Privacy Policy
Last updated: August 17, 2026. We may update this policy; material changes will be communicated via email when appropriate.
1. What We Collect & Why
We collect the minimum needed to deliver your digest:
- Email address — to send your digests
- Research description — to personalize your paper recommendations
- Optional share summary — at signup, we use Groq to create and store one short sentence describing your broader research focus. It remains private unless you explicitly choose to create a share card.
- Delivery preferences — frequency, sources, and paper count
- Feedback submissions — bug reports, feature requests, optional unsubscribe reasons/comments, optional contact email, and basic technical context when you choose to send feedback
- Paper ratings — when rating controls are available and you choose “More” or “Less,” we store that explicit choice with the paper, digest, ranking position, displayed match score, and an optional structured reason. The follow-on page can show the other papers from that digest, but papers you do not rate are not stored as ratings. Not rating a paper is missing feedback, not an implicit dislike. These ratings do not yet personalize future digests automatically.
- Additional Pro matches — when this feature is available, we temporarily store up to 50 paper cards that met a Pro digest’s relevance setting but ranked below the papers delivered in that email. The private snapshot contains paper metadata, match scores/reasons, and frozen digest settings, but not your email address, research description, abstracts, or full text.
- Agreement records — acceptance timestamp and agreement version for Terms of Service / Privacy assent
We do not sell your data. We do not use advertising, analytics cookies, or tracking pixels.
If you choose to share your LitDigest, the summary and a random public link become visible to anyone with that link so social platforms can display the card. The link is disabled when you unsubscribe or change your research focus, and deleted with your account. Copies or previews already cached by a social platform may remain subject to that platform’s retention practices.
2. Third-Party Services
We share limited data with these services to operate LitDigest:
- Postmark — transactional email delivery and delivery-event handling (policy)
- Google Gmail — temporary fallback email provider during migration/rollback windows (policy)
- Groq — model inference for research-description processing and ranking (policy)
- hCaptcha — bot verification at signup and on public feedback submissions. hCaptcha's Privacy Policy and Terms of Service apply.
- Railway — infrastructure hosting (policy)
3. Data Retention & Deletion
Your data is retained while your subscription is active. To delete your data, use the unsubscribe link in any digest email. After unsubscribing, your subscription data is deleted within 30 days, although we may retain limited records such as consent/unsubscribe events where reasonably necessary for legal compliance, security, fraud prevention, or dispute resolution.
Additional Pro match snapshots expire after 30 days. Access is disabled while the account is unsubscribed, the digest is deleted, or the Pro entitlement is inactive; restoration can restore access only before the snapshot expires.
Feedback, including explicit paper ratings, is stored separately from the subscription database and may be retained as product and operations history unless deletion is required or requested.
4. For EU/EEA Users
Legal basis for processing: consent (you voluntarily subscribe). You may withdraw consent at any time by unsubscribing. Our paper ranking is content curation only and has no legal or significant effect on you.
5. Geography, Restrictions, and Compliance
Because privacy, sanctions, export-control, and sector-specific rules vary by jurisdiction, we may restrict or deny service in certain countries, regions, institutions, or regulated contexts. We may use account, delivery, or basic technical information to help enforce those restrictions and protect the service.