The short version: Our apps are built to keep your work private. Your essays, PDFs, notes, highlights, and reference library stay on your devices and in your own iCloud account — we run no servers that store your content and have no access to it. All AI features run on your device. There is no advertising, no third-party analytics, and no tracking. The limited data that does leave your device — bibliographic lookups, optional integrations you enable, consent-gated crash reports, and anonymous subscription records — is described in full below.
This policy covers the apps Essayist and Researchist, developed by Essayist Software Inc., based in Canada ("we", "us"). The two apps share infrastructure — including iCloud sync of your reference library between them — so this single policy describes both. Where a data flow exists in only one app, it is labeled accordingly. You can reach us at contact@essayist.app.
The following never reaches our servers:
iCloud sync is provided by Apple under your Apple Account and governed by Apple's Privacy Policy. You can disable iCloud for either app at any time in your device's iCloud settings.
To find metadata for your sources, the apps query third-party scholarly databases. Requests contain only what is needed for the lookup — an identifier (DOI, arXiv ID, PubMed ID, ISBN, or similar), or a title/author search query — never your account information or any user identifier. Like any internet request, they reveal your IP address to the service.
If you choose to connect a Zotero account, Essayist accesses the Zotero API to import your collections, reference metadata, and PDF attachments. Sign-in happens on zotero.org; a small backend function we operate (on Google Firebase) performs the login handshake and passes the resulting access key to your device — it does not store your Zotero data. Your Zotero API key is kept in your iCloud Keychain, where we cannot read it. Zotero's handling of your account is governed by the Zotero Privacy Policy. You can disconnect Zotero at any time in Essayist's settings.
Essayist includes an in-app Google Scholar browser: your searches and browsing there go to Google just as they would in Safari, under Google's Privacy Policy. If you paste a link to generate a reference, Essayist fetches that page (and any PDF you choose to import) directly from the website you pasted, which sees the request as a normal visit.
Both apps — If an app crashes, it asks on the next launch whether to send a crash report. Nothing is sent unless you agree, and you are asked for each crash. Reports go to Google's Firebase Crashlytics and include technical details such as device model, OS version, and the state of the app at the time of the crash — none of your documents or notes, and nothing linked to your identity. See Firebase's privacy documentation.
Both apps — Apple's App Attest / DeviceCheck together with Firebase App Check exchange a device attestation token with Apple and Google confirming the app is a genuine, unmodified copy. It does not identify you personally.
Both apps — Subscriptions are processed by Apple through your Apple Account. To manage entitlements, the apps use RevenueCat, which receives your purchase receipt and subscription status under a randomly generated anonymous identifier — we do not link it to your name or email address. To understand how the apps are used and improve them, a few pieces of app-level information may be attached to this anonymous profile: your answer to the optional onboarding survey (for example, your role — student, educator, researcher) and coarse usage milestones such as when onboarding was completed or a paywall was shown. No document content, reading activity, or browsing data is ever included. See the RevenueCat Privacy Policy.
Both apps — When you import a paper from a link (for example an arXiv or publisher URL), the app downloads the file directly from the source you chose, which sees the request as it would a browser visit. Links you tap to view sources open in your browser.
The support options open a pre-filled email that includes the app version, OS version, and device model so we can help you faster. Researchist's "Report Extraction Problem" additionally includes the paper's identifier or URL and file name — never the PDF itself or any extracted text. You see the full email before sending and can edit or remove anything. We use what you send us solely to respond and to improve the apps.
Your content lives on your devices and in your iCloud account, so you control it: deleting an app removes its local data, and iCloud data can be removed in your device's iCloud storage settings. Disconnecting Zotero in Essayist's settings removes the stored access key. Consented crash reports are retained by Firebase Crashlytics for 90 days. Subscription records at RevenueCat are kept for as long as needed to manage your entitlement and meet legal obligations. To exercise any data rights — including access, correction, or deletion of data held by our service providers on our behalf — email contact@essayist.app and we will respond promptly.
The service providers named above — Google (Firebase), RevenueCat, the Allen Institute for AI (Semantic Scholar), Crossref, ISBNdb, and Zotero (Corporation for Digital Scholarship) — are based in the United States, so the limited data described above may be processed there. Where the GDPR or UK GDPR applies, these transfers are protected by appropriate safeguards, such as the provider's certification under the EU-U.S. Data Privacy Framework or standard contractual clauses.
Where the GDPR or UK GDPR applies, we process the limited data described above on these bases: performance of a contract (providing the apps and your subscription), consent (crash reports and optional integrations such as Zotero), and legitimate interests (preventing abuse of our services, fetching metadata you request, and understanding aggregate app usage).
You have the right to request access to, rectification or erasure of, or restriction of the processing of your personal data; the right to data portability; the right to object to processing based on legitimate interests; and the right to withdraw consent at any time (crash reporting asks before each report, so simply decline; integrations can be disconnected in settings). To exercise any of these rights, email contact@essayist.app. You also have the right to lodge a complaint with your local supervisory authority.
Our apps are not directed at children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from children.
If we change how the apps handle data, we will update this policy and revise the effective date above. Material changes will be highlighted in the apps or in release notes.
Questions about this policy or your data: contact@essayist.app