Legal
Privacy Policy
What we collect, why we use it, where it lives, and the rights you have over it.
Last updated: [[DATE]]
In plain English: We collect what we need to run Littview and nothing we sell.
That's your account details, the research content you put into your projects
(references, PDFs, annotations, decisions, extracted data), a record of your
activity and AI usage, and basic billing status — your card details are handled by
Paddle and never reach us. When you use an AI feature, the relevant paper text and
your project's criteria are sent to OpenAI to generate the suggestion, and OpenAI
does not use that content to train its models. We use a small set of trusted
providers to host, email, measure and bill, all listed below. We keep your data
while your account is open, and delete it when you ask. You can access, correct,
export or delete your data by emailing info@littview.com.
1. Who we are
Littview Inc., a corporation constituted under the laws of Quebec, Canada (NEQ [[NEQ]]), is the data controller — in Quebec terms, the enterprise responsible — for the personal information described in this policy.
- Person in charge of the protection of personal information (privacy officer):
the President of Littview Inc., reachable at
info@littview.com - General and support contact:
support@littview.com - Postal address available on request.
We're subject to Quebec's Act respecting the protection of personal information in the private sector (as modernised by Law 25) and to Canada's PIPEDA. Where you're in the EEA or the UK, we also apply the GDPR standards described here.
2. What this policy covers
This policy covers the Littview marketing website (littview.com) and the
Littview application (app.littview.com). It does not cover third-party websites
we link to, or the publishers, databases and reference managers you obtain papers
from.
A note on roles. For your account, billing and usage data, we're the
controller. For the research content you upload — which is normally published
literature and its bibliographic metadata, but which you control — we handle it
on your instructions to provide the Service. If your institution needs a Data
Processing Agreement covering that content, contact us at info@littview.com
and we'll provide one.
3. Where your data comes from
Almost all of it comes from you: what you type, upload and do in the app. Some comes from Google if you choose to sign in with it (§4a), some from Paddle when you buy (§4d), and some is generated automatically as you use the Service (§4c, §4e, §4f).
4. What we collect
(a) Account data
Your email address, display name and nickname, avatar image if you upload one, your password in hashed form (we never store it in readable form), and authentication identifiers. If you use Sign in with Google, Google gives us your email address, name, and profile picture — we don't receive your Google password, and we don't get access to your Google account beyond that basic profile.
(b) Your research content
Everything you put into a project: reference libraries imported from BibTeX, RIS, PubMed MEDLINE or EndNote XML files; uploaded PDFs; PDF annotations and highlights; inclusion/exclusion criteria; screening decisions, votes, notes and conflict resolutions; data-extraction templates and the extracted data; project settings, tags and generated report text.
This content is normally published academic literature and its metadata — but it can contain personal data about third parties (author names and affiliations in citations, and anything you type into a note). See §9.
(c) Usage and activity data
Which projects you belong to, what you did in them and when (imports, screening decisions, extraction submissions, report generations), your assignments, and AI usage events — which AI feature was used, by whom, for which project, when, and how many credits it consumed. Project owners can see this per-member AI usage for their own projects, because AI usage is billed to the owner (Terms §5).
(d) Billing data
From Paddle we receive and store your subscription status, plan, billing cycle, renewal date, and Paddle's own subscription and customer identifiers, plus your credit balances and a ledger of credit purchases and spends. We do not receive or store your card number, CVC, or bank details — those go to Paddle directly (Terms §6). Paddle also processes your billing address and tax status, as its own controller, to calculate tax.
(e) Technical and log data
IP address, browser and device type, pages requested, timestamps and error information — produced automatically by our hosting, database, authentication and security layers, and used to run and defend the Service.
(f) Analytics, error reports and session recordings
We use PostHog (EU Cloud) to understand how the Service is used and to diagnose bugs. This covers page views, a small set of product events (project created, references imported, screening decision recorded, extraction submitted, report generated, checkout completed), uncaught application errors with technical context, and session recordings.
Analytics runs only if you accept it — see §13. Until you accept, nothing analytics-related is loaded and nothing is stored on your device.
