Privacy
Privacy notice
Last updated: 17 September 2026
This notice explains how ResearchCal uses and stores personal data.
Who is responsible
ResearchCal is the controller of your personal data. ResearchCal is an eenmanszaak (sole proprietorship) registered in the Dutch Business Register under KVK number 42166128. The address is on the provider information page. For privacy questions or requests, email [email protected].
Information you give us
ResearchCal stores your email address, name if you give it, research and calendar preferences, source requests, feedback, and willingness-to-pay answers.
Account activity
ResearchCal stores your recommendation choices, events you add, email-delivery records, sign-in-link records, and your private calendar link. These records operate your account, calendar, and email.
Visit information
ResearchCal can store campaign labels and limited information about how you found the site. ResearchCal does not use a tracking cookie or browser storage for this information.
Why we use your data and the legal basis
- Your account and calendar. ResearchCal uses your email address, preferences, recommendation choices, events you add, sign-in links, and private calendar link to provide the service you ask for. This includes sign-in and welcome emails and emails about changes to events in your calendar. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- Recommendation emails and reminders. ResearchCal sends emails with new event recommendations and reminders to finish setting up your calendar. Legal basis: legitimate interest in helping you use the service (Art. 6(1)(f) GDPR). You can turn these emails off in Preferences or with the link in each email.
- Optional AI-assisted personalization. If you choose this feature, ResearchCal analyzes your CV, working papers, or research source links. Legal basis: your consent (Art. 6(1)(a) GDPR). You can withdraw your consent at any time by removing your sources in Preferences. This does not affect processing that happened before you withdrew your consent.
- Feedback, source requests, and willingness-to-pay answers. ResearchCal uses these answers to improve the service. Giving them is optional. Legal basis: legitimate interest in improving the service (Art. 6(1)(f) GDPR).
- Visit information, analytics, and system logs. ResearchCal uses campaign labels, aggregate traffic data, and system logs to understand how people find the site and to keep the service reliable and secure. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
Where ResearchCal relies on legitimate interest, you can object to the processing. Email [email protected].
ResearchCal does not make decisions based only on automated processing that have legal or similarly significant effects for you. Personalization only changes which events ResearchCal recommends, and you can edit your preferences.
Optional AI-assisted personalization
If you choose this feature, ResearchCal extracts text from the first 10 pages of your CV and the first 5 pages of each of up to 5 working papers. The total limit is 100,000 characters. The text is not anonymized and can include names and contact details.
ResearchCal uses only Mistral's text API for this step and does not use Mistral tools or web search. Mistral returns document-based suggestions. ResearchCal does not separately send your account ID, sign-in records, filenames, file hashes, private calendar link, or activity history.
Mistral Zero Data Retention is active, and API training use is disabled. Mistral does not use the input or output to train its models. Mistral does not keep the API input or output after it returns the response. ResearchCal keeps limited technical records, such as the provider, model, request time, token counts, and estimated cost. These records do not contain document text or suggestion text.
Storage and deletion
ResearchCal keeps your account data until you delete your account. When you permanently delete your account, ResearchCal deletes your active account data, including your preferences, recommendation choices, email-delivery records, sign-in-link records, private calendar link, and signup record. ResearchCal keeps signup records that do not lead to an account until you ask for deletion.
When research source imports are enabled, you can also submit public profile and paper links. ResearchCal reads supported sources and sends bounded extracted content to the same Mistral text service. OpenAlex and HAL imports require an author confirmation. RePEc links are saved without importing content.
For these imports, source links, publication titles and identifiers, content fingerprints, and generated evidence remain until source removal. Raw files and extracted text are deleted after processing. Unprocessed content expires seven days from submission, or after 35 days when waiting for the monthly AI budget. Accepted preferences remain when a source is removed. Generated profile information can affect matching before you accept visible preference suggestions.
For the previous document import feature, ResearchCal deletes uploaded files, filenames, file hashes, and extracted text after successful processing. Failed or replaced input expires after seven days. These previous imports can be removed as one group. The research source retention periods above apply to new imports under the new acknowledgement.
ResearchCal system logs do not contain uploaded document text or generated suggestion text. ResearchCal deletes these logs after 30 days.
You can delete your documents and document-based suggestions in Preferences. You can permanently delete your active account data on the account deletion page.
Provider logs and backups follow each provider's retention rules. They may not be deleted at the same time as your active ResearchCal data.
Service providers and transfers outside the EEA
ResearchCal uses these service providers. They process personal data on behalf of ResearchCal:
- Railway hosts the application and its database in the United States.
- Resend delivers account, digest, and reminder email from the United States.
- Cloudflare provides cookieless web analytics on public pages.
- Mistral AI (France) provides the text API for optional AI-assisted personalization.
Railway, Resend, and Cloudflare are based in the United States. When personal data is transferred outside the European Economic Area, these transfers rely on the EU-U.S. Data Privacy Framework where the provider is certified, or on the European Commission's standard contractual clauses in the provider's data processing terms.
Cloudflare Web Analytics is not loaded on account pages, sign-in links, private calendar links, or internal tools. ResearchCal does not send email addresses, preferences, recommendation choices, private calendar links, or URL query strings to this service.
ResearchCal does not sell your data. ResearchCal does not access your Google, Outlook, or Apple account.
Your rights
You have the right to access, correct, delete, restrict, and export your personal data, and to object to processing based on legitimate interest. Where processing is based on consent, you can withdraw your consent at any time. To use these rights, email [email protected]. ResearchCal answers within one month.
You can also complain to the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens.