Privacy Policy
Last updated: 2026-08-27
2026-08-27 — correction to our file-deletion practice
We discovered that the automated job which deletes uploaded source files had been failing silently since 2026-04-28. Uploads from that period remained in our storage instead of being deleted on schedule. Those files were only ever held in a private storage bucket reachable with our own service credentials, were never part of any public page, feed or share link, and were permanently deleted on 2026-08-27 when the failure was found. The job is fixed, and its result is now independently monitored rather than assumed. We have also corrected the stated deletion window on this page from “24 hours” to “within about 30 hours”, which is how the cleanup actually runs.
1. Who We Are
AudioScholar is operated by Dr. Nikhil Shah, a practicing academic nephrologist in Edmonton, Alberta. For privacy questions, email nikhil.shah@audioscholar.cc.
2. What We Collect
Account information
- Email address (used as identifier)
- Display name (only if you sign in with Google; we receive your Google profile name)
- Login timestamps (last sign-in time, used to compute "X new since" greeting)
- Plan tier (currently
freefor all users)
Content you create
- PDFs you upload via
/add(automatically deleted once they are 24 hours old; the cleanup runs every 6 hours, so removal completes within about 30 hours of upload) - Audio summaries and transcripts generated from your uploads and your Specialty Weekly and Topic Watch subscriptions (kept indefinitely tied to your account, until you delete the account)
- Subscriptions you create (specialty, frequency, voice preference, schedule)
- Episode state (whether you've played, archived, or marked an episode)
- Playback position (for resuming where you left off)
System logs
- Audit log entries when you or an admin perform sensitive actions (e.g., creating or deleting a subscription, updating system config, sending claim emails). These record that an action happened — identifiers, timestamps, outcomes and sizes — and deliberately do not record the subject matter: not the topic you typed, not the research question you asked, not the URL you submitted.
- Standard server logs for debugging and abuse prevention
What we do NOT collect
- PHI (forbidden by Terms; if accidentally uploaded, deleted with your PDF after 24h)
- Behavioural analytics, pixel-tracking, or third-party advertising identifiers
- Payment data (Stripe is not yet integrated; this section will be updated when it is)
- Geolocation beyond what's incidental to standard web traffic (IP address visible to our hosts during requests, not stored long-term)
- Recordings of your voice or your microphone
Public engagement signals
When you visit a publicly shared AudioScholar listen page (e.g., /episode/<slug> or /pdf/<slug>), we record anonymized engagement events: page view, play start, playback depth at 25 / 50 / 75 / 100%, and clicks on the share, download, email, and copy-link buttons. Your IP address is never retained in raw form. Before storage it is one-way hashed together with a secret key and the current date, so the resulting value changes every day and cannot be used to link your visits across days. Within a single day the value is stable, which is what lets us count distinct visitors without knowing who they are. We do not collect identifying information from visitors to public pages; you do not need an AudioScholar account to view them.
3. How We Use Your Data
- Generate audio summaries from your uploaded papers and your subscription queries
- Send you transactional emails (an audio is ready, your account has been migrated, your account has been claimed, etc.)
- Operate, secure, and improve the service
- Communicate with you about your account, important changes, and support requests
- Comply with applicable law
We do not use your content to train AI models. We do not sell your data.
4. Third-Party Processors
To deliver the service, we use the following processors. By using AudioScholar you consent to your data being processed by these parties for the stated purposes:
| Processor | Purpose | Data Processed | Region |
|---|---|---|---|
| Supabase | Database, authentication, file storage | All account + content data | Hosted in our chosen Supabase region (subject to Supabase's infrastructure) |
| Resend | Transactional email delivery | Recipient email + email body | US-based |
| Google Cloud TTS | Audio synthesis (text → speech) | Generated script text (transient; not retained by Google for model training under our API agreement) | Global Google Cloud infrastructure |
| Anthropic (Claude) | Primary AI provider: writes the audio briefing scripts, selects which papers to cover, and summarizes documents and links you submit | PubMed abstracts and metadata; the full text of any PDF you upload and any article at a URL you submit (transient; processed under Anthropic's commercial API terms, which do not permit training on our inputs) | US-based |
| Google Gemini | Secondary AI provider: initial sorting of search results, building PubMed queries from a topic you type, and an automatic fallback if Anthropic is unavailable | PubMed abstracts and metadata; a topic phrase you type; the same document text as above when acting as a fallback (transient) | Global Google Cloud infrastructure |
| US National Library of Medicine (PubMed / NCBI) and NIH iCite | Finding published papers and retrieving citation counts | Search terms and article identifiers. On our research tools these requests are sent directly from your browser, so your IP address and the terms you type reach NIH without passing through our servers | US Government (National Institutes of Health) |
| Google OAuth | Optional sign-in via Google account | OAuth identity (email, name, sub identifier) | Global Google infrastructure |
| Cloudflare | DNS for audioscholar.cc | Routine DNS query metadata | Global edge network |
| Lovable | Build and deploy platform; also relays the Topic Watch query builder to an AI model | Source code. Additionally, when you create a Topic Watch, the topic phrase you type passes through Lovable's AI gateway on its way to the model (transient) | Lovable infrastructure |
| Crossref, Unpaywall and doi.org | Resolving a DOI to publication metadata and finding legal open-access copies | Article identifiers (DOIs) only — never your identity | US / UK / global |
| Google Public DNS | Safety check on links you submit, to block requests to private/internal addresses | The hostname of a URL you submit | Global Google infrastructure |
| Publer | Scheduling AudioScholar's own social posts (operator-initiated, not user content) | Episode titles and post copy for content we publish ourselves | EU-based |
Each processor has its own privacy policy governing how they handle data we send them. We have selected these providers with attention to industry-standard security practices but cannot assume responsibility for their conduct.