About session recordings, specifically: we may record how you interact with
the app — mouse movement, clicks, navigation and page content — so we can
reproduce bugs and see where the interface confuses people. All input fields are
masked, so what you type into forms is not captured. Recordings are stored by
PostHog in the European Union. Analytics requests are routed through our own
domain, so you may see them as requests to app.littview.com/lv/… — the processor
is still PostHog.
When you're signed in, analytics events are associated with your account ID and email so we can support you and understand real workflows. Signed-out visitors are pseudonymous.
(g) Communications
Emails you send us and support tickets, so we can help you and keep a record of what was asked.
(h) What we deliberately do not collect
We don't collect special-category data by design, we don't buy data about you, we don't run advertising or advertising trackers, and we don't attach the contents of your forms to error reports.
5. Why we use it, and our legal basis
The same processing happens wherever you are. The legal-basis column below is framed under the GDPR, because it's the most prescriptive of the regimes that apply to us; under Quebec's Law 25 and Canada's PIPEDA the same purposes are covered by the consent you give when you create an account and by the exceptions those laws provide for performing a contract, meeting a legal obligation, and protecting the security of the service.
| What we do | Data used | Legal basis (GDPR) |
|---|---|---|
| Create and run your account; authenticate you | (a) account | Contract — Art. 6(1)(b) |
| Provide the review workflow: store and display your projects, references, PDFs, decisions and extractions | (b) content | Contract |
| Generate AI suggestions and report drafts when you invoke them | (b) content, (c) usage | Contract |
| Meter and bill AI credits; enforce plan limits | (c) usage, (d) billing | Contract |
| Take payment, renew subscriptions, issue invoices | (d) billing | Contract; legal obligation for tax/accounting records |
| Send transactional email: reviewer invitations, project notifications, report-ready notices, security and billing notices | (a) account | Contract, and legitimate interests in operating the Service |
| Keep the Service secure: rate limiting, bot protection, abuse and fraud detection, audit logs | (a), (c), (e) | Legitimate interests (security); legal obligation where applicable |
| Diagnose errors and fix bugs | (e), (f) | Legitimate interests (a working product) |
| Measure product usage and improve the Service, including session recordings | (f) | Consent — asked before anything runs, withdrawable any time (§13) |
| Provide support | (a), (g), and (b) only when you ask us to look at a specific project | Contract / legitimate interests |
| Comply with law; establish, exercise or defend legal claims | as needed | Legal obligation / legitimate interests |
| Send product or marketing email, if you opt in | (a) account | Consent — withdrawable any time |
On analytics and consent. Analytics and session recording run only after you accept them in our banner. Until then, nothing analytics-related is loaded and nothing is stored on your device — analytics is off by default. You can change your mind at any time (§13).
You have the right to object to anything we do on the basis of legitimate interests — see §12.
6. AI processing — the detail
When you use an AI feature, we send the following to our AI provider, OpenAI, over its API:
| Feature | What is sent |
|---|---|
| AI screening | The paper's title and abstract; your project's inclusion/exclusion criteria; a few already-decided papers from the project as examples. If you explicitly escalate a paper to full-text analysis, the extracted text of the PDF is also sent. |
| AI data extraction | The extracted text of the PDF, and your extraction template (fields, types, instructions). |
| AI conflict resolution | The paper's metadata, the reviewers' votes, their notes and annotations, and the project criteria. |
| Methods / Results report drafting | Project configuration and aggregated review data — criteria, screening setup, extraction template, screening counts, and extracted data across included papers. |
What this means for you:
- We do not send your account details, your colleagues' identities, or your billing data to the AI provider. Reviewer notes sent for conflict resolution are the content of the note, not a profile of the reviewer.
- Your content is not used to train AI models — neither by us (Terms §10) nor, under its API terms, by our provider. Content sent through OpenAI's API is not used to train its models by default, and is retained by OpenAI only for a limited abuse-monitoring window before deletion.
- Processing may occur outside your country, including in the United States — see §8.
- AI processing only happens when you invoke it. We don't send your content to the AI provider in the background, and Free accounts have no AI features at all, so nothing is sent for them.
