Privacy Policy
Version —
This notice explains what litscout does with your personal data, why, on what legal basis, who else sees it, how long we keep it, and what you can make us do about it.
1. Who is responsible
The data controller is Shagufta Shaheen, Mango, Jamshedpur, Jharkhand 831012, India.
Privacy contact: privacy@litscout.app.
A gap we are disclosing rather than hiding. Because we are established in India and make this service available to people in the European Union and the United Kingdom, Article 27 GDPR requires us to appoint a representative in each. We have not yet done so. We are a very small operation, the appointments cost several times what it costs to run the service, and we judged that keeping it available to researchers in Europe was better than withdrawing from those countries. We will appoint representatives as soon as we can afford to.
This does not reduce your rights and it does not change how we handle your data. Write to privacy@litscout.app and we will deal with your request directly, and you may complain to the supervisory authority in your own country — see section 10.
We have not appointed a Data Protection Officer. Article 37 requires one only for public authorities, large-scale systematic monitoring, or large-scale processing of special-category data; we do not currently meet those thresholds. Privacy questions go to the address above.
2. What we collect
Data you give us
- Account data — your email address, and a password if you do not sign in with Google, Apple or Microsoft.
- Search content — the queries, references, pasted abstracts and notes you submit, and any attachments.
- Correspondence — what you send through the contact and feedback forms, including any files you attach.
- Billing details — name and address if you subscribe. Card numbers go directly to Dodo Payments, which sells the subscription as merchant of record; we never receive or store them.
Data we generate
- Derived intent — the structured requirements and references our extraction step produces from your query.
- Relevance signals — which results you save, open or exclude, used to rank future results for you.
- Usage counters — how many searches you have run in the current hour, day and month, for quota enforcement.
Data collected automatically
- Technical data — IP address, timestamp, user agent, and the endpoint requested, written to server logs for security, rate limiting and debugging.
- Essential cookies — the session and security cookies described in section 8.
3. Sensitive information in your searches
A search query is free text. We do not ask for sensitive personal information, we do not use it to profile you beyond ranking your own results, and we do not infer anything from it.
Please do not enter health, legal or other sensitive details, patient data, client data, or anyone else's personal information in a query.
4. Why we use it, and on what legal basis
| What we do | Why | Legal basis (GDPR Art.6) |
|---|---|---|
| Run your search: extract intent, retrieve and rank papers, return results | It is the service you asked for | Art.6(1)(b) — performance of a contract |
| Keep your history, collections and alerts | So you can return to your own work | Art.6(1)(b) — performance of a contract |
| Rank results using what you have previously found useful | Relevance is the product | Art.6(1)(b), and Art.6(1)(f) legitimate interest in a useful service |
| Take payment and manage your subscription | To charge you what you agreed to pay | Art.6(1)(b), and Art.6(1)(c) for tax and accounting records |
| Rate limiting, abuse prevention, security logging | To keep the service available and not be defrauded | Art.6(1)(f) — legitimate interest in security |
| Answer your contact or feedback message | You wrote to us | Art.6(1)(f), or Art.6(1)(c) where it is a data-rights request |
| Record your cookie choices and your acceptance of these terms | We have to be able to prove both | Art.6(1)(c) — legal obligation (Art.7(1)); Art.6(1)(f) for the acceptance record |
Providing your email is necessary to have an account: without it we cannot create one. Everything else is optional, and the service works without it.
5. Automated decision-making and profiling
We rank search results automatically, and that ranking is influenced by what you have saved and opened before. Every result carries an explanation of why it was selected, and you can clear the signals feeding it by deleting your search history.
6. Who else sees your data
We do not sell your personal information, and we do not share it for advertising or cross-context behavioural advertising. We do use the recipients below to deliver the service. Where they are outside the EEA or UK, the stated safeguard is the Chapter V basis for the transfer.
Some rows name a company; others describe a category of recipient. We name the services you have your own relationship with — the one you sign in through and the one you pay through. For the rest we tell you the purpose, exactly what is sent, where it goes and under what safeguard, but not the vendor: which retrieval, ranking and research providers sit behind the product is part of how it is built. If you want to know the specific recipients of your own personal data, ask us at privacy@litscout.app and we will tell you — that is your right of access, and a category here does not narrow it.
| Recipient | Purpose | What they receive | Location | Transfer safeguard |
|---|---|---|---|---|
| Google LLC | Signing you in when you choose "Continue with Google" | Only what Google necessarily learns by authenticating you: that you signed in to this service, at that time. We receive your email address, name and profile picture from Google; we send Google nothing about you. Email/password accounts do not involve Google at all. | United States | EU Standard Contractual Clauses; EU–US Data Privacy Framework |
| Dodo Payments | Selling and billing your subscription as merchant of record — Dodo is the seller for the transaction, issues your invoice, and handles any tax due | Email address, billing name and address, card details (collected by Dodo directly — we never see or store a card number), subscription status. We receive back only whether you are subscribed and when the period ends. | United States and India | EU Standard Contractual Clauses |
| AI processing providers | Interpreting what you typed: extracting references and requirements from your query, and scoring how well candidate papers match your goal | The text of your query, and any notes or abstracts you paste in. Your name, email and account identifiers are never sent. | United States and the European Union | EU Standard Contractual Clauses |
| Web research providers | Running a deep research task: searching the open web for sources and retrieving the pages found, so the report can be written and cited | The research task you wrote, and search terms derived from it. Your name, email and account identifiers are never sent. | United States and the European Union | EU Standard Contractual Clauses |
| Scholarly metadata sources | Looking up papers, resolving identifiers, and finding legal open-access copies | Search terms and identifiers derived from your query, plus our own contact email so they can reach us about our usage. Nothing that identifies you is sent. | United States, United Kingdom and the European Union | No personal data of yours is transferred; search terms and identifiers only |
The service is operated by us on infrastructure we control. Hosting region: US East (N. Virginia), United States.
