Privacy policy

Effective 19 September 2026 · Publisher: Xingze Wang

Paperlane is a research reader. You can discover, read and save papers without a Paperlane account. This policy covers the Paperlane website, iPhone app and reading service.

Your reading space

Your saved library, notes, highlights, preferences and reading positions are stored on your device. Downloaded PDFs and figures use app storage. They remain until you remove the app or its stored data; removing a bookmark keeps associated notes and cached content. When you sign in, saved paper metadata, collection names and assignments, notes, highlights, reading positions and preferences are synchronized to your account using Supabase. Guest data stays separate unless you choose Copy guest library or import a backup into your signed-in account. Importing a backup while signed in also uploads its library records, notes, reading positions and preferences for sync. Downloaded public arXiv PDFs, figures and full text stay on the device. Private PDF imports are described separately below. Your operating system or device backup service may include app data.

Recently read keeps up to 50 paper visits on this device, separately for guests and each account. Clear history in Library removes that list without deleting bookmarks, notes, downloads or saved reading positions.

Exporting a backup or sharing content is your choice. A backup includes your library, collections, notes and settings; original PDFs and figures must be downloaded again after import. Shared paper messages contain the paper’s public details and any message you add. They do not automatically include private notes. Other apps handle material you share according to their own policies.

Private PDF imports

Importing a private PDF uploads its original bytes, filename, editable title, page count and file checksum to private Supabase storage associated with your verified account. These files are not added to Explore, public search or community posts. The checksum detects duplicate and interrupted uploads within your account. Files are limited to 25 MB each and 200 files / 500 MB per account; new uploads also have a daily 200-file / 500-MB limit. Signed file links expire after five minutes. Private reading positions and notes are stored for your account. You can explicitly keep an offline copy on this device or export the original PDF.

Deleting a private paper removes its metadata and notes and queues removal of the file; cleanup also retries late uploads that were already in progress. Deleting your account removes its private documents and the active account’s local cache. Another device may retain an offline copy until it reconnects or you remove its stored data. Importing or reading a private PDF does not send it to an AI provider. Original private PDFs are not embedded in the ordinary JSON library backup; export them separately.

Reading purposes and briefs

Your optional reading purpose and followed topics are reading preferences, stored on your device and synchronized when signed in. You can skip setup or change them later. Purpose-based recommendations are ranked on your device using paper titles, abstracts and existing source links. Reading briefs select excerpts from public author abstracts on your device; they do not analyze the full paper or send a new request to an AI provider. Guided notes are ordinary notes with the same storage and sync behavior described above.

Personalized search on the web

When Use reading interests is on, the web app uses public titles of papers you have opened, saved or made notes on to order similar results in Search, Ask and For you. Opening is a weaker signal than saving or making a note. Repeated visits or notes do not multiply a paper's weight. The app does not read note text or highlighted passages to infer interests. This ranking runs on your device after search results arrive; your reading history and interest profile are not added to search or AI requests.

You can view why an interest was learned, add or remove interests, mark a paper less relevant, turn personalization off, or reset learned interests from Search or Settings. Explicit interests, the on/off setting, feedback and reset time are preferences included in account sync and backups. The inferred profile is calculated locally from available records; the recently read list stays on this device. Resetting learned interests excludes earlier activity from this ranking while retaining your saved papers, notes, reading history and interests you added yourself. New activity can build new interests. Exact-title matches and newest-first ordering are preserved.

Optional accounts

When available, Google, Sign in with Apple, and X identify your Paperlane account. We receive a provider identifier and the email address you choose to share, including an Apple private relay address. Your provider may also supply a display name and profile-image URL, which Supabase stores with the sign-in profile. Paperlane does not receive your provider password. X sign-in uses your X identifier, profile information and confirmed email when available; Paperlane does not fetch your X posts or direct messages. Supabase stores the account and synchronized data in Singapore. Authentication tokens keep you signed in; the iOS app stores them in the device Keychain. Apple authorization tokens needed for account deletion are encrypted on our server and are not included in backups or sent to AI.