7. Who we share data with (sub-processors)
We don't sell your data and we don't share it for advertising. We use these providers to run the Service, each under a contract that limits them to our instructions:
| Provider | What they do for us | What they handle | Where |
|---|---|---|---|
| Supabase | Database, authentication and file storage — the primary home of your account and content | (a) account, (b) content incl. PDFs, (c) usage, (e) logs | Canada (ca-central-1) |
| Cloudflare | Hosting and CDN for the app, plus Turnstile bot protection on sign-in forms | (e) technical/log data, traffic metadata | Global edge network |
| OpenAI | AI features — screening, extraction, conflict resolution, report drafting | (b) content submitted for AI processing (§6) | United States |
| Paddle (Paddle.com Market Ltd) | Merchant of Record — sells, charges, invoices, and remits tax | Payment and billing data, as its own controller | EU / UK / US |
| Amazon Web Services (SES) | Transactional email delivery, from noreply@littview.com | Recipient email addresses and message content | Canada (ca-central-1) |
| PostHog | Product analytics, error tracking and session recordings — only after you consent (§4f, §13) | (f) analytics data | European Union |
| "Sign in with Google" (only if you choose it) | Your email, name and profile picture, at sign-in | Global |
Your account and your research content are stored in Canada. Supabase hosts our database and file storage in the Canadian region, and our transactional email is sent from the Canadian AWS region. The routine flows outside Canada are two: OpenAI in the United States (content you submit to the AI features you invoke, §6) and PostHog in the European Union (analytics data, only if you've accepted analytics, §4f).
Not sub-processors, but worth naming: when you import from Zotero or look up open-access availability, data is fetched from those services at your request; we don't send them your content.
We may also disclose data if legally required (court order, valid legal process), to protect our rights, safety, or the security of the Service, or in connection with a merger, acquisition or sale of assets — in which case we'll notify you and the acquirer remains bound by this policy.
We keep this list current. Material additions are announced under §15.
8. International transfers
We're established in Quebec, Canada, and that's where your account and content are stored (§7). Some processing happens elsewhere — the United States (OpenAI, and parts of Cloudflare's and Paddle's infrastructure) and the European Union / UK (Paddle, and PostHog for analytics data).
- If you're in the EEA or the UK: transfers of your data to us in Canada rely on the European Commission's adequacy decision for Canada (and its UK equivalent), which covers commercial organisations subject to PIPEDA — so no Standard Contractual Clauses are needed for the EU→Canada leg. Onward transfers to the United States rely on an appropriate safeguard: Standard Contractual Clauses, or the EU–US Data Privacy Framework where the recipient is certified.
- If you're in Quebec: before sending personal information outside Quebec we assess whether it will receive adequate protection, taking account of the sensitivity of the information, the purpose, the protections in place and the legal framework where it's going — and the transfer is covered by a written agreement with the provider. This is what Law 25 requires, and we do it for each provider in §7.
You can ask us for details of the safeguard applying to a specific transfer at
info@littview.com.
9. Personal data about other people
Two situations where you give us data about someone else:
- Inviting colleagues. When you invite a reviewer, you give us their email
address and we email them an invitation from
noreply@littview.com. Please invite only people who expect it. If you're invited and don't want an account, ignore the email — or write to us and we'll remove the record. - Content that contains personal data. Bibliographic records contain author names and affiliations, and your notes may mention people. That's normal research use. You're responsible for having a lawful basis for any personal data you put into Littview, and for not uploading identifiable patient, participant or other special-category data without a specific agreement with us (Terms §9).
If you're an author whose personal data appears in someone's private research
project and you want to exercise rights over it, contact us at
info@littview.com — we'll route the request to the controller (the
project owner) and support them in answering it.
10. How long we keep things
| Data | Retention |
|---|---|
| Account data | While your account exists, then deleted on closure or request (see below) |
| Your research content (references, PDFs, annotations, decisions, extractions, reports) | While your account exists — we never delete project data because you downgraded to Free (Terms §7) |
| AI usage events and credit ledger | While your account exists, then 12 months — they're the record behind what you were charged |
| Billing records (invoices, payment status) | 6 years from the end of the tax year they relate to, as Canadian tax law requires |
| Technical and security logs | 30 days |
| Analytics events | 12 months |
| Session recordings | 30 days |
| Support emails | 24 months from last contact |
| Backups | Deleted content persists in encrypted backups until they age out — normally within 30 days |
Deleting your account. Email info@littview.com from your account address
and ask us to delete your account. We'll confirm your identity, give you a chance
to export your work, and then delete your account and content within
30 days, except where we must keep billing and tax records (row 4 above)
and except for backups aging out. Deletion is permanent.
