Syntology LLC (“Syntology”, “we”, “us”) runs syntology.ai, app.syntology.ai and the API and MCP endpoints behind them. This policy says what personal data those surfaces collect, why, who else touches it, how long we keep it and what you can make us do about it. It applies from 20 September 2026.
If you want something deleted, write to privacy@syntology.ai and say so. You do not need to cite a statute and you do not need to live anywhere in particular.
Syntology LLC, a limited liability company formed in Colorado, United States, is the controller of the personal data described here. Privacy requests go to privacy@syntology.ai; legal notices to legal@syntology.ai. A postal address is available on request.
The service is offered worldwide. We do not geo-fence it, which means this policy is written to work for visitors in the European Economic Area, the United Kingdom, Switzerland, Colorado, California and everywhere else, rather than for one jurisdiction with the others ignored.
This is the whole list, written from the code that does the collecting rather than from a template. Where a field is optional, it says so.
| Surface | What is collected | Why |
|---|---|---|
| Waitlist | Your email address and the time you submitted it. | To email you when there is something to tell you about. Nothing else is sent to it. |
| Beta feedback | Your message, a category, an optional rating, optional notes on what you were doing, and an optional identifier — a name, an email address, or nothing. Your choice; it is never validated or required. | To reproduce and fix what you reported, and to reply if you left a way to. |
| Graph corrections | The correction you submit and the record it points at. | A human reviews every correction before anything changes. Corrections never write to the graph directly. |
| Account and billing | A Stripe customer identifier, your plan and entitlement, a prepaid balance, and a usage ledger of calls made. Card numbers never reach us — Stripe collects and holds them. | To know what you bought, to meter it honestly, and to show you your own usage. |
| Signing in | One cookie holding a signed session token, plus the privacy alias described below. Secure, HttpOnly, SameSite=Lax, 30 days. | So the site knows you are signed in. It is not readable from page JavaScript and it is not used for tracking. |
| API and MCP tokens | The token, its tier, and its remaining query budget. | To authorise calls and count them against what you are entitled to. |
| Abuse prevention | A counter keyed to your IP address, and your IP address passed to Cloudflare Turnstile when a bot check runs. | Rate limits and bot filtering. Free endpoints would otherwise be trivially drained. |
| Service telemetry | Event type and reason, endpoint, RPC method and tool name, HTTP status, duration, the first 12 characters of the token used, user agent, referring page, country, network (ASN and operator), the Cloudflare location that served you, and your IP address. | To see whether the service works, who is being turned away and why, and where it breaks. |
| What agents ask for | The query string, truncated, with the verdict and result count, and the same non-reversible 12-character token prefix. The token itself is deliberately never written. | An agent asking for something we do not hold is the only honest signal of what the corpus is missing. It is what we build from. |
| The reviewer tool | The text you paste or the PDF you upload, and the review generated from it. | To produce the review you asked for. |
| Server logs | Ordinary request logs at our hosting providers, including IP addresses and user agents. | Security, debugging and abuse investigation. |
Service telemetry and the agent-demand log include your IP address and the query text. In the European Economic Area and the United Kingdom an IP address is personal data, so we treat it as such: the lawful basis is our legitimate interest in running a service that is not being abused, the retention is short, and you can object. We do not join telemetry to your billing identity to build a profile of you, and the rotating alias below exists so that we cannot do it accidentally.
Accounts carry an alias rather than an identity. By default the alias rotates, which means your activity in one session cannot be linked to your activity in another. You can opt into a stable alias if you want a continuous history.
Switching back to rotating does not merely stop using the stable alias — it deletes it. Opting in again later mints a new one; the old history is not recoverable, by us or by you. That is the point. We built it that way so that the private setting is a real property of the system and not a checkbox that shows you a different screen.
