Privacy Policy
Last updated July 6, 2026
This Privacy Notice for Refine Technologies, Inc. (doing business as Refine) ("we," "us," or "our") describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services").
Please read this Privacy Notice carefully. If you have any questions or concerns about our privacy practices, please don't hesitate to contact us.
1. Research Use and Model Training
A core value at Refine is that the content you upload is strictly confidential. We will not train any large language models on your uploaded content, and we do not permit our AI service providers to do so either.
AI model processing is routed through OpenRouter Enterprise, our LLM gateway provider. Our agreement with OpenRouter Enterprise contractually prohibits the use of submitted content to train or improve AI models. This obligation extends to the underlying model providers accessed through OpenRouter's infrastructure. This no-training guarantee applies to all users.
For users accessing Refine through an organizational account (institutional or enterprise tier), we additionally require Zero Data Retention (ZDR) with our LLM providers, meaning submitted content is not stored by any model provider even transiently. For individual consumer accounts, ZDR is not enabled; submitted content may be processed by model providers subject to their standard operational data handling practices, but use of your content for model training remains prohibited under our agreements with those providers. If you are interested in organizational access with ZDR enabled, please contact us at institutional-support@refine.ink.
Separately, we use PostHog for product analytics and session replay to improve our service and assist with troubleshooting. For users accessing Refine through an organizational account, session content is masked. For individual consumer accounts, this includes session recordings linked to your account. Where required by applicable law, including for users in the European Economic Area and United Kingdom, session replay will only be activated after you have provided your consent via our cookie consent banner. You may withdraw that consent at any time through our Cookie Policy. PostHog processes this data as a contracted sub-processor and is prohibited from using it for any purpose other than providing analytics services to Refine.
The content you upload may not be shared or sold by us or our providers to any third party.
Your data is protected by industry-standard security practices on Microsoft Azure infrastructure. When you delete a session in your history, we delete all its associated data permanently and unrecoverably.
We may use your interactions with comments to improve feedback ranking and quality. You may opt out of such use by notifying help@refine.ink from the email address associated with your Refine account.
For more information about our AI model gateway provider's privacy practices:
2. What Information Do We Collect?
Personal information you disclose to us
We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.
The personal information that we collect depends on the context of your interactions with us and the Services, the choices you make, and the products and features you use. The personal information we collect may include the following: names, email addresses, usernames, billing addresses, contact or authentication data, passwords.
We do not intentionally collect sensitive personal information. Uploaded content may incidentally contain such data, which we process solely to deliver the requested service and do not use for any other purpose.
We may collect data necessary to process your payment if you choose to make purchases, such as your payment instrument number and the security code associated with your payment instrument. All payment data is handled and stored by Stripe. You may find their privacy notice here: stripe.com/privacy.
We may provide you with the option to register with us using your existing social media account details, like your Google or other social media account. If you choose to register in this way, we will collect certain profile information about you from the social media provider. All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.
Information automatically collected
We automatically collect certain information when you visit, use, or navigate the Services. This information does not reveal your specific identity (like your name or contact information) but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, information about how and when you use our Services, and other technical information. This information is primarily needed to maintain the security and operation of our Services, and for our internal analytics and reporting purposes.
Like many businesses, we also collect information through cookies and similar technologies. You can find out more about this in our Cookie Notice: refine.ink/cookie-policy.
The information we collect includes: Log and Usage Data (service-related, diagnostic, usage, and performance information our servers automatically collect when you access or use our Services and which we record in log files) and Device Data (information about your computer, phone, tablet, or other device you use to access the Services, including IP address, device and application identification numbers, location, browser type, hardware model, Internet service provider and/or mobile carrier, operating system, and system configuration information).
Google API
Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3. How Do We Process Your Information?
We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent.
We process personal information for the following purposes:
- To facilitate account creation and authentication and otherwise manage user accounts. We may process your information so you can create and log in to your account, as well as keep your account in working order.
- To deliver and facilitate delivery of services to the user. We may process your information to provide you with the requested service.
- To process user-submitted content. We process the drafts or papers that users upload — which may incidentally contain personal information such as author names and institutional affiliations — in order to generate and return feedback as part of our service. Submitted content is processed through our AI pipeline solely to serve the submitting user.
- To improve our services and troubleshoot issues. We use product analytics and session replay tools to understand how our Services are used and to diagnose technical issues. For individual consumer accounts, this may include session recordings linked to your account. See Section 5 for details on how this data is handled.
