Skip to main content

Privacy Policy

Last updated July 6, 2026

This Privacy Notice for Refine Technologies, Inc. (doing business as Refine) ("we," "us," or "our") describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services").

Please read this Privacy Notice carefully. If you have any questions or concerns about our privacy practices, please don't hesitate to contact us.

1. Research Use and Model Training

A core value at Refine is that the content you upload is strictly confidential. We will not train any large language models on your uploaded content, and we do not permit our AI service providers to do so either.

AI model processing is routed through OpenRouter Enterprise, our LLM gateway provider. Our agreement with OpenRouter Enterprise contractually prohibits the use of submitted content to train or improve AI models. This obligation extends to the underlying model providers accessed through OpenRouter's infrastructure. This no-training guarantee applies to all users.

For users accessing Refine through an organizational account (institutional or enterprise tier), we additionally require Zero Data Retention (ZDR) with our LLM providers, meaning submitted content is not stored by any model provider even transiently. For individual consumer accounts, ZDR is not enabled; submitted content may be processed by model providers subject to their standard operational data handling practices, but use of your content for model training remains prohibited under our agreements with those providers. If you are interested in organizational access with ZDR enabled, please contact us at institutional-support@refine.ink.

Separately, we use PostHog for product analytics and session replay to improve our service and assist with troubleshooting. For users accessing Refine through an organizational account, session content is masked. For individual consumer accounts, this includes session recordings linked to your account. Where required by applicable law, including for users in the European Economic Area and United Kingdom, session replay will only be activated after you have provided your consent via our cookie consent banner. You may withdraw that consent at any time through our Cookie Policy. PostHog processes this data as a contracted sub-processor and is prohibited from using it for any purpose other than providing analytics services to Refine.

The content you upload may not be shared or sold by us or our providers to any third party.

Your data is protected by industry-standard security practices on Microsoft Azure infrastructure. When you delete a session in your history, we delete all its associated data permanently and unrecoverably.

We may use your interactions with comments to improve feedback ranking and quality. You may opt out of such use by notifying help@refine.ink from the email address associated with your Refine account.

For more information about our AI model gateway provider's privacy practices:

2. What Information Do We Collect?

Personal information you disclose to us

We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.

The personal information that we collect depends on the context of your interactions with us and the Services, the choices you make, and the products and features you use. The personal information we collect may include the following: names, email addresses, usernames, billing addresses, contact or authentication data, passwords.

We do not intentionally collect sensitive personal information. Uploaded content may incidentally contain such data, which we process solely to deliver the requested service and do not use for any other purpose.

We may collect data necessary to process your payment if you choose to make purchases, such as your payment instrument number and the security code associated with your payment instrument. All payment data is handled and stored by Stripe. You may find their privacy notice here: stripe.com/privacy.

We may provide you with the option to register with us using your existing social media account details, like your Google or other social media account. If you choose to register in this way, we will collect certain profile information about you from the social media provider. All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.

Information automatically collected

We automatically collect certain information when you visit, use, or navigate the Services. This information does not reveal your specific identity (like your name or contact information) but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, information about how and when you use our Services, and other technical information. This information is primarily needed to maintain the security and operation of our Services, and for our internal analytics and reporting purposes.

Like many businesses, we also collect information through cookies and similar technologies. You can find out more about this in our Cookie Notice: refine.ink/cookie-policy.

The information we collect includes: Log and Usage Data (service-related, diagnostic, usage, and performance information our servers automatically collect when you access or use our Services and which we record in log files) and Device Data (information about your computer, phone, tablet, or other device you use to access the Services, including IP address, device and application identification numbers, location, browser type, hardware model, Internet service provider and/or mobile carrier, operating system, and system configuration information).

Google API

Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

3. How Do We Process Your Information?

We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent.

We process personal information for the following purposes:

  • To facilitate account creation and authentication and otherwise manage user accounts. We may process your information so you can create and log in to your account, as well as keep your account in working order.
  • To deliver and facilitate delivery of services to the user. We may process your information to provide you with the requested service.
  • To process user-submitted content. We process the drafts or papers that users upload — which may incidentally contain personal information such as author names and institutional affiliations — in order to generate and return feedback as part of our service. Submitted content is processed through our AI pipeline solely to serve the submitting user.
  • To improve our services and troubleshoot issues. We use product analytics and session replay tools to understand how our Services are used and to diagnose technical issues. For individual consumer accounts, this may include session recordings linked to your account. See Section 5 for details on how this data is handled.
  • To respond to user inquiries and offer support. We may process your information to respond to your inquiries and solve any potential issues you might have with the requested service.
  • To fulfill and manage your orders. We may process your information to fulfill and manage your orders, payments, returns, and exchanges made through the Services.
  • To request feedback. We may process your information when necessary to request feedback and to contact you about your use of our Services.
  • To send you marketing and promotional communications. We may process the personal information you send to us for our marketing purposes, if this is in accordance with your marketing preferences. You can opt out of our marketing emails at any time.
  • To protect our Services. We may process your information as part of our efforts to keep our Services safe and secure, including fraud monitoring and prevention.
  • To identify usage trends. We may process information about how you use our Services to better understand how they are being used so we can improve them.
  • To determine the effectiveness of promotional campaigns. We track responses to campaigns and communications.

