Privacy
Privacy for the controlled pilot
This is an interim factual notice for the controlled MVP pilot. The registered operator/controller details and final legal-basis language are still being verified and will be added before access is broadened. Privacy questions and requests can be sent to [email protected].
Data ResearchCal uses
ResearchCal stores signup and account information you provide, including your email, name where supplied, research and calendar preferences, source requests, calendar-client choice, pilot feedback, and willingness-to-pay signals. It can also store limited campaign labels and a reduced referrer: a path for a ResearchCal page or the origin of an external site. ResearchCal does not use a tracking cookie or browser storage for this attribution. The private product also stores recommendation decisions, calendar inclusions, feedback, digest-delivery records, a secret calendar-feed token, and sign-in-link records. These records support the pilot account, calendar, communications, and product feedback.
Optional AI-assisted personalization
If the feature is enabled and you choose it, ResearchCal extracts text from the first 10 pages of your uploaded CV and the first 5 pages of each of up to 5 uploaded working papers, caps the combined text at 100,000 characters, and sends that text as written to Mistral AI's stateless API. Uploaded documents are not anonymized: the extracted text may include names, email addresses, phone numbers, URLs, or other personal data present on those pages. ResearchCal also sends controlled public catalogs and your current preference values. It does not separately send your ResearchCal account ID, login metadata, account email, filenames, source hashes, calendar token, or engagement history. Mistral returns a draft private research profile and editable preference proposals. ResearchCal does not fetch researcher-supplied paper URLs and does not use Mistral agents, files, libraries, conversations, tools, web search, feedback, or Labs models for this workflow.
The generated profile is not public. Deterministic ResearchCal code uses private profile data and preferences to rank events. Controlled keywords that have current event matches can activate privately after deterministic checks and remain editable; broad keywords remain ranking-only. JEL and event-type proposals are applied only if you accept them. The model does not propose conference series. Event discovery and calendar generation do not themselves call an AI model.
ResearchCal uses the paid Mistral Scale plan and the stateless /v1/chat/completions API. Mistral Zero Data Retention is active, and API training use is disabled. Mistral does not use the submitted input or output to train its models. Mistral does not keep the API input or output after it returns the response. ResearchCal records only the provider, model, approval and request IDs, request time, token counts, and estimated cost, not prompt or response contents.
Storage and deletion
The hosted pilot stores live application data in Railway/Postgres. Transactional email is delivered through Resend when configured. Uploaded source bytes, filenames, hashes, and extracted text are removed from ResearchCal after successful processing. Pending, failed, or superseded source material is scheduled for removal after seven days. Generated profile data remains until you delete your research sources or account. Local worker logs exclude source and generated text and expire after 30 days.
You can delete all research sources and their unmodified source-derived profile and keywords from Preferences even when AI processing is unavailable. Preferences you entered or explicitly accepted remain. Metadata-only AI attempt records stay linked to your account for cost and incident auditing after source deletion, without the source file, extracted text, generated text, filename, or hash; they are deleted when you permanently delete the account. You can permanently delete the live account and its account-linked records by entering the account email on the deletion page. Provider logs and backups follow the providers' actual settings and contracts and are not claimed to disappear synchronously with live database deletion.
Other recipients
ResearchCal uses cookieless Cloudflare Web Analytics on public pages to understand aggregate traffic and site performance. The analytics beacon does not use cookies, local storage, or fingerprinting, and is not loaded on account pages, one-time sign-in links, personal calendar-feed URLs, or internal tools. We do not send submitted profile information, recommendation decisions, email addresses, calendar tokens, or URL query strings to Web Analytics.
We do not sell your data. We do not access your Google, Outlook, or Apple account.
Your requests
You can ask for access, correction, export, restriction, objection, or deletion by contacting [email protected]. You may also complain to the Dutch Data Protection Authority. Final request-handling and controller details are part of the pilot's open legal review.