1. Who we are
RefPack (“we”, “us”) provides the website at refpack.io, the web app at app.refpack.io and the RefPack desktop app. This policy explains what personal information we process when you use them, why, and the choices you have.
2. How RefPack is built
- The desktop app runs on your computer. It reads your manuscript and reference PDFs, stores your projects and builds your reference packs there. The web app talks to it on your own computer.
- The web app runs in your browser. Our servers hold your account, project names and status, and billing records, not your documents.
- AI search is optional. When you start it, the selected reference PDFs and cited statements are sent to an AI provider, as described in section 4.
3. Information we collect
Account information
When you create an account, our sign-in provider Clerk processes your email address, your name if you give it, and how you sign in. Clerk manages passwords and sign-in security.
Billing information
If you take a paid plan, Stripe processes your payment details. We keep your plan, subscription status and transaction records. We do not store card numbers.
Project information
We store project names, the status of each step, counts such as the number of statements and references, and your settings.
Feedback
When you send feedback from the app, we store your message, its category, any rating you give and your account identifier.
Technical information
We use Sentry to receive error reports, which can include the page address, browser details and an account identifier. Upstash processes IP addresses briefly to limit request rates and protect the service. Our hosting provider keeps standard server logs.
What stays on your computer
Your manuscripts, reference PDFs, extracted text, decisions, notes and packs are stored by the desktop app on your computer. We do not receive them, except for what an AI search sends as described below.
4. AI search
When you start an AI search, the selected reference PDFs and cited statements, with the check instructions, are sent to an AI provider. RefPack shows the destination and asks you to confirm before anything is sent.
- With your own API key (OpenAI or Azure OpenAI), requests go straight from your computer to your provider under your agreement with them. Reference PDFs travel inside each request and no file is stored with the provider.
- On a plan with RefPack-funded searches, requests go through RefPack's relay, run on Cloudflare, to OpenAI under RefPack's account. The relay does not store your documents. Any file stored with the provider expires within 24 hours and is deleted after the check. We record usage, such as the amount and time of each search, for billing.
The provider's own data policy also applies. OpenAI states that data sent through its API is not used to train its models by default.
5. Cookies and local storage
We use essential cookies to keep you signed in and to protect your account. We do not use advertising or analytics cookies. Your browser's local storage keeps small preferences, such as your theme and whether you have dismissed the cookie notice.
6. How we use information
We use personal information to provide and secure RefPack, to bill paid plans, to answer support requests, to fix problems and to improve the product from your feedback. We do not sell personal information, and we do not use it for advertising.
7. Service providers
| Provider | What they do for RefPack |
|---|---|
| Clerk | Sign-in and accounts |
| Stripe | Payments |
| Vercel | Hosting for the website, web app and database |
| Upstash | Rate limiting |
| Sentry | Error reports |
| Cloudflare | The relay for RefPack-funded AI searches |
| OpenAI | AI searches on RefPack-funded plans |
Some of these providers process information in the United States. Where the law requires it, transfers rely on appropriate safeguards such as standard contractual clauses.
8. How long we keep information
- Account information: while your account is open.
- Project information: until you delete the project or your account.
- Billing records: as long as the law requires.
- Feedback and error reports: for a limited period, while they help us fix or improve RefPack.
- Data on your computer: until you delete it. Uninstalling the desktop app does not delete your projects.
9. Your rights
Depending on where you live, you can ask to access, correct, delete or export your personal information, object to or restrict some processing, and withdraw consent. Email support@refpack.io to make a request. You can also complain to your data protection authority.
10. Security
Connections to RefPack are encrypted, sign-in is handled by Clerk, and the desktop app pairs with your signed-in browser before it accepts requests. Files on your computer are not encrypted by RefPack; turn on your computer's disk encryption. Read more on the security page.
11. Children
RefPack is not intended for anyone under 18.
12. Changes to this policy
We update the date at the top when this policy changes, and tell account holders about significant changes.
13. Contact
Questions about this policy: support@refpack.io.