Privacy Policy

Last updated: September 11, 2026

This Privacy Policy explains how Scholarly, based in the United States (USA), collects, uses, discloses, and retains information when you use our website, applications, AI features, and shared workspaces (the Services), including when you:

  • Visit our website at scholarly.so, or any website of ours that links to this privacy notice
  • Engage with us in other related ways, including any sales, marketing, or events

Questions or concerns? You can use the privacy controls described below or contact us with questions or requests at hello@scholarly.so.

1. What Information Do We Collect?

Personal Information You Disclose to Us

We collect information you provide when creating an account, using the Services, subscribing, joining a team, connecting a service, recording audio, or contacting support. Uploaded material may contain information about other people; provide it only when you have the necessary rights and permissions.

Personal Information Provided by You. The personal information that we collect depends on the context of your interactions with us and the Services, the choices you make, and the products and features you use. The personal information we collect may include:

  • Names
  • Email addresses
  • Account credentials and authentication information
  • Profile, team membership, billing and transaction details, support messages, and User Content described in section 13. Payment processors handle payment-card details.

Social Media Login Data. If you use Google sign-in, we receive the profile information needed to authenticate you, such as your name, email address, and profile picture. Connected-file access is separate from sign-in; see section 6.

Please keep your account information current. Do not submit sensitive personal information unless you have authority to do so and the Service is appropriate for your use.

Information Automatically Collected

As you use the Service, we receive technical and usage information. This information can identify you or be linked to your account. Product analytics operates independently of the optional advertising cookie choice. Information may include:

  • Browser and device characteristics
  • Operating system
  • Language preferences
  • Referring URLs
  • Device name
  • Country, location, and time zone
  • Product interactions, feature usage, and, with analytics consent, masked session replays
  • IP address
  • Diagnostic and security logs; with advertising consent, campaign identifiers and ad-conversion information

2. How Do We Process Your Information?

We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent.

We process your personal information for a variety of reasons, depending on how you interact with our Services, including:

  • To facilitate account creation and authentication and otherwise manage user accounts
  • To manage subscriptions and teams, including billing, invitations, access controls, and usage allowances.
  • To provide and improve our Services, including AI-powered features, content generation, and study tools
  • To understand and improve the product, using operational data, permitted analytics, and feedback. Our content and AI-training limits are in section 13.
  • To communicate with you about your account and the service, and to send marketing where permitted. Marketing emails provide an unsubscribe option; essential account and billing messages may still be sent.

3. What Legal Bases Do We Rely On to Process Your Information?

We only process your personal information when we believe it is necessary and we have a valid legal reason (i.e., legal basis) to do so under applicable law, like with your consent, to comply with laws, to provide you with services to enter into or fulfill our contractual obligations, to protect your rights, or to fulfill our legitimate business interests.

If you are located in the EU or UK, this section applies to you.

The General Data Protection Regulation (GDPR) and UK GDPR require us to explain the valid legal bases we rely on in order to process your personal information. As such, we may rely on the following legal bases:

  • Consent. We request consent for optional browser analytics, advertising, and other processing where required. You can refuse or withdraw that consent without losing access to the core Service.
  • Legitimate Interests. We rely on legitimate interests for proportionate security, fraud prevention, service reliability, support, and product analysis, where those interests are not overridden by your rights. This does not authorize unrestricted use of private content for model training.
  • Legal Obligations. We retain and process information needed for tax, accounting, lawful requests, and other applicable legal duties.
  • Contract. We process account details, instructions, source material, outputs, and billing information as needed to provide the Services you request.

If you are located in Canada, this section applies to you.

We may process your information if you have given us specific permission (express consent) to use your personal information for a specific purpose, or in situations where your permission can be inferred (implied consent). You can withdraw your consent at any time.

4. When and With Whom Do We Share Your Personal Information?

We may share information in specific situations and with specific third parties, including:

  • Business Transfers. Information may be disclosed as part of a merger, financing, acquisition, or sale of assets, subject to confidentiality safeguards, applicable law, and any additional restrictions on connected-service data.
  • Third-Party Service Providers. We use providers for cloud hosting and storage, databases and search, AI inference and media generation, code execution, payments, email, support, security, and diagnostics. Examples include Google Cloud, MongoDB, Pinecone, Upstash, OpenAI, Anthropic, Google, xAI, OpenRouter, E2B, Stripe, Loops, Resend, Sentry, and PostHog. Providers receive the information needed for the feature or function they support; not every provider receives every upload.
  • Sharing, advertising, and legal disclosures. We share content with recipients you choose and workspace participants as described in section 13. With advertising consent, Google Ads receives conversion information, including a hashed email address for matching. We may disclose information when legally required or necessary to protect rights, safety, or security. We do not sell private uploads or chats to data brokers.

