Research Capture
Privacy Policy
This privacy policy explains how Research Capture handles account, workspace, support, and operations data.
Version 2026-07-13-resend-disclosure
Published July 13, 2026
Scope
This policy describes how Research Capture collects, stores, uses, and shares data when you use the product and its connected services.
Age eligibility and children's privacy
Research Capture is not directed to children under 13.
Do not use the service if you are under 13.
Research Capture does not provide a parental-consent flow.
Any deployment that intends to allow minors must add age-gate, parental-consent, and children's privacy controls before making the product available to them.
Information the product stores
Research workspace content, including ideas, nodes, sources, tasks, drafts, revisions, saved views, saved searches, archive records, import staging packages, export jobs, export artifacts, idempotency records, offline sync queues, conflict payloads, and attachment metadata.
Search data, including recent searches, search index projections for ideas, nodes, drafts, tasks, and source notes, plus search analytics events when search analytics consent is enabled. Search queries can contain sensitive information.
Account and subscription data, including account profiles, device records, device fingerprints, push tokens, collaborator identifiers, author labels, workspace membership, entitlements, subscription and billing records, transaction IDs, identity-provider subjects, support lookup keys, correlation identifiers, notification preferences, and unsubscribe state.
Support and compliance data, including support cases, export requests, deletion requests, access records, and related notes.
Security and operations data, including sessions, rate-limit and protection records, access events, revision snippets, alerts, incidents, backups, restore checks, certificates, and authorship timestamps.
Error and delivery data, including outbound notification events, outbox records, webhook delivery metadata, stored payload material used by delivery and billing actions, crash and error events, and related operational delivery logs.
Attachment and import data, including file names, local URIs, attachment scan records, signed download tokens, imported document staging content, and export manifest metadata.
How information is stored
Workspace content is stored so that you can reopen ideas, sources, notes, drafts, searches, and archive records across supported product sessions.
Signed-in account, subscription, support, security, and operational records are stored by the service connected to your account.
Some working data may also be retained on the device or browser you use, including session details, offline changes, import staging data, and recently opened workspace state.
Protect devices that contain Research Capture data with an operating-system passcode and appropriate disk encryption. Sign out and remove local product data before transferring a device to another person.
Search analytics consent
Search analytics consent is recorded through the product surfaces and may be reflected in device-local and account-backed state.
New raw query telemetry is recorded only while that consent is enabled, and search queries can contain sensitive information.
You can pause search analytics from the Search surface or the Trust Center summary.
Pausing consent stops new query telemetry from being recorded and clears retained search analytics for that product surface.
Imports, attachments, and heuristics
When you choose files to import, the app reads the selected documents from device storage and stages package content so it can be reviewed or imported later.
Deleting workspace objects can first mark records inactive or removed before any later purge or cleanup step occurs.
Removing an attachment or discarding an import staging record can leave metadata, staged content, or cached files in persisted state until that state is explicitly cleared or replaced by later product actions.
Attachment review is heuristic. It checks file names and local URIs for suspicious patterns and is not a full antivirus or deep content inspection service.
Secure attachment download flows use signed, time-limited tokens delivered through authenticated request headers.
Notifications and third-party processors
Infrastructure providers may process and store account, billing, operations, and backup data to operate Research Capture.
App store and billing providers may process subscription, transaction, entitlement, and restore data.
Webhook-based notification providers may receive recipient addresses, user identifiers, notification categories, unsubscribe paths, and unsubscribe tokens when outbound delivery is enabled.
When direct Resend email delivery is configured, Resend, Inc. receives recipient and sender addresses, reply-to addresses, rendered email subject, HTML and text content, notification category, unsubscribe URLs and headers, and delivery metadata through api.resend.com. Resend acts as an email delivery processor; the deployment owner must maintain the applicable data-processing agreement and review Resend's subprocessors, security posture, and retention controls before enabling delivery.
Research Capture retains its local outbound notification and delivery-attempt records for 90 days after final delivery state. Resend may retain message content, delivery events, provider message identifiers, suppression data, and account logs according to the deployment owner's Resend account configuration and Resend's applicable terms. A Research Capture deletion request cannot be completed until the workflow records provider-specific deletion, revocation, suppression, inapplicability, or legally approved retention evidence, including the applicable provider-side deletion or suppression result, after which repository-owned notification records are pseudonymized.
External identity providers may receive session tokens, identity claims, workspace identifiers, and revocation or introspection requests when the external auth boundary is enabled.
External key-management providers may receive workspace identifiers, encrypted key material, key aliases, and authenticated KMS boundary requests when external KMS mode is enabled.
Data rights and request timing
The account surface supports export requests, deletion requests, notification preferences, unsubscribe handling, and support contact workflows.
Export and deletion requests create request records and are not complete when the request is first created.
When an account deletion request is completed, the backend first requires complete provider-specific action evidence and then pseudonymizes the account profile, identities, devices, subscription account records, workspace ownership records, support records, outbound notification records, export/deletion request records, abuse signals, admin overrides, billing transaction references, and matching email suppressions before resolving the request.
Closed support, completed deletion, and completed export records are retained for 395 days after resolution, outbound notification and delivery-attempt records are retained for 90 days after final delivery state, and backend commercialization analytics records are retained for 180 days or the configured record-count limit, whichever prunes first.
Export artifacts, staging packages, sync queues, idempotency records, derived search-index records, backup artifacts, and security operations records are retained according to their cleanup, replay, backup, or access-event windows.
Research Capture targets review within 30 days of request creation. If provider coordination or unusually large scope is required, the request may remain open for one additional 30-day extension.
A request is not complete until it is explicitly reviewed and closed.
When the product is configured to rely on downstream providers, request creation does not itself guarantee that every provider-side export, deletion, revocation, or suppression action has already completed.
Support, identifiers, and operational records
Support and billing actions can process transaction IDs, identity-provider subjects, correlation keys, device identifiers, and workspace identifiers submitted through the product.
The product can record crash and error events, route keys, trace IDs, and related debugging details when those operational flows are enabled.
Rate-limiting and protection records can include client IP addresses, account identifiers, principal labels, operator labels, and related enforcement metadata.
Web use
Research Capture may be available through supported web pages in addition to the native app.
The product does not use advertising or behavioral-tracking cookies. It may use browser storage and essential session cookies to keep you signed in and preserve product state.
If non-essential tracking is introduced, Research Capture will present the required consent controls before enabling it.
Updates
This policy will be updated when material data handling, analytics, notification delivery, processor, or web practices change.