Privacy Policy

ProfessorAI · Effective 2026-09-03

What ProfessorAI collects, why it exists, where it is stored, and how to get rid of it. Every claim on this page describes something the software actually does.

Draft notice: the operator name and contact address on this page are placeholders until the operator completes them.

1. Who we are

ProfessorAI is operated by [Operator legal name] (“we”, “us”). This policy describes what the service does with your information. It is written to match the software as it actually behaves, not as a general template. Anything on this page can be raised with us at [contact email].

2. What we collect

  • Account. Your email address and the name you enter when you sign up. If you sign in with Google or Apple, we receive the email address the provider releases and, when it supplies one, your name. We never see your password for those accounts.
  • Your studies. Everything you enter or generate across the eleven steps: your research question, brief, keywords, selected sources, notes, drafts, and the text the professor writes. This is stored so you can leave and come back.
  • Usage records. Which module ran, which model answered, how many tokens went in and out, and whether it succeeded. These records exist for cost accounting and abuse prevention. They do not contain your prompts or your text.
  • Credit records. What an action cost and what your balance is.
  • Session. A cookie that keeps you signed in.

3. What we do not collect

  • No tracking. There is no analytics service, no advertising pixel, and no third-party tracker anywhere in the application. The only cookies are the ones that keep you signed in.
  • No uploaded files. Word, PDF, and text documents you open are parsed inside your browser. The file itself never reaches our servers. Only the text extracted from it is sent, and only at the moment you run a step that needs it.
  • No payment data. There is no payment mechanism in the service yet, so there is nothing to collect.
  • No profiling. We do not build advertising profiles, and we do not sell, rent, or trade anything about you.

4. The AI provider

To answer you, we send the relevant part of your text to Anthropic, our AI provider, over its commercial API. Under Anthropic’s commercial terms, content sent through the API is not used to train its models.

We will not tell you that nothing is retained on the provider’s side. We have not purchased a zero-retention arrangement, and retention there is governed by the provider’s own terms rather than by us. If you are working with unpublished data that you are not permitted to disclose to a processor, do not paste it into the service.

5. Academic databases

When you run a literature search, expand a citation map, or check a reference list, the search terms and reference entries are sent to public scholarly services: OpenAlex, Crossref, OpenAIRE, DOAJ, PubMed, Europe PMC, DataCite, Unpaywall, Open Library, Google Books, and Project Gutenberg. These services receive the query. They do not receive your account, your identity, or the rest of your study.

6. Where your data is kept

Accounts and studies are stored in a Supabase database hosted in Frankfurt, in the European Union. The application itself is served by Vercel. Both act as our infrastructure providers and process data on our instructions.

7. How long we keep it

Studies stay until you delete them or delete your account. Usage and credit records are kept while the account exists, because they are the accounting trail for what the service cost. When you delete your account yourself, your profile, your studies, their contents, and your credit history are removed immediately. Usage totals stay for cost accounting with the link to you removed, so they can no longer be traced back to a person.

8. Deleting your account

You can delete your own account from the Account page inside the app. It asks you to type your email address to confirm, then removes the account and everything stored under it straight away. We do not ask for a reason and we do not try to talk you out of it.

Deletion cannot be undone and we cannot restore anything afterwards, so download whatever you want to keep first. If you cannot sign in, write to [contact email] from the address on your account and we will delete it for you within 30 days.

9. Your rights

Depending on where you live, you may have the right to ask for a copy of your data, to have it corrected, to have it deleted, to receive it in a portable form, or to object to how it is processed. Write to [contact email] from the address on your account and we will answer within thirty days. If you are in the European Union or the United Kingdom, you may also complain to your local data protection authority.

10. Age

ProfessorAI is built for researchers and students in higher education. It is not designed for children and we do not knowingly collect data from anyone under 16. If you believe a child has created an account, tell us and we will remove it.

11. Security

Every table is protected by row level security, so a signed-in account can read only its own rows; this is enforced by the database, not by the interface. Traffic is encrypted in transit. No system is perfect. If you find a weakness, write to [contact email] and we will treat it as a defect rather than as a complaint.

12. Changes to this policy

If this policy changes, the effective date at the top of the page changes with it. Where a change materially affects what happens to your data, we will publish it here before it takes effect.

Questions about this page: [contact email]