Skip to main content
ScholarlyNotes

Privacy

Privacy Policy

Last updated 21 September 2026

This policy explains what personal data ScholarlyNotes collects, why, who else receives it, and the choices you have. The service is operated by ScholarlyNotes (“we”), 51 Ricardo Street, London, UK. It is a beta service, so please also read the Terms of Use.

The short version

  • We collect what is needed to run your account and your library, notes and drafts.
  • Your notes and drafts are never sent to an AI provider. The Reading assistant only receives the title and abstract of a paper, when you ask for it.
  • We do not sell your data, show advertising, or use analytics or tracking cookies.
  • You can export everything and delete your account yourself, at any time, in Settings.

What we collect

Account details: your name, email address, and a password (stored only as a salted one-way hash, never in readable form). Optionally your institution and field of research. We also record the time you created the account, roughly when you were last active (updated at most once an hour), whether you are an administrator, and when you accepted these documents and which version.

Your content: the papers you save (metadata, abstract, tags and your own reading notes), your notes, your paper drafts (including earlier versions kept for version history), figures you attach, your saved searches, and any feedback you send us.

Security data: one-time codes for email verification and password reset, stored only as a keyed hash and removed when used or expired; short-lived counters used to slow down repeated login or signup attempts, keyed by a hash of your IP address or email address, which expire within about an hour; and the web server’s access log (IP address, time, page requested, browser type), which we keep for about 14 days to investigate abuse and faults.

What we do not collect: no payment details (the service is free), no advertising or analytics identifiers, no location data, and no contents of your device.

Cookies and local storage

We use one cookie, a strictly necessary sign-in cookie (rn_token) that keeps you logged in for a limited time (7 days by default). It is not readable by scripts on the page and is sent only over HTTPS. Your browser’s local storage holds one setting, rn_theme, which remembers light or dark mode. No other cookies are set by us, so there is no cookie banner.

Why we use your data

  • To provide the service you signed up for: your account, library, notes, drafts, search and citations.
  • To keep the service secure: verifying email addresses, preventing abuse, and fixing faults.
  • To email you: verification and password-reset codes, and, only if you follow searches, a weekly digest with an unsubscribe link in every message. We also email the administrators when you send feedback.
  • To understand how the beta is going, using counts such as sign-ups and saved papers, and your feedback.

[Legal bases for processing (for example contract, legitimate interests, consent), where the law requires them to be stated, must be added here after legal review.]

Who else receives data

We use a small number of service providers. Each receives only what it needs:

  • Hosting and database. Our application runs on a server we control, and your data is stored in a MongoDB Atlas database. Location: MongoDB Atlas EU (Ireland).
  • Email delivery. Gmail delivers our emails, so it receives your email address and the content of each message (codes, digests, notices).
  • OpenAlex and Crossref (public scholarly indexes). When you search Discover, look up an author or import by DOI, our server sends the search text, author or DOI to them. The request comes from our server, so it does not include your name, email or account, and they do not see your IP address. Our contact email address is included so they can reach us if needed.
  • AI providers (Groq, and Anthropic as a fallback). Only when you ask the Reading assistant, we send the title and abstract of the paper (or papers) you chose. Nothing else: not your name, email, notes, drafts, tags or reference lists. See Our approach to AI. The answer is stored once per paper and shared with other users who ask about the same abstract; it contains nothing about you. The abstract sent is the one stored on the paper, which you can edit, so please do not paste private text into an abstract field if you plan to use the Reading assistant on that paper.
  • Authorities or advisers if the law requires it, or to protect the service and its users.

Links to papers take you to publisher and repository websites, which have their own privacy practices.

How long we keep it

We keep your data while your account exists. When you delete your account in Settings, your profile, library, notes, drafts, saved searches, feedback and AI usage counters are removed from our live database straight away. Backups made before that can contain your data until they are replaced, which takes up to 14 days. Short-lived security data expires by itself as described above.

Your choices and rights

  • Access and export: Settings → Export gives you all your data as JSON, and your library as BibTeX.
  • Correct: change your name, institution and field in your profile.
  • Delete: Settings → Delete account.
  • Emails: every digest has an unsubscribe link, and you can switch digests off in Settings.
  • Anything else (questions, objections, or exercising other rights that apply to you where you live): write to rajumolla@scholarlynotes.com. If you are not satisfied with our answer you can complain to the Information Commissioner's Office (ICO)".

Security

The site is served over HTTPS. Passwords are hashed, sign-in cookies are protected from scripts, login and code entry are rate limited, and administrator functions are checked on the server. No system is perfectly secure, and this is a beta: please keep your own copy of important work by using Export.

Age

ScholarlyNotes is intended for people aged All ages (with parental consent if required by law) or over. If you believe someone younger has created an account, contact us and we will remove it.

Changes and contact

If we change this policy in a way that matters, we will update the date above and, for significant changes, tell you in the app or by email. Questions: rajumolla@scholarlynotes.com.