Overview
Researchful is built to be deployed in regulated environments — universities, research institutions, government labs, and healthcare-adjacent research teams. This page summarizes the compliance frameworks we support and the responsibilities we share with our users.
This page is informational and does not modify our Terms of Service or Privacy Policy. For institution-specific compliance questions, signed DPAs, or vendor risk assessment questionnaires, contact partnerships@researchful.app.
General Data Protection Regulation (GDPR)
Researchful complies with the GDPR for users in the European Economic Area, the United Kingdom, and Switzerland. Our compliance posture includes:
- Lawful bases — we process personal data under contract, legal obligation, legitimate interests, and consent, as described in our Privacy Policy.
- Data subject rights — we support access, rectification, erasure, restriction, portability, objection, and consent withdrawal. Requests can be made from
/app/settingsor by emailing privacy@researchful.app. We respond within 30 days. - Data Protection Officer — contactable at privacy@researchful.app for any GDPR-related inquiry.
- International transfers — we rely on Standard Contractual Clauses approved by the European Commission for transfers outside the EEA.
- Breach notification — we notify affected users within 72 hours of confirming a breach that affects their personal data, in accordance with Article 34.
- Data Processing Agreements — available to institutional customers on request.
Family Educational Rights and Privacy Act (FERPA)
For users at US educational institutions, Researchful can be configured to comply with FERPA. When an institution provisions Researchful accounts for its students, the institution controls whether student educational records (including research projects, drafts, and advisor comments) are considered directory information or education records under FERPA.
- School official exception — Researchful acts as a "school official" with legitimate educational interest when providing the Service to an institution. The institution must provide direct control over the use and maintenance of education records.
- Annual notification — institutions are responsible for notifying students that Researchful is used and for obtaining any necessary consent.
- Access and amendment — students can access their data from
/app/settingsand request amendment of inaccurate records through the institution. - Disclosure — we do not disclose education records to third parties without the institution's written consent, except as required by law.
Academic integrity commitments
Researchful is built around academic integrity. The following features are non-negotiable and shipped with every plan:
- Effort Balance Index — visible per chapter, showing the ratio of student-authored to AI-assisted content.
- Contribution labels — every paragraph is labeled Student-Authored, AI-Assisted, or Quoted. The audit trail preserves the original label even if converted.
- Compliance gate — the Compliance Agent runs similarity, originality, bias, and fabricated-citation checks before any finalization. Overrides require explicit acknowledgment.
- Source-bounded AI — the Research Agent does not make external claims without sources. Unsupported assertions are labeled, never hidden.
- Fabricated-citation detection — the Compliance Agent flags citations that do not resolve to real sources before finalization.
- Audit trail — every agent action is logged with timestamp, input hash, and output hash, visible to anyone the project is shared with.
- Integrity report export — accompany your submission with a one-page integrity report documenting effort-balance, contribution labels, compliance check results, and any overrides.
We do not guarantee that any particular institution will accept AI-assisted work. Users should consult their institution's academic integrity policy before using Researchful for graded work.
Accessibility
Researchful is committed to making the platform usable by everyone, including users with disabilities. Our accessibility posture includes:
- WCAG 2.1 AA target — we design and test against WCAG 2.1 Level AA. We are working toward formal VPAT publication.
- Keyboard navigation — every interactive element is reachable and operable by keyboard alone. Focus indicators are visible.
- Screen reader support — semantic HTML, ARIA labels where necessary, and live regions for dynamic content (agent trace, notifications).
- Color contrast — text and interactive elements meet WCAG AA contrast ratios in both light and dark themes.
- Reduced motion — animations and transitions respect
prefers-reduced-motion. - Alternative text — all meaningful images and icons have descriptive alt text or are marked
aria-hiddenwhen decorative.
If you encounter an accessibility barrier, please report it to support@researchful.app with the page URL and a description of the issue. We prioritize accessibility fixes.
Data portability
You can export your data at any time from /app/settings → Export my data. Exports include:
- All projects, chapters, drafts, and version history (in Markdown and DOCX).
- All sources, citations, and annotations (in BibTeX, RIS, and CSV).
- All datasets and analyses (in CSV and JSON).
- All notes and reading collections (in Markdown).
- The full agent activity log (in JSON).
- Your account profile and settings (in JSON).
Exports are generated on demand and delivered as a signed download link valid for 7 days.
Institutional obligations
Institutions deploying Researchful are responsible for:
- Provisioning and de-provisioning user accounts in line with their identity lifecycle.
- Notifying students of the use of Researchful and obtaining any necessary consent under FERPA, GDPR, or local law.
- Configuring institution-specific integrity thresholds (e.g., maximum similarity percentage) through the admin dashboard.
- Reviewing audit logs and integrity reports in line with their academic integrity policy.
- Maintaining their own data retention and records-management policies for any data exported from Researchful.
Contact
For compliance questions, contact privacy@researchful.app (GDPR, FERPA, privacy) or partnerships@researchful.app (institutional deployment, DPAs, vendor risk). For security vulnerability reports, see Security.