Privacy Policy | Paperguide
Last updated: 17th Sep 2026 · Effective: 1st Oct 2026
This Privacy Policy explains how Paperguide collects, uses, stores, and shares information when you use paperguide.ai, the Paperguide research workspace, our browser extension, our free tools, and any connectors or integrations we publish (together, the "Service"). Paperguide is operated by Keevs Health Inc, 2925, Manor Bridge Drive, Alpharetta, GA 30004, USA. Questions: [email protected].
Summary
The short version, with the detail below:
- You own everything you upload. We claim no ownership of your documents, prompts, notes, or generated outputs.
- We do not use your uploaded content to train generalized or public AI models — ours or anyone else's.
- We do not sell your personal information and do not share your research content with third parties for advertising.
- A small number of AI providers process your requests as our contracted processors and are prohibited from training on your content.
- You can delete your content and account at any time; deletion timelines are in the Data Retention section.
1. Information we collect
1.1 Account information. Name, email, password (stored only as a salted hash), and if you claim a student/faculty discount, evidence of academic affiliation such as a university email domain.
1.2 Payment information. Processed by Stripe/Chargebee. We receive limited billing records (billing name, country, plan, amount, card brand and last four digits). We do not receive or store full card numbers.
1.3 User Content. Everything you put into or generate through the Service: PDFs and documents you upload; papers you save, including references imported from Zotero/Mendeley etc or captured by the browser extension; prompts, questions and messages to AI Search, Chat with PDF, the Literature Review Agent, Deep Research Reports and AI Writer; notebooks, extraction tables, literature-review tables, notes and drafts; and AI-generated outputs. This is the most sensitive category we hold and is governed by Section 4.
1.4 Usage and device information. Pages viewed, features used, AI credits consumed, IP address, browser and device type, operating system, time zone, referring URL and timestamps — used for security, fraud prevention, billing accuracy, debugging and product improvement.
1.5 Browser extension. Collects only the page metadata needed to capture a reference or generate a citation (URL, title, authors, publication details) at the moment you invoke it. It does not passively read or transmit your general browsing history.
1.6 Connectors and integrations. If you connect Paperguide to a third-party AI assistant through a connector we publish, we receive only the parameters of the specific request made and return only that request’s results. See Section 5.
1.7 Support and communications. Messages and contact details you send us, kept to respond and maintain a support record.
2. How we use information
We use information to: provide the Service and run the AI features you request (User Content, account data — to perform our contract); authenticate and secure your account; process payments and prevent billing fraud; provide support; debug, monitor reliability and improve the Service using usage and aggregated/anonymized data; send service and security notices; send product/marketing email only with your consent, withdrawable at any time; and comply with law. We do not make decisions producing legal or similarly significant effects about you using solely automated processing.
3. Cookies and analytics
We use strictly necessary cookies (authentication, session, security), which cannot be disabled. These include cookies set by our in-product support chat (Intercom), which we treat as part of providing the Service to you.
We also use the following non-essential technologies, and where the law requires it we ask for your consent before setting them:
- Google Analytics and Google Tag Manager — usage analytics (opt out at tools.google.com/dlpage/gaoptout)
- Google Ads — measuring conversions from our search advertising
- PostHog — product analytics. PostHog's session replay feature is enabled only while we are investigating a specific technical problem or a support request you have raised, and is otherwise switched off
- Tolt — affiliate referral attribution
- Cloudflare — bot protection and performance measurement
We do not use advertising or remarketing pixels, and we do not use cookies to build advertising profiles. We do not use your uploaded documents, papers, prompts, chats or AI-generated outputs for advertising.
Where session replay is active for troubleshooting, it may record what is displayed on your screen, which can include your User Content. Access to those recordings is limited to the personnel described in Section 4.4 and they are used only to diagnose the issue.
You can review and change your choices at any time through the "Your Privacy Choices" link in our website footer, or through your browser settings.
Global Privacy Control. We do not currently detect the GPC browser signal automatically. You can opt out of non-essential cookies and of any sharing for advertising purposes at any time using the "Your Privacy Choices" link in our footer, or by emailing [email protected].
4. User Content and AI processing
This section governs your uploaded documents, prompts, chats, notebooks and AI outputs, and mirrors Section 2A of our Terms of Service; where they conflict, the more protective provision applies.
4.1 You own your content. You retain full ownership of all User Content; Paperguide claims no ownership rights in it.
4.2 Limited license. You grant Paperguide a limited, non-exclusive, non-transferable, revocable license to process, store, index and display your User Content solely to provide and operate the Service for you. This does not permit resale, public disclosure, marketing use, or training of generalized AI models.
4.3 No training on your content. We do not use your User Content to train, fine-tune or improve public or generalized AI models, our own or any third parties.
