Privacy
The short version
PaperCurrent stores the research profile you write, watches public literature against it, and emails you a short weekly digest. Your profile can contain unpublished ideas, so we treat it as the most sensitive data here: it is never shared between users, never used to train any model, and never written to our logs. Everything runs in the EU. You can export or delete everything at any time.
What's stored
- Account: your email address (sign-in is by magic link — we store no password).
- Research profile: all versions of your area, methods, active positions, boundaries, seed papers, and derived terms.
- Monitoring: your monitors, search queries, the candidates found, their evaluations, and your feedback.
- Operational: short-lived sign-in tokens (hashed), a usage/cost ledger, and brief technical logs. Sign-in request IPs are removed after 7 days.
We do not store PDFs or full texts, and we don't build an advertising profile.
Why, and on what legal basis
- To provide the service (Art. 6(1)(b) GDPR): storing your profile, running searches and evaluations, sending digests.
- Legitimate interest (Art. 6(1)(f) GDPR): security logging, rate limiting, and abuse prevention — balanced against your rights by short retention and IP scrubbing.
We do not rely on consent-based processing, and we never use your data for automated decisions with legal effect.
Who else sees it
We use a small number of processors, each under a data processing agreement:
- netcup GmbH (Germany) — hosting, database, backups.
- Anthropic — the language model that scores relevance. Only the profile parts needed for scoring and public paper metadata are sent; your data is contractually excluded from training [and covered by zero-data-retention].
- Brevo (France) — sends your sign-in and digest emails.
- [Sentry, EU region] — error tracking, with profiles and abstracts scrubbed.
- OpenAlex, Crossref, Europe PMC, Unpaywall — public bibliographic lookups. These receive only the search terms you confirmed, not your profile text.
The current list is maintained here and you are informed of changes.
How long it is kept
- Account and profile data: until you delete your account.
- Sign-in tokens: 15 minutes (then invalid); request-IP: 7 days.
- Technical logs: [short period, e.g. 14 days].
- Backups: [e.g. 14 days onsite, 90 days offsite], encrypted.
Your data, and your rights
You have the right of access, rectification, erasure, portability, objection, and restriction (Art. 15–21 GDPR). In the app you can export everything as JSON and BibTeX and delete your account immediately and irreversibly. For anything else, contact us. You may also complain to your supervisory authority.
Who is responsible, and how to reach us
Controller: Cognimize — [legal form, address], represented by Marian Sauter.
Privacy contact: privacy@papercurrent.app · Security: see security.txt.