We may also disclose data where we are legally required to, or to establish or defend legal claims. We will tell you if that happens unless we are prohibited from doing so.
When this list changes we update it here and bump the version of this notice.
7. Training — what we do not do
We do not use your queries, notes, uploads or results to train any model. We do not sell them, and we do not share them for advertising. Nothing you type here becomes training data for us.
To work out what you are asking for, we send the text of your query to the AI providers named by category in section 6. What those providers may do with it is governed by their own terms, not ours. We choose providers whose terms restrict training on customer content, and if that ever stops being true of a provider we use, we will say so here before the change takes effect.
Two practical consequences worth stating plainly. Your name, email and account identifiers are never sent to them — only the text you typed. And if your work is confidential or unpublished and you are not willing to have it leave our systems at all, do not paste it into a query.
8. Cookies
We use only cookies that are strictly necessary to run the service. We do not use analytics cookies, advertising cookies or third-party trackers, and no third-party script runs on these pages. Our display fonts are served from our own origin, not from a font CDN, so loading a page does not disclose your IP address to anyone else.
| Cookie | Provider | Purpose | Duration | Category |
|---|---|---|---|---|
| sb-*-auth-token | Supabase (first-party) | Keeps you signed in | Session / until sign-out | Essential |
| cookie_consent | litscout | Remembers that you have seen this notice, so we stop asking | 180 days | Essential |
| consent_subject_id | litscout | A random value with no link to your identity, so we can prove which consent record is yours | 180 days | Essential |
Because none of these are optional, there is nothing to switch off — the notice you see is information, not a request for permission. If we ever add an analytics or marketing cookie, this table and the banner will both change first, and the script will not load until you have said yes.
9. How long we keep things
We keep personal data only as long as we need it for the purposes in section 4, and delete it automatically on a schedule when we no longer do.
| Data | Criteria |
|---|---|
| Searches, their ranked results, and research agent runs | Kept while useful to your account, then deleted automatically on a schedule |
| The raw text of a search query | Replaced with a placeholder well before the surrounding record expires |
| Contact messages, feedback and its attachments | Kept only as long as needed to deal with the matter and to meet limitation periods |
| Cookie-consent records | Kept as evidence of your consent for as long as that evidence must be available |
| Terms acceptance records | Kept while the account exists, and afterwards for the period in which a legal claim could be brought |
| Account data (email, plan) | Until you delete your account |
| Server logs (IP, timestamp, user agent) | A short operational period, then deleted |
10. Your rights
If you are in the EEA or the UK, you have the right to:
- Access a copy of your data (Art.15). Available in Settings → Export my data.
- Rectify inaccurate data (Art.16).
- Erase your data (Art.17). Available in Settings → Delete account.
- Restrict processing (Art.18).
- Port your data — the export is machine-readable JSON (Art.20).
- Object to processing based on legitimate interests (Art.21).
- Withdraw consent at any time, without affecting processing already carried out (Art.7(3)).
Use the in-product controls where they exist. Otherwise write to privacy@litscout.app or use our contact form.We start on a request as soon as it reaches us and aim to answer well inside the deadline. One month is the outside limit the law sets, not our target — and if a request is genuinely complex it can be extended by two further months, in which case we will tell you why within the first month.
One exception to erasure. When you delete your account we keep the record that you accepted a specific version of our Terms — your user id, the version, and a timestamp, with no content. We rely on Art.17(3)(e), the establishment and defence of legal claims. Everything else goes.
Complaining about us
You can complain to a data protection supervisory authority. Complain to the authority in your own country of residence or place of work: find your EU authority. In the UK: Information Commissioner's Office — https://ico.org.uk/make-a-complaint/.
11. If you are in India
We operate from India, so the Digital Personal Data Protection Act 2023 applies to what we do with your personal data. Under it we are a Data Fiduciary and you are a Data Principal.
The rights in section 10 are available to you. The Act adds two more:
- Nomination. You may nominate another person to exercise your rights on your behalf if you die or become unable to exercise them yourself. Write to us and we will record it.
- Grievance redressal. You may raise a grievance with us directly, and you may take it to the Data Protection Board of India if you are not satisfied with how we deal with it.
Our Grievance Officer is Shagufta Shaheen, reachable at privacy@litscout.app or by post at the address in section 15. We acknowledge grievances promptly and answer them within the period the Act allows.
12. Children
This service is not for children or for anyone under 18. You must be at least 18 to create an account, and we ask you to confirm that when you sign up. We do not knowingly collect data from anyone younger, and we do not knowingly direct any part of the service at minors. If you believe someone under 18 has given us data, write to privacy@litscout.app and we will delete the account and its data.
13. Security
We use technical and organisational measures appropriate to the risk to protect your data, including encryption in transit. No system is perfectly secure. If a personal data breach occurs we will notify regulators and affected users as required by law.
To report a vulnerability: security@litscout.app.
14. Changes to this notice
We version this document. When we change it materially we bump the version shown above. Where a change requires your consent, we will ask for it.
15. Contact
Shagufta Shaheen, Mango, Jamshedpur, Jharkhand 831012, India
Privacy: privacy@litscout.app · Security: security@litscout.app