Last updated: September 18, 2026
1. Scope
This policy explains what ResearchViz ("we," "our," or "us") collects, why, who else sees it, and how long we keep it. It covers the ResearchViz website and application.
It applies to account holders and, in the limited way described in Section 6, to people who open a shared diagram without an account. What you are permitted to do with the Service is governed separately by our Terms and Conditions.
2. What we collect
2.1 Information you give us
- Account details — your name, email address, and either a password (stored only as a one-way hash) or a Google account identifier if you sign in with Google. A profile picture where your sign-in provider supplies one.
- Content you submit — research papers and other documents you upload, prompts and text you type, diagrams you create or edit, comments you write, and the outputs generated from them.
- Billing details — handled by Stripe. We store your Stripe customer reference, your plan, your credit balance and your invoice history. We never receive or store your full card number.
- Correspondence — feedback, support requests and anything you send us directly.
2.2 Information collected automatically
- Usage records — which features you ran, when, and what they cost in credits. This is what your usage history and our billing records are built from.
- Technical data — your IP address, browser and device type, and request timestamps. IP addresses are used transiently for rate limiting, abuse prevention and security logging.
- Site analytics — first-party page-view and referrer records for our public pages, used to understand which content brings people to the product. These are collected by us and are not sold or shared with an advertising network.
2.3 Information about other people that you give us
When you invite someone to a diagram, you give us their email address so we can deliver the invitation. You are responsible for having a proper basis to share that address with us, and for the warranties in Section 10.3 of the Terms.
3. How we use it
- To provide the Service: running generations, storing your work, and showing it back to you.
- To operate accounts, authentication, and email verification.
- To take payment, allocate credits, and produce invoices.
- To send transactional email you need — verification, password resets, invitations, access changes, and billing notices.
- To keep the Service safe: rate limiting, spam and abuse prevention, and investigating misuse.
- To fix problems and improve the product, including reviewing failed generations so we can correct them.
- To meet legal, tax and accounting obligations.
We do not sell your personal information, and we do not use the content you upload to target advertising at you.
4. AI processing of your content
Features that generate or refine content send the relevant material — your prompt, and where applicable the document or diagram it applies to — to third-party AI model providers through OpenRouter. This transmission is what makes the feature work; it cannot be switched off for a feature while still using it.
We do not train our own models on your content. We do not control the internal practices of the underlying model providers, and their handling of a request is governed by their own terms. If a document is subject to confidentiality, embargo, or an institutional data policy that prohibits sending it to an external processor, do not submit it to an AI feature.
We retain the prompt and the generated output on your account so that your history and version records work, and so that support and administrators can investigate a generation that failed or produced an unexpected result.
5. Who else receives data
We share data with service providers who process it on our behalf, under contract, for the purposes below. We also share it where we are legally required to, or where it is necessary to investigate abuse or protect the Service and its users.
- Stripe — Payments and subscriptions. Card details go to Stripe directly and are never stored on our servers.
- OpenRouter — Routes AI generation requests to the underlying model providers. Receives the prompt and source content for the action you ran.
- Amazon Web Services — File storage for uploads and generated outputs, and application hosting.
- Resend — Sends transactional email — verification, password resets, diagram invitations and notifications.
- Google reCAPTCHA — Distinguishes human users from automated abuse on public forms.
Stock imagery is fetched from Unsplash, Pexels, Pixabay and Picsum when you browse or insert an image. Those requests are proxied through our servers, so those providers do not receive your IP address.
If ResearchViz is ever acquired or merged, account data may transfer to the acquiring entity. We will say so before that happens.
6. Shared diagrams and collaboration
Sharing a diagram makes data about you visible to the other people in it. Specifically:
- To an owner, we show the name, email address, avatar and role of everyone with access to their diagram, and the email address of anyone they have invited but who has not yet accepted.
- To collaborators, we show the names and avatars of the other people currently viewing the diagram, who is editing, who last edited it, and the author of each comment and saved version.
- Invited people without an account — we store the email address the invitation was sent to, and a hashed invitation token, until the invitation is accepted, revoked, or expires after 14 days. Where an invitation page shows the address it was sent to, it is masked.
- Visitors who open a share link without signing in — we process a temporary session identifier, any display name they choose to enter (shown to others in the diagram), and their IP address for rate limiting and abuse prevention. We do not create an account for them and do not use link visits to build a marketing profile. Presence records are short-lived and expire automatically.
A diagram's owner controls this. They can remove a collaborator, revoke an invitation, or disable a share link at any time, and deleting a diagram deletes its comments, version history and access records with it. The mechanics are set out in Section 10 of the Terms.
Ownership of a diagram can be transferred to a collaborator. When that happens, the new owner gains the visibility described above over everyone with access, including you.
7. Cookies and similar technologies
We use a small number of cookies, all first-party:
- Session cookie — keeps you signed in. Strictly necessary; the Service cannot work without it.
- Guest session cookie — lets you try an analysis before registering.
- Attribution cookie — records which page brought you to the site, so a later signup can be credited to it. Used for our own reporting only.
Your browser's local storage also holds interface preferences, such as your chosen view and sort order. These never leave your device.
Google reCAPTCHA sets its own cookies on pages where it runs. That is governed by Google's privacy policy, linked in Section 5.
8. How long we keep it
- Account data and your content — for as long as your account is open.
- Deleted content — deleting a diagram, project or analysis removes it and its version history from the live Service. Residual copies may persist in encrypted backups for a limited period before being overwritten.
- Invitations — until accepted, revoked, or 14 days have passed.
- Presence records — minutes; they expire automatically once you stop viewing.
- Billing and invoice records — retained after account closure where tax and accounting law requires it.
9. Your rights and choices
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to complain to a data protection authority. You can:
- view and correct your name, email and profile from your account settings;
- delete individual diagrams, projects and analyses at any time from the app;
- unsubscribe from non-essential email using the link in any such message. Transactional email about your account, billing and access cannot be switched off while your account is open; and
- request account deletion, a copy of your data, or correction of anything you cannot change yourself by writing to support@researchviz.io.
One limit worth stating plainly: deleting your account does not retract a diagram from somebody you transferred ownership to, and it does not recall anything a collaborator has already exported or copied.
10. Security
Data is encrypted in transit. Passwords are stored as one-way hashes and are never retrievable, by us or anyone else. Access to a diagram is checked on every request against the grants its owner has made, rather than being inferred from the link you arrived by. Share-link and invitation tokens are long random values, and invitation tokens are stored hashed.
No system is perfectly secure. If a breach affects your data we will tell you and any relevant authority as required by law.
11. International transfers
Our service providers operate in several countries, including the United States, so your data may be processed outside the country you live in. Where required, we rely on appropriate safeguards such as standard contractual clauses.
12. Children
The Service is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has given us personal information, contact us and we will delete it.
13. Changes to this policy
We may update this policy as the Service changes. The date at the top always reflects the current version, and material changes will be communicated in the app or by email.
14. Contact us
For any privacy question, or to exercise any of the rights in Section 9, contact us at support@researchviz.io.