Privacy Policy
This version is published for information and may change after legal review.
Summary in plain words
We collect what we need to run your account, take payment, write your documents and keep the platform safe. We do not sell your personal data. You can ask to see, correct or delete your data.
Data controller: [Company legal name], [address], Nigeria. Contact: [privacy email]. Data Protection Officer or contact: [name, email, if required]. This policy is written to align with the Nigeria Data Protection Act 2023 and related Nigeria Data Protection Commission guidance.
1. Data we collect
- Account data (from you): name, email, password (stored hashed), Google profile details if you use Google sign-in, verification status.
- Phone data (from you): phone number and SMS verification codes (for groups).
- Your Content (from you): search topics, project briefs, notes, uploaded files (PDF, Word, PowerPoint, TXT, Markdown, CSV, Excel, images), instructions, feedback and photos given for corrections.
- Output (generated): documents, summaries, slides, versions and exports generated for you.
- Usage data (automatic): features used, coin ledger, actions, errors, storage used, monthly upload counts, signed-in devices.
- Payment data (from you and the processor): order details, amounts, payment status, processor references. Card details are handled by the payment processor, not stored by us.
- Group and referral data (from you and automatic): group membership, Seat ID status, referral code, referrals, wallet balance and history.
- Security and fraud signals (automatic): device and browser details, network address, card checks, signals used to detect shared devices, networks or cards in groups and referrals.
- Support data (from you): chat and ticket messages, attachments, contact details.
- Cookies and similar (automatic): session and sign-in cookies, theme preference, "Keep me signed in".
2. How and why we use data
- Provide the service (accounts, research, writing, editing, exports): contract.
- Take payment and keep records: contract and legal obligation.
- Verify identity and protect accounts: legitimate interest and contract.
- Prevent fraud, abuse and fake groups or referrals: legitimate interest.
- Provide support and improve help: contract and legitimate interest.
- Send service messages (verification, reset, receipts, coin expiry warnings): contract.
- Send marketing: consent, which you may withdraw at any time.
- Improve and secure the service: legitimate interest.
- Comply with law: legal obligation.
Lawful bases are to be confirmed with a lawyer. We do not make decisions that have legal or similarly significant effects on you solely by automated means. Group review decisions involve human review, and you may contest them through support.
3. Artificial intelligence and your content
- To generate output, Your Content and relevant source text are sent to AI service providers who process it for us.
- Provider names and their handling terms: [list providers and confirm whether your content is used to train their models].
- We design writing to use only papers actually retrieved, with citations checked against them, and not to invent your details. AI output can still be wrong, so you must verify it.
- Uploaded files are private, streamed only to their owner, and counted as sources. We do not publish Your Content.
4. Academic search
When you search, your topic and filters are sent to academic sources (such as OpenAlex, Semantic Scholar and Unpaywall) to find papers. Those services receive the query and are subject to their own policies.
5. Who we share data with
Only as needed to provide the service, and under contracts that require appropriate protection:
- Hosting and file storage providers (for example Vercel and its storage service).
- AI model providers (section 3).
- Payment processors (Paystack, Flutterwave).
- SMS provider (for group verification, for example Termii) and email provider (for verification and reset messages, for example Resend).
- Google, if you sign in with Google.
- Academic data sources (section 4).
- Professional advisers, regulators, courts and law enforcement where the law requires, or to protect rights and safety.
- A buyer or successor, if our business is sold, with notice to you.
We do not sell your personal data.
6. International transfers
Some providers are located outside Nigeria. Where we transfer personal data abroad, we do so in line with the Nigeria Data Protection Act, using safeguards such as adequacy, contractual protections or your consent where required [confirm mechanisms with your lawyer].
7. Retention
- Exports: 7 days.
- Uploads and projects: while your account is active. Uploads from lapsed accounts are deleted after warning [state the period].
- Account data: while the account exists, and then up to [period] for legal and fraud reasons.
- Payment and order records: at least [period required by Nigerian tax and accounting law].
- Coin ledger: while the account exists, and then as required for audit and disputes.
- Consent records: for as long as needed to prove consent.
- Chat and support records: [12 months suggested], then deleted or anonymised.
- Fraud and group-review signals: [period, kept no longer than necessary].
A nightly process handles plan lapses, retention warnings, deletion of uploads from lapsed accounts, referral crediting and coin expiry.
8. Your rights
Under Nigerian law you may have the right to: be informed, access your data, correct it, delete it, restrict or object to processing, receive your data in a portable format, withdraw consent, and not be subject to solely automated decisions with significant effects. To use these rights, contact [privacy email]. We will respond within the period required by law, and we may need to verify your identity. You may also complain to the Nigeria Data Protection Commission.
Account deletion: you can request deletion from the Account page or by contacting us. We delete or anonymise your data, except records we must keep (for example payment records, consent records and fraud-prevention records).
9. Security
We use measures such as encrypted connections, hashed passwords, private file access limited to the owner, device limits, "Sign out of all devices", email confirmation before purchases after a global sign-out, access controls and audit logs for administrators, and fraud checks. No system is perfectly secure. If a breach affects your data, we will notify you and the Commission as required by law.
10. Children
The service is for people aged 18 or over. We do not knowingly collect data from children. If we learn that we have, we will delete it.
11. Cookies and similar technologies
We use essential cookies and local storage for sign-in, security and preferences such as theme and "Keep me signed in". We do not use advertising cookies.
12. Changes to this policy
We will post updates here with a new version and date, and notify you of material changes. Where consent is required, we will ask again.
13. Contact
[Company legal name], [address], [privacy email], [phone, optional].
Change log
1.0: first version (awaiting legal review).