Privacy Policy
Last updated: 8 July 2026
This policy explains what personal data ScholarThread collects when you use the web app, mobile apps, and api, why we collect it, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR) and equivalent legislation.
1. Who we are
ScholarThread is operated by MOYD LTD, based in the United Kingdom. For any privacy-related question or to exercise the rights described in section 7, contact [email protected].
2. What we collect
We collect four categories of data:
- Account data — handled by our authentication provider, Clerk: your email address, display name, profile photo (if you set one), and identifiers from any single-sign-on providers you choose to connect (e.g. Google, Microsoft, Apple).
- Study data — the documents, notes, concept links, and chat threads you create or import into ScholarThread. This is the content that makes the product useful to you.
- Operational data — server access logs (IP address, request path, timestamp, user-agent) retained for a short window for security and debugging, plus the session token issued by Clerk and stored as a cookie. Application errors (stack traces, browser + device metadata, session identifiers) are forwarded to our error-monitoring provider (Sentry) with obvious personal fields — email addresses, bearer tokens, JWTs — scrubbed before transmission.
- Analytics data— when you consent, we use Google Analytics 4 to collect aggregate usage statistics (pageviews, session duration, referrer, coarse geolocation derived from IP). If you decline, or if you are located in a region that requires opt-in consent under GDPR or ePrivacy rules and have not yet chosen, Google Analytics loads in “Consent Mode” and only emits cookieless, non-identifying aggregate signals until you consent.
On the anonymous and Free tiers, ScholarThread also displays advertising served by Google AdSense. Ads are removed entirely on the Pro tier. Personalised ads require your consent; without it, only contextual (non-personalised) ads are served, and AdSense stores no personal advertising identifiers on your device.
3. Why we collect it (lawful basis)
- Account data — necessary to perform the contract: we cannot sign you in without it (GDPR Art. 6(1)(b)).
- Study data — necessary to provide the service you signed up for (Art. 6(1)(b)).
- Operational data — legitimate interest in keeping the service running, secure, and abuse-free (Art. 6(1)(f)).
- Analytics + advertising data — consent (Art. 6(1)(a)), managed through a consent banner that you can accept, reject, or revisit at any time.
4. Who we share it with
ScholarThread relies on a small set of processors. We share personal data with them only to the extent each one needs to do its job, under a Data Processing Agreement or equivalent:
- Clerk, Inc. — authentication, user profile, session management. Clerk processes account data and may transfer it to the United States under the EU-US Data Privacy Framework.
- Amazon Web Services, Inc. (AWS)— the cloud infrastructure that hosts ScholarThread. Compute (Amazon EKS), paper and attachment storage (Amazon S3), the graph database that holds your study data (Neo4j), the background-job queue (Amazon ElastiCache for Valkey), and encryption keys (AWS KMS) all live in AWS's eu-north-1region (Stockholm). Operational data passes through AWS's networks.
- Stripe, Inc.— subscription payment processing on the Pro tier. Payment card details never touch ScholarThread's servers; Stripe processes them directly. Billing metadata (plan, status, invoice history) is exchanged with Stripe via Clerk Billing.
- Google LLC — analytics (Google Analytics 4), advertising (Google AdSense on web / AdMob on mobile), and consent management (Google Funding Choices). Loading of these services is gated on your consent, per section 2.
- Functional Software, Inc. (Sentry)— error and performance monitoring. Sentry receives scrubbed error events (see “Operational data” in section 2). Our Sentry project uses the EU ingestion region (Germany).
- New Relic, Inc. — backend application-performance and infrastructure monitoring (APM). New Relic receives operational telemetry from our servers: request and background-task timings, database and external-service call metrics (query text obfuscated), error traces, and Kubernetes host/container health. It is not used to collect personal data, and our New Relic account uses the EU data region.
- PagerDuty, Inc. — support-ticket intake. When you submit the contact form on /support, the message body, subject, contact email, and IP address are sent to PagerDuty as an incident so our on-call engineer can reply.
