AgingResearch.News

Privacy policy

Last updated

Who we are

AgingResearch.News is run by Paperfoot AI Pte. Ltd., a company incorporated in Singapore (“we”, “us”). We are responsible for the personal data described here.

Your account

  • When you join, we store your name, your email address and your password, which is kept only as a one-way hash.
  • In your account you choose the topics you follow, describe your research interests in your own words, and turn the weekly email on or off.
  • We store the papers you save and like.
  • Each sign-in session records the IP address and browser it began on, to keep the account secure. A session stops working after 60 days without a visit.

Cookies and browser storage

We use no advertising or third-party cookies.

  • __Secure-better-auth.session_token keeps you signed in. It is set when you sign in and lasts up to 60 days.
  • __Secure-better-auth.session_data holds a signed copy of your session for 5 minutes, so pages know you are signed in without looking you up each time.
  • In session storage, a random id groups one tab’s page views and reading records into a visit. It is deleted when the tab closes.
  • In local storage, whether this browser was last signed in, so the top bar keeps its shape while the page loads.
  • In local storage, the time of the newest entry you have seen on Updates, so the unread dot can show. It never leaves your browser.
  • In local storage, your recent searches, so the search box can offer them again. They never leave your browser.

We no longer set the arn_anon cookie, which held a random id for counting story reads. If your browser still has one, the site deletes it on your next visit.

Page views

We count page views with our own system, without cookies. For each view we record:

  • the page’s address, without its query string;
  • the site that sent you, as a host name such as x.com;
  • the utm_source, utm_medium and utm_campaign tags in the link you followed;
  • your country, worked out by our host from your IP address;
  • your type of device (phone, tablet or desktop) and the name of your browser;
  • a visitor code: a one-way hash of the date, your IP address, your browser’s user agent and a secret key. It changes every day, so it counts you once a day but cannot follow you from one day to the next;
  • a random id for the page view, which the reading records made on that page share.

We never store your IP address or your full user agent with a page view. If you are signed in, the view is also linked to your account.

What you read

To rank papers and learn which ones readers find worth their time, we record what you do with them:

  • which papers, news stories and trials were on your screen in a list, and for how long: we count the time while at least half of a card shows (30% of a card taller than half the screen), the tab is in front and you have scrolled, tapped or typed in the last 15 seconds, up to a minute per card on each page you view. We also record how long the card sat on the reading line 40% of the way down the screen, how many times it came into view, the most of it that showed, its place in the list and the page it was on;
  • the stories you open from a list, the cards you expand, and the stories you share or whose link you copy;
  • on a story’s page, how long you spend reading, counted the same way, and how far down the story you get;
  • the links you follow to papers, with the list each link was in and its position, and how long you were away if you come back to the tab, up to 30 minutes;
  • saves and likes, and when you undo them.

Reading records carry the daily visitor code described under Page views and the id of the page view. Records sent from the page also carry the random id of the tab’s visit and, with on-screen and reading times, your type of device. The actions you take, such as opening, sharing and following a link, also carry a second daily code made the same way from the first part of your IP address, which identifies your network; we delete it within three days. Crawlers and automated browsers are not recorded. With Global Privacy Control or Do Not Track turned on, these records carry no tab id and story reading is not recorded.

When you are signed out, these records count only towards each paper’s totals: we build no profile from them. When you are signed in, they are linked to your account and we use them to rank papers for you. While you are signed in, the page gets a signed token from our server when it loads, valid for 12 hours, and sends it with these records, so they stay linked to your account during a long visit. The token is kept in the page’s memory, not stored in your browser.

For signed-in readers we also keep what we work out from these records, rebuilt as you read: a summary of the kinds of papers you read and save most, made from the papers themselves, and your ranked list of new papers. We keep a copy of each For you page we show you.

Your Plus feed

Plus ranks new papers against the research interests you describe. To score each match, your description and the paper go to TypeSafe, and we keep the scores to build your feed.

Ask

When you ask a question, we keep it with its answer, the papers cited and whether you marked the answer useful, and use them to improve how Ask finds papers and writes answers. Your question and the last few turns of the conversation go to Google’s Gemini models to find matching papers and write the answer, and to TypeSafe to rank the papers by how directly they answer it.

Delete a conversation at any time and its questions and answers are deleted with it. We keep a count of the questions you ask each day, without their text, to apply the daily allowance.

