Privacy Policy
Last updated: April 5, 2026
This policy describes how aipr.pub ("the Service") collects, uses, and protects your information.
1. What We Collect
| Data | When |
|---|---|
| Email address | Account registration or Google sign-in |
| Name | Account registration or Google sign-in |
| Payment info | Checkout (processed by Stripe, we never see card numbers) |
| Uploaded PDFs/DOCX | Paper submission for review |
| Review pass key | Stored in your browser (localStorage + cookie) |
| IP address, browser info | Every request (standard server logs) |
2. How We Use It
- Uploaded documents: Sent to OpenAI for review generation, then stored so you can view the review later. Documents from anonymous users are deleted after 7 days if unclaimed.
- Email: Account login, review-ready notifications, password reset. We do not sell your email or send marketing without consent.
- Payment: Processed entirely by Stripe. We store pass/credit records but never card details.
- Server logs: Used for debugging and abuse prevention. Retained for 30 days.
3. Third-Party Services
- OpenAI: Submitted papers are sent to OpenAI's API for review generation. See OpenAI's privacy policy. API inputs are not used for model training per OpenAI's data usage policy.
- Stripe: Payment processing. See Stripe's privacy policy.
- DigitalOcean: Hosting and storage infrastructure.
4. Data Retention
- Anonymous uploads: Stored for 7 days, then automatically deleted.
- Account data: Retained while your account is active. Delete your account to remove your data.
- Reviews: Retained indefinitely as part of the Service. Public leaderboard reviews are visible to all users.
5. Your Rights
- Access: Request a copy of your data by emailing us.
- Deletion: Request account deletion. We will remove your account and personal data within 30 days.
- Correction: Update your account information through settings.
6. Cookies
We use two cookies:
- buyer_session: Links your browser to your review pass. HttpOnly, Secure, SameSite=Lax.
- user_session: Authenticates logged-in users. HttpOnly, Secure, SameSite=Lax.
We do not use tracking cookies, analytics cookies, or third-party advertising cookies.
7. Security
Passwords are hashed with bcrypt. Sessions use HMAC-signed tokens. All connections use HTTPS. We follow standard security practices but cannot guarantee absolute security.
8. Changes
We may update this policy. Material changes will be posted here with an updated date.
9. Contact
Privacy questions: [email protected]