Privacy & Data
A plain statement of what PaperOrbit stores, where it lives, and how it is used. Last updated August 2026.
What we store
Your account information: the email address and password credentials you sign up with, managed by Supabase Auth (passwords are hashed and never visible to us).
Publications you upload: the PDF files themselves, and the research profile extracted from each one (research question, methods, findings, keywords, and similar fields), including any edits you make to it.
Publications you import: when you import from an ORCID iD or an author-name search, we store the bibliographic record returned by those public services — title, authors, journal, year, DOI, PubMed ID, link, and the published abstract — plus any research profile built from it. No file is stored, because an import never includes the full text.
Content you generate: every visibility asset created from your profile (summaries, social posts, briefs, statements), and the funding matches found for it — including which you saved or dismissed. Deleting a publication deletes all of it.
Your account plan and a count of how many generations you have run this month, so free and paid limits can be applied. We do not store payment details; billing is not yet part of the product.
We never store or process student records, grades, advising notes, disability information, financial aid information, or protected health information. The platform only ever touches published research and public grant and funding data.
Where it's stored
All data lives in a Supabase project (Postgres database and file storage) tied to this application. Uploaded PDFs are stored in a private Supabase Storage bucket accessible only to your account.
Retention and deletion
Your data is retained for as long as your account exists. Deleting a publication removes the file and its extracted profile data. Deleting your account removes all of your data. To request deletion, contact us at the address on your account emails.
AI processing
Three things are sent to Anthropic's Claude API: the PDF you upload (to extract your research profile), the published abstract of any record you import (to build a profile from it), and your saved profile fields (to generate visibility content, and to judge which funding opportunities fit your work). Nothing else is sent. Anthropic does not train its models on API content, and we do not use your content to train models of any kind.
Funding data is read from two public U.S. government sources — grants.gov and NIH RePORTER. Keywords derived from your profile are sent to them as search terms; your publication itself is never uploaded to either.
Publication import reads three free public scholarly APIs — ORCID, Crossref, and PubMed (NCBI E-utilities). We send only what identifies the work you asked for: the ORCID iD or author name you typed, and the DOIs or PubMed IDs of the records it returned. Nothing about your account is sent, and we do not use Google Scholar, which has no public API.
Security
Access to your data is protected by Supabase authentication and row-level security, so your records and files are only readable by your own account. All traffic is encrypted in transit over HTTPS.

