RegCheck Privacy Policy
This Privacy Policy explains how RegCheck (“RegCheck”, “we”, “us”) collects and processes personal data when you use our website and services (the “Service”).
1) Data controller and contact
Data controller: Dr. Jamie Cummins, Fabrikstrasse 8, 3012 Bern, Switzerland.
Contact for privacy questions or deletion requests: jamie.cummins@unibe.ch
We do not currently appoint a data protection officer (DPO).
We act as the data controller for personal data processed to operate the Service. Our cloud infrastructure providers and the model provider you select generally act as processors (or sub-processors) when processing data on our behalf; in some cases they may act as independent controllers under their own terms.
2) Scope and important note about uploaded documents
The Service is intended for academic use. You may upload documents (e.g., papers, preregistrations) that can contain personal data (names, emails, acknowledgements, participant information, etc.).
Please do not upload sensitive personal data (e.g., health data, political opinions) unless you have a lawful basis to do so and it is strictly necessary. If feasible, redact sensitive content before uploading.
Data minimisation: Upload only what is necessary for the comparison and report generation.
3) Personal data we process and why
We process the following categories of data:
A. Content you upload (documents)
What: Papers, preregistrations, and related files you upload.
Why: To run the comparison and generate your report.
During processing: While a comparison runs, your uploaded file may be written to AWS S3 (object storage) to support reliable processing across our servers, and is deleted once processing finishes.
Stored with your report: To power the report viewer, we keep a copy of your source document and a rendered (PDF/text) view of it in AWS S3 for as long as the report itself is retained (see Section 7), then delete them. These document files are private — they are served only through access-controlled links, never made publicly readable on S3. We do not intentionally create separate backups of these files (subject to the underlying cloud provider’s standard technical operations).
B. Model prompts and outputs (processing data)
What: Prompts derived from your uploaded content and the resulting model outputs needed to generate the report.
Why: To generate report findings and quotations.
Where this goes: We send prompts/inputs to the model provider you select (see Section 5).
C. Reports and shareable report data (persistence)
What: Report content and quotations shown in the report viewer and any shareable report link.
Why: To let you view and share reports after processing.
We store the report’s text content and quotations in an encrypted Redis database, and the associated document files (your source document and its rendered view) in AWS S3, so that reports remain accessible via their link for the report’s lifetime (see Section 7: reports created without an account expire automatically after about 7 days; reports created while signed in are kept until you delete them).
D. Optional survey responses
What: Any feedback or survey responses you voluntarily submit.
Why: Product improvement and research/quality feedback.
Survey responses are stored keyed to the report they follow, so deleting the report (or its automatic expiry) also deletes the associated responses. They are not linked to your account, even when you are signed in. Please avoid including identifying or sensitive information in free-text fields.
E. Minimal operational and security data (logs)
What: Basic server and application logs (e.g., timestamps, request paths, error traces; may include IP addresses and user-agent strings as part of standard web/server operation).
Why: Security, abuse prevention, debugging, and reliability.
We do not use third-party analytics. We do not use advertising cookies. Accounts are optional (see Section 3G) — you can use RegCheck without signing in.
F. Local storage (device preferences)
What: Client-side local storage (e.g., UI preferences) and similar browser technologies.
Why: Convenience and usability.
We do not use advertising cookies.
G. Account data (optional sign-in)
What: If you choose to sign in with Google or ORCID, we receive and store a stable account identifier and, where the provider supplies it, your name and email address. We also store optional profile fields you enter (your role/use case, academic position, and research field) and any API keys you create — API keys are stored only as a hash and the full key is shown to you once.
Why: To keep your reports across sessions, let you set their visibility (public or private) and delete them, maintain a profile, and authenticate to the API. ORCID returns an ORCID iD (and name) but, under the scope we request, does not return your email.
Private reports: If you make a report private, we store the email addresses and/or ORCID iDs you grant access to. Those people can open the report once they sign in with a matching account; you can add or remove them at any time. We use these identifiers only to control access to that report.
Signing in is optional and only needed for persistent or private reports and for API access. Authentication is handled via Google and ORCID as identity providers; review their privacy terms for how they process the sign-in.
4) Legal bases (GDPR/UK GDPR)
Where GDPR/UK GDPR applies, our legal bases are:
- Performance of a contract (Art. 6(1)(b)): to provide the Service you request (processing uploads, sending prompts to your chosen model provider, generating and displaying reports, enabling report sharing).
- Legitimate interests (Art. 6(1)(f)): to maintain security, prevent abuse, troubleshoot, and ensure service reliability (including minimal logging).
- Consent (Art. 6(1)(a)): for optional survey responses (you can choose not to provide them).