- To respond to user inquiries and offer support. We may process your information to respond to your inquiries and solve any potential issues you might have with the requested service.
- To fulfill and manage your orders. We may process your information to fulfill and manage your orders, payments, returns, and exchanges made through the Services.
- To request feedback. We may process your information when necessary to request feedback and to contact you about your use of our Services.
- To send you marketing and promotional communications. We may process the personal information you send to us for our marketing purposes, if this is in accordance with your marketing preferences. You can opt out of our marketing emails at any time.
- To protect our Services. We may process your information as part of our efforts to keep our Services safe and secure, including fraud monitoring and prevention.
- To identify usage trends. We may process information about how you use our Services to better understand how they are being used so we can improve them.
- To determine the effectiveness of promotional campaigns. We track responses to campaigns and communications.
4. What Legal Bases Do We Rely On To Process Your Personal Information?
If you are located in the EU or UK, this section applies to you.
The General Data Protection Regulation (GDPR) and UK GDPR require us to explain the valid legal bases we rely on in order to process your personal information. We may rely on the following legal bases:
- Consent. We may process your information if you have given us permission to use your personal information for a specific purpose. You can withdraw your consent at any time.
- Performance of a Contract. We may process your personal information when we believe it is necessary to fulfill our contractual obligations to you, including providing our Services or at your request prior to entering into a contract with you.
- Legitimate Interests. We may process your information when we believe it is reasonably necessary to achieve our legitimate business interests and those interests do not outweigh your interests and fundamental rights and freedoms. For example, we may process your personal information to: send users information about special offers and discounts on our products and services; analyze how our Services are used so we can improve them to engage and retain users; diagnose problems and/or prevent fraudulent activities; understand how our users use our products and services so we can improve user experience; and assess and improve our marketing strategies.
- Legal Obligations. We may process your information where we believe it is necessary for compliance with our legal obligations, such as to cooperate with a law enforcement body or regulatory agency, exercise or defend our legal rights, or disclose your information as evidence in litigation in which we are involved.
- Vital Interests. We may process your information where we believe it is necessary to protect your vital interests or the vital interests of a third party, such as situations involving potential threats to the safety of any person.
In legal terms, we are generally the data controller under European data protection laws of the personal information described in this Privacy Notice, since we determine the means and/or purposes of the data processing we perform. This Privacy Notice does not apply to the personal information we process as a data processor on behalf of our institutional customers. In those situations, the customer that we provide services to and with whom we have entered into a Data Processing Agreement is the data controller responsible for your personal information, and we process your information on their behalf in accordance with their instructions. If you want to know more about our customers' privacy practices, you should read their privacy policies and direct any questions to them.
Data protection inquiries may be directed to privacy@refine.ink. The Information Security Officer currently fulfills data protection oversight responsibilities for Refine.
If you are located in Canada, this section applies to you.
We may process your information if you have given us specific permission (i.e., express consent) to use your personal information for a specific purpose, or in situations where your permission can be inferred (i.e., implied consent). You can withdraw your consent at any time.
In some exceptional cases, we may be legally permitted under applicable law to process your information without your consent, including for investigations and fraud detection and prevention, for business transactions provided certain conditions are met, to comply with a subpoena, warrant, or court order, or where the information is publicly available and specified by applicable regulations.
7. Do We Offer Artificial Intelligence-Based Products?
Use of AI Technologies
As part of our Services, we offer products, features, or tools powered by artificial intelligence, machine learning, or similar technologies (collectively, "AI Products"). These tools are designed to enhance your experience and provide you with innovative solutions. The terms in this Privacy Notice govern your use of the AI Products within our Services.
AI model processing is provided through OpenRouter Enterprise, our LLM gateway, which routes requests to one or more underlying model providers. As outlined in Section 1 of this Privacy Notice, your submitted content will not be used to train or improve any AI models, and this restriction applies to OpenRouter and to the underlying model providers accessed through OpenRouter's infrastructure. This no-training guarantee applies to all users. Users accessing Refine through an organizational account additionally benefit from Zero Data Retention (ZDR), meaning submitted content is not stored by any model provider even transiently. See Section 1 for more detail on the ZDR tier distinction.
You must not use the AI Products in any way that violates the terms or policies of any AI service provider.
