Data Handling

Last updated 24 July 2026

A plain description of what this service stores, what it sends to other services, and when it deletes things.

The short version

  • Your document is never sent to anyone. The file you upload stays on our servers. What we send to our AI providers is text and images extracted from it — see who we share with.
  • Your files are deleted automatically — after 7 days (no account), 30 days (signed-in free) or 90 days (paid).
  • We set no analytics or advertising cookies and run no trackers.
  • You can delete your account and content at any time from your account page.

Your account

If you create an account we store your email address, whether it is verified, when you signed up, when you last signed in, your role, and — if you buy credits — your credit balance.

Your password is never stored. We keep only a one-way value derived from it, using a deliberately slow, individually-salted method: it cannot be reversed into your password, and it is designed so that guessing attempts stay expensive even if the database were exposed.

An account is optional for the free Research Teaser. It is required for the paid formats.

Where offered, you can sign in with a Google account or a Microsoft account instead of a password. If you use that, we receive your email address from the provider and nothing else; no password is stored for such an account unless you later set one yourself.

Your documents, videos, and recordings

For each render we keep, in a folder for that job: the file you uploaded, the title/author/abstract metadata we extracted, the figures we extracted, the slide deck, the narration script, the per-slide audio, the slide images, the finished video, and the caption files. If you record your own voice in the studio, those recordings are stored with the job.

Alongside them we store the job's settings — the filename, the format you chose, audience and voice, and any citation details you typed.

We also record the network address the upload came from, used only to enforce the per-address limits. It is erased when you delete your account, along with the rest of the link between you and the job.

Papers sent for SheQAI Reviewed

If you order a SheQAI Reviewed video, the paper you upload is stored separately from the automatic renders above, because a person has to work from it.

We keep it while your order is open — including while you are still sending revisions — and the deletion clock starts when the order finishes. After that it is kept for the same 90 days a paid render gets, then deleted automatically. If an order is declined, never paid, or its payment hold expires, the paper is deleted sooner — within 14 days — because no work was done on it.

The order record itself (what you ordered, what it cost) is kept for our accounts. Your uploaded paper is deleted as above, and 365 days after the order closes we also remove your contact address and any notes you typed from that record — what stays is the accounting fact, not who you are. Deleting your account removes the contact address from your orders immediately.

Feedback you send us

A finished render has a feedback box. Everything in it is optional. If you fill it in we store your ratings and your note, plus whichever of your name, affiliation and email you chose to give, together with the render it refers to and the network address it was sent from.

The tick-box beside it is a separate, narrow permission: it is unticked unless you tick it, and it means we may email you once when a new feature launches. It is not a mailing list, and we do not use that address for anything else without asking you again.

If you delete your account, your name, email, affiliation and network address are erased from any feedback you sent, and the permission above is withdrawn. We keep the note itself, with nothing identifying attached, because it may be the only record of a real problem with the product.

You do not need an account for that to happen. After 90 days we remove the name, affiliation and network address from any feedback, and the email too unless you ticked the box above — the same schedule as a paid render. The note stays, with nothing identifying attached.

If you did tick it, we keep only your email address, and only for up to 365 days, so we can send that one message. After that the address is deleted and the permission ends — you would need to ask again.

Payments

We never see or store your card details. Payment happens on Stripe's or PayPal's own pages. What we keep is the customer and transaction identifiers they give us, the amount, and how many credits it bought — enough to reconcile your balance and process refunds.

Anti-abuse counters

We keep the minimum needed to stop abuse:

  • Per-IP counters for uploads, sign-in attempts and other rate-limited actions.
  • Failed sign-in records, so repeated guessing can be slowed down. These record the email address that was submitted, whether or not an account exists for it.
  • For signed-out visitors, a one-way value derived from your network address and a cookie — not the address itself — so the weekly free limit can be applied without recording who you are.

These counters are pruned automatically once they are older than the window they protect.

Cookies

We set two cookies. Both are HttpOnly and neither tracks you across sites.

sheqai_session Keeps you signed in — for up to 31 days, and cleared when you sign out or change your password.
docvideo_anon Lets us apply the free-tier limit to signed-out visitors. Expires after 400 days.

Analytics and advertising

We use neither. There is no analytics service, no advertising network, no tracking pixel and no tag manager in this product. We do not build profiles of you and we do not sell or share your data for advertising.

Who we share with

Producing a video requires these external services. The uploaded file itself is never sent to any of them — only text and images extracted from it.

Our AI text provider Text extracted from your document — the abstract, section text, figure captions and table contents — to write the slides and narration. For PDFs we also send images of the pages, so figures can be located accurately.
Our speech provider The narration script, to generate the voiceover. Nothing else — it never receives your document or any part of it beyond the script.
Backup providers If a provider above is unavailable, an equivalent one may be used instead, receiving the same data for the same purpose.
Stripe, PayPal Payment processing, on their own pages.
Crossref, arXiv If you paste a DOI or arXiv ID, we send that identifier to look up the publication details and licence.
Our email relay Your address and the message, for the transactional emails below.

Emails we send

Only transactional email: password resets, email verification, and a note when a render finishes or fails. We send no marketing email and there is no newsletter to unsubscribe from.

Sharing a video publicly

Videos are private by default. If you create a share link, we copy the video and its thumbnail to a separate public store so the link keeps working. That copy is not covered by the automatic deletion below — it stays until you turn sharing off, we remove it, or you delete your account. Turning sharing off deletes the copy immediately.

How long we keep things

Your uploaded file and everything we generated from it Deleted automatically, on a schedule that depends on the render: 7 days for a render made without an account, 30 days for a signed-in free render, and 90 days for a paid render.
Publicly shared copies Until you stop sharing or delete your account.
The record that a job existed Kept as our operational record after the files are deleted.
Backups We keep the 7 most recent rotating database backups — taken daily, plus one whenever the service restarts — so deleted records can persist in a backup for up to 7 days.
Payment records Retained after account deletion — purchases, refunds and subscription history are kept as the record of money that moved.

Deleting your account

Deleting your account from the account page does all of this:

  • Any public share links stop working and the shared copies are deleted.
  • Every job folder is deleted — your uploaded documents, figures, decks, audio and videos.
  • The remaining job records are unlinked from you, so they no longer identify you.
  • Your account, sign-in tokens and free-tier records are deleted.

Payment records are kept, as above. Staff accounts are removed by request rather than self-service.

How your account is protected

  • Passwords stored only as an irreversible, individually-salted, deliberately-slow value — never as text. Reset and verification links are likewise stored only as one-way values, are single-use, and are invalidated when a new one is issued.
  • Changing your password signs out your other sessions.
  • Sign-in attempts are slowed after repeated failures, in a way that does not reveal whether an account exists.
  • Safeguards are enabled by default to stop another site acting on your behalf, or injecting content into pages you are shown.
  • When we fetch a document from a URL you paste, we only allow public web addresses and cap the download size.

What you can do

  • Download your deck, video and captions at any time from the job page.
  • Turn off a share link at any time.
  • Change your email or password, or delete your account, from your account page.
  • Ask us to remove something — see below.

Changes

This page is updated as the software changes; the date at the top is the last change. A formal policy document will replace it.

Contact

Questions, or a request to remove content: get in touch.