Privacy Policy

Last updated: 2026-08-27

2026-08-27 — correction to our file-deletion practice

We discovered that the automated job which deletes uploaded source files had been failing silently since 2026-04-28. Uploads from that period remained in our storage instead of being deleted on schedule. Those files were only ever held in a private storage bucket reachable with our own service credentials, were never part of any public page, feed or share link, and were permanently deleted on 2026-08-27 when the failure was found. The job is fixed, and its result is now independently monitored rather than assumed. We have also corrected the stated deletion window on this page from “24 hours” to “within about 30 hours”, which is how the cleanup actually runs.

1. Who We Are

AudioScholar is operated by Dr. Nikhil Shah, a practicing academic nephrologist in Edmonton, Alberta. For privacy questions, email nikhil.shah@audioscholar.cc.

2. What We Collect

Account information

  • Email address (used as identifier)
  • Display name (only if you sign in with Google; we receive your Google profile name)
  • Login timestamps (last sign-in time, used to compute "X new since" greeting)
  • Plan tier (currently free for all users)

Content you create

  • PDFs you upload via /add (automatically deleted once they are 24 hours old; the cleanup runs every 6 hours, so removal completes within about 30 hours of upload)
  • Audio summaries and transcripts generated from your uploads and your Specialty Weekly and Topic Watch subscriptions (kept indefinitely tied to your account, until you delete the account)
  • Subscriptions you create (specialty, frequency, voice preference, schedule)
  • Episode state (whether you've played, archived, or marked an episode)
  • Playback position (for resuming where you left off)

System logs

  • Audit log entries when you or an admin perform sensitive actions (e.g., creating or deleting a subscription, updating system config, sending claim emails). These record that an action happened — identifiers, timestamps, outcomes and sizes — and deliberately do not record the subject matter: not the topic you typed, not the research question you asked, not the URL you submitted.
  • Standard server logs for debugging and abuse prevention

What we do NOT collect

  • PHI (forbidden by Terms; if accidentally uploaded, deleted with your PDF after 24h)
  • Behavioural analytics, pixel-tracking, or third-party advertising identifiers
  • Payment data (Stripe is not yet integrated; this section will be updated when it is)
  • Geolocation beyond what's incidental to standard web traffic (IP address visible to our hosts during requests, not stored long-term)
  • Recordings of your voice or your microphone

Public engagement signals

When you visit a publicly shared AudioScholar listen page (e.g., /episode/<slug> or /pdf/<slug>), we record anonymized engagement events: page view, play start, playback depth at 25 / 50 / 75 / 100%, and clicks on the share, download, email, and copy-link buttons. Your IP address is never retained in raw form. Before storage it is one-way hashed together with a secret key and the current date, so the resulting value changes every day and cannot be used to link your visits across days. Within a single day the value is stable, which is what lets us count distinct visitors without knowing who they are. We do not collect identifying information from visitors to public pages; you do not need an AudioScholar account to view them.

3. How We Use Your Data

  • Generate audio summaries from your uploaded papers and your subscription queries
  • Send you transactional emails (an audio is ready, your account has been migrated, your account has been claimed, etc.)
  • Operate, secure, and improve the service
  • Communicate with you about your account, important changes, and support requests
  • Comply with applicable law

We do not use your content to train AI models. We do not sell your data.

4. Third-Party Processors

To deliver the service, we use the following processors. By using AudioScholar you consent to your data being processed by these parties for the stated purposes:

ProcessorPurposeData ProcessedRegion
SupabaseDatabase, authentication, file storageAll account + content dataHosted in our chosen Supabase region (subject to Supabase's infrastructure)
ResendTransactional email deliveryRecipient email + email bodyUS-based
Google Cloud TTSAudio synthesis (text → speech)Generated script text (transient; not retained by Google for model training under our API agreement)Global Google Cloud infrastructure
Anthropic (Claude)Primary AI provider: writes the audio briefing scripts, selects which papers to cover, and summarizes documents and links you submitPubMed abstracts and metadata; the full text of any PDF you upload and any article at a URL you submit (transient; processed under Anthropic's commercial API terms, which do not permit training on our inputs)US-based
Google GeminiSecondary AI provider: initial sorting of search results, building PubMed queries from a topic you type, and an automatic fallback if Anthropic is unavailablePubMed abstracts and metadata; a topic phrase you type; the same document text as above when acting as a fallback (transient)Global Google Cloud infrastructure
US National Library of Medicine (PubMed / NCBI) and NIH iCiteFinding published papers and retrieving citation countsSearch terms and article identifiers. On our research tools these requests are sent directly from your browser, so your IP address and the terms you type reach NIH without passing through our serversUS Government (National Institutes of Health)
Google OAuthOptional sign-in via Google accountOAuth identity (email, name, sub identifier)Global Google infrastructure
CloudflareDNS for audioscholar.ccRoutine DNS query metadataGlobal edge network
LovableBuild and deploy platform; also relays the Topic Watch query builder to an AI modelSource code. Additionally, when you create a Topic Watch, the topic phrase you type passes through Lovable's AI gateway on its way to the model (transient)Lovable infrastructure
Crossref, Unpaywall and doi.orgResolving a DOI to publication metadata and finding legal open-access copiesArticle identifiers (DOIs) only — never your identityUS / UK / global
Google Public DNSSafety check on links you submit, to block requests to private/internal addressesThe hostname of a URL you submitGlobal Google infrastructure
PublerScheduling AudioScholar's own social posts (operator-initiated, not user content)Episode titles and post copy for content we publish ourselvesEU-based

Each processor has its own privacy policy governing how they handle data we send them. We have selected these providers with attention to industry-standard security practices but cannot assume responsibility for their conduct.