Our AI Products
Our AI Products are designed for the following functions: manuscript analysis, error detection in academic research, mathematical and logical reasoning analysis, and generation of structured feedback reports.
How We Process Your Data Using AI
All personal information processed using our AI Products is handled in line with this Privacy Notice and our agreements with third-party providers. Submitted content is processed through our AI pipeline solely to generate and return feedback to the submitting user. Refine's AI outputs are advisory in nature and do not constitute automated decisions with legal or similarly significant effects on users.
9. Is Your Information Transferred Internationally?
Our servers are located in the United States (Microsoft Azure, Central US region). Regardless of your location, please be aware that your information may be transferred to, stored by, and processed by us and the third-party providers with whom we share your personal information in the United States.
For users in the EEA, UK, and Switzerland
If you are a resident of the European Economic Area (EEA), United Kingdom (UK), or Switzerland, please be aware that the United States may not have data protection laws as comprehensive as those in your country. We take the following measures to protect your personal information in connection with international transfers:
Standard Contractual Clauses. For transfers of personal data from the EEA or UK to the United States, we rely on the European Commission's Standard Contractual Clauses (EU Commission Implementing Decision 2021/914) as the lawful transfer mechanism. These clauses impose data protection obligations on both parties to the transfer. A copy of the applicable Standard Contractual Clauses can be provided upon request by contacting privacy@refine.ink.
We have implemented equivalent safeguards with our third-party sub-processors that process personal data originating from the EEA or UK. Further details are available upon request.
10. How Long Do We Keep Your Information?
We retain different categories of personal information for different periods depending on their nature and purpose:
- Uploaded content and session data: Deleted permanently and unrecoverably when you delete a session from your history. We do not retain submitted manuscripts or generated feedback reports beyond the active session unless you choose to keep them.
- Account data (name, email address, account credentials): Retained for as long as your account is active and for a reasonable period thereafter as required to fulfill our legal and contractual obligations (for example, tax and accounting requirements).
- Log and diagnostic data: Retained for up to 90 days for security monitoring and operational purposes.
- Backup data: Retained for a minimum of 7 days as part of our standard backup lifecycle, after which backups are overwritten or deleted.
- Billing and transaction records: Retained for the period required by applicable tax and financial regulations.
When we have no ongoing legitimate business need to process your personal information, we will delete or anonymize it. If deletion is not immediately possible (for example, because personal information has been stored in backup archives), we will securely store your personal information, isolate it from any further processing, and delete it as soon as practicable.
11. How Do We Keep Your Information Safe?
We aim to protect your personal information through a system of organizational and technical security measures.
We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process. These include encryption of data in transit and at rest, access controls, and ongoing security monitoring. However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Although we will do our best to protect your personal information, transmission of personal information to and from our Services is at your own risk. You should only access the Services within a secure environment.
We are currently undergoing SOC 2 and ISO 27001 audits. Further information about our security program is available at trust.refine.ink.
What Happens in the Event of a Data Breach?
We maintain an incident response program designed to detect, contain, and remediate security incidents affecting personal information. In the event of a personal data breach, we will take the following steps:
- Regulatory notification. Where required by applicable law, we will notify the relevant supervisory authority within 72 hours of becoming aware of a breach (GDPR and UK GDPR), or within the timeframe required under applicable US state law.
- Individual notification. Where a breach is likely to result in a high risk to your rights and freedoms, we will notify affected individuals as soon as reasonably practicable, using the contact details we hold on record. We will provide information about the nature of the breach, the data affected, and the steps we are taking to address it.
- Remediation. We will investigate the breach, contain the incident, and take steps to prevent recurrence. We will document all breaches in accordance with our legal obligations regardless of whether regulatory notification is required.
If you have reason to believe that your personal information has been compromised, please contact us immediately at privacy@refine.ink.
12. Do We Collect Information From Minors?
We do not knowingly collect, solicit data from, or market to children under 18 years of age or the equivalent age as specified by law in your jurisdiction, nor do we knowingly sell such personal information. By using the Services, you represent that you are at least 18 or the equivalent minimum age as specified by law in your jurisdiction, or that you are the parent or guardian of such a minor and consent to such minor dependent's use of the Services. If we learn that personal information from users under 18 years of age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data we may have collected from children under age 18, please contact us at privacy@refine.ink.