- Zotero (Corporation for Digital Scholarship) — only if you choose to connect your Zotero library. ScholarThread exchanges OAuth tokens with Zotero to read (and, if you grant it, write) items in the collections you nominate. The Zotero API key is stored envelope-encrypted (AWS KMS) in our database.
- OurResearch (OpenAlex) — only if you provide an OpenAlex identifier. ScholarThread includes your email in the polite-pool
mailtoparameter on outgoing OpenAlex requests, per OpenAlex's recommended usage.
We do not sell personal data. We do not share personal data with data brokers.
5. Where data is stored
Study data, paper attachments, and background-job state are stored on infrastructure we operate in AWS eu-north-1 (Stockholm). Account data is stored by Clerk; see Clerk's own privacy policy for details on their storage regions and transfer mechanisms. Error events are stored by Sentry in the EU (Germany). Support tickets and their contents are stored by PagerDuty. Payment data is stored by Stripe. Analytics and advertising data is stored by Google in the region determined by their published terms.
6. Retention
- Account data — retained while your account exists. Deleted within 30 days of account deletion.
- Study data — retained while your account exists. Deleted within 30 days of account deletion.
- Operational logs — retained for up to 30 days, then deleted.
- Error events (Sentry)— retained per Sentry's default project retention (currently 30 days for events, 90 days for issue metadata).
- Support tickets (PagerDuty)— retained per PagerDuty's account retention. You can request deletion of a specific ticket by writing to [email protected].
- Analytics data (Google Analytics) — user- and event-level data retained for 14 months, then automatically purged; aggregate reports are kept indefinitely.
7. Your rights
Under GDPR you have the right to:
- Access the personal data we hold about you (Art. 15).
- Correct inaccurate data (Art. 16).
- Delete your data (Art. 17) — you can also delete your account from your settings page, which triggers deletion automatically.
- Restrict or object to processing (Art. 18 and 21).
- Export your data in a portable format (Art. 20).
- Withdraw consent for analytics and advertising at any time via the consent banner (which can be re-opened from the footer of any page), without affecting the lawfulness of processing that took place before withdrawal.
- Lodge a complaint with a supervisory authority.
8. Cookies
ScholarThread sets three broad categories of cookies:
- Strictly necessary — the session cookie issued by Clerk so you stay signed in across page loads, and a small cookie set by Google Funding Choices to remember your consent choice. These do not require consent under EU ePrivacy rules.
- Analytics— set by Google Analytics 4 only after you consent. Records aggregate usage statistics. If you decline or haven't yet chosen, no analytics cookies are set.
- Advertising — set by Google AdSense on the anonymous and Free tiers only, and only after you consent to personalised advertising. Pro removes ads (and their cookies) entirely.
9. Children
ScholarThread is not directed at children under 16 and we do not knowingly collect personal data from them. Several aspects of the service make it unsuitable for younger users:
- Advertising is displayed on the anonymous and Free tiers via Google AdSense. Google's advertising policies restrict personalised advertising to users under 13 (COPPA) and require parental consent for users under 16 in most EU member states.
- Analytics via Google Analytics 4 relies on the visitor's consent under GDPR. Under GDPR Article 8, children under 16 (13 in some EU jurisdictions) cannot give valid consent to non-essential data processing without parental authorisation.
- Paid subscription (Pro) is a legal contract that a minor cannot validly enter into without a parent or guardian.
- Single-sign-on providers (Clerk, Google, Microsoft, Apple) each impose their own minimum-age requirements.
- Future AI-powered features (grounded Q&A, viva coaching) transmit the notes and passages you submit to third-party language-model providers, which we consider inappropriate content flow for children's data.
If you become aware that a child under 16 has signed up, please contact [email protected] and we will delete the account.
10. Changes to this policy
We'll update this page when material things change and update the "Last updated" date. Substantial changes (new processors, new data categories) will also be announced by email to active users before they take effect.