We do not intentionally process special categories of personal data (Art. 9). If you upload such data, you are responsible for ensuring you have a lawful basis to do so.
Switzerland: We are based in Switzerland and process personal data in accordance with the Swiss Federal Act on Data Protection (nFADP), in addition to any other applicable laws.
5) Model providers and how they handle data
When you run a comparison, you choose which language model provider receives the prompts/inputs derived from your uploaded documents. These providers may process data in different jurisdictions and under different terms. Providers’ practices can change; you should review the provider documentation before choosing a provider.
Retrieval embeddings (always OpenAI): to find the passages of each document relevant to every comparison dimension, RegCheck computes text embeddings via the OpenAI API. This happens regardless of which provider you select for the comparison itself — so text from both documents is sent to OpenAI even when another provider is chosen as the judging model.
- OpenAI (API): OpenAI states that API inputs/outputs are not used to train models by default; it also describes retention of certain abuse monitoring logs. See OpenAI’s enterprise privacy page and their data-usage guide.
- DeepSeek: DeepSeek describes its data handling and jurisdictions in its documentation/policies, including that data may be processed in the People’s Republic of China (PRC). See DeepSeek’s platform privacy page and chat privacy policy.
- Groq (hosting Qwen3.6 27B): The open-weight Qwen model is served via Groq. Groq describes its retention approach and a Zero Data Retention (ZDR) option, and states it does not use inputs/outputs to train or fine-tune models unless explicitly permitted. See Groq’s data documentation.
- Anthropic (Claude): Anthropic states that inputs/outputs from its commercial products (including the Anthropic API) are not used to train its models by default; this differs from its consumer Claude apps, which RegCheck does not use. See Anthropic’s commercial terms and their data-usage documentation.
6) Sharing and access via report links
Each report has a long, random token link (an “unguessable URL”). How that link behaves depends on the report’s visibility:
- Public — anyone with the link can view it, and it is listed on your public profile page (if enabled). Anyone the link is forwarded to can open it.
- Private — only you and the specific people you grant access to (by email or ORCID iD) can open it, and they must sign in. The link alone is not enough.
Reports created without an account are always public. For public reports, do not share the link publicly or include sensitive information in uploads if you plan to share the resulting report.
7) Retention
- Uploaded files during processing (S3): the transient working copy used while a comparison runs is deleted automatically when processing finishes.
- Reports, quotations and their document files (Redis + S3): the report text/quotations (Redis) and the associated source/rendered document files (S3) share the report’s lifetime — reports generated without an account are automatically deleted about 7 days after creation; reports generated while signed in are retained until you delete them (from the report, your dashboard, or the API) or delete your account.
- Account data (database): Your account, profile, API keys, and any access grants on private reports are retained until you delete the relevant item (e.g. revoke a key, remove someone’s access) or delete your account; deleting your account also deletes your reports and their access grants.
- Survey responses: share the lifetime of the report they follow — they are deleted together with that report (including the automatic expiry of anonymous reports), or earlier on request.
- Server logs: retained for 1 day, then deleted.
For anonymous reports, we may not be able to locate a specific report without the report link or other identifying details you provide.
8) Security
We use reasonable technical and organisational measures, including:
- Encryption in transit (TLS) where supported.
- Encrypted Redis storage for report content, and private (non-public) AWS S3 storage for report document files, served only via access-controlled links.
- Access controls limited to essential systems/personnel.
No method of transmission or storage is 100% secure; however, we aim to use safeguards appropriate to the risk.
9) International data transfers
RegCheck is operated from Switzerland, but data may be processed in other countries depending on the infrastructure and the model provider you choose.
Where required, we rely on appropriate transfer mechanisms (e.g., contractual safeguards offered by providers). If you choose a provider that processes data in jurisdictions without an adequacy decision, your use of that provider may involve additional risks, and the transfer may be necessary to provide the Service you request using that provider.
10) Your rights and choices
Depending on your location and applicable law (including GDPR/UK GDPR and Swiss nFADP), you may have the right to:
- Request access to personal data we hold about you,
- Request deletion,
- Request correction (where applicable),
- Object to or request restriction of certain processing (where applicable),
- Withdraw consent for optional survey processing at any time (without affecting processing already performed).
Response timeline: Where required, we aim to respond to rights requests within 30 days.
Deletion requests: Email jamie.cummins@unibe.ch with the report link (or identifying details) and we will delete the relevant persisted report data and/or survey responses.
Local storage: You can clear local storage via your browser settings.
Complaints: You may lodge a complaint with your local supervisory authority. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC): the FDPIC website.
11) Changes to this policy
We may update this Policy from time to time. We will post the updated version and change the effective date above.