13. What Are Your Privacy Rights?
Depending on your state of residence in the US or your region (including the EEA, UK, Switzerland, and Canada), you have rights that allow you greater access to and control over your personal information. You may review, change, or terminate your account at any time, depending on your country, province, or state of residence.
In some regions (like the EEA, UK, Switzerland, and Canada), you have certain rights under applicable data protection laws. These may include the right to:
- Request access to and obtain a copy of your personal information
- Request rectification or erasure of your personal information
- Restrict the processing of your personal information
- Data portability (where applicable)
- Object to the processing of your personal information
- Not be subject to automated decision-making that produces legal or similarly significant effects solely by automated means. Where such a decision is made, we will inform you, explain the main factors involved, and offer a simple way to request human review.
You can make such a request by contacting us using the details provided in the section How Can You Contact Us About This Notice? below. We will respond to your request within 1 month (or 45 days for California residents), subject to extension as permitted under applicable law.
If you are located in the EEA or UK and you believe we are unlawfully processing your personal information, you have the right to complain to your Member State data protection authority or UK data protection authority.
If you are located in Switzerland, you may contact the Federal Data Protection and Information Commissioner.
Withdrawing your consent: If we are relying on your consent to process your personal information, you have the right to withdraw your consent at any time by contacting us using the details provided below. Please note that this will not affect the lawfulness of the processing before its withdrawal.
Opting out of marketing and promotional communications: You can unsubscribe from our marketing and promotional communications at any time by clicking on the unsubscribe link in the emails that we send, or by contacting us using the details provided below. You will then be removed from the marketing lists. However, we may still communicate with you regarding service-related announcements or other non-promotional information.
14. Controls for Do-Not-Track Features
Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track (DNT) feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this Privacy Notice.
15. Do United States Residents Have Specific Privacy Rights?
If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Louisiana, Maryland, Minnesota, Mississippi, Montana, Nebraska, New Hampshire, New Jersey, New Mexico, New York, North Dakota, Ohio, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, or Wyoming, you may have the right to:
- Request access to a copy of the specific pieces of personal information that we have collected about you, and the categories of personal information we collect, the sources of that information, our business purpose for collecting that information, and the categories of third parties with whom we share information.
- Request deletion of the personal information we have collected from you, subject to certain exceptions.
- Correct inaccuracies in your personal information.
- Get a copy of your information in a portable and readily usable format.
- Opt out of the sale or sharing of your personal information to third parties.
You may make such requests by contacting us using the details provided in the section How Can You Contact Us About This Notice? below. We will validate your request by verifying your identity to the extent possible. If you are an authorized agent submitting a request on behalf of a consumer, we may need additional information to verify your identity as an authorized agent.
16. Do Other Regions Have Specific Privacy Rights?
United Kingdom
If you are located in the United Kingdom, you have the right to make a request regarding your personal information to the extent provided under the UK GDPR and the Data Protection Act 2018. You may request: what personal information we hold about you; how we use your personal information and on what legal basis; for how long we store your personal information; who it has been, or will be, shared with; and whether there are automated decision-making processes that affect you.
You may submit your request using the contact details provided in the section How Can You Contact Us About This Notice? below. If you believe we are processing your information in breach of applicable law, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).
17. Do We Make Updates To This Notice?
Yes, we will update this notice as necessary to stay compliant with relevant laws. When we make material changes to this Privacy Notice, we will notify you either by prominently posting a notice of such changes prior to implementing the change or by directly sending you a notification. We encourage you to review this Privacy Notice frequently to be informed of how we are protecting your information.
18. How Can You Contact Us About This Notice?
If you have questions or comments about this notice, you may email us at privacy@refine.ink or by post to: Refine Technologies, Inc., Privacy Department, 131 Continental Dr, Suite 305, Newark, DE 19713, USA.
Data protection inquiries are handled by the Information Security Officer. If you are located in the European Union or United Kingdom and have an unresolved concern about our privacy practices, you have the right to lodge a complaint with the local data protection authority responsible for your jurisdiction.
19. How Can You Review, Update, or Delete the Data We Collect From You?
You have the right to request access to, update, or delete your personal information. To submit a request, please contact us at privacy@refine.ink. We will respond to your request in accordance with applicable data protection laws.
Privacy Questions?
If you have questions about our privacy practices, please contact us at:
Refine Technologies, Inc. - Privacy Department
131 Continental Dr, Suite 305, Newark, DE 19713, USA
Email: privacy@refine.ink