Private beta. Novaralis is currently an invite-only beta, operated by its founder ahead of formal incorporation. It is not yet a registered company and collects no payments. A registered legal entity will be named in this document before public launch. Questions:
hello@novaralis.com.
1. Who We Are
Novaralis is a personalized research intelligence platform that helps students, clinicians, and researchers discover and organize scientific literature. References to "Novaralis," "we," "us," or "our" in this policy refer to the founder of Novaralis, who currently operates the platform as an individual pending incorporation. Our contact email is hello@novaralis.com.
2. Information We Collect
Account information. When you create an account, we collect your name, email address, and password. Passwords are hashed using industry-standard one-way hashing via Supabase Auth — we never store or see your plaintext password.
Profile information. You may optionally provide your institution, role, and research interests. This is used to personalize your research feed and digest.
Usage data. We collect information about how you use Novaralis, including searches, saved articles, projects you create, and in-app actions. This helps us improve the platform.
Feedback. If you submit feedback through the app, we store that message along with your account email.
Cookies and session data. We use essential session cookies to keep you logged in. These are set by Supabase Auth and are strictly necessary for the Service to function. We do not use advertising or tracking cookies. See Section 6 for more detail.
3. How We Use Your Information
- To provide, maintain, and improve the Novaralis platform
- To personalize your research feed, digest, and article recommendations
- To send transactional emails (account confirmation, password resets, weekly digest if opted in)
- To respond to your feedback and support requests
- To understand how the platform is used and where to improve it
- To detect and prevent fraud, abuse, and security incidents
- To comply with applicable laws and legal obligations
We do not sell your personal information to third parties. We do not use your data for advertising profiling.
4. Legal Bases for Processing (GDPR)
If you are located in the European Economic Area (EEA) or United Kingdom, our legal bases for processing your personal data are:
- Contract performance: Processing necessary to provide the Service you signed up for (account management, search, saved articles)
- Legitimate interests: Improving the platform, detecting fraud, ensuring security
- Consent: Sending the weekly email digest (you can withdraw consent by opting out in Settings at any time)
- Legal obligation: Complying with applicable laws
5. Cookies and Tracking
We use only the following cookies:
- Session cookies (Supabase Auth): Strictly necessary to authenticate your session. These are set when you log in and deleted when you log out or the session expires. Named
sb-[projectRef]-auth-token.
We do not use:
- Advertising or tracking cookies
- Third-party analytics cookies (e.g., Google Analytics)
- Social media tracking pixels
6. Third-Party Services We Use
To operate Novaralis, we share data with the following third-party service providers. These providers process data only as necessary to provide their services and are bound by their own privacy policies.
- Supabase (US) — authentication, database storage, and Edge Functions. Your account data and research content are stored here. Privacy policy
- Vercel (US) — platform hosting and deployment. Serves the web application. Privacy policy
- Resend (US) — transactional email delivery (account confirmation, password resets, weekly digest). Your email address is transmitted to Resend to deliver emails. Privacy policy
- Anthropic (US) — AI assistant powered by Claude. When you use the AI research assistant feature, the article abstracts you select and your research question are sent to Anthropic's API to generate a response. We do not send your name, email, or account details to Anthropic. Privacy policy
- PubMed / NCBI (US Government) — article search. Your search queries are sent directly from your browser to NCBI's public API.
- Europe PMC (UK/EU) — article search. Your search queries are proxied through our servers to Europe PMC's API.
- Semantic Scholar (US) — article search and citation data. Queries proxied through our servers.
- Crossref (US) — article metadata. Queries proxied through our servers.
- OpenAlex (US) — article discovery. Queries proxied through our servers.
- DOAJ (EU/UK) — open-access journal search (Directory of Open Access Journals). Your search queries are proxied through our servers.
- arXiv (US) — preprint search (physics, mathematics, computer science, and related fields). Your search queries are proxied through our servers.
