Privacy Policy
Effective Date: 12th December 2026
See also: Terms of Use
Oystack, Inc. and its affiliates ("Oystack," "we," "our," or "us") respect the privacy of researchers, academics, and knowledge workers who use our platform. This Privacy Policy explains how we collect, use, store, and share personal data in connection with our website, applications, and related services (collectively, the "Services"), as well as the rights available to individuals under applicable data protection laws.
By accessing or using the Services, you acknowledge that your personal data will be handled as described in this Policy. This Policy should be read together with our Terms of Use.
1. Applicability and Scope
This Privacy Policy applies to personal data processed by Oystack in the course of providing its Services, including data collected from:
- Visitors to the Oystack website
- Individuals who create or manage user accounts
- Users who upload, store, annotate, or analyse research materials
- Participants in surveys, research studies, or product feedback initiatives
- Individuals who receive communications, updates, or marketing materials from Oystack
- Academic institutions, publishers, and partners engaging with Oystack
Oystack acts as a data controller when processing personal data for its own purposes and may act as a data processor when handling content on behalf of institutional or enterprise customers. In such cases, processing is governed by contractual agreements with those customers.
2. Categories of Personal Data We Collect
The personal data we collect depends on how you interact with Oystack and the features you use.
Information You Provide Directly
This may include:
- Account Information: Name, email address, institutional affiliation, username, authentication credentials, and account preferences
- Research Content: Files, notes, annotations, prompts, citations, references, and other materials you upload or generate while using the Services
- Communications: Messages, inquiries, feedback, survey responses, and correspondence with our team
- Payment and Billing Data: Transaction details and billing information processed through secure third-party payment providers
- Professional Information: Academic role, research interests, or organisational details when provided voluntarily
Oystack does not intentionally solicit or require sensitive personal data such as health records, biometric data, or government-issued identifiers.
3. Information Obtained from Third Parties
We may receive personal data from trusted third parties, including:
- Authentication and identity providers (e.g., single sign-on services)
- Academic or public research databases accessed at your direction
- Analytics and infrastructure providers
- Institutional partners or administrators managing enterprise accounts
- Referral programs or invitations initiated by other users
Where you provide third-party content or data about others, you represent that you have the appropriate rights or authority to do so.
4. Automatically Collected Information
When you access or use the Services, we may automatically collect technical and usage data, including:
- Device type, browser version, operating system, and IP address
- Log data, timestamps, feature usage, and session duration
- Approximate geographic location derived from network information
- Interaction data related to searches, document usage, and workflows
This data is used to ensure platform stability, improve usability, maintain security, and understand how the Services are used in practice.
5. Purposes of Processing
Oystack processes personal data for the following legitimate purposes:
- Service Delivery: Providing access to core research, writing, and collaboration features
- Account Administration: Creating, maintaining, and securing user accounts
- Platform Improvement: Evaluating performance, developing new features, and improving reliability
- Research Enablement: Supporting document analysis, citation workflows, and AI-assisted research functionality
- Communication: Responding to inquiries, providing updates, and delivering service-related notices
- Security and Integrity: Detecting abuse, preventing unauthorised access, and enforcing our Terms
- Compliance: Meeting legal, regulatory, and contractual obligations
- Business Operations: Internal reporting, audits, financing, and organisational planning
6. Use of Artificial Intelligence and Automated Processing
Certain features of Oystack rely on machine learning and artificial intelligence technologies to assist with document analysis, summarisation, and research workflows.
- User-submitted content may be processed by automated systems solely to provide requested functionality
- Oystack does not use private user content to train public or third-party AI models without explicit authorisation
- Automated processing does not produce legal, academic, or professional determinations without human oversight
- Users retain ownership of their research content, subject to our Terms of Use
Where required by law, Oystack provides transparency regarding automated decision-making and allows users to raise concerns or objections.
7. Disclosure of Personal Data
We may share personal data only in limited circumstances, including:
- Service Providers: Vendors supporting infrastructure, analytics, payment processing, or AI functionality under confidentiality obligations.
- Institutional Customers: Where accounts are managed or sponsored by an academic institution.
- Legal and Regulatory Authorities: Where disclosure is required to comply with applicable law or lawful requests.
- Corporate Transactions: In connection with mergers, acquisitions, or restructuring, subject to appropriate safeguards.
We do not sell personal data.
8. Legal Bases for Processing
Where required by law, Oystack relies on the following legal grounds to process personal data:
- Performance of a Contract: Providing the Services requested by users
- Legitimate Interests: Improving and securing the platform, supporting research workflows, and operating our business responsibly
- Consent: Where users voluntarily provide data or opt into specific features or communications
- Legal Obligations: Compliance with applicable laws, regulations, and institutional requirements
You may withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing.
9. International Data Processing and Transfers
Oystack operates as a globally accessible research platform. As a result, personal data may be processed or stored in jurisdictions outside the country in which you reside, including regions that may have different data protection standards.
Where required by applicable law, Oystack implements appropriate safeguards to ensure that international transfers of personal data are protected. These safeguards may include the use of Standard Contractual Clauses, reliance on adequacy decisions issued by relevant authorities, or other legally recognised transfer mechanisms.
We take reasonable steps to ensure that any third-party processors involved in international data handling provide a level of protection consistent with this Policy and applicable data protection laws.
10. Third-Party Services and Integrations
The Services may include integrations with, or links to, third-party platforms, tools, or services that are not operated or controlled by Oystack. These may include reference managers, authentication providers, analytics tools, or external academic resources.
This Privacy Policy applies solely to data processed by Oystack. We are not responsible for the privacy practices, content, or data handling policies of third parties. We encourage users to review the privacy policies of any third-party services they choose to access in connection with Oystack.
Where third-party services process personal data on our behalf, they do so under contractual obligations designed to protect confidentiality, security, and compliance with applicable laws.
11. Children's Data
Oystack is designed exclusively for use by researchers, scholars, and academic professionals. The Services are not directed to individuals under the age of 13, and we do not knowingly collect personal data from children.
If we become aware that personal data has been collected from a child in violation of applicable laws, we will take appropriate steps to delete such information promptly. Parents or guardians who believe that a child has provided personal data to Oystack may contact us using the details provided below.
12. Data Security and Confidentiality
Oystack employs technical, organisational, and administrative measures designed to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure. These measures include access controls, secure infrastructure, and internal policies governing data handling.
While we take data protection seriously, no method of transmission or storage can be guaranteed to be completely secure. Users are responsible for maintaining the confidentiality of their account credentials and for any activity conducted under their account.
Oystack limits access to personal data to authorised personnel and service providers who require such access to perform their responsibilities.
13. Updates to This Privacy Policy
Oystack may revise this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the Services we provide.
When we make material changes, we will provide notice through appropriate means, which may include updates on our website or direct communication to users where required by law. The "Effective Date" at the top of this Policy indicates when the most recent version came into effect.
Continued use of the Services after an updated Policy becomes effective constitutes acknowledgement of the revised terms.
14. Contact Information and Data Requests
If you have questions about this Privacy Policy, our data handling practices, or your rights under applicable data protection laws, you may contact us at:
Requests related to access, correction, deletion, or portability of personal data should be submitted in writing. We may take reasonable steps to verify your identity before fulfilling such requests and will respond within the timeframes required by applicable law.
Oystack is committed to addressing privacy concerns transparently and in good faith.