Sign out returns to the separate guest library on that device. Your account’s local copy remains available when you sign back in, including changes not yet synchronized. In Settings, Delete account removes your account and associated data from the active cloud service and clears this device’s local account copy. Apple authorization is revoked before deletion completes. Local account copies on other devices are not remotely erased; clear Paperlane’s app or browser storage on those devices to remove them. Operational logs and provider backups follow their retention schedules. Exported copies and data you shared with other applications are not deleted. Supabase processes data under its privacy policy.

Search and paper requests

Search terms and paper identifiers pass through Paperlane’s service to retrieve public research from arXiv, OpenAlex and Hugging Face. Source queries and results may be cached for 15 minutes; stale cached responses may be served for up to an additional hour while refreshing. In the iOS app, original PDFs are requested directly from arXiv by your device and can be kept in private app storage. arXiv receives ordinary connection information, including your IP address. The web reader uses Paperlane’s service for supported PDFs and can download directly from arXiv when the service cannot provide the file. Public full text and figures can be cached by our service longer to support reading. These caches are not an account-based reading history.

Network services receive connection information, including IP addresses, requested URLs, timestamps and technical information. Paperlane uses Vercel hosting. Operational request and diagnostic logs may remain available for up to 30 days, depending on the hosting retention settings. Vercel may separately process security, billing and legal records under its privacy policy. We do not deliberately log AI request bodies, API keys or private notes.

Your recent paper-search results and Ask conversation are kept in this tab’s session storage so reload and Back can restore them. They are separated by account, excluded from account sync and backups, and expire when the browser ends the tab session. Search results are reused for up to 15 minutes. New search in Ask clears the saved conversation; API keys are never included in this storage. Ordinary paper-search terms appear in the page URL and may remain in browser history.

For offline search, this device keeps a bounded account-specific catalog of up to 150 public paper records (titles, authors and abstracts) from papers you loaded or saved, plus an included starter collection. It is separated by account, stays on the device and is not sent to AI or synced to your account. It does not contain private notes or API keys. Local results are incomplete and are labelled when online sources are unavailable. A separate device-wide cache of up to 100 generic discovery records supports the public first screen; it contains no personal searches, library records or private notes.

Visual creation and AI

Visual creation is optional and requires a signed-in account and explicit confirmation for each source. You can preview the text before sharing it. Paperlane sends the selected paper title and abstract, selected licensed full-text passages, or research text you supply, together with the requested language, to Paperlane AI (Agnes). Attached personal images, your library and unrelated notes are not sent for this action. Do not submit confidential material without permission. Generated drafts can contain errors and are labelled with their actual source coverage; verify their claims and citations before publishing.

The server stores the source, result and task status so a task can survive navigation or a dropped connection. Completed drafts remain private until you submit a post for community review. Local edits and ordinary post drafts stay in your account’s separate storage on this device. Publishing exposes the visual pages and the source passages they cite; it does not expose unused private source text. Exporting a page creates an image on your device or sends it to an app you choose.

Paperlane asks permission before sharing your current question, relevant earlier questions from the conversation and selected public paper abstracts with an AI provider. Source search and reading still work when you choose “Search without AI.” You can turn AI off or withdraw provider permission in AI settings. Consent and the AI on/off setting are saved on the device.

The shared Agnes option sends your current question, relevant earlier questions and public abstracts through our server to Agnes. Your notes and library are not sent. Agnes may retain inputs, outputs and technical usage data. Its policy permits model improvement on eligible free services unless an available opt-out applies, and excludes paid token and enterprise content from training by default. Paperlane does not promise zero retention or a universal training opt-out. See the Agnes privacy policy.