Two things worth calling out specifically. First, our research tools (the PubMed search and trial-finder pages) query NIH from your browser rather than from our servers. We never see or store those searches — but NIH does, along with your IP address, under their web policies. Second, which AI provider handles a given request can change: we may switch providers, or fall back automatically from one to another if a provider is unavailable. Both providers listed above should be treated as able to receive any content you submit.
5. Cookies and Local Storage
AudioScholar uses only essential storage in your browser:
- Authentication tokens in localStorage, set by Supabase Auth. Used to keep you signed in.
dashboard.welcomeDismissedin localStorage. A simple1flag indicating you've dismissed the welcome card.
No tracking cookies, no analytics pixels, no advertising tags, no third-party trackers. You can clear these via your browser settings at any time; doing so will sign you out and re-show the welcome card.
6. Data Retention
| Data | Retention |
|---|---|
| Account info (email, login timestamps, plan) | Until you delete your account |
| Subscriptions (Specialty Weekly / Topic Watch config) | Until you delete the subscription or your account. Deleting a subscription stops it immediately and removes it from your dashboard; the underlying record is retained in a deactivated state so past episodes keep working |
| Generated audio + transcripts | Until you delete your account, or until we discontinue the service |
| Uploaded source PDFs | Deleted once 24 hours old; cleanup runs every 6 hours, so within about 30 hours of upload |
| Audit log entries | 90 days |
| Server / error logs | Approximately 30 days |
| Email metadata (Resend) | According to Resend's retention; typically 30 days |
If you delete your account, we will delete or anonymize your account data within 30 days. Backups may retain residual data for an additional 30–60 days before purge.
7. Your Rights
You have the right to:
- Access your data — visible to you in the app
- Correct your data — update via the app or email us
- Delete your account — email nikhil.shah@audioscholar.cc with "Delete my account" in the subject. Processed within 30 days
- Withdraw consent — stop using the service and request deletion as above
- Receive a copy — for tabular data, available on request via email; audio files can be downloaded directly from the app
- Lodge a complaint with a relevant privacy regulator (Office of the Privacy Commissioner of Canada, Office of the Information and Privacy Commissioner of Alberta, or your local equivalent if outside Canada)
8. Children
AudioScholar is intended for adults (18+) engaged with the medical literature. We do not knowingly collect data from children under 18. If you become aware that a minor has created an account, please email us so we can delete it.
9. International Transfers
Our database (Supabase) is hosted in our chosen region. Some processing — AI script writing and summarization, voice synthesis, literature search, email delivery, OAuth — necessarily transits the infrastructure of Anthropic, Google, NIH, Resend and other providers, which may include the United States and the European Union. By using AudioScholar you consent to this cross-border transfer.
For users in jurisdictions with stricter cross-border data rules (e.g., EU/EEA under GDPR), please assess whether AudioScholar's current setup meets your obligations before uploading content.
10. Security
- All traffic between your browser and AudioScholar is encrypted via HTTPS/TLS
- Authentication is handled by Supabase Auth with hashed passwords + optional Google OAuth
- Database row-level security restricts data access to your own account
- Server-side functions run with least-privilege credentials
- No PHI is processed; we do not assume HIPAA-grade controls
We are a small-team early-stage product. We follow industry-standard practices but cannot guarantee absolute security. If you believe you've discovered a security issue, please email nikhil.shah@audioscholar.cc with "Security report" in the subject — we appreciate responsible disclosure.
11. Changes to This Policy
Episode feedback. When you submit feedback on an episode (via the Inaccuracy / Audio / Idea buttons at the end of the player), we store the category, your note, and a record of your IP address (auto-deleted after 24 hours, used solely for spam prevention). Your feedback is anonymous by default — we do not store your identity, even if you are signed in. If you check "Include my email so Dr. Shah can follow up," we additionally store your email address solely to respond to your specific submission, and we never use it for marketing or other purposes.
We may update this Privacy Policy as the service evolves. Material changes will be communicated by email. The "Last updated" date at the top of this page reflects the most recent revision.
12. Contact
Privacy questions, deletion requests, security reports:
Email: nikhil.shah@audioscholar.cc
Subject prefix: AudioScholar — [Privacy / Delete my account / Security report / etc.]
© 2026 Dr. Nikhil Shah · University of Alberta directory