SYNTOLOGY The Modern Ontology for AI Home Explorer Atlas Code Methodology Attribution About Developers
Privacy policy ยท effective 20 September 2026

What we collect, why, and how to make us stop.

Start here

The short version

Syntology LLC (“Syntology”, “we”, “us”) runs syntology.ai, app.syntology.ai and the API and MCP endpoints behind them. This policy says what personal data those surfaces collect, why, who else touches it, how long we keep it and what you can make us do about it. It applies from 20 September 2026.

  • Most of what we hold is not about people at all. It is research papers, code and citations.
  • You can use the Atlas, read papers, and ask an agent whether we hold something, without an account.
  • We do not sell personal data and we do not share it for advertising. There are no ad networks, tracking pixels or third-party analytics scripts on our pages.
  • One first-party cookie, and it exists only to remember that you are signed in.
  • If you have an account, your query activity is unlinkable across sessions by default. A stable identity is something you switch on, not something we assume.
  • We do not use the content of your queries to train models. We do read what agents ask for, so that we can tell what the corpus is missing — the table below says exactly what that log holds.

If you want something deleted, write to privacy@syntology.ai and say so. You do not need to cite a statute and you do not need to live anywhere in particular.

Who is responsible

Syntology LLC, a limited liability company formed in Colorado, United States, is the controller of the personal data described here. Privacy requests go to privacy@syntology.ai; legal notices to legal@syntology.ai. A postal address is available on request.

The service is offered worldwide. We do not geo-fence it, which means this policy is written to work for visitors in the European Economic Area, the United Kingdom, Switzerland, Colorado, California and everywhere else, rather than for one jurisdiction with the others ignored.

The inventory

What we collect, surface by surface

This is the whole list, written from the code that does the collecting rather than from a template. Where a field is optional, it says so.

SurfaceWhat is collectedWhy
WaitlistYour email address and the time you submitted it.To email you when there is something to tell you about. Nothing else is sent to it.
Beta feedbackYour message, a category, an optional rating, optional notes on what you were doing, and an optional identifier — a name, an email address, or nothing. Your choice; it is never validated or required.To reproduce and fix what you reported, and to reply if you left a way to.
Graph correctionsThe correction you submit and the record it points at.A human reviews every correction before anything changes. Corrections never write to the graph directly.
Account and billingA Stripe customer identifier, your plan and entitlement, a prepaid balance, and a usage ledger of calls made. Card numbers never reach us — Stripe collects and holds them.To know what you bought, to meter it honestly, and to show you your own usage.
Signing inOne cookie holding a signed session token, plus the privacy alias described below. Secure, HttpOnly, SameSite=Lax, 30 days.So the site knows you are signed in. It is not readable from page JavaScript and it is not used for tracking.
API and MCP tokensThe token, its tier, and its remaining query budget.To authorise calls and count them against what you are entitled to.
Abuse preventionA counter keyed to your IP address, and your IP address passed to Cloudflare Turnstile when a bot check runs.Rate limits and bot filtering. Free endpoints would otherwise be trivially drained.
Service telemetryEvent type and reason, endpoint, RPC method and tool name, HTTP status, duration, the first 12 characters of the token used, user agent, referring page, country, network (ASN and operator), the Cloudflare location that served you, and your IP address.To see whether the service works, who is being turned away and why, and where it breaks.
What agents ask forThe query string, truncated, with the verdict and result count, and the same non-reversible 12-character token prefix. The token itself is deliberately never written.An agent asking for something we do not hold is the only honest signal of what the corpus is missing. It is what we build from.
The reviewer toolThe text you paste or the PDF you upload, and the review generated from it.To produce the review you asked for.
Server logsOrdinary request logs at our hosting providers, including IP addresses and user agents.Security, debugging and abuse investigation.
The one thing worth reading twice

Service telemetry and the agent-demand log include your IP address and the query text. In the European Economic Area and the United Kingdom an IP address is personal data, so we treat it as such: the lawful basis is our legitimate interest in running a service that is not being abused, the retention is short, and you can object. We do not join telemetry to your billing identity to build a profile of you, and the rotating alias below exists so that we cannot do it accidentally.

A design choice, not a promise

Your identity here is rotating unless you change it

Accounts carry an alias rather than an identity. By default the alias rotates, which means your activity in one session cannot be linked to your activity in another. You can opt into a stable alias if you want a continuous history.

Switching back to rotating does not merely stop using the stable alias — it deletes it. Opting in again later mints a new one; the old history is not recoverable, by us or by you. That is the point. We built it that way so that the private setting is a real property of the system and not a checkbox that shows you a different screen.