5. Do We Use Cookies and Other Tracking Technologies?

Essential cookies and similar storage support sign-in, security, language, and requested preferences. PostHog measures product use and may record session replays with text and inputs masked; this product analytics stays active whether you accept or deny optional advertising cookies and is not used for advertising. Optional advertising uses Google Ads, campaign and click identifiers, and hashed email matching where available to measure ads. Advertising tracking stays off until accepted. Use Accept or Deny in the cookie banner, or open Cookie preferences from the footer, Settings, or the top of this page to change the advertising choice. Choices apply to this browser and are stored for up to 180 days; advertising attribution cookies last up to 90 days. Provider cookie lifetimes vary. Blocking all storage in your browser may affect sign-in or prevent a choice from surviving a reload.

6. Google Sign-In and Connected Services

Google sign-in supplies identity and profile information for authentication. If you separately connect Google Drive, we receive authorization tokens and access the files you select through the picker, including their contents and metadata. Existing grants may have broader read permissions. We use selected files to answer your requests and create outputs; relevant material may be sent to AI and infrastructure providers that support those features.

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy and the Google Workspace API user data and developer policy, including Limited Use requirements. Google Workspace data is not used to train or improve general-purpose AI models or for advertising. Human access is limited to the exceptions those policies permit. Disconnect in Connections or revoke access in your Google account to stop future access. Disconnecting does not itself delete files already imported, chat history, or generated outputs; delete those separately or request account deletion.

7. How Long Do We Keep Your Information?

We retain account information and saved content while needed to provide the Services or until you delete them, subject to the exceptions below. Retention depends on the information, its purpose, your settings, the life of a support request or dispute, and applicable legal duties. Billing and transaction records may outlast account closure for tax, accounting, and fraud-prevention obligations. Operational logs and backups follow their applicable retention cycles.

Deletion starts removal from active systems and associated storage. Processing may take time across systems and providers, and backup copies may persist until their normal expiry; retained copies are not a license for unrelated use or general model training. We may retain limited information for legal duties, security, fraud prevention, or resolving claims, with access restricted to those purposes. De-identified information is treated as outside personal-data rules only when it meets the applicable legal standard; removing a name or hashing an identifier alone does not establish anonymity.

8. How Do We Keep Your Information Safe?

We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process. However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information.

9. What Are Your Privacy Rights?

In some regions (like the EEA, UK, and Canada), you have certain rights under applicable data protection laws. These may include the right to: (i) request access and obtain a copy of your personal information, (ii) request rectification or erasure, (iii) restrict the processing of your personal information, and (iv) if applicable, data portability. In certain circumstances, you may also have the right to object to the processing of your personal information.

Withdrawing your consent. If we are relying on your consent to process your personal information, you have the right to withdraw your consent at any time. You can withdraw your consent at any time by contacting us at hello@scholarly.so.

Account Information. You can update account details and request account deletion in Settings. Export the material you need before deleting your account; deletion removes access and initiates the cleanup described in section 7. Copies downloaded by other people, independently duplicated content, and organization-controlled material may remain subject to their control.

Cookies and similar technologies. Use Cookie preferences to accept or deny optional advertising cookies. Product analytics stays active with either choice. You can also manage browser storage directly. Withdrawal applies to future advertising processing.

10. Browser Privacy Signals

When this browser sends Global Privacy Control (GPC), we disable optional advertising tracking even if a stored preference allows it. GPC does not turn off essential functionality or product analytics. Older Do Not Track signals are distinct from GPC; use Cookie preferences to control optional advertising.

11. US State Privacy Rights

Where applicable state privacy laws cover our processing, residents may have rights to access, correct, delete, and obtain a portable copy of personal information; opt out of sale, sharing for cross-context behavioral advertising, targeted advertising, or certain profiling; and limit specified uses of sensitive information. We do not discriminate for exercising applicable rights. Submit requests or an appeal of a denied request to hello@scholarly.so. We verify requests when required, accept authorized agents with appropriate proof, and respond within the applicable legal deadlines. Cookie preferences and GPC control the browser advertising described above.

