Research Grove (the “Service”) is designed and operated with the protection of a researcher’s unpublished context as its first principle: what you read reveals what you are working on. This policy sets out what the Service holds and how it is protected.
We do not ask for your name, institution, or payment details. Payment details go to Paddle and never reach us.
Generating a note means sending paper text to a language-model provider. We use providers whose API terms state that submitted content is not used for training. Text is sent for the duration of a request and is not retained by us beyond your own storage.
Account deletion is available inside the app on every plan. Individual also includes a product Markdown export. A legally required data access request is separate from that product feature and is available on every plan by emailing [email protected].
Two categories of data remain after deletion; neither contains your text or your identity. The first is what the shared cache holds about a paper rather than about you: its bibliographic details, and the derived vectors and structured facts that let the same paper serve everyone without being processed again. That cache contains no statement about any person, and once your account is gone nothing links it to you. This is what makes the Service affordable to run.
The second is a minimal payment ledger — transaction identifiers and amounts — kept separately for accounting and refund obligations we are required to meet. It is detached from your account: the personal identity is removed and the figures remain.
We keep your data for as long as your account exists. Sign-in links expire shortly after being sent. Usage events are kept in aggregate. We run our own database and take our own encrypted backups to the private R2 bucket described above; we do not use a managed database provider with its own retention window. Those backups are deleted on a rolling 30-day schedule, so a record you delete disappears from the live database immediately and from the last backup that contains it within 30 days, after which the deletion is final.
Wherever you live, you can delete your account in the app and request access to personal data on any plan. Individual's product Markdown archive is not the only route for a legal data access or portability request. If you are in the EU/UK, you may also request rectification, restriction, objection, portability, or erasure; write to us and we will act within 30 days. Our legal basis for processing is performance of the contract you enter by using the Service.
Traffic is encrypted in transit. Third-party credentials you provide (such as a Zotero API key) are encrypted at rest. Sessions are held in an HTTP-only cookie. For Zotero, the Service reads supported paper records and accessible PDF attachments; it does not write, move, or modify Zotero content. You choose and manage the key's permissions in Zotero.
The Service is not directed at anyone under 16 and we do not knowingly collect their data.
This English text is the authoritative version. A Korean translation is provided to help you read it; where the two differ, this version governs. Nothing here limits the rights your own country's law gives you.
Material changes are announced by email at least 14 days in advance. Questions, or a request about your data: [email protected].