Data Policy

Last updated: 12 June 2026

AIPR keeps your unpublished work yours. This page states plainly what happens to a manuscript when AIPR reads it, how long anyone holds it, and the deployment options you control. A condensed view for security reviews lives at aipr.pub/trust/security.

No training, ever

We never use your submitted content to train a model. Neither do the model providers we route to. AIPR runs under standard commercial API terms, which contractually exclude your prompts and documents from any training or fine-tuning. This holds for every reviewer, every manuscript, on every tier.

What we process and for how long

Your manuscript content is used only to generate the review you asked for. The model provider may retain a request for around 30 days for abuse monitoring, after which it is deleted. On accounts where we enable zero data retention, that short window is removed and content is dropped immediately after the response. Nothing is kept to build a profile of you, your work, or your institution.

Deployment options

AIPR meets your institution where its data-governance bar sits.

  1. Standard runs on our managed keys under the no-training terms above. This is the default and needs nothing from your side.
  2. Cloud-routed sends requests through your own cloud tenancy on Amazon Bedrock, Google Vertex AI, or Azure OpenAI, so the data path stays inside infrastructure your institution already governs.
  3. BYO-key or self-host lets you supply your own provider credentials or run AIPR against models inside your own environment, so review content never leaves your boundary.

Data processing agreement

A data processing agreement is available and signable as-is, so your procurement and legal teams can review the same terms every pilot runs under. The full text is published at aipr.pub/trust/dpa.

What we collect

An account requires an email and a password. You can optionally link an ORCID iD from settings so reviews are attributable to the verified researcher; the link is removable at any time. Submitted papers (PDF or DOCX) and the reviews we generate are stored against your account so you can return to them. Stripe handles checkout end-to-end. We receive a customer reference and entitlement records, never card data. Standard server logs (IP, user agent, request path) are kept for 30 days for debugging and abuse response.

Encryption and transport

All connections use TLS 1.2 or newer. Database backups are encrypted at rest before upload to object storage and tested on a recurring restore cadence. Passwords are stored as bcrypt hashes. Sessions use HMAC-signed, HttpOnly/Secure cookies with SameSite=Lax.

Subprocessors

A small set of vendors handles parts of the service. Each one sees only what it needs to do its job.

  • OpenAI. Performs the model inference that generates the review, under enterprise API terms with no training on submitted content. Receives the manuscript text and returns the structured review. Privacy policy.
  • DigitalOcean. Application hosting, managed PostgreSQL, and Spaces (S3-compatible) blob storage. SOC 2 Type II certified. Holds stored papers, reviews, account records, and encrypted database backups. Privacy policy.
  • Stripe. Payment processing. Handles checkout end-to-end. We receive a customer reference and entitlement records, never card data. Privacy policy.
  • Resend. Transactional email delivery. Sees the recipient address and the content of each transactional email. Privacy policy.
  • Google Analytics. Aggregate, anonymized traffic measurement on the public site, never used for advertising. Sees anonymized, aggregate traffic measurements. No manuscript content reaches it. Loads only after you accept the cookie notice. Privacy policy.

Retention

Anonymous uploads (no account attached) are deleted after 7 days. Account-attached papers and reviews are kept for as long as the account is active. Deleting the account removes the associated personal data within 30 days. Reviews that have been made public via the leaderboard remain visible; the corresponding author can request takedown by email (see the Your rights section). Encrypted backups follow a tiered retention of 7 daily / 4 weekly / 3 monthly snapshots and are tested on a recurring restore cadence.

Cookies

Two functional cookies, both HttpOnly/Secure/SameSite=Lax:user_session authenticates a logged-in account, andbuyer_session binds an unclaimed review-pass purchase to your browser. If you accept the cookie notice, Google Analytics sets cookies to measure aggregate site usage so we can see which pages are useful. Analytics is off by default and stays off if you decline; nothing about the product depends on it, and the choice is stored locally in your browser rather than in a cookie. We run no advertising cookies and no cross-site tracking pixels.

Your rights

You can request a copy of your data, an export of your reviews, an account deletion, or a takedown of a review you authored, by emailing [email protected]. We respond within five working days. Deletions complete within 30 days. Account details (name, email, ORCID link) can be edited directly from the settings page.

Changes and contact

Material changes to this policy will be posted here with an updated date. Questions about the policy itself, or anything related to data handling: [email protected].