Privacy Policy
Last Updated: August 9, 2026
Data We Collect
Account Data: Email address, display name, auth provider — retained until account deletion.
Usage Data: Search queries are stored locally until browser data is cleared. When Firebase is configured, a normalized query of at most 100 characters may also be stored in a shared trend collection without a direct user ID. Saved papers and research-workspace data remain until cleared or deleted under their applicable storage paths.
Technical Data: Browser/user-agent, platform, a broad timezone-derived region, error details, feature metrics, and an anonymous local analytics identifier may be processed. The repository does not enforce one universal retention period for these records.
AI Processing of Your Inputs
Your search queries and any text you submit are processed by large language models and embedding models (Google Vertex AI / Gemini) to generate results.
Please do not enter confidential, personal-health, financial-account, or proprietary information that you are not authorized to share with third-party AI processors.
Data We Do NOT Collect
- Payment-card details are not stored by ScholarLM; a payment processor handles them if paid processing is enabled.
- Precise GPS location is not collected by the analytics code reviewed here; a broad region may be inferred from browser timezone.
- Advertising cookies are not configured by ScholarLM.
Research inputs, normalized search text, uploaded PDF content, browser/device metadata, and an anonymous local analytics identifier can be processed or stored when the corresponding feature is used.
Third-Party Processors
We rely on trusted sub-processors, each governed by its own terms:
- Google Firebase — authentication and identity.
- Google Cloud / Vertex AI — LLM generation and embeddings.
- Stripe — payment processing (if/when paid plans launch).
- PostHog — optional configured product analytics; autocapture and session recording are disabled, and Do Not Track is respected.
- Academic data providers — OpenAlex, arXiv, PubMed, Semantic Scholar, Crossref and others are queried to fulfil your searches.
Cookies & Local Storage
We use browser storage for authentication, session continuity, preferences, caches, and local analytics. We do not configure advertising cookies. If PostHog is configured, its client uses local-storage and cookie persistence for product analytics, with autocapture and session recording disabled and Do Not Track respected.
Data Security
Traffic is encrypted in transit (TLS) and routed through a trusted ingress gateway with scoped internal access. No method of transmission or storage is 100% secure, so we cannot guarantee absolute security.
Your Rights
All Users: Request access, request account deletion, export supported artifact formats, and update profile.
GDPR (EU/EEA): Right to access, rectification, erasure, restrict processing, data portability, object, and withdraw consent.
CCPA (California): Right to know, delete, opt-out (we don't sell data), non-discrimination.
International Data Transfers
Data may be processed on Google Cloud infrastructure located outside your country of residence. Where required, appropriate safeguards (such as Standard Contractual Clauses) apply.
Children's Privacy
ScholarLM is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.
Changes to This Policy
We may update this policy as the product evolves. Material changes will be reflected in the "Last Updated" date above and, where appropriate, communicated in-app.
Data Deletion
Go to Account Settings → Click "Delete Account" → Confirm deletion. The flow attempts to delete enumerated Firestore user records and subcollections, clear local application storage, and delete the Firebase Authentication account. Analytics and audit-log records may be retained for aggregate or compliance purposes and are not deleted by that flow. If deletion reports an error, or you want retained records reviewed, contact us.
Contact
For privacy inquiries: bharath@scholarlm.dev