pass to our API. |
| OpenAI | Language models for paper analysis, Ask answers, daily AI briefs and custom-topic design. | Paper content, and the text from your account listed under “Language models and your content”. |
| Google (Gemini API) | Embeddings for matching and search; paper scoring and analysis; a back-up model. | Paper content, your interview answers, search and Ask queries, and the names of collections you follow. |
| Resend | Sends our emails. | Your email address and the content of each email. |
| Stripe | Payments and subscription management. | Your email address, your account ID and the payment details you enter on Stripe’s pages. |
| Cloudflare (R2) | Stores snapshots of paper collections, figure images and recovery copies. | Mostly public paper data. Paper sets for custom topics are filed under your account ID. |
| Exa | Web search for Deep Find. | The text of your Deep Find searches. |
To find and enrich papers, we also query public literature databases, including PubMed, Europe PMC, bioRxiv, medRxiv, arXiv, OpenAlex, Semantic Scholar, Crossref and NIH RePORTER. When you run Deep Find, search for a paper to import, or build a custom topic, your search terms are sent to some of them. We never send your account details.
Google (for sign-in) and GitHub (for Obsidian sync) receive data only if you choose to use them, under their own privacy policies.
Emails we send
- Account emails: a welcome email when you sign up, and password-reset emails when you ask for one.
- Briefing emails, on paid plans: the daily paper screen and the weekly briefing. You can turn each off in Settings.
- Watchlist digests, if you set up watchlists. To stop them, remove your watchlists or email us.
We don't currently send marketing emails. Stripe may email you receipts and payment notices for a paid plan.
How long we keep data
- Account and research data is kept while your account is open, so your history, briefs and matching keep working.
- When you ask us to delete your account, we delete your personal data within 30 days. The exceptions are records we must keep for legal, tax or accounting reasons, and copies in backups, which are removed as the backups are replaced.
- Usage analytics events from a signed-in browser carry your account ID, not your name or email. That link, and the record of where you first arrived from, are removed when the account is deleted.
- Revoked agent keys stay on record, as hashes, until your account is deleted, so that a revoked key can never work again.
- Free-plan tool-call counts expire after about 40 days.
- Server logs are kept by our hosting provider for a limited period.
Your choices and rights
- You can change your interview answers, projects, followed collections and email preferences in the app at any time, and revoke agent keys from Settings.
- You can export your paper collections as BibTeX from the app.
- To see the personal data we hold about you, correct it, get a copy, or have your account and data deleted, email theonlytoufic@gmail.com from the address on your account. There is no self-service delete button yet, so we handle deletion by request. We will reply within 30 days.
- If you are in the European Economic Area or the UK, you have the right to access, correct, erase, restrict and port your data, and to object to processing based on our legitimate interests. You can also complain to your local data protection authority.
Security
Data travels over encrypted HTTPS connections. Passwords are hashed with bcrypt, and agent keys and upload tokens are stored as SHA-256 hashes. Access to production systems is limited to authorised staff. No system is perfectly secure; if a breach affects your personal data, we will tell you as the law requires.
International transfers
Our service providers are based in the United States, and your data is processed there and wherever they operate. Where the law requires safeguards for these transfers, we rely on the mechanisms our providers offer, such as the standard contractual clauses in their data processing terms.
Children
Research Monitor is a tool for researchers and is not directed at children. You must be at least 16 to use it. If you believe a child has given us personal data, email theonlytoufic@gmail.com and we will delete it.
Changes to this policy
When we update this policy, we will change the date at the top of the page. If a change is material, we will also tell you by email or in the app before it takes effect. Our Terms of Service explain the rules for using Research Monitor.
Contact
For privacy questions and requests, email theonlytoufic@gmail.com.