Two things worth calling out specifically. First, our research tools (the PubMed search and trial-finder pages) query NIH from your browser rather than from our servers. We never see or store those searches — but NIH does, along with your IP address, under their web policies. Second, which AI provider handles a given request can change: we may switch providers, or fall back automatically from one to another if a provider is unavailable. Both providers listed above should be treated as able to receive any content you submit.

5. Cookies and Local Storage

AudioScholar uses only essential storage in your browser:

  • Authentication tokens in localStorage, set by Supabase Auth. Used to keep you signed in.
  • dashboard.welcomeDismissed in localStorage. A simple 1 flag indicating you've dismissed the welcome card.

No tracking cookies, no analytics pixels, no advertising tags, no third-party trackers. You can clear these via your browser settings at any time; doing so will sign you out and re-show the welcome card.

6. Data Retention

DataRetention
Account info (email, login timestamps, plan)Until you delete your account
Subscriptions (Specialty Weekly / Topic Watch config)Until you delete the subscription or your account. Deleting a subscription stops it immediately and removes it from your dashboard; the underlying record is retained in a deactivated state so past episodes keep working
Generated audio + transcriptsUntil you delete your account, or until we discontinue the service
Uploaded source PDFsDeleted once 24 hours old; cleanup runs every 6 hours, so within about 30 hours of upload
Audit log entries90 days
Server / error logsApproximately 30 days
Email metadata (Resend)According to Resend's retention; typically 30 days

If you delete your account, we will delete or anonymize your account data within 30 days. Backups may retain residual data for an additional 30–60 days before purge.

7. Your Rights

You have the right to:

  • Access your data — visible to you in the app
  • Correct your data — update via the app or email us
  • Delete your account — email nikhil.shah@audioscholar.cc with "Delete my account" in the subject. Processed within 30 days
  • Withdraw consent — stop using the service and request deletion as above
  • Receive a copy — for tabular data, available on request via email; audio files can be downloaded directly from the app
  • Lodge a complaint with a relevant privacy regulator (Office of the Privacy Commissioner of Canada, Office of the Information and Privacy Commissioner of Alberta, or your local equivalent if outside Canada)

8. Children

AudioScholar is intended for adults (18+) engaged with the medical literature. We do not knowingly collect data from children under 18. If you become aware that a minor has created an account, please email us so we can delete it.

9. International Transfers

Our database (Supabase) is hosted in our chosen region. Some processing — AI script writing and summarization, voice synthesis, literature search, email delivery, OAuth — necessarily transits the infrastructure of Anthropic, Google, NIH, Resend and other providers, which may include the United States and the European Union. By using AudioScholar you consent to this cross-border transfer.

For users in jurisdictions with stricter cross-border data rules (e.g., EU/EEA under GDPR), please assess whether AudioScholar's current setup meets your obligations before uploading content.

10. Security

  • All traffic between your browser and AudioScholar is encrypted via HTTPS/TLS
  • Authentication is handled by Supabase Auth with hashed passwords + optional Google OAuth
  • Database row-level security restricts data access to your own account
  • Server-side functions run with least-privilege credentials
  • No PHI is processed; we do not assume HIPAA-grade controls

We are a small-team early-stage product. We follow industry-standard practices but cannot guarantee absolute security. If you believe you've discovered a security issue, please email nikhil.shah@audioscholar.cc with "Security report" in the subject — we appreciate responsible disclosure.

11. Changes to This Policy

Episode feedback. When you submit feedback on an episode (via the Inaccuracy / Audio / Idea buttons at the end of the player), we store the category, your note, and a record of your IP address (auto-deleted after 24 hours, used solely for spam prevention). Your feedback is anonymous by default — we do not store your identity, even if you are signed in. If you check "Include my email so Dr. Shah can follow up," we additionally store your email address solely to respond to your specific submission, and we never use it for marketing or other purposes.

We may update this Privacy Policy as the service evolves. Material changes will be communicated by email. The "Last updated" date at the top of this page reflects the most recent revision.

12. Contact

Privacy questions, deletion requests, security reports:
Email: nikhil.shah@audioscholar.cc
Subject prefix: AudioScholar — [Privacy / Delete my account / Security report / etc.]


© 2026 Dr. Nikhil Shah · University of Alberta directory