Privacy policy
Last updated: [DATE]. Draft — placeholders in [brackets] must be completed and the text reviewed by counsel before launch.
[COMPANY NAME], [ADDRESS] ("we") operates scientistworkbench.com and the ScientistWorkbench API. This policy explains what we collect and why. Contact: ops@scientistworkbench.com.
1. What we collect
- Account data: your email address, the organisation name you enter, sign-in timestamps, and the one-time sign-in links we issue (stored hashed).
- API and job data: API key hashes and labels, the prompts and files you submit, everything a job produces (reports, figures, tables, code, transcript, execution log, reviewer record), job metadata (timestamps, state, tokens, cost) and the credit ledger.
- Payment data: handled by Stripe; we receive the payment status, amount, a Stripe event id and a receipt link, never card numbers.
- Technical data: IP address and user agent in request logs (retained [30] days), used for security and rate limiting. We set one strictly necessary session cookie (
wb_session); we do not use analytics or advertising cookies.
2. Why we process it
To provide the Service you asked for (contract); to secure the Service, prevent abuse and keep records of what ran (legitimate interests); to bill you and keep accounts (contract, legal obligation); to send transactional email — sign-in links, low-balance and billing notices (contract). We do not send marketing email without consent.
3. Confidentiality of your data
Everything you upload or submit to the Service — prompts, input files, and everything a job produces from them (reports, figures, tables, code, transcripts, execution logs, reviewer records) — is your confidential information ("Customer Content"). We treat it as such:
- Never used to train models. We do not use Customer Content to train, fine-tune, evaluate or otherwise improve any machine-learning model, ours or anyone else's. Our model and sandbox provider is contractually bound to the same: Customer Content is processed only to run your job and is not used for training.
- Never disclosed. We do not sell, license, publish, share or otherwise disclose Customer Content to any third party, other than the sub-processors listed below acting on our instructions to run the Service, or where the law compels us (see below). We do not use it for benchmarking, marketing, case studies or examples without your prior written consent. The examples on this site come from our own synthetic datasets, not from customers.
- Never mixed with other customers. Each job runs in its own sandbox that is destroyed when the job ends; nothing carries over between jobs, and nothing is shared between customers. Files are mounted read-only and the upload is deleted after mounting. Outputs are stored under keys that belong to your account only and are served through expiring, signed links. Job ids are unguessable, and every read is checked against the account holding the API key.
- Limited human access. Our staff do not read Customer Content in the ordinary course of operating the Service. Access happens only when you ask us for support on a specific job, or when it is strictly necessary to investigate a security incident or abuse of the Service, and such access is logged.
- Legal requests. If we are legally compelled to disclose Customer Content, we disclose only what is required, challenge overbroad requests where we can, and notify you before disclosure unless the law prohibits it.
- Deletion. You can delete any job or your whole account from the dashboard or by emailing ops@scientistworkbench.com; Customer Content is then removed from live systems within 30 days and from backups on their normal rotation. Artifacts also expire automatically after 90 days. On request we confirm deletion in writing.
- Sub-processors bound the same way. Every sub-processor that can touch Customer Content is bound by written terms at least as protective as this section, including the no-training commitment.
These commitments apply regardless of your plan, and they survive termination of your account for as long as we hold any Customer Content.
4. Who we share it with (sub-processors)
- Model and sandbox provider (USA) — runs the models and the per-job sandbox; receives prompts and input files and produces outputs under commercial terms with no training on your content. Named in our DPA on request.
- Fly.io (USA) — application hosting and the database.
- Tigris Data (USA) — object storage for job files.
- Stripe, Inc. — payments.
- DreamHost, LLC (USA) — outbound transactional email (SMTP).
We do not sell personal data or Customer Content. Legal disclosures are handled as described in section 3.
5. International transfers
Data is processed in the United States. For customers in the EU/UK we rely on the EU Standard Contractual Clauses / UK Addendum through our DPA.
6. Retention
Job artifacts: 90 days. Result documents, ledger and account data: while your account exists and for [7] years afterwards where needed for tax and accounting. Sign-in links: 20 minutes (consumed links kept 30 days for abuse investigation). Request logs: [30] days.
7. Your rights
Depending on where you are, you may have rights to access, correct, delete, export or restrict processing of your personal data, and to complain to a supervisory authority. Email ops@scientistworkbench.com from the address on the account; we answer within 30 days.
8. Security
TLS everywhere; API keys stored only as SHA-256 hashes; sessions signed with a server secret; per-tenant storage keys; presigned expiring download links; secrets kept in the hosting platform's secret store. No system is perfectly secure; report issues to ops@scientistworkbench.com.
9. Children
The Service is not directed at anyone under 18.
10. Changes
We will post changes here and, for material changes, email account holders 14 days in advance.