Publitera

Privacy Policy

Last updated August 20, 2026

Publitera ("we", "us") provides a personalized service that summarizes newly published medical and scientific literature and delivers it to you as digests. This policy explains what we collect, how we use it, and the choices you have. We do not sell your personal information, and we do not use third-party advertising or tracking.

Information we collect

Product activity logs intentionally do not contain passwords, authentication tokens, typed interest or form text, digest titles, prompts, article text, raw error messages, tracebacks, or arbitrary page URLs. They are first-party operational records, not third-party advertising or cross-site tracking.

How we use your information

How we share information

We share information only with service providers acting on our behalf, to the extent needed to run the service:

We do not sell your personal information or share it for advertising.

Public research content

To build digests, Publitera retrieves publicly available research metadata (for example from PubMed and journal sources). This is public literature data, not your personal information.

Data retention and deletion

We keep your account and content while your account is active. You can delete your account at any time from the app's Settings, which removes your account and personal content from active systems (residual copies in backups are purged on our normal backup cycle).

Under our standard configuration, detailed non-error product activity becomes eligible for automatic deletion after 180 days, detailed error activity after 365 days, and compact session evidence after 400 days. Privacy-bounded daily rollups become eligible after 1,095 days. Settled, content-free administrative-email delivery-cap and idempotency evidence becomes eligible only when its most recent delivery attempt is at least 1,095 days old or, if no attempt was made, 1,095 days after creation. Operational configuration may lengthen, but cannot shorten, these periods. A daily maintenance process first compacts each finalized activity day and confirms its aggregate coverage before deleting eligible detail. It never deletes an in-flight, unattempted, or retryable administrative-email record; those records are retained until delivery settles. If an account is deleted, granular activity, session identifiers, and the stable actor key are removed. Existing per-actor daily rollups are merged into an anonymous aggregate grain so the global event, error, and active-time totals used in summary and trend views are not silently rewritten, but that retained aggregate no longer identifies the deleted account. It does not reconstruct distinct-person or session counts and is not used to identify a person or to recreate feature-adoption, people-list, funnel, or surface detail. Authorized staff can access current activity information in Admin Central.

When an administrator enables an activity email alert, the selected event can also be sent through our existing administrative email system. Activity records still exclude typed interests, digest titles, raw errors, and other content listed above. A bounded delivery outbox temporarily holds the recipients and email copy needed for an enabled alert. That copy is erased when delivery reaches a terminal result or when account cleanup makes it unnecessary; a retryable notice keeps it only until delivery settles. Under the standard configuration, settled non-content delivery attempt records remain until their most recent attempt is at least 1,095 days old—or, if there was no attempt, until 1,095 days after creation—so the global email safety limit and idempotency protections cannot be bypassed; this period may be lengthened operationally. After a successful send, the subject, body, delivery metadata, and established operational detail are retained only in the administrative email log under its separate existing communications-retention policy. Deleting an account removes the account-linked Product Activity records described above and scrubs terminal outbox copy, but does not automatically erase already-sent administrative email records, including the established account-deletion notice. A pending account-deletion notice may retain its delivery copy only until that notice settles.

Security

Data is encrypted in transit, and we apply reasonable administrative and technical safeguards to protect it. No method of transmission or storage is completely secure.

Children

Publitera is intended for medical and research professionals and is not directed to children.

Changes

We may update this policy; we will revise the "Last updated" date above when we do.

Contact

Questions about privacy? Email support@publitera.com.