Scholar Sidekick is designed to be safe by default. We minimise data collection, avoid long-term storage, and aim to be transparent about how requests are handled.
This page explains what information is processed, why, and how it is handled.
When you use Scholar Sidekick, you may provide identifiers or references such as:
How this data is used:
Like most web services, we temporarily process limited technical metadata, such as:
Purpose:
Retention:
Accounts are optional. The tools on this site, the browser extensions, and the free tier of the API all work without one. If you choose to create an account, we process:
Account records are held in a Postgres database provided by Neon; API-key records are held in Vercel KV. Both are kept for as long as your account exists. You can revoke any key yourself at any time from your account page, and you can ask us to delete your account and everything attached to it - see Your choices and rights below.
If you hold an account we may send you email that is necessary to operate it: a sign-in link when you ask for one, confirmation that an API key was issued or revoked, security notices, and advance warning of changes that would break your integration or of significant service disruption. These are part of providing the service you signed up for, and by default they are the only email we send you.
We do not send marketing or promotional email unless you have separately opted in to it. Where we offer such an opt-in it is a distinct choice you make yourself - never a pre-ticked box, and never a condition of holding an account. Every non-essential message carries an unsubscribe link that we act on promptly, and you can opt out at any time by emailing us. We identify ourselves in every message we send, and we never sell, rent, or share your email address.
Email is delivered on our behalf by Resend, which processes the recipient address and the message itself solely in order to deliver it.
Our official browser extensions for Chrome, Firefox, and Edge transmit user-selected text to our citation-formatting API to produce a formatted citation. The data flow is the same as the public API:
Scholar Sidekick is available as a ChatGPT app (built on the OpenAI Apps SDK) that connects to a public, no-authentication endpoint. When you use it inside ChatGPT, the data flow is the same as the public API - the identifiers or citation details you ask about are processed in memory to produce the result and are not retained as application data after the request completes.
openai/subject) with each request. We use it only as an ephemeral rate-limit key to apply fair-use limits. It is not stored, not logged alongside citation content, and not linked to any account or profile.Scholar Sidekick does not use:
We may use limited, non-identifying first-party and platform telemetry mechanisms for reliability, aggregate performance, and anonymous feature-usage measurement - for example, how often a tool is used or whether an action such as an audit completes, never the content you enter. These are not used for advertising or behavioural profiling.
If you sign in, we set a strictly-necessary first-party session cookie so that you stay signed in. It has no advertising or tracking function and is cleared when you sign out. If you buy an evidence report, your browser also keeps a Stripe checkout-session identifier locally so the purchase can be re-confirmed.
We record server-side usage events - which surface and tool were used, whether the request succeeded, and how long it took - to understand aggregate demand and reliability. These events never contain bibliography content, reference text, identifiers, email addresses, or full referring URLs. Where a request is authenticated they carry your account identifier; otherwise they carry only a short irreversible hash derived from the API key or the IP address of the request, which lets us tell callers apart without identifying anyone.
The optional evidence-report purchase on the bibliography audit tool is processed by Stripe on Stripe-hosted checkout pages; card details are entered with Stripe and never touch this site. We store no payment information - your browser keeps only a Stripe checkout-session identifier, used to re-confirm the purchase with Stripe. Your bibliography is never shared with Stripe.
To resolve bibliographic metadata, Scholar Sidekick may query external public services, such as:
What is shared:
What is not shared:
Hosting & telemetry services used:
Each third-party service is subject to its own privacy policies.
Scholar Sidekick does not:
Scholar Sidekick is available globally. Operational infrastructure is provided by Vercel Inc., based in the United States, with content delivered via a global edge network; error monitoring is provided by Sentry. Citation requests may be processed in any of these jurisdictions. The data handling principles described here apply regardless of where a request is processed.
Scholar Sidekick aims to handle personal data consistently with applicable data protection laws, including the EU General Data Protection Regulation (GDPR) and UK GDPR, for users in those jurisdictions, and the Australian Privacy Principles. The volume of personal data processed is intentionally minimal: for anonymous use there is none beyond transient technical metadata, and for account holders it is limited to the account and API-key records described above. We keep no long-term record of the citations anyone looks up.
Account and API-key data is stored with providers that may process it outside your country, including in the United States. Where we send you email, it is delivered by Resend on our behalf.
If you use Scholar Sidekick without an account, we hold no personal records about you, so there is typically nothing to access, correct, or delete.
If you hold an account, you can ask us to:
You can revoke individual API keys yourself at any time from your account page. For anything else - including deleting your account - email us and we will respond within 30 days. Depending on where you live you may also have the right to complain to a data protection authority: in Australia the Office of the Australian Information Commissioner, and in the EU or UK your national supervisory authority.
If you have questions about this policy or about how operational metadata is handled, you can contact:
Email: privacy@scholar-sidekick.com.
If this policy changes, the updated version will be posted on this page with a revised “Last updated” date.