Privacy Policy
Who runs this service
PaperPatrol is a personal, independent project. It is not affiliated with, endorsed by, or operated by Lund University, or by any other university, institution or company. It is run by one individual, in a private capacity.
The data controller is Federico, established in Italy. For anything related to this policy or to your data, write to hello@paperpatrol.me.
What data is collected
Everything below is either given by you or generated by the service while it runs.
| Data | Where it comes from |
|---|---|
| Your email address | You, at signup. Used to send the digest and nothing else. |
| Your research interest phrases | You, at signup or when you edit your preferences. Free text, written by you. |
| Which sources you enable (PubMed, bioRxiv) | You, at signup or when you edit your preferences. |
| Account status and dates: whether your subscription is pending or active, when you signed up, when you confirmed, when you accepted this policy | Generated by the service. |
| The day of the week your digest is sent | Assigned by the service at signup, to spread the workload across the week. |
| Your account identifier at the sign in provider, and the email address it confirms | From the provider, only if you choose to sign in with it. Signing in is optional: the links in your emails work without it. |
| Sign in sessions: a random value that keeps you signed in, stored only as an irreversible fingerprint, with the dates it was created and last used | Generated by the service when you sign in. |
| Random identifiers: an internal account id, a single-use confirmation token, and a long-lived unsubscribe token that appears in the links in your emails | Generated by the service. |
| A record of which articles have already been sent to you: the source, the article identifier, and a simplified form of the title | Generated by the service, so the same paper is not sent to you twice. |
| A copy of each digest generated for you: article titles, journals, links, and the short reason the screening step gave for each match | Generated by the service, so the digest can be shown as a web page. |
| Papers you mark as favourites: the source, the article identifier (a DOI or a PubMed number), and when you marked it | You, when you mark a paper in your personal area. Nothing is recorded unless you do. |
| The IP address of sign in attempts | Recorded when a sign in code is requested or entered, and when a Google sign in is started, to limit abuse of those routes. |
Operational records of each scheduled run are also kept. These hold counts and, when a run fails, the technical error. They are not about you, although an error message can occasionally contain an email address if the failure happened while sending to that address.
Why each piece is collected
- Email address: to send you the digest, the confirmation message, and nothing else.
- Interest phrases: to search the literature databases and to judge whether a paper is relevant to you.
- Enabled sources: to know which databases to search for you.
- Status and dates: to know whether your subscription is active, and to keep a record that you consented.
- Digest day: to spread the daily workload so the service stays within the limits of the free services it runs on.
- Identifiers and tokens: to let you confirm your subscription, unsubscribe, view your digest and edit your preferences without needing an account or a password.
- Sign in provider identifier: to recognise you when you come back. It is the provider's own identifier for your account, and it is used instead of your email address because it does not change if your address does.
- Sign in sessions: to keep you signed in between visits, and to let a sign out actually end access rather than only clearing your browser.
- Record of articles already sent: to avoid sending you the same paper twice.
- Copy of each digest: so the email can stay short and link to a web page instead of listing everything inline.
- Favourites: so a paper you marked stays marked, and so you can show only those papers in your archive. They are not used to change what is searched for you or how papers are judged.
- IP address of sign in attempts: to stop the routes that send email or start a sign in from being flooded.
Legal basis
Processing is based on your consent, under Article 6(1)(a) of the GDPR. You give it by ticking the box when you sign up, and the date you gave it is recorded. If you sign up by signing in with Google, you tick the same box on the page where you choose your research interests, and your email address needs no separate confirmation because the provider has already confirmed it. You can withdraw consent at any time, and withdrawing it deletes your data. See Your rights.
What this service does not do
- Your data is not sold, rented, or shared with anyone for their own purposes.
- There is no advertising of any kind.
- There is no tracking and no analytics. No visitor statistics are collected, on this page or anywhere else on the site.
- There is no profiling beyond the obvious one: your interest phrases are compared against newly published papers to decide which ones to send you. Nothing is inferred about you as a person, and no automated decision is made that has any legal or similarly significant effect on you.
Service providers
Running the service requires a small number of external providers. Each one is named below with what it does. Each processes data according to its own terms of service and privacy policy, linked below.
| Provider | What it does | Its policy |
|---|---|---|
| Vercel | Hosts this website and runs the small server functions behind signup, confirmation, unsubscribe, preferences and the digest page. | Privacy policy |
| Supabase | Hosts the database that stores your email address, interest phrases, preferences and digest history. | Privacy policy |
| Resend | Sends the emails. Your email address and the content of the message pass through it. Resend in turn relies on its own providers to deliver mail, described in its documentation. | Privacy policy |
| Google (Gemini) | Provides the Gemini API used to screen article abstracts. See the section below for exactly what is sent. | Privacy policy |
| Google (sign in) | A separate role from the one above. If you choose to sign in with Google, Google confirms to this service that the email address is yours and supplies its own identifier for your account. Google knows you signed in here. This service never receives your Google password. | Privacy policy |
| GitHub | Runs the scheduled job that performs the daily search and sends the digests. | Privacy policy |
Providers of providers are not listed here. Where a provider uses its own sub-processors, that is described in its documentation, linked above.