5. When and With Whom Do We Share Your Personal Information?

Service Providers and Sub-processors

We share your data with third-party vendors and service providers who perform services for us or on our behalf. We have contracts in place with all such parties designed to safeguard your personal information. They may not do anything with your personal information unless we have instructed them to do so, and they commit to protect the data they hold on our behalf.

We engage service providers in the following categories:

  • Cloud infrastructure: Microsoft Azure (primary compute, storage, and networking)
  • AI and LLM processing: OpenRouter Enterprise (LLM gateway). AI model processing is routed through OpenRouter, which contractually prohibits training on submitted content. The full list of current sub-processors, including the underlying model providers accessed through OpenRouter, is maintained at trust.refine.ink.
  • Document processing: Mathpix (mathematical notation and formula parsing of submitted documents)
  • Product analytics and session replay: PostHog. For users accessing Refine through an organizational account, session content associated with manuscript uploads is masked. For individual consumer accounts, PostHog may receive session recordings and usage events linked to your account, including content associated with your sessions, which Refine uses for product improvement and troubleshooting. PostHog processes this data under a Data Processing Agreement that prohibits use of the data for its own purposes, including AI model training.
  • Authentication: Clerk
  • Invoice and billing: Stripe
  • Email communications: Customer.io (transactional and marketing email delivery)
  • User account registration: Google Sign-In

The current named sub-processor list is maintained at trust.refine.ink and is updated in accordance with our vendor change management process. Institutional customers are notified of material sub-processor changes per the terms of their Data Processing Agreement. Session replay tools may be active during your use of the Services; please refer to our Cookie Policy for details and opt-out options.

Business Transfers

We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.

6. Do We Use Cookies and Other Tracking Technologies?

We may use cookies and similar tracking technologies (like web beacons and pixels) to gather information when you interact with our Services. Some online tracking technologies help us maintain the security of our Services and your account, prevent crashes, fix bugs, save your preferences, and assist with basic site functions.

We also permit third parties and service providers to use online tracking technologies on our Services for analytics and session replay purposes. These tools help us improve the Services and troubleshoot technical issues. Session replay tools may capture interactions with the Services, including for individual consumer accounts, content associated with your session. For users in the European Economic Area and United Kingdom, session replay tools will only be activated after you have provided your consent via our cookie consent banner. You may withdraw your consent at any time and update your preferences through our Cookie Policy.

To the extent these online tracking technologies are deemed to be a sale or sharing (which includes targeted advertising, as defined under applicable US state laws), you can opt out by submitting a request as described in the section Do United States Residents Have Specific Privacy Rights? below.

Specific information about how we use such technologies and how you can refuse certain cookies is set out in our Cookie Notice: refine.ink/cookie-policy.

7. Do We Offer Artificial Intelligence-Based Products?

Use of AI Technologies

As part of our Services, we offer products, features, or tools powered by artificial intelligence, machine learning, or similar technologies (collectively, "AI Products"). These tools are designed to enhance your experience and provide you with innovative solutions. The terms in this Privacy Notice govern your use of the AI Products within our Services.

AI model processing is provided through OpenRouter Enterprise, our LLM gateway, which routes requests to one or more underlying model providers. As outlined in Section 1 of this Privacy Notice, your submitted content will not be used to train or improve any AI models, and this restriction applies to OpenRouter and to the underlying model providers accessed through OpenRouter's infrastructure. This no-training guarantee applies to all users. Users accessing Refine through an organizational account additionally benefit from Zero Data Retention (ZDR), meaning submitted content is not stored by any model provider even transiently. See Section 1 for more detail on the ZDR tier distinction.

You must not use the AI Products in any way that violates the terms or policies of any AI service provider.

Our AI Products

Our AI Products are designed for the following functions: manuscript analysis, error detection in academic research, mathematical and logical reasoning analysis, and generation of structured feedback reports.

