← Archipelago

Privacy

Draft — last updated 4 August 2026

Draft. This document is pending legal review, and the bracketed placeholders below are not yet filled in. The description of how the product handles data is accurate; the legal framing is not final.

Who we are

__PRODUCT_NAME__ is operated by __LEGAL_ENTITY__, and this policy is governed by the laws of __JURISDICTION__. You can reach us about anything on this page at __CONTACT_EMAIL__.

What we store

The content you create: your researches, the articles you save (including their full text and any PDF you upload), your notes, the images you upload, and the tags and titles you give them.

Your account: the email address you sign in with, your name, and the optional professional title you enter. There are no passwords — sign-in is by emailed link only.

How you use the product: the searches you run and their results, which results you opened, and a record of activity within your organizations. We also keep the signals a search was ranked on, so that ranking can be evaluated and improved.

Who else processes it

OpenAI — to make your library searchable and to surface connections, we send the text of what you save, the titles of your documents, the questions you ask, short excerpts from pairs of documents, and a temporary link to any image you upload. This powers search, the synthesised answer above your results, research takeaways, connection explanations, conflict detection, and the descriptions attached to images. Content sent through their API is not used to train their models.

Supabase — our database, authentication, and file storage, hosted in __DATA_REGION__.

Resend — delivers your sign-in and email-change messages.

Sentry — records technical errors so we can fix them. Error reports may incidentally include the page you were on.

Vercel and Railway — host the application itself.

Some processing deliberately stays on our own servers and is never sent to a third party: image search, the re-ranking of your search results, and the detection of names and organisations in your text.

Nothing is sold, and nothing is shared with advertisers.

How long we keep it

Your content stays until you delete it or close your account. Activity records and notifications are deleted automatically after 90 days.

Your search history and the record of which results you opened are kept for the life of the account rather than expiring on a timer, because they are both your own history and the only way to tell whether search is improving. They are deleted with your account.

What you can do

Export. Settings → Data & privacy → Download my data gives you a single JSON file of your researches, articles, notes, and search history. Note that uploaded images and PDFs are not currently part of that file — you can download them from the app individually.

Delete. Settings → Account → Danger zone deletes your account, your personal organization, and every research, article, note, and image in it. If you are the last owner of a shared organization that still has other members, we will ask you to transfer ownership or delete that organization first. Uploaded files are removed by a clean-up process that runs nightly, so they may persist in storage for up to a day after the account is gone.

Depending on where you live you may also have the right to correct your data, object to processing, or complain to a supervisory authority. Write to __CONTACT_EMAIL__.

Organizations

Content saved into a shared organization is visible to every member of that organization. Your personal organization is yours alone. Your search history is always private to you — other members of an organization cannot see what you searched for, including its owners.

Cookies

We use cookies only to keep you signed in, to remember which organization you are working in, and to remember your light or dark theme preference. There is no advertising or analytics tracking.

Changes

If this policy changes materially we will say so in the product before the change takes effect.