Overview
Researchful is the all-in-one research platform operated by Researchful (referred to in this policy as "we", "us", or "our"). We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains what data we collect, why we collect it, how we use it, who we share it with, and the rights you have to control it.
This policy applies to all Researchful products — ResearchFlow, ResearchLib, ResearchLounge, and ResearchLab — and to all visitors, registered users, and account holders, regardless of plan. By creating an account or using any Researchful product, you acknowledge that you have read and understood this policy.
If you do not agree with the practices described in this policy, you should not create an account or use Researchful. If you already have an account and wish to close it, you can do so from /app/settings at any time; we will delete your personal data in accordance with the retention schedule below.
Data we collect
We collect only the data we need to operate the platform, provide customer support, comply with legal obligations, and improve the product. We do not buy data brokers' lists, we do not scrape social media for personal information, and we do not track you across third-party websites.
Account data
- Name — used to address you, attribute authorship on ResearchLib, and display on collaborator lists.
- Email address — used for sign-in, notifications, account recovery, and customer support.
- Hashed password — stored using bcrypt with a per-user salt. We never see your plaintext password.
- Institution (optional) — used for institution-scoped features and to suggest relevant ResearchLounge communities.
- Profile photo (optional) — stored as an uploaded file; avatar initials are generated automatically if no photo is provided.
Research data
- Projects, chapters, sources, notes, datasets, analyses, drafts, and annotations — everything you create in Researchful is stored against your account. This data is yours. We do not read it, we do not train models on it, and we do not use it to inform product recommendations for other users.
- Collaboration activity — comments, annotations, chat messages, and meeting recordings you create during collaboration sessions. Meeting recordings are stored only when the host explicitly starts recording; participants are notified via the consent banner.
- Agent activity logs — every action taken by an AI agent on your behalf is logged with timestamp, agent name, input hash, and output hash. This data is visible to you and to anyone you explicitly share the project with.
Usage data
- Product analytics — aggregated, pseudonymous usage data (which features are used, how often, and where users drop off) collected to improve the product. We do not link this data to your identity.
- Device and browser information — browser type, operating system, screen size, and approximate location (country-level) used for security monitoring and to optimize the mobile experience.
- Logs — server logs containing IP address, request timestamp, and route. Retained for 30 days for security and abuse prevention, then automatically purged.
How we use your data
We use your data for the following purposes:
- To provide the service — operating your account, displaying your research, running AI agents on your behalf, syncing data across devices, and enabling collaboration features.
- To communicate with you — sending transactional emails (password resets, collaboration invitations, meeting summaries), product updates, and security notifications. You can opt out of marketing email at any time from
/app/settings. - To provide customer support — when you contact us, we use your account data and any information you provide to diagnose and resolve your issue. Support conversations are retained for two years for quality and training purposes.
- To detect, prevent, and respond to fraud, abuse, and security incidents — we monitor sign-in patterns, API usage, and content uploads for signs of automated abuse, account takeover, or terms-of-service violations.
- To comply with legal obligations — responding to lawful requests from authorities where we are legally required to do so, and to enforce our Terms of Service.
- To improve the product — aggregated, pseudonymous analytics help us understand which features work, where users struggle, and what to build next. Individual user data is never used for product decisions about specific users.
Legal basis for processing (GDPR)
For users in the European Economic Area, the United Kingdom, and Switzerland, we process personal data under the following lawful bases:
- Contract (Article 6(1)(b)) — processing your account and research data to provide the Researchful service you signed up for.
- Legal obligation (Article 6(1)(c)) — retaining server logs, billing records, and tax documents as required by law.
- Legitimate interests (Article 6(1)(f)) — detecting fraud, preventing abuse, and improving the product. We balance these interests against your privacy rights and only process data that is necessary for these purposes.
- Consent (Article 6(1)(a)) — for optional activities like receiving marketing email, recording collaboration sessions, and using non-essential cookies. You can withdraw consent at any time without affecting your ability to use the platform.
Sharing and disclosure
We do not sell your personal data. We do not rent it, trade it, or share it for cross-context advertising. We share data only in the following limited circumstances:
- With your explicit consent — when you invite a collaborator to a project, share a source collection, or post in ResearchLounge, the content you share is visible to the people you shared it with.
- With service providers — we use third-party vendors for email delivery, error monitoring, and cloud hosting. These vendors have access to the minimum data necessary to perform their functions and are bound by data protection agreements.
- For legal compliance — if we receive a lawful request from a court or government authority, we may be required to disclose data. We review every request for legal validity and narrow scope, and we notify you unless we are legally prohibited from doing so.
- In connection with a business transfer — if Researchful is acquired, merged, or sells assets, user data may be transferred to the acquiring entity. We will notify you by email before any such transfer and the acquiring entity must honor this Privacy Policy.
- To protect rights and safety — we may disclose data where we believe it is necessary to protect the rights, property, or safety of Researchful, our users, or the public.
Data retention
We retain your data only as long as necessary to provide the service and comply with legal obligations:
- Active accounts — all data is retained for the life of your account.
- Closed accounts — when you close your account, we delete your personal data within 30 days. Anonymized, aggregated analytics data may be retained.
- Server logs — retained for 30 days.
- Billing records — retained for 7 years as required by tax law.
- Support conversations — retained for 2 years.
- Meeting recordings — retained until the host deletes them or for 90 days after the meeting ends, whichever comes first.
Security
We use industry-standard security measures to protect your data, including TLS 1.3 in transit, AES-256 at rest, bcrypt password hashing, secure cookies with HttpOnly, Secure, and SameSite=Lax flags, CSRF protection on all state-changing routes, rate limiting on auth and AI endpoints, and audit logging for all sensitive operations. See our Security page for full details.
Your rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Rectification — request correction of inaccurate or incomplete data.
- Erasure — request deletion of your personal data (also known as the "right to be forgotten").
- Restriction — request that we limit processing of your data in certain circumstances.
- Portability — receive your personal data in a structured, machine-readable format and transmit it to another service. Use
/app/settings→ Export my data. - Objection — object to processing based on legitimate interests or for direct marketing.
- Withdrawal of consent — withdraw consent at any time for processing that relies on consent.
To exercise any of these rights, email privacy@researchful.app. We respond within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.
International data transfers
Researchful is a remote-first company with infrastructure hosted in multiple regions. Your data may be processed in a country different from your own. Where this involves transferring personal data outside the European Economic Area, we rely on Standard Contractual Clauses approved by the European Commission, or another lawful transfer mechanism. We monitor changes to international data transfer law and update our practices accordingly.
Children
Researchful is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe we have collected data from a child under 16, please contact us at privacy@researchful.app and we will delete it promptly. Users aged 16 and 17 may use Researchful with parental consent; institutional users should verify their institution's policy on student data before onboarding.
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and post a notice on the Researchful dashboard at least 30 days before the changes take effect. We encourage you to review this policy periodically. The "Last updated" date at the top of this page reflects the most recent revision.
Contact
If you have any questions about this Privacy Policy or your personal data, please contact our Data Protection Officer at privacy@researchful.app. For security vulnerability reports, see Security. For legal inquiries, contact legal@researchful.app.