Security and data handling
What stays on your computer, what is sent and where, and what RefPack's servers hold.
On your computer
Your manuscript, reference PDFs, projects, decisions and packs. The desktop app does the reading and the building.
Sent when you start an AI search
The selected reference PDFs and cited statements, to the AI provider you chose, after you confirm.
On RefPack's servers
Your account, project names and status, and billing. Not your documents.
When you start an AI search
AI search is optional. Nothing leaves your computer until you start one; RefPack then names the destination and asks you to confirm.
| Topic | Your own API key | RefPack-funded plan |
|---|---|---|
| Route | From your computer straight to your provider: OpenAI or Azure OpenAI. | From your computer through RefPack's relay to the provider. |
| What is sent | The selected reference PDFs, the cited statements and the check instructions. | The same. |
| Files at the provider | PDFs travel inside each request. No file is stored with the provider. | Any file the relay stores with the provider expires within 24 hours and is deleted after the check. |
| Retention and training | Your agreement with your provider applies. | The provider's API data policy applies. The relay does not store your documents. |
On your computer
Projects are stored in a RefPack folder in your home directory. RefPack does not encrypt them; turn on FileVault on a Mac or BitLocker on Windows to encrypt your disk.
The desktop app listens only on your own computer and pairs with your signed-in browser before it accepts requests. Uninstalling the app does not delete your projects.
On RefPack's servers
- Your account: email address and name
- Projects: names, step status and counts
- Billing: plan and payment records, handled by Stripe
- Technical error reports, used to fix problems
RefPack's web app and database are hosted in the United States. The privacy policy explains how this information is used and your rights.
Service providers
| Clerk | Sign-in and accounts |
|---|---|
| Stripe | Payments |
| Vercel | Web hosting and database |
| Upstash | Rate limiting |
| Sentry | Error reports |
| Cloudflare | Relay for RefPack-funded AI searches |
| OpenAI, Microsoft Azure | AI providers, when you choose them |
Sensitive content
RefPack is built for manuscripts and published references. Before you send a document to an AI provider, check your client agreements and regulatory obligations, and leave out patient-identifiable information.
Report a vulnerability
Email security@refpack.io with the steps to reproduce. For procurement, we can share our data protection impact assessment and answer security questionnaires at the same address.