Legal
Privacy policy
Paper Scout is a product about showing its working. This document is written the same way: what we hold, why we hold it, exactly who else sees it, and how to make us delete it.
The short version. We collect the account you sign in with, the research interests you write, the papers we find for you and what you do with them, plus standard app analytics and crash data. We send your interests and public paper abstracts to AI providers so they can rank and summarise them. We do not sell your data, we do not use it for advertising, and there are no advertising or tracking SDKs in the app. You can delete your account from inside the app, or email us and we will do it for you.
1. Who we are
Paper Scout is operated by Oslr Ltd, a company registered in England and Wales ("we", "us", "our"). For the purposes of the UK GDPR and the EU GDPR, Oslr Ltd is the data controller for the personal data described in this policy.
This policy covers the Paper Scout mobile apps for iOS and Android, the Paper Scout web app, and this website. If you want to talk to a human about any of it, write to privacy@paperscout.net.
2. What we collect, and why
Everything below is collected because a specific feature needs it. Where a feature is optional, so is the data.
| What | Examples | Why |
|---|---|---|
| Account details | Your name, email address and profile picture, as supplied by Google or Apple when you sign in. A Paper Scout account identifier. | To create and secure your account, and to contact you about the service. |
| Your research profile | The paragraph describing your research interests, the authors you follow, and optionally your website, institutional page or ORCID. | This is the input to every ranking decision. It is the whole model of you, which is why you can read and edit it. |
| Your interests history | Every earlier version of that paragraph, with a note of what changed it — you, a miss diagnosis, a calibration, or the first automatic draft. | So you can see how your profile has changed and roll any change back. |
| Papers and what you do with them | The papers we found for you, their scores and the reason written for each one; what you saved, dismissed, read, shared, queued, played or tagged; and any notes you write. | To build your feed and library, to power Calibrate, and to answer "why did you miss this?". |
| Run journals | For each search run: the queries written for you, what was retrieved, what was screened out at each stage, and a snapshot of the interests used. | This is what makes miss diagnosis possible. Without it we could not tell you where a paper was lost. |
| Audio | Scripts and audio files for the briefings and per-paper summaries you generate, and their transcripts. | To produce and play back the audio you asked for. |
| Device and push data | A push notification token, a device identifier, the device name your operating system reports, and the platform. | To send notifications you have opted into, and to avoid sending the same one twice. |
| Subscription data | Subscription status, plan, purchase and renewal dates, and store transaction identifiers. We never see your card details — Apple and Google handle payment. | To know what you are entitled to, and to keep the accounting records the law requires. |
| Usage analytics | Screens viewed, features used, sign-in method, searches within your own library, and app errors — linked to your account identifier. Google also collects device model, operating system, an app instance identifier and coarse location derived from your IP address. | To understand which parts of the product work and which are broken. See section 8, including what we are still fixing there. |
| Service logs | Technical records of requests to our backend, and a ledger of AI calls recording model names, token counts, durations and errors — not the text sent or received. | Security, debugging, and knowing what the service costs to run. |
What we deliberately do not collect
- Payment card details. Those go to Apple or Google, never to us.
- Precise location. We never ask for it and the apps do not request location permission.
- Your microphone. The iOS app declares a microphone purpose string because of the audio library it uses, but Paper Scout never records anything.
- Advertising identifiers. There is no advertising in Paper Scout, and the Android build explicitly strips the advertising ID permission.
- Your contacts, calendar, photos, or the contents of other apps.
A word about free-text fields. Your research interests, your notes on a paper, and anything you paste into a miss diagnosis are free text, and they are sent to our AI providers to be processed. Please don't put patient data, identifiable clinical information, unpublished confidential results or anything else you would not want leaving your organisation into those boxes. Describe the topic you work on, not the people or the data you work with.
3. How your data is used by AI
Paper Scout is an AI product, so this deserves its own section rather than a line in a table.
When you run a search, the following is sent to an AI provider:
- your research interests paragraph and the authors you follow, to write the search queries;
- the titles of the papers retrieved, to decide which deserve a full read;
- the abstracts of the shortlisted papers together with your interests, to score each one and write the reason you see.