If you choose your own NVIDIA, Groq or OpenAI connection, your key is kept in app memory and sent through Paperlane’s server, which forwards it with the question context and public abstracts to the selected provider for the request. The key is cleared on reload or provider switching, and excluded from backups. A one-way key fingerprint may be held briefly to honor a provider’s rate limit. Provider account settings and policies govern their retention and use of submitted data: NVIDIA, Groq, and OpenAI. Provider billing applies separately. Avoid including confidential or sensitive personal information in questions.

Questions while reading

The “Ask the paper” assistant is optional and requires an account. Before each request, you review the exact source passages and confirm the selected AI provider. With your confirmation, Paperlane sends your question, the reviewed author abstract or text extracted from your selected public or private PDF, and up to six earlier question/answer pairs from that same paper through its server to that provider. The PDF file itself, unrelated notes and other papers are not sent. Provider retention, training policies and separate personal-key charges described above also apply to these requests.

Your account stores each question, answer, selected-source snapshot, provider/model, request status and daily allowance counters. The latest conversations and unfinished question drafts are also cached in separate account storage on your device. API keys are kept in memory and are excluded from saved conversations and exports. You can export a conversation as Markdown or clear it from the assistant. Deleting a private PDF removes its associated cloud conversation; account deletion removes all cloud conversations and counters. Previously cached copies on other devices are updated when those devices reconnect and are not remotely erased. Clearing a conversation does not reset the daily allowance or delete your PDF or notes.

Community posts and moderation

Your approved display name and biography, published research posts, images, visual stories and comments are public. Proposed profile changes are visible only to you and authorized moderators until approved; your existing approved profile remains public while changes await review. Paperlane stores likes, saves, follows and blocks to provide these features. Saved posts and your list of blocked accounts are private. Paperlane engagement is separate from Hugging Face or GitHub statistics. Uploaded images are resized and re-encoded to remove original metadata; uploaded and reviewed material is stored using Supabase. Unpublished posts are shown to their author and authorized moderators. Moderators can review contributions, reports and related source material, remove content or restrict accounts. Reporting does not publish your report to the reported author.

Deleting a post removes it from public access. Moderation decisions retain the related internal identifiers, decision and reviewer note for 90 days, including after account deletion; expired records are removed by scheduled maintenance. Account deletion removes your community profile, posts, comments, private creations and wallet, and schedules uploaded-file removal. Previously issued image links can continue to work briefly until they expire. Other people may retain screenshots or exported copies. Local drafts and copies on your other devices are not remotely erased.

App Store purchases

Apple handles payment details; Paperlane does not receive your card number. To verify membership, renewal, grace periods, expiry and refunds, we verify signed App Store transactions and retain the original and current transaction identifiers, product, environment, subscription status and dates, renewal setting, and purchase-account token. The account token is your internal Paperlane account UUID, not your email. Production and sandbox subscriptions are separate. We do not retain signed receipts or payment details. On account deletion, minimal transaction and account-token records remain to prevent a subscription being reassigned or replayed; private generated drafts are removed. Deleting your Paperlane account does not cancel your Apple subscription.

Advertising and tracking

Paperlane has no advertising or third-party analytics SDK and does not sell personal data or use it for cross-app advertising tracking. Service providers still process the request information described above to deliver, secure and operate their services. Choosing a personal AI key may associate requests with your provider account.

Support and your choices

Email xw2893@columbia.edu for support or privacy requests. We receive the email address and information you choose to send. We keep correspondence while resolving your request and where needed for follow-up or legal obligations. Do not send API keys, passwords or private research in a support report.

You can export your library and notes, delete notes, turn AI off, or remove locally stored app data. For access, correction or deletion requests concerning information held by the publisher, contact the address above. We may need information to identify the relevant request; guest libraries do not identify an account. We cannot retrieve notes stored only on your device or erase copies you shared with another app. Contact your selected provider for data held under your own provider account.

Service providers and changes

Requests may be processed outside your country where our hosting and selected providers operate. Links to external research sites and applications are governed by their own policies. We use HTTPS for network requests, but no service can guarantee absolute security. Material changes to this policy will be published here with a new effective date.