Privacy Policy
Effective September 2026
1. Overview
This policy explains what information Litworking collects, how it's used, and the choices you have. It applies to your account, your projects, and everything you create or upload while using the service.
We built Litworking as a research tool, not an advertising or data-brokerage business. The short version: your research is yours, we don't sell it, and deleting it actually deletes it.
2. Information we collect
We collect three broad kinds of information:
- Account information — your name, email address, and a securely hashed password (or a linked sign-in provider).
- Content you create — projects, canvases, nodes and connections, papers, notes, citations, evaluations, tasks and any files you upload.
- Usage data — basic technical logs (timestamps, error reports, session identifiers) used to keep the service reliable and secure.
3. How we use your information
We use your information to operate the service you signed up for: authenticating you, storing and syncing your projects, rendering your canvases, sending account-related email, and processing payment when you choose a paid plan.
We do not use the content of your papers, notes, claims or canvases to train machine learning models, and we do not sell or rent your personal information or research content to third parties.
4. Your content and ownership
You own everything you create in Litworking. Projects, canvases, papers, notes, claims, evidence, citations and uploaded files are private to your account and to any collaborators you explicitly invite — we don't make them discoverable to other users.
Uploaded PDFs and other files are stored for the sole purpose of serving them back to you (and your collaborators) inside the app.
5. Third-party processors
Depending on how a given deployment is configured, a small number of third-party services help us run infrastructure — never to see or sell your data for their own purposes:
- An email delivery provider, used to send verification, password-reset and notification email when email is configured.
- An object-storage provider, used to store uploaded PDFs and other files when cloud storage is configured (otherwise files are stored locally to the deployment).
- A payment processor, used to handle checkout and billing when billing is configured (we never see or store your full card number).
6. Data retention & deletion
Your content stays available for as long as your account exists. From Settings → Data, you can request deletion of your account, which removes your projects, papers, notes, canvases, evaluations and uploaded files.
A small amount of information may be retained briefly afterward where needed for security, fraud prevention, or a legal obligation, and is not used for any other purpose.
7. Security
Passwords are hashed with scrypt and never stored in plain text. Sessions are stored server-side and referenced by an HttpOnly cookie, so session tokens are not accessible to page scripts. Traffic between your browser and the service is encrypted in transit.
8. Children's privacy
Litworking is intended for students, researchers, teachers and professors and is not knowingly directed at or collecting information from children under 13.
9. Changes to this policy
If we make a material change to this policy, we'll update the effective date below and, where appropriate, notify account holders by email before the change takes effect.
10. Contact
Questions about this policy can be sent to the address listed for your deployment's support contact.