For visitors in the EEA, the United Kingdom and Switzerland, the General Data Protection Regulation requires a lawful basis for each purpose. Ours:
| Purpose | Lawful basis |
|---|---|
| Providing the service you asked for, including accounts, tokens and metering | Performance of a contract (GDPR Art. 6(1)(b)) |
| Taking payment, keeping billing records, and meeting tax and accounting duties | Contract, and legal obligation (Art. 6(1)(b) and (c)) |
| Waitlist email | Consent (Art. 6(1)(a)) — you asked to be on it, and you can leave at any time |
| Feedback and corrections you send us | Consent, and our legitimate interest in fixing what you reported (Art. 6(1)(a) and (f)) |
| Security, rate limiting, bot filtering and abuse investigation | Legitimate interests (Art. 6(1)(f)) |
| Service telemetry and understanding what the corpus is missing | Legitimate interests (Art. 6(1)(f)) |
| Author and reviewer information inside the research corpus | Legitimate interests in scholarly indexing (Art. 6(1)(f)) — see the section on the corpus below |
Where we rely on legitimate interests we have weighed them against your rights, and you can object at any time using the address at the end of this page. Where we rely on consent you can withdraw it, which does not affect processing that already happened.
This is the part a generic privacy policy would miss, and it matters more here than the cookie question.
Syntology indexes academic literature. That literature names people. The graph therefore holds author names, author affiliations and institutions, and the text of peer reviews, all taken from public sources — arXiv, Semantic Scholar, OpenReview, Crossref, OpenAlex and the papers themselves. Where we hold code, it comes from public repositories and may contain the names and email addresses its own authors chose to put in it, in commit metadata or a licence header.
We process this in our legitimate interest in building an accurate index of published research, which is a recognised purpose and the same one every bibliographic database relies on. We do not enrich it, we do not sell it, we do not build profiles of researchers, and we do not attempt to identify anonymous peer reviewers. Reviewer identity is not stored even where the upstream source exposes it.
Write to privacy@syntology.ai. You can ask us to correct what we say about you, or to remove it. We will do it, or explain why we cannot — and the honest constraint is that a correction made only in the graph gets undone by the next load, so a real fix means fixing the source record too, which takes longer than a delete. We would rather tell you that than quietly re-import it. Bibliographic facts that are part of the public scholarly record, such as the authorship of a published paper, we will generally keep; that is the one case where we may decline, and we will say so plainly.
We use one cookie. It holds a signed session token, it is set only after you sign in, it is HttpOnly so page scripts cannot read it, and it expires after 30 days. It is strictly necessary to provide a service you asked for, which is why there is no consent banner in your way.
Cloudflare Turnstile may set a short-lived token when a bot check runs. It is there to tell a browser from a script, and it is not an advertising or profiling technology.
We store no analytics cookies, no advertising cookies and no third-party cookies. Our telemetry is recorded server-side, which is why it can be honest about IP addresses rather than hiding behind a tag manager.
We use a small number of providers, each under a data processing agreement that limits them to acting on our instructions. This is the whole list.
| Provider | What it does | Where |
|---|---|---|
| Cloudflare, Inc. | Serves the site, stores account, token, waitlist and feedback records in Workers KV, runs Turnstile bot checks, and holds service telemetry. | Global edge; United States |
| Stripe, Inc. | Takes payment and holds card data. We never receive card numbers. Stripe is an independent controller for its own compliance purposes, under its own privacy policy. | United States |
| Amazon Web Services, Inc. | Runs the API backend and holds its request logs; Amazon Bedrock runs the language models behind conversational answers and generated text. | United States |
| Neo4j, Inc. (Aura) | Hosts the graph database, which holds the research corpus. | United States |
| Google LLC | Serves the web fonts our pages use. | Global |
Amazon Bedrock does not use prompts or responses to train its models, and our configuration does not opt into any such use. We will also disclose personal data where the law actually requires it — a valid legal process, or to establish or defend a legal claim — and, if we are ever bought or merged, to the acquirer, who would be bound by this policy until it tells you otherwise.
We are in the United States and so are our providers, so if you are in the EEA, the United Kingdom or Switzerland your personal data is transferred to the United States. We rely on the European Commission’s Standard Contractual Clauses, and the UK International Data Transfer Addendum, in our agreements with Cloudflare, Stripe, Amazon Web Services and Neo4j. Several of them are additionally certified under the EU–US Data Privacy Framework.
