Privacy Policy
Last updated: July 2026 · Beta version
Research Roadmap is currently in beta. This document is a working draft and has not been reviewed by a lawyer — it describes our actual current practices honestly, but should not be relied on as a final legal agreement.
1. What we collect
When you use Research Roadmap, we collect:
- Account information: your name, email address, and password (stored as a salted hash, never in plain text)
- Project content: research topics, titles, descriptions, and every piece of AI-generated or edited content you create
- Literature sources you search for, import, or upload (including any PDFs you upload for metadata extraction)
- Basic usage data: which stages you've generated, when, and how many projects you've created
2. Third parties your data goes to
Being direct about this, since it matters:
- Google Gemini and Anthropic Claude — your project content (research topic, selected context from prior stages) is sent to these AI providers to generate each stage's output. We don't control their internal data handling beyond their own published policies.
- OpenAlex, Crossref, and Semantic Scholar — your search queries are sent to these literature databases; no account information is shared with them.
- Zoho Mail — used to send verification and password-reset emails; your email address and name pass through their systems.
We do not sell your data to advertisers, and we do not use your project content to train AI models ourselves.
3. How we store it
Your data is stored in a PostgreSQL database on infrastructure we operate directly. Authentication uses JSON Web Tokens stored in your browser's local storage — this is a known limitation for a beta product (a more robust httpOnly-cookie approach is planned before general availability).
4. How long we keep it
We keep your account and project data for as long as your account is active. Archiving a project hides it from your dashboard but does not delete it. Deleting a project removes it permanently. You can request full account deletion by contacting us.
5. Your rights
You can access, export (via PDF), correct, or delete your project data directly within the app at any time. For account-level deletion or other requests, contact us at the email below.
6. Cookies and local storage
We use browser local storage to keep you signed in, and session storage for minor UI preferences (like whether you've dismissed the beta banner). We don't use tracking or advertising cookies.
7. Changes to this policy
We'll update this page as our practices evolve, particularly as we move from beta toward general availability and introduce paid plans.
8. Contact
Questions or requests regarding your data can be sent to uma@acads.in.