Privacy
The short version
PaperCurrent uses your research profile to check new papers and send you a short weekly digest. Your profile may include unpublished hypotheses or grant ideas. We keep it private to your account, exclude it from model training, and keep it out of our logs. The app and database run in Germany; AI assessments use Anthropic in the United States, as described below. You can download your data or delete your account at any time. Deletion takes effect immediately, with the access-log and backup retention described below. We use no tracking cookies, third-party analytics, or advertising.
What’s stored
- Account: your email address. You sign in through an emailed link, so we don't store a password for your account.
- Research profile: every version of your research area, methods, hypotheses and claims, topics to leave out, the seed papers you selected, and terms derived from them. Versions are kept so that a past evaluation still shows the profile it was judged against.
- Monitoring: your monitors and confirmed search queries, the papers found, their assessments (score, explanation, and evidence quote), and your ratings.
- Digests: which digest was sent to you in which week, and what it contained.
- Service records: sign-in tokens (stored only as a SHA-256 hash, valid 15 minutes) and a usage and cost ledger for the model and source APIs. The IP address that requested a sign-in link is kept for 7 days for abuse response, then erased; the token records themselves are deleted after 30 days.
- Cookies (two, both strictly necessary): a session cookie so you stay signed in, and a security token (CSRF) that protects forms against cross-site request forgery. The security cookie is set on every page, including before you sign in and on this page. Neither is used to track you, and neither requires consent.
- Access log: a record of sensitive events on your account — each data export, each account deletion, and each occasion on which staff opened your data — with the time, the page, and for staff access the staff member involved. This lets us check who accessed your data. The record is kept after account deletion, linked only to your former numeric account id.
- Beta research notes: if we spoke with you during the private beta about whether PaperCurrent would be worth paying for, we record your answer, any amount you named, and a short internal note of that conversation. This is entered by staff, is not shown to you in the app, and is deleted with your account.
We do not store PDFs or full texts, we do not set tracking cookies, and we do not build an advertising or behavioural profile.
Why we use your data
- Running the service — your account, your profile, the weekly searches and evaluations, and the digest emails: performance of our contract with you, Art. 6(1)(b) GDPR. We need this data to provide the service.
- Security and stability — sign-in rate limiting, the request IP kept for 7 days, error logs, cost limits and encrypted backups: our legitimate interest in keeping the service secure, available and recoverable, Art. 6(1)(f) GDPR, balanced against your rights by short retention and by keeping profile text out of logs entirely.
- Payments — contract performance and legal obligation, when paid plans launch. PaperCurrent is free during the beta and no payment data is processed today.
No processing here relies on consent, so there is no consent to withdraw. A language model scores papers to help you decide what to read. This has no legal or similarly significant effect on you within the meaning of Art. 22 GDPR. Each result includes an explanation and evidence for you to review.
Who processes your data
Your data is private to your account. Database access controls keep other users from seeing it. We use the following providers to run the service:
- netcup GmbH (Germany) — hosting, database and encrypted backups, under an Art. 28 data processing agreement. Your data is stored in the EU.
- Anthropic PBC (United States) — the language model that scores relevance. Papers are checked in two steps, and each request carries only what that step needs. A quick first pass sends a short extract of your research area together with the terms derived from your seed papers. The full scoring pass sends your research area, methods, hypotheses and topics to leave out, the public details of the paper being assessed, and — as calibration examples — the titles of up to ten papers you previously judged in that monitor, each with your verdict. Your email address and account id are never sent. Under Anthropic’s commercial terms, inputs and outputs are not used to train models. This is a transfer to the United States; it is covered by the EU Standard Contractual Clauses.
- Brevo (Sendinblue SAS, France) — delivers your sign-in links and digest emails. A digest contains the titles of the papers selected for you and the explanations shown in it, so that content passes through Brevo to your mailbox.
- OpenAlex, Crossref, Europe PMC, Unpaywall — public bibliographic lookups. These receive the search terms you confirmed and DOIs to resolve. They do not receive your profile text or account details. If you enter your ORCID iD during setup, we send it to OpenAlex to find your publications. OpenAlex can then see which researcher was looked up. Import a BibTeX file or skip the import instead if you would rather not disclose it.
We use no analytics provider, no error-tracking provider, no advertising network and no content delivery network. We'll update this list and let you know if that changes.
How long we keep your data
- Account, profile, monitoring data and beta research notes: until you delete your account.
- Sign-in tokens: valid 15 minutes, records deleted after 30 days.
- The IP address that requested a sign-in link: 7 days.
- Encrypted backups: 14 days, then deleted. We use these to recover from server failures, rather than to restore individual deleted accounts.
- The access log described above: kept beyond account deletion, to show who accessed your data and when.
Your choices and rights
In the app you can export your data as JSON — your email address, every profile version with its derived terms, your seed papers, your monitors and their queries, the candidate papers found with their evaluations, your feedback, and the digests you were sent — and your selected papers as BibTeX. Internal operational records (the usage/cost ledger, the access log and any beta research note) are not in the file; ask and we will send you a copy of what is held about you. You can delete your account in the app. Deletion is immediate and permanent; we cannot restore your account from a backup. Download your data first if you want to keep a copy.
You have the right of access, rectification, erasure, restriction, objection and portability (Art. 15–21 GDPR). You can download your data or delete your account in the app. For other requests, contact us at the address below. You may also complain to a supervisory authority — for the operator that is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, though you may approach the authority where you live.
Who to contact
PaperCurrent is operated by Dr. Marian Sauter, trading as Cognimize Consulting,
Schlößlesgasse 3, 89077 Ulm, Germany — the data controller under
Art. 4(7) GDPR.
Write to hello@papercurrent.app about anything on this
page; full details are in the imprint. Security reports:
see security.txt.