4.4 Confidentiality. We treat User Content as confidential, do not sell it, and do not share it for commercial purposes. Internal access is limited to authorized personnel under confidentiality obligations who need it to operate the Service, investigate a security incident, or handle a support request you raised.
4.5 AI outputs belong to you. Summaries, analyses, extractions, literature reviews, citations and drafts generated from your User Content belong to you. Outputs may contain errors or misattributed citations and should be verified against primary sources.
4.6 Aggregated/anonymized data. We may use aggregated, anonymized usage data that cannot identify you or your content to improve reliability and performance.
4.7 Public research directories. Our Papers, Journals and Top Research Papers directories contain publicly available bibliographic metadata only. Your library, uploads and notebooks are never published to these directories.
4.8 Lawfulness of uploaded content. You are responsible for having the rights to upload and use the content you submit. Our handling of User Content does not grant you any rights in third-party or publisher content, and your obligations regarding licensed materials are set out in the Terms of Service (User Responsibilities and Copyright/DMCA sections).
5. Connectors and third-party AI assistants
If you connect Paperguide to a third-party AI client through a connector we publish: the connection is authorized by you via OAuth 2.0 and revocable at any time from Settings -> MCP and from the third-party client; we receive only the parameters of the specific request and return only that request's result; we do not collect conversation data beyond what is required to fulfil the request, and we do not request, retrieve or store the assistant's memory, chat history, conversation summaries or files outside the scope of the request; connector requests are logged for security, abuse prevention and billing on the same schedule as in-app requests; and once data reaches the third-party client it is governed by that provider's privacy policy, not this one.
6. Who we share information with
We share personal information only with the categories listed in Annexure A at the end of this policy, each acting as our processor under a written agreement, only on our instructions, and prohibited from using your content for their own purposes including model training. The categories are: cloud hosting/storage; AI model providers; payment processing; analytics and product analytics (Google Analytics, PostHog); advertising measurement (Google Ads); affiliate attribution (Tolt); bot protection and performance (Cloudflare); plagiarism detection; email/support; error monitoring; and content distribution/partner platforms.
We also disclose information where legally required (valid subpoena, court order or lawful request), to enforce our Terms, or to protect the rights, safety and property of Paperguide, our users or the public, notifying you where it is legally permitted. In a merger, acquisition or asset sale, information may transfer to the acquirer, and we will notify you before your information becomes subject to a materially different policy.
7. Health, clinical and other sensitive data
Paperguide is a research tool and is not intended as a repository for regulated health information. (a) You must not upload protected health information (PHI), individually identifiable health data, or other regulated personal data unless covered by a separate written agreement; Paperguide does not act as a HIPAA Business Associate under the standard Service; (b) if you need to upload PHI for medtech/HEOR or other relevant use cases, a Business Associate Agreement (BAA) is required before any such data is uploaded and used along with necessary compliances as required by the specific regional laws. Where you process special-category data under GDPR (e.g. health data) through the Service, you are responsible for establishing a lawful basis and any required consents.
8. Data retention
We keep personal information for as long as your account is active and as needed to provide the Service. After account closure:
- User Content (uploaded documents, saved papers, prompts and chats, notebooks, extraction and literature-review tables, notes, drafts and AI-generated outputs) is deleted from our active systems within 90 days;
- Account data is deleted or anonymized within 90 days;
- Backups expire on a rolling schedule within 35 days of the data leaving active systems;
- Billing and tax records are kept as required by law, typically up to 7 years;
- Security and audit logs are kept for up to 12 months;
- Analytics data is retained for up to 26 months;
- Support correspondence is kept for up to 24 months after the request is resolved.
You can delete individual documents, chats and notebooks at any time from within the product, and you can delete your account from Settings -> Others tab and write to us at [email protected] for assistance. We may retain information longer where required by law or necessary to establish, exercise, or defend legal claims, after which we delete or de-identify it.
9. Security
We protect information with TLS in transit (enforced by our hosting providers across all production endpoints), encryption at rest (provided by default by our infrastructure providers), access controls and least-privilege permissions (session-based authentication, role-based workspace and review permissions, SHA-256-hashed API keys, OAuth token validation, CAPTCHA on authentication forms, and per-user rate limiting), multi-factor authentication for staff access to infrastructure and production systems, logging and monitoring (application logs with security-relevant events like authentication failures, rate-limit hits, token validation errors etc., explicitly captured, along with an append-only audit log for data operations). We conduct security reviews as part of our development process. No system is perfectly secure; if a breach affects your personal information we will notify you and relevant authorities as required by law.
10. International transfers
Paperguide operates from the United States and processes data in the United States. For EEA/UK/Swiss users we rely on the EU Standard Contractual Clauses, the UK IDTA where applicable, and supplementary measures; request the safeguards at [email protected].