A copy of the transfer terms we rely on is available on request from privacy@syntology.ai.
| Data | Retention |
|---|---|
| Session cookie | 30 days from issue, then it expires on its own |
| Account usage ledger | 90 days, then it expires on its own |
| Account transfer codes | 10 minutes |
| Trial and subscription tokens | The life of the token — minutes for a trial, 7 or 30 days by tier |
| Rate-limit counters | 60 seconds to 24 hours depending on the limit, then they expire on their own |
| Service telemetry | Cloudflare’s retention for the analytics dataset, currently 92 days |
| Agent-demand log | Held in our backend logs while we work out what the corpus is missing; reviewed and pruned rather than kept indefinitely |
| Waitlist entries | Until you ask to be removed, or we retire the waitlist |
| Feedback and corrections | Until the report is resolved and long enough after to know the fix held |
| Billing records | As long as tax and accounting law requires, typically seven years |
| Reviewer-tool uploads and output | For as long as needed to deliver the review, and then deleted on request |
Where a retention period above is an expiry written into the system, it happens whether or not anyone remembers to do it. Where it is a judgement, you can force the issue by asking us to delete.
If you are in the EEA, the UK or Switzerland, you have the right to access your personal data, to have it corrected, to have it erased, to restrict or object to processing, to data portability, and to withdraw consent. You may also complain to your supervisory authority — in the UK, the Information Commissioner’s Office; in the EEA, the authority where you live or work — though we would rather you told us first.
If you are in California, you have the right to know what we collect and why, to access and delete it, to correct it, and to be free of discrimination for asking. We do not sell or share personal information as the CCPA defines those terms, so there is no opt-out to exercise, and we do not use or disclose sensitive personal information for purposes that require one. You may use an authorised agent.
If you are in Colorado, Virginia, Connecticut, Texas, Oregon, Montana or another state with a comprehensive privacy law, you have broadly the same rights of access, correction, deletion, portability and opt-out. Under the Colorado Privacy Act you may also appeal a refusal: if we decline a request, reply to our answer and a human will review it and respond within 45 days, and you may contact the Colorado Attorney General if you remain unsatisfied.
Everyone else gets the same rights anyway. We are not going to run two standards of behaviour based on where you happen to live.
Email privacy@syntology.ai and say what you want. We will acknowledge within 10 days and answer within 30 days, or 45 where the law allows longer and the request needs it — and we will tell you if it will take the longer period rather than letting the deadline pass. We may need to verify that a request about an account really comes from that account; for anything else, we will ask for the least we can get away with, and we do not create an account for you in order to answer you.
Traffic is served over HTTPS. Session cookies are signed, Secure, HttpOnly and SameSite=Lax. Every response carries X-Content-Type-Options, X-Frame-Options, a Referrer-Policy and a Permissions-Policy. Database access is split into separate reader and writer credentials so that a read path cannot write. Code harvested from public repositories is executed only inside a network-isolated, read-only, unprivileged container, never on a machine that holds credentials.
We do not yet serve a Content Security Policy, because the pages are generated with inline styles and scripts and a policy written carelessly around that would break the site rather than protect it. It is a known gap rather than an oversight, and it is on the list.
No system is perfectly secure. If you find a vulnerability, write to legal@syntology.ai; we will not pursue you for a good-faith report that does not exfiltrate other people’s data or degrade the service.
The service is not directed at children and is not designed for them. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, tell us and we will delete it.
Nothing here makes an automated decision with a legal or similarly significant effect on you. Rate limits and bot checks are automated, and they can turn a request away; if you think one has wrongly locked you out, email us and a person will look. Scores the service publishes about papers — novelty, verification level — are statements about documents and code, not about people.
If we change this policy materially we will update the date below and, for changes that reduce your rights or widen what we collect, tell account holders by email before it takes effect. The previous version stays available on request. We will not make a material change quietly and count on you not to read it.
Privacy requests and questions: privacy@syntology.ai.
Legal notices and security reports: legal@syntology.ai.
Everything else: media@syntology.ai.
Syntology LLC, Colorado, United States. A postal address is available on request and will be provided to any supervisory authority that asks for it.
See also our Terms of Service and our attribution and upstream licences page, which lists where the material in the graph came from.