When you generate a profile from your name or website, a briefing summarising your public publication record — your name, institution, recent paper titles and frequent co-authors — is sent as well. When you generate audio, the script is sent to a text-to-speech provider. When you ask why a paper was missed, the paper you pasted is sent along with the relevant part of the run journal.
These providers act as our processors: they handle this content in order to return a result to you, under their API terms. We do not use your content to train our own models, and we do not authorise our providers to use it to train theirs. The papers themselves are public scientific literature; the personal part of what is sent is your interests paragraph and anything you typed into it.
Which provider is used can change — the service is built so that the text model can be switched between Google and Anthropic without a code release. Both are named in section 4 so this policy stays accurate whichever is active.
4. Who else sees your data
We do not sell your personal data and we have never disclosed it for advertising. We share it only with the service providers below, each of which processes it on our instructions and for the stated purpose.
| Provider | What it receives | Why |
|---|---|---|
| Supabase | Everything: authentication, the database, generated audio files, and backend logs. | It is our backend. Nothing about Paper Scout works without it. |
| Google (Gemini API) | Your interests, paper titles and abstracts, profile briefings, diagnosis input and calibration labels. | Our default text-model provider: query writing, screening, ranking, summaries. |
| Anthropic | The same content as above, when it is the active provider. | Our alternate text-model provider and fallback. |
| OpenAI | The text of audio scripts, at the point you generate audio. | Text-to-speech for briefings and summaries. |
| NCBI / PubMed (U.S. National Library of Medicine) | The search queries generated from your interests and author names. No account details, no name, no email. | Finding and fetching the papers themselves. |
| OpenAlex (OurResearch) | Your name, when you ask it to build a profile from your publication record. Journal identifiers otherwise. | Finding your public bibliography, and journal-level metadata. |
| Google Firebase (Analytics, Cloud Messaging, Crashlytics) | Analytics events with your account identifier attached; push tokens and the content of notifications sent to your device. | Product analytics and push delivery. |
| RevenueCat | Your account identifier and subscription events from the app stores. | Managing subscriptions across iOS and Android. |
| Apple and Google (sign-in and billing) | Sign-in tokens; purchase transactions. | Authentication and payment processing. |
| Vercel | Standard web request data — IP address, user agent — when you use the website or web app. | Hosting. |
If you ask Paper Scout to build a profile from a website you supply, our servers fetch that page.
The site's operator will see a request from us, identified as PaperScout.
Other disclosures
We may also disclose personal data where we are legally required to, where it is necessary to establish or defend legal claims, or to protect the safety of our users. If Oslr Ltd is ever sold or merged, your data may transfer to the acquirer, who would remain bound by this policy until you are told otherwise.
5. Our legal bases (UK & EU GDPR)
| Purpose | Legal basis |
|---|---|
| Creating your account, running searches, showing your feed, storing your library, generating audio you request | Contract — we cannot provide Paper Scout without it. |
| Subscription management and keeping accounting records | Contract and legal obligation. |
| Security, abuse prevention, debugging and understanding running costs | Legitimate interests — operating a service that works and does not lose money. |
| Product analytics | Consent where required, otherwise legitimate interests. See section 8. |
| Push notifications | Consent — granted through your device's permission prompt, and revocable in your device settings at any time. |
| Service emails about your account or a change to this policy | Legitimate interests. |
Where we rely on legitimate interests, we have considered your rights and concluded the processing is proportionate. You can object at any time — see section 9.
6. Where your data goes
Paper Scout is operated from the United Kingdom. Several of the providers in section 4 are based in, or process data in, the United States — in particular Google, Anthropic, OpenAI, RevenueCat, Vercel and the U.S. National Library of Medicine.
Where personal data leaves the UK or the EEA, we rely on the UK International Data Transfer Addendum and the European Commission's Standard Contractual Clauses, or on an adequacy decision where one applies, together with the provider's own technical and organisational safeguards.