How We Process Your Data Using AI

All personal information processed using our AI Products is handled in line with this Privacy Notice and our agreements with third-party providers. Submitted content is processed through our AI pipeline solely to generate and return feedback to the submitting user. Refine's AI outputs are advisory in nature and do not constitute automated decisions with legal or similarly significant effects on users.

8. How Do We Handle Your Social Logins?

If you choose to register or log in to our Services using a social media account, we may have access to certain information about you.

Our Services offer you the ability to register and log in using your third-party social media account details (like your Google account). Where you choose to do this, we will receive certain profile information about you from your social media provider. The profile information we receive may vary depending on the social media provider concerned, but will often include your name, email address, and profile picture, as well as other information you choose to make public on such platform.

We will use the information we receive only for the purposes described in this Privacy Notice or that are otherwise made clear to you on the relevant Services. Please note that we do not control, and are not responsible for, other uses of your personal information by your third-party social media provider. We recommend that you review their privacy notice to understand how they collect, use, and share your personal information.

9. Is Your Information Transferred Internationally?

Our servers are located in the United States (Microsoft Azure, Central US region). Regardless of your location, please be aware that your information may be transferred to, stored by, and processed by us and the third-party providers with whom we share your personal information in the United States.

For users in the EEA, UK, and Switzerland

If you are a resident of the European Economic Area (EEA), United Kingdom (UK), or Switzerland, please be aware that the United States may not have data protection laws as comprehensive as those in your country. We take the following measures to protect your personal information in connection with international transfers:

Standard Contractual Clauses. For transfers of personal data from the EEA or UK to the United States, we rely on the European Commission's Standard Contractual Clauses (EU Commission Implementing Decision 2021/914) as the lawful transfer mechanism. These clauses impose data protection obligations on both parties to the transfer. A copy of the applicable Standard Contractual Clauses can be provided upon request by contacting privacy@refine.ink.

We have implemented equivalent safeguards with our third-party sub-processors that process personal data originating from the EEA or UK. Further details are available upon request.

10. How Long Do We Keep Your Information?

We retain different categories of personal information for different periods depending on their nature and purpose:

  • Uploaded content and session data: Deleted permanently and unrecoverably when you delete a session from your history. We do not retain submitted manuscripts or generated feedback reports beyond the active session unless you choose to keep them.
  • Account data (name, email address, account credentials): Retained for as long as your account is active and for a reasonable period thereafter as required to fulfill our legal and contractual obligations (for example, tax and accounting requirements).
  • Log and diagnostic data: Retained for up to 90 days for security monitoring and operational purposes.
  • Backup data: Retained for a minimum of 7 days as part of our standard backup lifecycle, after which backups are overwritten or deleted.
  • Billing and transaction records: Retained for the period required by applicable tax and financial regulations.

When we have no ongoing legitimate business need to process your personal information, we will delete or anonymize it. If deletion is not immediately possible (for example, because personal information has been stored in backup archives), we will securely store your personal information, isolate it from any further processing, and delete it as soon as practicable.

11. How Do We Keep Your Information Safe?

We aim to protect your personal information through a system of organizational and technical security measures.

We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process. These include encryption of data in transit and at rest, access controls, and ongoing security monitoring. However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Although we will do our best to protect your personal information, transmission of personal information to and from our Services is at your own risk. You should only access the Services within a secure environment.

We are currently undergoing SOC 2 and ISO 27001 audits. Further information about our security program is available at trust.refine.ink.

What Happens in the Event of a Data Breach?

We maintain an incident response program designed to detect, contain, and remediate security incidents affecting personal information. In the event of a personal data breach, we will take the following steps:

  1. Regulatory notification. Where required by applicable law, we will notify the relevant supervisory authority within 72 hours of becoming aware of a breach (GDPR and UK GDPR), or within the timeframe required under applicable US state law.
  2. Individual notification. Where a breach is likely to result in a high risk to your rights and freedoms, we will notify affected individuals as soon as reasonably practicable, using the contact details we hold on record. We will provide information about the nature of the breach, the data affected, and the steps we are taking to address it.
  3. Remediation. We will investigate the breach, contain the incident, and take steps to prevent recurrence. We will document all breaches in accordance with our legal obligations regardless of whether regulatory notification is required.

If you have reason to believe that your personal information has been compromised, please contact us immediately at privacy@refine.ink.

12. Do We Collect Information From Minors?

We do not knowingly collect, solicit data from, or market to children under 18 years of age or the equivalent age as specified by law in your jurisdiction, nor do we knowingly sell such personal information. By using the Services, you represent that you are at least 18 or the equivalent minimum age as specified by law in your jurisdiction, or that you are the parent or guardian of such a minor and consent to such minor dependent's use of the Services. If we learn that personal information from users under 18 years of age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data we may have collected from children under age 18, please contact us at privacy@refine.ink.