- PostHog (US) — product analytics and error reporting. We record which pages you visit and which features you use (for example that an evidence table was built), tied to your account ID. We do not send PostHog your name, email address, search terms, notes, or document contents, and PostHog is configured to store nothing on your device — no analytics cookies are set. Privacy policy
- Cloudflare (US) — CDN, DDoS protection, and DNS. Network-level traffic passes through Cloudflare's infrastructure. Privacy policy
7. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. Specifically:
- Account data: Retained until you delete your account. Upon deletion, your data is removed from our active systems immediately, and any residual copies in encrypted backups are purged within 30 days.
- Research content (projects, notes, saved articles): Deleted from active systems immediately when you delete your account, via our cascade-delete database structure.
- Feedback submissions: Retained for up to 2 years for product improvement purposes, then deleted. If you delete your account, your email address is removed from any feedback you submitted and the message is no longer linked to you.
- Server logs: Retained for up to 90 days for security and debugging, then automatically purged.
8. Data Security
We implement reasonable technical and organizational security measures to protect your data, including:
- All data in transit is encrypted via TLS/HTTPS
- Database access is protected by Row-Level Security (RLS) — each user can only access their own data
- Passwords are never stored in plaintext; they are protected with industry-standard one-way hashing
- Service role keys and API credentials are stored in server-side environment variables, never exposed to the browser
- HTTP security headers are enforced on all responses (CSP, HSTS, X-Frame-Options, etc.)
While we take reasonable precautions, no system is perfectly secure. Please use a strong, unique password for your account and enable any two-factor authentication when available.
9. International Data Transfers
Novaralis is operated from the United States. If you access the Service from outside the United States — including from the European Economic Area (EEA) or United Kingdom — your data will be transferred to and processed in the United States. The US may not have data protection laws equivalent to those in your country. By using the Service, you consent to this transfer. For EEA/UK users, where such transfers require additional safeguards, we use service providers that offer Standard Contractual Clauses (SCCs).
10. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
All users:
- Access and update your profile information in the Settings panel
- Delete your account and all associated data via Settings → Delete Account
- Opt out of the weekly email digest at any time in Settings
EEA / UK users (GDPR):
- Right of access: Request a copy of the personal data we hold about you
- Right to rectification: Request correction of inaccurate data
- Right to erasure: Request deletion of your personal data ("right to be forgotten")
- Right to restriction: Request that we limit how we process your data
- Right to data portability: Request your data in a machine-readable format
- Right to object: Object to processing based on legitimate interests
- Right to withdraw consent: For processing based on consent (e.g., email digest), withdraw at any time
California residents (CCPA):
- Right to know what personal information we collect, use, and disclose
- Right to delete your personal information
- Right to opt out of the "sale" of personal information — We do not sell your personal information.
- Right to non-discrimination for exercising your CCPA rights
To exercise any of these rights, email us at hello@novaralis.com. We will respond within 30 days (GDPR) or 45 days (CCPA). We may need to verify your identity before fulfilling certain requests.
11. Children's Privacy
Novaralis is not directed to anyone under the age of 18. We do not knowingly collect personal information from anyone under 18. If we become aware that we have collected personal information from someone under 18, we will delete that information. If you believe we may have information from or about someone under 18, please contact us at hello@novaralis.com.
12. Data Breach Notification
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users and, where required by law, the relevant supervisory authority, within the timeframes required by applicable law (72 hours under GDPR where applicable). Notifications will be sent to the email address associated with your account.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by a prominent notice in the app at least 30 days before changes take effect. Continued use of Novaralis after the effective date of a material change constitutes your acceptance of the updated policy. The "Last updated" date at the top of this page will always reflect the most recent revision.
14. Contact
Questions, concerns, or requests regarding this policy? Please reach us at hello@novaralis.com. If you are an EEA resident and believe we have not addressed your concern adequately, you have the right to lodge a complaint with your local data protection authority.