Privacy Policy
Last updated: 8 July 2026
This policy explains what personal data ScholarThread collects when you use the web app, mobile apps, and api, why we collect it, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR) and equivalent legislation.
1. Who we are
ScholarThread is operated by MOYD LTD, based in the United Kingdom. For any privacy-related question or to exercise the rights described in section 7, contact [email protected].
2. What we collect
We collect four categories of data:
- Account data — handled by our authentication provider, Clerk: your email address, display name, profile photo (if you set one), and identifiers from any single-sign-on providers you choose to connect (e.g. Google, Microsoft, Apple).
- Study data — the documents, notes, concept links, and chat threads you create or import into ScholarThread. This is the content that makes the product useful to you.
- Operational data — server access logs (IP address, request path, timestamp, user-agent) retained for a short window for security and debugging, plus the session token issued by Clerk and stored as a cookie. Application errors (stack traces, browser + device metadata, session identifiers) are forwarded to our error-monitoring provider (Sentry) with obvious personal fields — email addresses, bearer tokens, JWTs — scrubbed before transmission.
- Analytics data— when you consent, we use Google Analytics 4 to collect aggregate usage statistics (pageviews, session duration, referrer, coarse geolocation derived from IP). Until you accept, and permanently if you decline, Google Analytics runs in “Consent Mode” and emits only cookieless, non-identifying aggregate signals with nothing stored on your device.
ScholarThread does not display advertising on any tier, and we do not share your data with advertising networks.
3. Why we collect it (lawful basis)
- Account data — necessary to perform the contract: we cannot sign you in without it (GDPR Art. 6(1)(b)).
- Study data — necessary to provide the service you signed up for (Art. 6(1)(b)).
- Operational data — legitimate interest in keeping the service running, secure, and abuse-free (Art. 6(1)(f)).
- Analytics data — consent (Art. 6(1)(a)), collected through a banner you can accept, decline, or revisit at any time.
4. Who we share it with
ScholarThread relies on a small set of processors. We share personal data with them only to the extent each one needs to do its job, under a Data Processing Agreement or equivalent:
- Clerk, Inc. — authentication, user profile, session management. Clerk processes account data and may transfer it to the United States under the EU-US Data Privacy Framework.
- Amazon Web Services, Inc. (AWS)— the cloud infrastructure that hosts ScholarThread. Compute (Amazon EKS), paper and attachment storage (Amazon S3), the graph database that holds your study data (Neo4j), the background-job queue (Amazon ElastiCache for Valkey), and encryption keys (AWS KMS) all live in AWS's eu-north-1region (Stockholm). Operational data passes through AWS's networks.
- Stripe, Inc.— subscription payment processing on the Pro tier. Payment card details never touch ScholarThread's servers; Stripe processes them directly. Billing metadata (plan, status, invoice history) is exchanged with Stripe via Clerk Billing.
- Google LLC — analytics (Google Analytics 4). Loading of this service is gated on your consent, per section 2.
- Functional Software, Inc. (Sentry)— error and performance monitoring. Sentry receives scrubbed error events (see “Operational data” in section 2). Our Sentry project uses the EU ingestion region (Germany).
- New Relic, Inc. — backend application-performance and infrastructure monitoring (APM). New Relic receives operational telemetry from our servers: request and background-task timings, database and external-service call metrics (query text obfuscated), error traces, and Kubernetes host/container health. It is not used to collect personal data, and our New Relic account uses the EU data region.
- PagerDuty, Inc. — support-ticket intake. When you submit the contact form on /support, the message body, subject, contact email, and IP address are sent to PagerDuty as an incident so our on-call engineer can reply.
- Zotero (Corporation for Digital Scholarship) — only if you choose to connect your Zotero library. ScholarThread exchanges OAuth tokens with Zotero to read (and, if you grant it, write) items in the collections you nominate. The Zotero API key is stored envelope-encrypted (AWS KMS) in our database.
- OurResearch (OpenAlex) — only if you provide an OpenAlex identifier. ScholarThread includes your email in the polite-pool
mailtoparameter on outgoing OpenAlex requests, per OpenAlex's recommended usage.
We do not sell personal data. We do not share personal data with data brokers.
5. Where data is stored
Study data, paper attachments, and background-job state are stored on infrastructure we operate in AWS eu-north-1 (Stockholm). Account data is stored by Clerk; see Clerk's own privacy policy for details on their storage regions and transfer mechanisms. Error events are stored by Sentry in the EU (Germany). Support tickets and their contents are stored by PagerDuty. Payment data is stored by Stripe. Analytics data is stored by Google in the region determined by their published terms.
6. Retention
- Account data — retained while your account exists. Deleted within 30 days of account deletion.
- Study data — retained while your account exists. Deleted within 30 days of account deletion.
- Operational logs — retained for up to 30 days, then deleted.
- Error events (Sentry)— retained per Sentry's default project retention (currently 30 days for events, 90 days for issue metadata).
- Support tickets (PagerDuty)— retained per PagerDuty's account retention. You can request deletion of a specific ticket by writing to [email protected].
- Analytics data (Google Analytics) — user- and event-level data retained for 14 months, then automatically purged; aggregate reports are kept indefinitely.
7. Your rights
Under GDPR you have the right to:
- Access the personal data we hold about you (Art. 15).
- Correct inaccurate data (Art. 16).
- Delete your data (Art. 17) — you can also delete your account from your settings page, which triggers deletion automatically.
- Restrict or object to processing (Art. 18 and 21).
- Export your data in a portable format (Art. 20).
- Withdraw consent for analytics at any time — via “Cookie settings” in the footer of any public page, or under Settings → Privacy when signed in — without affecting the lawfulness of processing that took place before withdrawal.
- Lodge a complaint with a supervisory authority.
8. Cookies
ScholarThread sets two broad categories of cookies:
- Strictly necessary — the session cookie issued by Clerk so you stay signed in across page loads. These do not require consent under EU ePrivacy rules.
- Analytics— set by Google Analytics 4 only after you accept. Records aggregate usage statistics. If you decline or haven't yet chosen, GA4 stays in cookieless Consent Mode and no analytics cookies are set.
We set no advertising cookies and serve no ads on any tier. Your consent choice itself is stored in your browser's local storage rather than a cookie, so the consent mechanism sets nothing of its own.
9. Children
ScholarThread is not directed at children under 16 and we do not knowingly collect personal data from them. Several aspects of the service make it unsuitable for younger users:
- Analytics via Google Analytics 4 relies on the visitor's consent under GDPR. Under GDPR Article 8, children under 16 (13 in some EU jurisdictions) cannot give valid consent to non-essential data processing without parental authorisation.
- Paid subscription (Pro) is a legal contract that a minor cannot validly enter into without a parent or guardian.
- Single-sign-on providers (Clerk, Google, Microsoft, Apple) each impose their own minimum-age requirements.
- Future AI-powered features (grounded Q&A, viva coaching) transmit the notes and passages you submit to third-party language-model providers, which we consider inappropriate content flow for children's data.
If you become aware that a child under 16 has signed up, please contact [email protected] and we will delete the account.
10. Changes to this policy
We'll update this page when material things change and update the "Last updated" date. Substantial changes (new processors, new data categories) will also be announced by email to active users before they take effect.