Skip to main content

Security and data handling

What stays on your computer, what is sent and where, and what RefPack's servers hold.

On your computer

Your manuscript, reference PDFs, projects, decisions and packs. The desktop app does the reading and the building.

Sent when you start an AI search

The selected reference PDFs and cited statements, to the AI provider you chose, after you confirm.

On RefPack's servers

Your account, project names and status, and billing. Not your documents.

On your computer

Projects are stored in a RefPack folder in your home directory. RefPack does not encrypt them; turn on FileVault on a Mac or BitLocker on Windows to encrypt your disk.

The desktop app listens only on your own computer and pairs with your signed-in browser before it accepts requests. Uninstalling the app does not delete your projects.

On RefPack's servers

  • Your account: email address and name
  • Projects: names, step status and counts
  • Billing: plan and payment records, handled by Stripe
  • Technical error reports, used to fix problems

RefPack's web app and database are hosted in the United States. The privacy policy explains how this information is used and your rights.

Service providers

ClerkSign-in and accounts
StripePayments
VercelWeb hosting and database
UpstashRate limiting
SentryError reports
CloudflareRelay for RefPack-funded AI searches
OpenAI, Microsoft AzureAI providers, when you choose them

Sensitive content

RefPack is built for manuscripts and published references. Before you send a document to an AI provider, check your client agreements and regulatory obligations, and leave out patient-identifiable information.

Report a vulnerability

Email security@refpack.io with the steps to reproduce. For procurement, we can share our data protection impact assessment and answer security questionnaires at the same address.