AgingResearch.News

Privacy policy

Last updated

Who we are

AgingResearch.News is run by Paperfoot AI Pte. Ltd., a company incorporated in Singapore (“we”, “us”). We are responsible for the personal data described here.

Your account

  • When you join, we store your name, your email address and your password, which is kept only as a one-way hash.
  • In your account you choose the topics you follow, describe your research interests in your own words, and turn the weekly email on or off.
  • We store the papers you save and upvote.
  • Each sign-in session records the IP address and browser it began on, to keep the account secure. A session stops working after 60 days without a visit.

Cookies and browser storage

We use no advertising or third-party cookies.

  • __Secure-better-auth.session_token keeps you signed in. It is set when you sign in and lasts up to 60 days.
  • __Secure-better-auth.session_data holds a signed copy of your session for 5 minutes, so pages know you are signed in without looking you up each time.
  • arn_anon holds a random id, set when you open a story while signed out, so we can count which stories are read. It lasts a year. Block it in your browser and the site works the same.
  • In session storage, a random id groups one tab’s page views into a visit. It is deleted when the tab closes.
  • In local storage, the time of the newest entry you have seen on Updates, so the unread dot can show. It never leaves your browser.
  • In local storage, your recent searches, so the search box can offer them again. They never leave your browser.

Page views

We count page views with our own system, without cookies. For each view we record:

  • the page’s address, without its query string;
  • the site that sent you, as a host name such as x.com;
  • the utm_source, utm_medium and utm_campaign tags in the link you followed;
  • your country, worked out by our host from your IP address;
  • your type of device (phone, tablet or desktop) and the name of your browser;
  • a visitor code: a one-way hash of the date, your IP address, your browser’s user agent and a secret key. It changes every day, so it counts you once a day but cannot follow you from one day to the next.

We never store your IP address or your full user agent with a page view. If you are signed in, the view is also linked to your account.

What you read

To rank papers and learn which ones readers find worth their time, we record what you do with them:

  • saves and upvotes, and when you undo them;
  • the stories you open;
  • the links you follow to papers, with the list each link was in and its position.

When you are signed in, these records carry your account. When you are signed out, they carry only the random id in the arn_anon cookie.

Your Plus feed

Plus ranks new papers against the research interests you describe. To score each match, your description and the paper go to TypeSafe, and we keep the scores to build your feed.

Ask

When you ask a question, we keep it with its answer, the papers cited and whether you marked the answer useful, and use them to improve how Ask finds papers and writes answers. Your question and the last few turns of the conversation go to Google’s Gemini models to find matching papers and write the answer, and to TypeSafe to rank the papers by how directly they answer it.

Delete a conversation at any time and its questions and answers are deleted with it. We keep a count of the questions you ask each day, without their text, to apply the daily allowance.

Plus payments

Plus is sold through Stripe. You pay on Stripe’s checkout page and manage or cancel the subscription in Stripe’s billing portal, so we never see or store your card details. Stripe tells us your customer and subscription ids, your plan, its status and when the current period ends, and we keep those with your account. Stripe handles payment data under its privacy policy.

Email

We send email through Amazon SES:

  • a welcome email when you join;
  • a link to reset your password when you ask for one, which expires after an hour;
  • the weekly email, on Mondays, with the week’s most important papers. It is on unless you untick it when you join. Every weekly email has an unsubscribe link, mail apps that offer one-click unsubscribe can stop it directly, and you can turn it off in your account.

API keys

For each key you create for the data API, we store its name, its first few characters and a one-way hash of it, never the key itself, with when it was created, last used and revoked. We count each key’s requests per minute and per day to apply the limits, and keep the daily counts as your usage history.

Research datasets

Every day we archive the previous day’s records to Amazon S3: the papers we read, our judgements and stories, the record of each decision our models make, and the reading records described above. We keep the archive indefinitely and use it to study how readers use the site, and to train and evaluate the models that judge, rank and write about papers.

In the archive your account id is replaced by a pseudonymous code made with a secret key, and no name, email address or IP address is included. The research interests you write for Plus are part of the scoring records, so they are archived under that code. Page views, searches and Ask conversations are not archived.

Who processes data for us

These companies process personal data for us, only to provide their service:

  • Vercel hosts the site and runs its code. It handles every request, including your IP address.
  • Neon runs our database.
  • Amazon Web Services sends our email (Amazon SES) and stores the research archive (Amazon S3).
  • Stripe takes payments and runs the billing portal.
  • Google writes stories and news briefs with its Gemini models, and receives Ask questions and search words to find papers and write answers.
  • TypeSafe scores papers and checks stories with its JEV models, and receives Plus research interests and Ask questions to rank papers.

We don’t sell personal data or share it with advertisers. We disclose it to anyone else only when the law requires it, or to a buyer of the business, and we would tell you before a sale.

How long we keep it

  • Your account and settings: until you close the account.
  • Saves, upvotes, followed searches and Ask conversations: until you remove them or close the account.
  • API keys, including revoked ones, and their daily usage: until you close the account.
  • The scores and scoring records made from your Plus research interests: until you close the account.
  • Sign-in sessions, with their IP address and browser: until you sign out or close the account. A session stops working after 60 days without a visit.
  • Password reset links: they stop working after an hour.
  • Page views, reading records and searches: indefinitely, to measure the site and improve rankings and search over time. Those linked to your account are deleted with it.
  • The research archive: indefinitely, under the pseudonymous code.
  • Billing records: as long as tax law requires. Stripe keeps its own.

Your rights

Depending on where you live, you can ask for a copy of your data, have it corrected or deleted, restrict or object to how we use it, or take it elsewhere. Change your topics, interests and weekly email in your account. For anything else, write to hello@agingresearch.news from the email address on your account. We reply within 30 days.

Deleting your account removes your profile, sessions, saves, upvotes, followed searches, Ask conversations and API keys, and the page views, reading records, searches and Plus scoring records linked to it. If you have Plus, we cancel it. Records already in the research archive stay under their pseudonymous code, with no link to your name or email address.

If you think we have mishandled your data, tell us first. You can also complain to the data protection authority where you live, such as the PDPC in Singapore or the ICO in the UK.

International transfers

We are based in Singapore. The site, its database and the research archive run in the United States, as do Google, TypeSafe and Stripe, and email is sent from the United Kingdom, so your data is handled outside your own country. Where the law requires it, these transfers rely on our providers’ data processing terms, including standard contractual clauses.

Security

Connections to the site are encrypted. Passwords and API keys are stored only as one-way hashes, and card details stay with Stripe. Access to our data is limited to the people who run the service.

Children

Accounts are for people aged 16 and over. If you think a child has given us personal data, write to us and we will delete it.

Changes

When this policy changes, so does the date at the top. We email account holders before a significant change takes effect.

Contact

Paperfoot AI Pte. Ltd., Singapore
hello@agingresearch.news