What we do not do

  • We do not sell personal information, and we do not share it for cross-context behavioural advertising. Under the California Consumer Privacy Act, and the equivalent laws in Colorado, Virginia, Connecticut, Texas and the other states that have them, we have no “sale” or “sharing” to disclose.
  • We run no advertising, no ad-network tags, no third-party analytics script and no tracking pixels. There is nothing on the page that reports to anyone else about you.
  • We do not track you across other websites, and we set no third-party cookies.
  • We do not store peer-review authorship. Reviews from OpenReview are held one node per review with the rating and confidence kept exactly as published; reviewer identities are not stored.
  • We do not use the content of your queries, your feedback or your uploads to train machine-learning models.
  • We do not ask for, or want, special category data — health, biometrics, political opinions, and the rest. Please do not put any into a feedback box.

Why we are allowed to process it

For visitors in the EEA, the United Kingdom and Switzerland, the General Data Protection Regulation requires a lawful basis for each purpose. Ours:

PurposeLawful basis
Providing the service you asked for, including accounts, tokens and meteringPerformance of a contract (GDPR Art. 6(1)(b))
Taking payment, keeping billing records, and meeting tax and accounting dutiesContract, and legal obligation (Art. 6(1)(b) and (c))
Waitlist emailConsent (Art. 6(1)(a)) — you asked to be on it, and you can leave at any time
Feedback and corrections you send usConsent, and our legitimate interest in fixing what you reported (Art. 6(1)(a) and (f))
Security, rate limiting, bot filtering and abuse investigationLegitimate interests (Art. 6(1)(f))
Service telemetry and understanding what the corpus is missingLegitimate interests (Art. 6(1)(f))
Author and reviewer information inside the research corpusLegitimate interests in scholarly indexing (Art. 6(1)(f)) — see the section on the corpus below

Where we rely on legitimate interests we have weighed them against your rights, and you can object at any time using the address at the end of this page. Where we rely on consent you can withdraw it, which does not affect processing that already happened.

Authors, reviewers and code

Personal data inside the research corpus

This is the part a generic privacy policy would miss, and it matters more here than the cookie question.

Syntology indexes academic literature. That literature names people. The graph therefore holds author names, author affiliations and institutions, and the text of peer reviews, all taken from public sources — arXiv, Semantic Scholar, OpenReview, Crossref, OpenAlex and the papers themselves. Where we hold code, it comes from public repositories and may contain the names and email addresses its own authors chose to put in it, in commit metadata or a licence header.

We process this in our legitimate interest in building an accurate index of published research, which is a recognised purpose and the same one every bibliographic database relies on. We do not enrich it, we do not sell it, we do not build profiles of researchers, and we do not attempt to identify anonymous peer reviewers. Reviewer identity is not stored even where the upstream source exposes it.

If you are named in the corpus and want that changed

Write to privacy@syntology.ai. You can ask us to correct what we say about you, or to remove it. We will do it, or explain why we cannot — and the honest constraint is that a correction made only in the graph gets undone by the next load, so a real fix means fixing the source record too, which takes longer than a delete. We would rather tell you that than quietly re-import it. Bibliographic facts that are part of the public scholarly record, such as the authorship of a published paper, we will generally keep; that is the one case where we may decline, and we will say so plainly.

Cookies and similar technologies

We use one cookie. It holds a signed session token, it is set only after you sign in, it is HttpOnly so page scripts cannot read it, and it expires after 30 days. It is strictly necessary to provide a service you asked for, which is why there is no consent banner in your way.

Cloudflare Turnstile may set a short-lived token when a bot check runs. It is there to tell a browser from a script, and it is not an advertising or profiling technology.

We store no analytics cookies, no advertising cookies and no third-party cookies. Our telemetry is recorded server-side, which is why it can be honest about IP addresses rather than hiding behind a tag manager.

Who else processes it

We use a small number of providers, each under a data processing agreement that limits them to acting on our instructions. This is the whole list.

ProviderWhat it doesWhere
Cloudflare, Inc.Serves the site, stores account, token, waitlist and feedback records in Workers KV, runs Turnstile bot checks, and holds service telemetry.Global edge; United States
Stripe, Inc.Takes payment and holds card data. We never receive card numbers. Stripe is an independent controller for its own compliance purposes, under its own privacy policy.United States
Amazon Web Services, Inc.Runs the API backend and holds its request logs; Amazon Bedrock runs the language models behind conversational answers and generated text.United States
Neo4j, Inc. (Aura)Hosts the graph database, which holds the research corpus.United States
Google LLCServes the web fonts our pages use.Global

Amazon Bedrock does not use prompts or responses to train its models, and our configuration does not opt into any such use. We will also disclose personal data where the law actually requires it — a valid legal process, or to establish or defend a legal claim — and, if we are ever bought or merged, to the acquirer, who would be bound by this policy until it tells you otherwise.

