Privacy Policy
Last updated: 05/07/2026
1. Who we are
Corpus (“we,” “us,” “our”) is a personal library and reading-tracking application available at usecorpus.app.
Contact: reachmaako@gmail.com
Data controller: Maako, reachmaako@gmail.com
2. What we collect
| Category | Examples | Why |
|---|---|---|
| Account info | Email, name, username, bio, password (hashed) | Create and secure your account |
| Library content | Entries, collections, notes, reading sessions, bibliographies you create | Core app functionality |
| Research profile data | Interest vectors, paper scores, reading history used for recommendations | To generate personalized recommendations |
| Usage/product data | Feedback, notifications, queue items, connections with other users | App functionality |
| AI processing logs | Records of content sent to Google Gemini for AI features, and associated usage/cost | To provide AI-powered features and manage usage |
| Technical data | IP address (via hosting logs), timestamps | Security, debugging |
3. How we use your data
- To provide the app's core features (library, collections, recommendations)
- To generate AI-assisted features (via Google Gemini — see Section 11)
- To pull reference data from Semantic Scholar for papers you look up
- To send account-related emails (via Resend)
- To sign you in via Google, if you choose that option
We do not use your data for advertising. We do not currently run any analytics or tracking tools.
4. Legal basis for processing (GDPR)
Because Corpus may be used by people in the EEA/UK regardless of where the app is based, GDPR can apply to any EU user's data. Our legal bases:
- Contract: providing the service you signed up for
- Legitimate interest: security, debugging, improving the app
- Consent: where you opt into specific features (e.g. Google sign-in)
5. Data sharing — third parties we use
| Service | Purpose | What it receives |
|---|---|---|
| Vercel | Hosting | Request/traffic data, logs |
| Neon (PostgreSQL) | Database | All stored account/library data |
| Google (OAuth) | Sign-in | Email, name, if you use Google sign-in |
| Google Gemini | AI features | Content you submit for AI-assisted processing |
| Resend | Transactional email | Your email address |
| Semantic Scholar | Paper/reference lookup | Search queries you make |
| Upstash Redis | Rate limiting | Request metadata (not content) |
We do not sell personal data.
6. Data retention
We do not currently have automated data retention or deletion schedules. Data is retained indefinitely on our servers until you request deletion (see Section 7). Password reset and email verification tokens are time-limited for use but are not automatically purged after expiry.
7. Your rights
You may have rights under GDPR/CCPA to access, correct, delete, or export your data, and to object to certain processing.
Account deletion: You can permanently delete your account and all associated data at any time from Account Settings. This action is immediate and irreversible, and removes your library content, collections, research profile, and account information from our systems, other than a minimal internal log (retained 30 days) confirming a deletion occurred, used only for support/debugging purposes.
Data export: Corpus does not yet have a self-service data export feature. If you'd like a copy of your data, contact us at reachmaako@gmail.com and we'll provide it manually while we build automated export.
California residents (CCPA/CPRA): the same deletion and export rights apply as described above.
8. Data security
Passwords are hashed using bcrypt and are never stored in plaintext. No system is 100% secure.
9. Children's privacy
Corpus is not directed at children under 13 (16 in the EEA). We do not currently verify age at signup. If you believe a child has provided us data, contact reachmaako@gmail.com.
10. Cookies
We use a session cookie required for you to stay logged in. This is strictly functional — we do not use analytics or advertising cookies, and no consent banner is currently needed for this reason. If analytics tools are added later, this section and a consent mechanism will need to be added at that time.
11. AI features
Some features send your content (e.g. entries, queries) to Google's Gemini API for AI-assisted processing. This content is subject to Google's API terms/privacy policy. We log usage of these features for cost/usage tracking tied to your account.
12. International data transfers
Our infrastructure is hosted on AWS in the US East region. If you are located outside the United States, your data will be transferred to and processed in the US. For users in the EEA/UK, this means data leaves the EEA/UK; we rely on our subprocessors' (Vercel, Neon) own data protection agreements and safeguards to help ensure adequate protection.
13. Changes to this policy
We'll update the “Last updated” date and notify users of material changes via email/in-app notice.