What is sent to Google Gemini
This deserves its own section, because it is the only step where your data leaves the service to be processed by a general-purpose AI system.
Each time the service screens a paper for you, the request sent to Google contains:
- The title and abstract of the paper. These are public scientific content, published by journals and preprint servers. They are not your data.
- Your interest phrase. This is your data, and it forms part of the prompt, because the model is being asked to judge relevance against it.
Your email address, your identifiers and your digest history are never sent to Google. The request contains no way of telling which person an interest phrase belongs to.
Your interest phrases are also sent to Google in a second, similar step, where the model is asked to suggest related search terms so the databases can be searched more broadly.
On how Google may use what is sent: Google's Gemini API Additional Terms of Service state that for users located in the European Economic Area, Switzerland or the United Kingdom, the data use terms that apply to paid services apply to all services, including free quota. Under those terms Google does not use prompts or responses to improve its products. This service calls the Gemini API from the European Economic Area. The terms are published at ai.google.dev/gemini-api/terms.
Data leaving the European Union
The database that holds your account, your interest phrases and your digest history is hosted in the European Union, in the Ireland region.
Several of the providers listed above are established outside the European Union, or may process data outside it. This applies to Vercel, Supabase, Resend, Google and GitHub. The safeguards that apply to those transfers are described in each provider's own terms and privacy policy, linked in the table above.
How long data is kept
| Data | Kept for |
|---|---|
| Accounts that were never confirmed | 7 days, then deleted automatically. If you sign up and never click the confirmation link, your email address is removed. |
| Confirmed accounts, interest phrases, preferences | Until you unsubscribe or ask for deletion. |
| Record of articles already sent to you, and copies of your digests | Until you unsubscribe or ask for deletion. These are not deleted on a timer. |
| Favourites | Until you unmark the paper, unsubscribe, or ask for deletion. Unmarking deletes the record immediately. |
| IP addresses of sign in attempts | 2 days, then deleted automatically. |
| Sign in sessions | 180 days from their last use, or immediately when you sign out. Deleted with your account. |
| A sign in that was started and never finished | 1 hour, then deleted automatically. No account is created until you finish, so nothing else remains. |
| Operational records of scheduled runs | Kept without a fixed limit. They contain counts and technical errors. |
Unsubscribing deletes, it does not hide. Clicking the unsubscribe link in any email and confirming removes your account row from the database, and with it your interest phrases, your record of sent articles, your stored digests and the papers you marked as favourites. Nothing is anonymised and kept, and nothing is retained as a suppressed or hidden entry.
Providers keep their own operational logs as part of hosting and delivering the service, on their own schedules. Those are described in their policies, linked above.
Your rights
Under the GDPR you have the right to:
- Access the data held about you
- Correct it if it is wrong
- Delete it
- Receive a copy of it in a portable format
- Withdraw your consent at any time, which stops the processing from that point on
- Complain to a supervisory authority if you think your data is being handled improperly
The fastest way to delete everything is the unsubscribe link at the bottom of any email you receive. It is immediate and needs no request.
For anything else, write to hello@paperpatrol.me. Correcting your interest phrase or your enabled sources can also be done yourself, from the digest page that every email links to.
Requests sent to that address are answered within one month, which is the time limit set by the GDPR.
You have the right to lodge a complaint with the supervisory authority of the Member State where you live. The authority for the controller of this service is the Italian Garante per la protezione dei dati personali.
Cookies
This site sets four cookies, all strictly necessary: three if you choose to sign in, and one if you fill in the form on the home page. Reading this page, browsing the site, or following any link from an email sets none of them.
| Cookie | What it is for | How long it lasts |
|---|---|---|
pp_session |
Keeps you signed in, so you are not asked to sign in again on every visit. | 180 days, extended while you keep using the service. Removed when you sign out. |
pp_oauth_state |
Ties the sign in you started to the answer that comes back from the provider, so a sign in cannot be completed on your behalf by somebody else. | 10 minutes |
pp_pending |
Remembers the sign in you have just completed while you finish creating your account. | 1 hour |
pp_intent |
Remembers the topic and the sources you typed on the home page, and that you accepted this policy there, so none of it has to be asked again after signing in. It holds what you asked for and nothing about who you are. It is cleared as soon as your account is created. | 1 hour, or until your account is created |
All four are set by this site itself, cannot be read by scripts running in your browser, and are not sent anywhere else. None of them is used for analytics, advertising or profiling, and none of them records anything about what you read or where you came from. Nothing is stored in your browser through any other means, such as local storage or session storage.
Cookies that are strictly necessary to provide something you have asked for do not require consent, and there are no others here, so there is still no consent banner on this site. There is nothing optional to agree to.
Changes to this policy
If this policy changes, the date at the top of the page changes with it, and the current version is always the one published here.
For substantial changes, subscribers are also notified by email. Smaller edits, such as rewording or a corrected link, are not announced separately.
Questions
Write to hello@paperpatrol.me. This is a small project run by one person, and questions about how it handles data are welcome.