7. How long we keep things
| Data | Kept for |
|---|---|
| Your account, profile, interests history, library, notes and generated audio | Until you delete your account, or ask us to delete them. |
| Search run journals | 30 days, then deleted automatically. This is why a miss diagnosis works best on a recent paper. |
| Calibration runs | 90 days, then deleted automatically. |
| Purchase and subscription records | Up to 7 years after the transaction, to meet UK accounting and tax obligations. These survive account deletion, by law. |
| Analytics data | Per Google's retention settings for our Firebase project, currently a maximum of 14 months for event-level data. |
| Backups | Deleted data may persist in encrypted backups for a short period before those backups roll over. |
8. Analytics, and what we are still fixing
Paper Scout uses Google Firebase Analytics to understand how the app is used, and Firebase's crash reporting to find out when it breaks. There is no advertising SDK, no third-party tracker, no social media pixel and no cross-app tracking. We have never shown an App Tracking Transparency prompt because we do not track you across other companies' apps or websites.
Being straight with you about two things, in the spirit of the rest of this document:
- Analytics currently starts when the app starts. There is not yet an in-app toggle to switch it off, and we are building one. Until it ships, you can email privacy@paperscout.net and we will disable analytics collection for your account and delete the analytics data we hold about you.
- Your Paper Scout account identifier is attached to analytics and subscription records. That means those records are linked to your account rather than anonymous, and we would rather say so than describe them as anonymised when they are not.
This website — the pages you are reading now — sets no cookies, runs no analytics and loads nothing from a third party. Our web host records standard server request logs.
9. Your rights
If you are in the UK or the EEA, you have the right to:
- access the personal data we hold about you, and get a copy of it;
- correct anything that is inaccurate — much of it you can edit yourself in the app;
- delete your data (see section 10);
- restrict or object to processing based on legitimate interests;
- port your data to another service in a machine-readable format;
- withdraw consent at any time, where we relied on it.
Similar rights apply under California's CCPA/CPRA and other US state privacy laws, including the right to know what we collect and to opt out of any "sale" or "sharing" of personal information. We do not sell or share personal information as those laws define it, and we do not use it for cross-context behavioural advertising.
To exercise any of these, email privacy@paperscout.net. We will respond within 30 days. There is no automated data export in the app yet, so a copy of your data is currently produced by hand on request — it works, it is just not instant.
10. Deleting your account
In the app: Account → Delete Account. That removes your profile, your research interests and their history, your saved papers and notes, your run journals, your device tokens and the audio we generated for you.
What survives, and why:
- Purchase and subscription records, kept for up to seven years for accounting and tax purposes as described above.
- De-identified operational records — the AI cost ledger keeps token counts and model names with the link to your account removed.
- Encrypted backups, until they roll over.
If the in-app deletion ever fails, or you would rather we handled it, email privacy@paperscout.net from your account address and we will delete everything above by hand within 30 days and confirm when it is done.
Deleting your Paper Scout account does not cancel a subscription bought through the App Store or Google Play — those are managed by Apple and Google. Cancel it in your device's subscription settings before deleting your account.
11. Security
Data is encrypted in transit and at rest by our infrastructure providers. Database access is governed by row-level security so that queries run on your behalf can only reach your own rows. Generated audio is held in private storage and served through short-lived signed links. API credentials are held as server-side secrets and are never shipped in the app.
No system is perfectly secure. If we discover a breach affecting your personal data we will notify the Information Commissioner's Office within 72 hours where required, and tell you directly where the risk to you is high. If you believe you have found a vulnerability, please write to security@paperscout.net before disclosing it publicly — we will work with you and we will not pursue good-faith research.
12. Children
Paper Scout is built for professional researchers and clinicians and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, email privacy@paperscout.net and we will delete it.
13. Changes to this policy
When we change this policy we will update the date at the top. If the change materially affects your rights or how your data is used, we will tell you in the app or by email before it takes effect. Previous versions are available on request.
14. Contact and complaints
Privacy questions and rights requests: privacy@paperscout.net
Anything else: support@paperscout.net
Security reports: security@paperscout.net
Postal address: Oslr Ltd, United Kingdom. We will supply the full registered address on request.
If you are unhappy with how we have handled your data, please tell us first — we would like the chance to fix it. You also have the right to complain to the UK's Information Commissioner's Office, or to the supervisory authority in your EU member state.