Privacy policy
Last updated
Who we are
AgingResearch.News is run by Paperfoot AI Pte. Ltd., a company incorporated in Singapore (“we”, “us”). We are responsible for the personal data described here.
Your account
- When you join, we store your name, your email address and your password, which is kept only as a one-way hash.
- In your account you choose the topics you follow, describe your research interests in your own words, and turn the weekly email on or off.
- We store the papers you save and upvote.
- Each sign-in session records the IP address and browser it began on, to keep the account secure. A session stops working after 60 days without a visit.
Page views
We count page views with our own system, without cookies. For each view we record:
- the page’s address, without its query string;
- the site that sent you, as a host name such as x.com;
- the utm_source, utm_medium and utm_campaign tags in the link you followed;
- your country, worked out by our host from your IP address;
- your type of device (phone, tablet or desktop) and the name of your browser;
- a visitor code: a one-way hash of the date, your IP address, your browser’s user agent and a secret key. It changes every day, so it counts you once a day but cannot follow you from one day to the next.
We never store your IP address or your full user agent with a page view. If you are signed in, the view is also linked to your account.
What you read
To rank papers and learn which ones readers find worth their time, we record what you do with them:
- saves and upvotes, and when you undo them;
- the stories you open;
- the links you follow to papers, with the list each link was in and its position.
When you are signed in, these records carry your account. When you are signed out, they carry only the random id in the arn_anon cookie.
Search
When you search, we record the words and filters you used, how many results came back, and which result you opened and where it sat, with the daily visitor code and, if you are signed in, your account. Your search words go to Google’s Gemini models to find papers by meaning. A search you follow is kept with your account until you unfollow it.
Your Plus feed
Plus ranks new papers against the research interests you describe. To score each match, your description and the paper go to TypeSafe, and we keep the scores to build your feed.
Ask
When you ask a question, we keep it with its answer, the papers cited and whether you marked the answer useful, and use them to improve how Ask finds papers and writes answers. Your question and the last few turns of the conversation go to Google’s Gemini models to find matching papers and write the answer, and to TypeSafe to rank the papers by how directly they answer it.
Delete a conversation at any time and its questions and answers are deleted with it. We keep a count of the questions you ask each day, without their text, to apply the daily allowance.
Plus payments
Plus is sold through Stripe. You pay on Stripe’s checkout page and manage or cancel the subscription in Stripe’s billing portal, so we never see or store your card details. Stripe tells us your customer and subscription ids, your plan, its status and when the current period ends, and we keep those with your account. Stripe handles payment data under its privacy policy.
We send email through Amazon SES:
- a welcome email when you join;
- a link to reset your password when you ask for one, which expires after an hour;
- the weekly email, on Mondays, with the week’s most important papers. It is on unless you untick it when you join. Every weekly email has an unsubscribe link, mail apps that offer one-click unsubscribe can stop it directly, and you can turn it off in your account.
API keys
For each key you create for the data API, we store its name, its first few characters and a one-way hash of it, never the key itself, with when it was created, last used and revoked. We count each key’s requests per minute and per day to apply the limits, and keep the daily counts as your usage history.
Research datasets
Every day we archive the previous day’s records to Amazon S3: the papers we read, our judgements and stories, the record of each decision our models make, and the reading records described above. We keep the archive indefinitely and use it to study how readers use the site, and to train and evaluate the models that judge, rank and write about papers.
In the archive your account id is replaced by a pseudonymous code made with a secret key, and no name, email address or IP address is included. The research interests you write for Plus are part of the scoring records, so they are archived under that code. Page views, searches and Ask conversations are not archived.
Who processes data for us
These companies process personal data for us, only to provide their service:
- Vercel hosts the site and runs its code. It handles every request, including your IP address.
- Neon runs our database.
- Amazon Web Services sends our email (Amazon SES) and stores the research archive (Amazon S3).
- Stripe takes payments and runs the billing portal.
- Google writes stories and news briefs with its Gemini models, and receives Ask questions and search words to find papers and write answers.
- TypeSafe scores papers and checks stories with its JEV models, and receives Plus research interests and Ask questions to rank papers.
We don’t sell personal data or share it with advertisers. We disclose it to anyone else only when the law requires it, or to a buyer of the business, and we would tell you before a sale.
Legal bases
Where UK or EU data protection law applies, we rely on:
- contract, to run your account, followed searches, Plus, Ask and API keys, and to send the welcome and password emails;
- legitimate interests, to keep the service secure, count visits, rank papers from what readers do, improve search and Ask, build the research archive and train our models, and send account holders the weekly email. You can object to any of these;
- legal obligation, to keep billing records.
We also handle personal data in line with Singapore’s Personal Data Protection Act 2012.
How long we keep it
- Your account and settings: until you close the account.
- Saves, upvotes, followed searches and Ask conversations: until you remove them or close the account.
- API keys, including revoked ones, and their daily usage: until you close the account.
- The scores and scoring records made from your Plus research interests: until you close the account.
- Sign-in sessions, with their IP address and browser: until you sign out or close the account. A session stops working after 60 days without a visit.
- Password reset links: they stop working after an hour.
- Page views, reading records and searches: indefinitely, to measure the site and improve rankings and search over time. Those linked to your account are deleted with it.
- The research archive: indefinitely, under the pseudonymous code.
- Billing records: as long as tax law requires. Stripe keeps its own.
Your rights
Depending on where you live, you can ask for a copy of your data, have it corrected or deleted, restrict or object to how we use it, or take it elsewhere. Change your topics, interests and weekly email in your account. For anything else, write to hello@agingresearch.news from the email address on your account. We reply within 30 days.
Deleting your account removes your profile, sessions, saves, upvotes, followed searches, Ask conversations and API keys, and the page views, reading records, searches and Plus scoring records linked to it. If you have Plus, we cancel it. Records already in the research archive stay under their pseudonymous code, with no link to your name or email address.
If you think we have mishandled your data, tell us first. You can also complain to the data protection authority where you live, such as the PDPC in Singapore or the ICO in the UK.
International transfers
We are based in Singapore. The site, its database and the research archive run in the United States, as do Google, TypeSafe and Stripe, and email is sent from the United Kingdom, so your data is handled outside your own country. Where the law requires it, these transfers rely on our providers’ data processing terms, including standard contractual clauses.
Security
Connections to the site are encrypted. Passwords and API keys are stored only as one-way hashes, and card details stay with Stripe. Access to our data is limited to the people who run the service.
Children
Accounts are for people aged 16 and over. If you think a child has given us personal data, write to us and we will delete it.
Changes
When this policy changes, so does the date at the top. We email account holders before a significant change takes effect.
Contact
Paperfoot AI Pte. Ltd., Singapore
hello@agingresearch.news