Where your data goes

We are in the United States and so are our providers, so if you are in the EEA, the United Kingdom or Switzerland your personal data is transferred to the United States. We rely on the European Commission’s Standard Contractual Clauses, and the UK International Data Transfer Addendum, in our agreements with Cloudflare, Stripe, Amazon Web Services and Neo4j. Several of them are additionally certified under the EU–US Data Privacy Framework.

A copy of the transfer terms we rely on is available on request from privacy@syntology.ai.

How long we keep it

DataRetention
Session cookie30 days from issue, then it expires on its own
Account usage ledger90 days, then it expires on its own
Account transfer codes10 minutes
Trial and subscription tokensThe life of the token — minutes for a trial, 7 or 30 days by tier
Rate-limit counters60 seconds to 24 hours depending on the limit, then they expire on their own
Service telemetryCloudflare’s retention for the analytics dataset, currently 92 days
Agent-demand logHeld in our backend logs while we work out what the corpus is missing; reviewed and pruned rather than kept indefinitely
Waitlist entriesUntil you ask to be removed, or we retire the waitlist
Feedback and correctionsUntil the report is resolved and long enough after to know the fix held
Billing recordsAs long as tax and accounting law requires, typically seven years
Reviewer-tool uploads and outputFor as long as needed to deliver the review, and then deleted on request

Where a retention period above is an expiry written into the system, it happens whether or not anyone remembers to do it. Where it is a judgement, you can force the issue by asking us to delete.

And how to use them

Your rights

If you are in the EEA, the UK or Switzerland, you have the right to access your personal data, to have it corrected, to have it erased, to restrict or object to processing, to data portability, and to withdraw consent. You may also complain to your supervisory authority — in the UK, the Information Commissioner’s Office; in the EEA, the authority where you live or work — though we would rather you told us first.

If you are in California, you have the right to know what we collect and why, to access and delete it, to correct it, and to be free of discrimination for asking. We do not sell or share personal information as the CCPA defines those terms, so there is no opt-out to exercise, and we do not use or disclose sensitive personal information for purposes that require one. You may use an authorised agent.

If you are in Colorado, Virginia, Connecticut, Texas, Oregon, Montana or another state with a comprehensive privacy law, you have broadly the same rights of access, correction, deletion, portability and opt-out. Under the Colorado Privacy Act you may also appeal a refusal: if we decline a request, reply to our answer and a human will review it and respond within 45 days, and you may contact the Colorado Attorney General if you remain unsatisfied.

Everyone else gets the same rights anyway. We are not going to run two standards of behaviour based on where you happen to live.

How to exercise any of this

Email privacy@syntology.ai and say what you want. We will acknowledge within 10 days and answer within 30 days, or 45 where the law allows longer and the request needs it — and we will tell you if it will take the longer period rather than letting the deadline pass. We may need to verify that a request about an account really comes from that account; for anything else, we will ask for the least we can get away with, and we do not create an account for you in order to answer you.

Security

Traffic is served over HTTPS. Session cookies are signed, Secure, HttpOnly and SameSite=Lax. Every response carries X-Content-Type-Options, X-Frame-Options, a Referrer-Policy and a Permissions-Policy. Database access is split into separate reader and writer credentials so that a read path cannot write. Code harvested from public repositories is executed only inside a network-isolated, read-only, unprivileged container, never on a machine that holds credentials.

We do not yet serve a Content Security Policy, because the pages are generated with inline styles and scripts and a policy written carelessly around that would break the site rather than protect it. It is a known gap rather than an oversight, and it is on the list.

No system is perfectly secure. If you find a vulnerability, write to legal@syntology.ai; we will not pursue you for a good-faith report that does not exfiltrate other people’s data or degrade the service.

Children

The service is not directed at children and is not designed for them. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, tell us and we will delete it.

Automated decision-making

Nothing here makes an automated decision with a legal or similarly significant effect on you. Rate limits and bot checks are automated, and they can turn a request away; if you think one has wrongly locked you out, email us and a person will look. Scores the service publishes about papers — novelty, verification level — are statements about documents and code, not about people.

Changes to this policy

If we change this policy materially we will update the date below and, for changes that reduce your rights or widen what we collect, tell account holders by email before it takes effect. The previous version stays available on request. We will not make a material change quietly and count on you not to read it.

Contact

Privacy requests and questions: privacy@syntology.ai.
Legal notices and security reports: legal@syntology.ai.
Everything else: media@syntology.ai.

Syntology LLC, Colorado, United States. A postal address is available on request and will be provided to any supervisory authority that asks for it.

See also our Terms of Service and our attribution and upstream licences page, which lists where the material in the graph came from.

The Modern Ontology for AITermsPrivacyAttributionlegal@syntology.aiLast reviewed 20 September 2026