Your paper stays yours
Submitting an unpublished paper takes trust. Here is exactly how we handle it.
We never train on your manuscript
Your paper is sent to the OpenAI API only to generate your report. OpenAI does not train its models on data sent through the API (their policy since 2023). We never use your paper to train anything, and we never sell or share it.
Your paper is not stored as a file
The PDF you upload is processed in memory to produce your report and is not kept as a file afterwards. What we store is the report itself, tied to your account.
Your reports are private to you
Legacy reports are readable only by the account that created them, enforced at the database layer, and have no sharing mechanism. Workspace analysis results are private the same way unless you explicitly create a share link for one. Nobody else, including us in normal operation, browses your reports or results.
You can delete your reports anytime
Delete any report from the Reports tab and it is removed. Deleting a report does not refund the credit it cost.
Encrypted in transit and at rest
All traffic uses HTTPS, and stored data is encrypted at rest by our cloud provider.
Project versions
Pasted text, PDF, and DOCX files you submit to create a version are processed in memory and are not retained as original files.
A normalized plain-text copy of the manuscript is stored privately with the project version so later workspace features can reference it; only the signed-in owner can read it.
A bounded excerpt of that text is sent to the OpenAI API to infer the contribution fingerprint; OpenAI's API terms govern that processing.
Reports and project-version text remain private to their owner.
When you run an explicit literature search in the evidence workspace, the query text you submit is sent to OpenAlex to find published works. Suggested queries may contain short confirmed-fingerprint fields, and are sent only if you choose and submit them. Your manuscript text and uploaded files are never sent to OpenAlex.
When you start Discover, the confirmed contribution-fingerprint fields and the selected-source metadata (titles, authors, venues, years) are sent to the OpenAI API. Discover does not send the stored normalized manuscript text. OpenAI's API terms govern that processing.
When you start Validate, the confirmed contribution-fingerprint fields, the selected-source metadata, and verified public OpenReview review excerpts are sent to the OpenAI API. Validate does not send the stored normalized manuscript text. OpenAI's API terms govern that processing.
When you start Strengthen, the confirmed contribution-fingerprint fields of the current and preceding versions, the selected-source metadata, verified public OpenReview review excerpts, and the preceding version's recommendation are sent to the OpenAI API. Strengthen does not send the stored normalized manuscript text. OpenAI's API terms govern that processing.
Sharing workspace results
A workspace analysis result is shared only when you create a private link for it. The link contains an unguessable token; we store only a hash of it, so a link cannot be recovered or reconstructed after creation.
A shared page shows an allowlisted copy of that one completed result: its summary, findings, severities, recommendation, movement, and public literature references. It never includes your manuscript text, normalized text, uploaded files, source library, fingerprints, project or version identifiers, credentials, or any billing data.
Every share link expires 30 days after creation. You can revoke or delete a link at any time from the result page, and shared pages are marked so search engines do not index them.
Legacy reports have no share links; they stay private to your account.
Deleting a project
Deleting a project permanently removes the project, every version, the stored normalized manuscript text, the evidence source library, all analysis runs and results, share links, and the conversion record that linked a legacy report to it.
Anonymous accounting records (credit ledger entries, spend budgets, daily-start counters, starter grants, and rate-limit counters) are retained; they contain no project content. Deleting a project does not refund credits already spent.
If a deletion is interrupted, the project stays locked in a deleting state and a retry resumes and completes it.
Questions about your data? Email support@submitcue.com.