11. Your rights
Everyone can access, correct, export or delete their content in-product and close their account. EEA/UK/Swiss residents have GDPR rights (access, rectification, erasure, restriction, objection, portability, withdrawal of consent) and may complain to a supervisory authority (in the UK, the ICO). California residents have CCPA/CPRA rights (know, delete, correct, opt out of sale or sharing, and limit use of sensitive personal information). We do not sell personal information for money. We use the advertising measurement technologies described in Section 3, which may constitute "sharing" for cross-context behavioural advertising under the CPRA. You can opt out at any time using the "Your Privacy Choices" link in our website footer, or by emailing [email protected]. We do not sell or share the personal information of users we know to be under 16. Residents of other US states and of jurisdictions such as Canada, Brazil and India may have comparable rights, which we honor for verified requests. To exercise rights, email [email protected]; we verify identity and respond within the period required by law (generally 30 days).
12. Children
The Service is not directed to children. To create and hold an account you must be at least the age of majority in your state, province or country of residence and able to form a binding contract with us. A minor dependent may use the Service only through an account held by, and with the consent and supervision of, a parent or guardian, as set out in Section 1 of our Terms of Service; that parent or guardian is responsible for the minor's use. We do not knowingly collect personal information directly from children, and if we learn we have collected a child's data without the required consent we will delete it — contact [email protected].
13. Institutional, team and enterprise accounts
If you access Paperguide through an organization/company, lab or university, your administrator may access account-level information and control provisioning and deletion, and use may be governed by an additional agreement. We offer a Data Processing Agreement (DPA) to institutional customers on request at [email protected].
14. Changes to this policy
We may update this policy and will change the "Last updated" date; for material changes we will notify you by email or in-product before they take effect, and seek consent where required. Previous versions are available on request.
CONTACT US
For more information about our privacy practices, if you have questions, or if you would like to make a complaint, please contact us by e-mail at [email protected] or through our contact page at https://paperguide.ai/contact/.
Postal: 2925, Manor Bridge Dr, Alpharetta, GA, USA 30004. Data protection contact: [email protected].
Annexure A — Sub-processors
| Sub-processor | Purpose | Country |
|---|---|---|
| Microsoft Azure | Cloud hosting, blob storage, and serverless functions for document storage and processing | US |
| Amazon Web Services (AWS) | Cloud storage (S3) and AI model hosting (Bedrock) | US |
| Render.com | Application hosting and deployment | US |
| OpenAI | AI models used to power Chat with PDF, AI Writer, systematic review screening, and other AI features | US |
| Anthropic | AI models (Claude) used to power AI writing, chat, and research features | US |
| Google Cloud / Vertex AI | AI models (Gemini) used for AI-powered features and natural language processing | US |
| xAI | AI models (Grok) used for AI-powered features | US |
| Voyage AI | Text embedding models used for semantic search over documents (numerical vectors only, not readable text) | US |
| Pinecone | Vector database for semantic search over user documents (stores numerical embeddings, not readable text) | US |
| Turbopuffer | Vector database for semantic search over user documents (stores numerical embeddings, not readable text) | US |
| Zilliz Cloud (Milvus) | Vector database for semantic search over user documents (stores numerical embeddings, not readable text) | US |
| Chargebee | Subscription billing and payment processing | US |
| AppSumo | Marketplace partner for license sales | US |
| PostHog | Product analytics (page views, feature usage, event tracking) and session replay, enabled only for troubleshooting | US |
| Langfuse | LLM observability and quality monitoring for AI responses | Germany |
| Mailmodo | Transactional and campaign email delivery | US |
| Brevo (Sendinblue) | Transactional email delivery | France |
| Intercom | In-app customer support chat | US |
| Better Stack (Logtail) | Application logging and error monitoring | Czech Republic |
| Inngest | Background job orchestration and task queuing | US |
| Cloudflare | CAPTCHA (Turnstile) for bot protection, and performance and reliability measurement | US |
| Oxylabs | Proxy infrastructure used by the built-in plagiarism checker to query public web pages | Lithuania |
| Semantic Scholar | Academic paper metadata and search API (bibliographic identifiers only) | US |
| OpenAlex | Academic paper metadata API (bibliographic identifiers only) | US |
| CrossRef | DOI resolution and citation metadata API (bibliographic identifiers only) | US |
| Vercel | AI gateway for PDF extraction service | US |
| Upstash | Managed Redis for rate limiting and caching | US |
| Google (Analytics, Tag Manager, Ads) | Website usage analytics, tag management, and conversion measurement for search advertising | US |
| Tolt | Affiliate referral tracking and attribution | US |