Advertising disclosures may constitute sale or sharing under some state laws even when no money changes hands. Our collected categories, purposes, and recipient categories are described in sections 1–6. California residents may also request information about disclosures for third-party direct marketing under the Shine the Light law. Any additional rights and exceptions depend on the law that applies.

12. Children and Younger Users

The Services are not directed to children under 13, and they may not create an account. Users below the age of legal majority must have a parent or guardian’s permission and meet any higher minimum age required locally.

If you believe a child has provided personal information without the necessary authorization, contact hello@scholarly.so so we can investigate and take appropriate action, including deletion where required.

13. Content, AI Processing, and Teams

You retain your rights in your content. Providing the Service requires processing that content, but does not give Scholarly unrestricted rights to publish it or use it for unrelated purposes.

What User Content We Collect

User Content includes documents, PDFs, images, notes, recordings and transcripts, prompts, chat history, connected files you select, and generated outputs such as slides, video, podcasts, quizzes, and research. Team membership, sharing permissions, usage, and activity records are also processed.

How We Use User Content

We use User Content for the following purposes:

  • Service delivery: To store, retrieve, transform, and display your material, run AI inference, and produce the outputs you request. Relevant content may pass through more than one model or provider in an agent workflow.
  • Product improvement: To understand feature performance through operational data and permitted analytics, and address feedback you share with us.
  • Model training: Scholarly does not use private User Content to train general-purpose AI models by default. Any optional Scholarly training program would require a separate, informed opt-in. Google Workspace data remains subject to its stricter restrictions regardless of any general opt-in. AI inference to answer your request is different from training a model.
  • Support and troubleshooting: Authorized personnel may access relevant information when needed to provide requested support, investigate failures or abuse, and meet legal obligations, subject to applicable access and connected-service restrictions.
  • Aggregated and de-identified data: We may use statistics and information that meet applicable de-identification standards to understand and improve the Service. We do not treat identifiable source material as unrestricted merely because an identifier was removed.
  • Safety and integrity: To ensure the safety, security, and integrity of the Service, including detecting and preventing fraud, abuse, and policy violations.

Sharing and Team Workspaces

Sharing a link or publishing content may make it available to others according to the selected access settings. Recipients may download or independently duplicate material. Revoking a link cannot recall copies already obtained. In Teams, administrators manage membership, roles, billing, and activity reporting; access to shared content follows workspace and project permissions. Your organization may control material placed in its workspace and retain it when a member leaves. Leaving a team and deleting an individual account are different actions.

AI Providers and International Processing

Scholarly operates from the USA and uses providers that may process information in the USA and other countries. The provider and processing location depend on the feature, selected model, and routing. Selecting an EU-hosted model does not, by itself, mean all storage, support, analytics, or other processing stays in the EU. Where law requires transfer safeguards, the applicable arrangements must support those transfers, such as adequacy decisions or appropriate contractual safeguards. Contact us for information about a specific workflow or your organization’s requirements before submitting data subject to location restrictions.

Organization-Controlled Data

For account administration and our own service operations, Scholarly determines the purposes of processing. For personal data an organization supplies for processing on its behalf, its instructions and applicable data-processing agreement govern. Contact your organization first about access or deletion of organization-controlled information; we assist as required. This policy does not replace a required data-processing agreement or make consent to unrelated uses a condition of using the Service.

14. Do We Make Updates to This Notice?

We will post updates with a revised date and provide notice of material changes through the Service or by email as required. Changes do not retroactively authorize unrelated uses of previously collected information. Where a new purpose requires consent, we will request it before that processing.

15. How Can You Contact Us About This Notice?

Scholarly, United States (USA). For privacy questions, contact hello@scholarly.so.

16. How Can You Review, Update, or Delete the Data We Collect From You?

To exercise applicable rights, request details about retention or transfers, or appeal a request decision, email hello@scholarly.so. We may request information reasonably necessary to verify identity or authority. We respond within the deadlines set by applicable law, explaining any permitted extension or refusal. You may also complain to your local data-protection authority; you do not have to contact us first.