Plus payments

Plus is sold through Stripe. You pay on Stripe’s checkout page and manage or cancel the subscription in Stripe’s billing portal, so we never see or store your card details. Stripe tells us your customer and subscription ids, your plan, its status and when the current period ends, and we keep those with your account. Stripe handles payment data under its privacy policy.

Email

We send email through Amazon SES:

  • a welcome email when you join;
  • a link to reset your password when you ask for one, which expires after an hour;
  • the weekly email, on Mondays, with the week’s most important papers. It is on unless you untick it when you join. Every weekly email has an unsubscribe link, mail apps that offer one-click unsubscribe can stop it directly, and you can turn it off in your account.

API keys

For each key you create for the data API, we store its name, its first few characters and a one-way hash of it, never the key itself, with when it was created, last used and revoked. We count each key’s requests per minute and per day to apply the limits, and keep the daily counts as your usage history.

Research datasets

Every day we archive the previous day’s records to Amazon S3: the papers we read, our judgements and stories, the record of each decision our models make, and the saves and likes described above. We keep the archive indefinitely and use it to study how readers use the site, and to train and evaluate the models that judge, rank and write about papers.

In the archive your account id is replaced by a pseudonymous code made with a secret key, and no name, email address or IP address is included. The research interests you write for Plus are part of the scoring records, so they are archived under that code. Page views, the other reading records, searches and Ask conversations are not archived.

Who processes data for us

These companies process personal data for us, only to provide their service:

  • Vercel hosts the site and runs its code. It handles every request, including your IP address.
  • Neon runs our database.
  • Amazon Web Services sends our email (Amazon SES) and stores the research archive (Amazon S3).
  • Stripe takes payments and runs the billing portal.
  • Google writes stories and news briefs with its Gemini models, and receives Ask questions and search words to find papers and write answers.
  • TypeSafe scores papers and checks stories with its JEV models, and receives Plus research interests and Ask questions to rank papers.

We don’t sell personal data or share it with advertisers. We disclose it to anyone else only when the law requires it, or to a buyer of the business, and we would tell you before a sale.

How long we keep it

  • Your account and settings: until you close the account.
  • Saves, likes, followed searches and Ask conversations: until you remove them or close the account.
  • API keys, including revoked ones, and their daily usage: until you close the account.
  • The scores and scoring records made from your Plus research interests: until you close the account.
  • Sign-in sessions, with their IP address and browser: until you sign out or close the account. A session stops working after 60 days without a visit.
  • Password reset links: they stop working after an hour.
  • Page views, reading records and searches: indefinitely, to measure the site and improve rankings and search over time. Those linked to your account are deleted with it.
  • The network code on the actions you take: three days at most.
  • The summary of what you read and your ranked list of papers: until you close the account. The copies of For you pages we showed you are kept with the reading records.
  • The research archive: indefinitely, under the pseudonymous code.
  • Billing records: as long as tax law requires. Stripe keeps its own.

Your rights

Depending on where you live, you can ask for a copy of your data, have it corrected or deleted, restrict or object to how we use it, or take it elsewhere. Change your topics, interests and weekly email in your account. For anything else, write to hello@agingresearch.news from the email address on your account. We reply within 30 days.

Deleting your account removes your profile, sessions, saves, likes, followed searches, Ask conversations and API keys, the summary of what you read and your ranked list, and the page views, reading records, searches and Plus scoring records linked to it. If you have Plus, we cancel it. Records already in the research archive stay under their pseudonymous code, with no link to your name or email address.

If you think we have mishandled your data, tell us first. You can also complain to the data protection authority where you live, such as the PDPC in Singapore or the ICO in the UK.

International transfers

We are based in Singapore. The site, its database and the research archive run in the United States, as do Google, TypeSafe and Stripe, and email is sent from the United Kingdom, so your data is handled outside your own country. Where the law requires it, these transfers rely on our providers’ data processing terms, including standard contractual clauses.

Security

Connections to the site are encrypted. Passwords and API keys are stored only as one-way hashes, and card details stay with Stripe. Access to our data is limited to the people who run the service.

Children

Accounts are for people aged 16 and over. If you think a child has given us personal data, write to us and we will delete it.

Changes

When this policy changes, so does the date at the top. We email account holders before a significant change takes effect.

Contact

Paperfoot AI Pte. Ltd., Singapore
hello@agingresearch.news