Privacy Policy
Last updated August 21, 2026
This policy explains what Research Woven collects, why, and what you can do about it. Research Woven is a research operations platform that keeps your sources, notes, evidence, and manuscripts connected in one workspace. We try to collect as little as possible and to keep your research content private to you and the collaborators you invite.
Information we collect
We collect three kinds of information:
- Account information. Your name and email address, and, if you sign in with a password, a one-way scrypt hash of that password. We never store your password in a readable form. If you sign in with Google, we receive your verified email address and name from Google and nothing else.
- Research content. Everything you create or upload in the workspace: projects, research questions, sources and their highlights, notes, evidence, claims, datasets, manuscripts, figures, tasks, and any files you upload. This content belongs to you. We process it only to provide the service.
- Usage data. A small, aggregate signal of which of the six tool areas you open and when. We use this only to understand overall product health (how many people use the platform, how actively, and which areas are most used). We do not record the contents of what you write in these usage events, and the administrator dashboard shows only aggregates, never any individual person’s work.
How we use your information
- To provide the workspace: storing your research, computing provenance and citations, and rendering your pages.
- To authenticate you: session cookies, and, for administrators, a second-factor code sent by email.
- To send you service email: sign-in links, password reset links, account confirmation, and security codes.
- To keep the product healthy and secure: aggregate usage trends and abuse prevention.
We do not sell your personal information, and we do not use your research content to train machine learning models.
Cookies
We use a small number of strictly functional cookies. These include a signed session cookie that keeps you logged in, a short-lived state cookie used during Google sign-in, and, for administrators, short-lived cookies for the two-factor step and the optional trusted-device setting. These cookies are required for sign-in to work and are not used for advertising.
The optional AI feature
Most of Research Woven is deterministic and runs without any external AI. One optional feature can format your material (for example turning notes into a slide outline, or plain text into LaTeX) using a third-party model provider. This runs only when the workspace operator has enabled it, and only on the specific text you choose to format. The human writes the argument; the AI feature never authors your intellectual contribution.
Where your data lives and who processes it
We rely on a small set of infrastructure providers to run the service: a hosting provider for the application, a managed PostgreSQL database for your content, a file storage service for uploads, and an email provider to send the service messages described above. These providers process data on our behalf under their own security and privacy terms.
Data retention and deletion
We keep your account and research content for as long as your account is active. You can ask us to delete your account and its content, and we will remove it from our active systems. Deleting your account cascades to the research objects you own. Backups may persist for a limited period before they age out.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to certain processing. To exercise any of these, contact us using the details below. You can also edit most of your profile information directly in the app.
Security and encryption
Your data is encrypted in transit and at rest. All traffic to and from the service uses TLS, and the database and file storage that hold your content encrypt it at rest. Passwords are never stored in a readable form; we keep only a one-way scrypt hash. Sessions use signed cookies that fail closed when misconfigured, and administrators pass an email second factor.
Research Woven needs to read your content on the server to do its core job: computing provenance, resolving citations, and checking structure. For that reason the service is not end-to-end encrypted, which would require the server to be unable to read your work. No system is perfectly secure, so we also encourage strong, unique passwords and keeping your own backups of work that matters to you.
Children
Research Woven is intended for researchers and is not directed to children under 16. We do not knowingly collect personal information from children.
Changes to this policy
We may update this policy as the product evolves. When we make a material change we will update the date at the top of this page.
Contact
Questions about privacy, or a request about your data, can be sent to [email protected]. See also our Terms of Service.