13. What Are Your Privacy Rights?

Depending on your state of residence in the US or your region (including the EEA, UK, Switzerland, and Canada), you have rights that allow you greater access to and control over your personal information. You may review, change, or terminate your account at any time, depending on your country, province, or state of residence.

In some regions (like the EEA, UK, Switzerland, and Canada), you have certain rights under applicable data protection laws. These may include the right to:

  • Request access to and obtain a copy of your personal information
  • Request rectification or erasure of your personal information
  • Restrict the processing of your personal information
  • Data portability (where applicable)
  • Object to the processing of your personal information
  • Not be subject to automated decision-making that produces legal or similarly significant effects solely by automated means. Where such a decision is made, we will inform you, explain the main factors involved, and offer a simple way to request human review.

You can make such a request by contacting us using the details provided in the section How Can You Contact Us About This Notice? below. We will respond to your request within 1 month (or 45 days for California residents), subject to extension as permitted under applicable law.

If you are located in the EEA or UK and you believe we are unlawfully processing your personal information, you have the right to complain to your Member State data protection authority or UK data protection authority.

If you are located in Switzerland, you may contact the Federal Data Protection and Information Commissioner.

Withdrawing your consent: If we are relying on your consent to process your personal information, you have the right to withdraw your consent at any time by contacting us using the details provided below. Please note that this will not affect the lawfulness of the processing before its withdrawal.

Opting out of marketing and promotional communications: You can unsubscribe from our marketing and promotional communications at any time by clicking on the unsubscribe link in the emails that we send, or by contacting us using the details provided below. You will then be removed from the marketing lists. However, we may still communicate with you regarding service-related announcements or other non-promotional information.

14. Controls for Do-Not-Track Features

Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track (DNT) feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this Privacy Notice.

15. Do United States Residents Have Specific Privacy Rights?

If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Louisiana, Maryland, Minnesota, Mississippi, Montana, Nebraska, New Hampshire, New Jersey, New Mexico, New York, North Dakota, Ohio, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, or Wyoming, you may have the right to:

  • Request access to a copy of the specific pieces of personal information that we have collected about you, and the categories of personal information we collect, the sources of that information, our business purpose for collecting that information, and the categories of third parties with whom we share information.
  • Request deletion of the personal information we have collected from you, subject to certain exceptions.
  • Correct inaccuracies in your personal information.
  • Get a copy of your information in a portable and readily usable format.
  • Opt out of the sale or sharing of your personal information to third parties.

You may make such requests by contacting us using the details provided in the section How Can You Contact Us About This Notice? below. We will validate your request by verifying your identity to the extent possible. If you are an authorized agent submitting a request on behalf of a consumer, we may need additional information to verify your identity as an authorized agent.

16. Do Other Regions Have Specific Privacy Rights?

United Kingdom

If you are located in the United Kingdom, you have the right to make a request regarding your personal information to the extent provided under the UK GDPR and the Data Protection Act 2018. You may request: what personal information we hold about you; how we use your personal information and on what legal basis; for how long we store your personal information; who it has been, or will be, shared with; and whether there are automated decision-making processes that affect you.

You may submit your request using the contact details provided in the section How Can You Contact Us About This Notice? below. If you believe we are processing your information in breach of applicable law, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).

17. Do We Make Updates To This Notice?

Yes, we will update this notice as necessary to stay compliant with relevant laws. When we make material changes to this Privacy Notice, we will notify you either by prominently posting a notice of such changes prior to implementing the change or by directly sending you a notification. We encourage you to review this Privacy Notice frequently to be informed of how we are protecting your information.

18. How Can You Contact Us About This Notice?

If you have questions or comments about this notice, you may email us at privacy@refine.ink or by post to: Refine Technologies, Inc., Privacy Department, 131 Continental Dr, Suite 305, Newark, DE 19713, USA.

Data protection inquiries are handled by the Information Security Officer. If you are located in the European Union or United Kingdom and have an unresolved concern about our privacy practices, you have the right to lodge a complaint with the local data protection authority responsible for your jurisdiction.

19. How Can You Review, Update, or Delete the Data We Collect From You?

You have the right to request access to, update, or delete your personal information. To submit a request, please contact us at privacy@refine.ink. We will respond to your request in accordance with applicable data protection laws.

Privacy Questions?

If you have questions about our privacy practices, please contact us at:

Refine Technologies, Inc. - Privacy Department

131 Continental Dr, Suite 305, Newark, DE 19713, USA

Email: privacy@refine.ink