11. How we protect your data
- Access control at the database level. Every table enforces row-level security, so a query can only ever return rows the signed-in user is entitled to. Permission checks that matter — project membership, ownership, plan limits, credit balances — are enforced on the server, not in the browser.
- Encryption. Data is encrypted in transit (HTTPS/TLS everywhere) and at rest by our hosting provider.
- Private file storage. Uploaded PDFs live in private buckets and are served through short-lived signed URLs; they are not publicly addressable.
- Authentication hardening. Passwords are hashed, sign-in uses the PKCE OAuth flow, and sign-in forms are protected against automated abuse by Cloudflare Turnstile. A Content Security Policy is enforced on the app.
- Least privilege and audit. Administrative operations are restricted and logged; production access is limited to those who need it.
No system is perfectly secure. If a confidentiality incident affects your personal information and presents a risk of serious injury, we'll notify you and the Commission d'accès à l'information du Québec, and any other authority the law requires, with reasonable promptness — and tell you plainly what happened and what to do. We keep a register of confidentiality incidents, as Quebec law requires.
12. Your rights
Depending on where you live, you have some or all of these rights:
- Access — get a copy of the personal data we hold about you.
- Rectification — correct anything inaccurate (you can edit most of it in the app yourself).
- Erasure — have your data deleted (§10).
- Portability — receive the personal information you gave us in a structured, commonly used technological format. In the app you can already export evidence tables to CSV and Methods and PRISMA sections to DOCX; for a full export, ask us.
- Restriction and objection — including the right to object to processing based on legitimate interests.
- Withdraw consent — where we rely on consent (for example marketing email), you can withdraw it at any time without affecting past processing.
- No automated decision-making. We don't make decisions with legal or similarly significant effects about you by automated means. AI features suggest to you; they don't decide about you.
How to exercise them: email info@littview.com from your account address.
We respond within 30 days. There's no charge unless a request is manifestly
unfounded or excessive.
Complaints. Tell us first — we'd like the chance to fix it. You can also
complain to the Commission d'accès à l'information du Québec (cai.gouv.qc.ca),
to the Office of the Privacy Commissioner of Canada (priv.gc.ca), or to your
own local data protection authority if you're outside Canada.
If you're in the United States. We do not sell your personal information, and we do not share it for cross-context behavioural advertising or targeted advertising. We don't run advertising at all. The access, correction, deletion and portability rights above are offered to everyone, wherever you live, and we won't treat you differently for exercising them.
13. Cookies and similar technologies
We use very little, and nothing for advertising. No advertising cookies, no cross-site trackers. Analytics items are stored on your device only after you accept them.
| Cookie / storage | Purpose | Category |
|---|---|---|
lv_consent | Remembers your analytics choice | Strictly necessary |
| Supabase authentication tokens (browser local storage) | Keeps you signed in | Strictly necessary |
| Cloudflare Turnstile | Bot protection on sign-in and sign-up | Strictly necessary |
| Paddle checkout cookies | Runs the payment checkout — set only when you open checkout, on Paddle's domain | Strictly necessary / payment |
PostHog ph_* (cookie + local storage) | Recognises a returning visitor for analytics | Analytics — set only after you accept |
Strictly necessary items can't be switched off — without them you can't sign in or pay, and consent isn't required for them under EU/UK or Quebec rules. Analytics items are off by default: nothing analytics-related is loaded or stored until you say yes — on our website via the consent banner, and in the app when we ask on your first signed-in visit. "Accept" and "Reject" are equally prominent, and you can change your choice at any time via the "Cookie settings" link in the website footer or in the app's Account settings.
14. Children
The Service is not directed at children and is not intended for anyone under
18. We don't knowingly collect data from children. If you believe a
child has given us personal data, contact info@littview.com and we'll delete
it.
15. Changes to this policy
We'll update this policy as the Service changes. For material changes — a new category of data, a new purpose, or a new sub-processor handling your content — we'll give notice by email and/or in the app 30 days before it takes effect, and we'll always update the "Last updated" date. Minor clarifications take effect on posting.
16. Contact
Littview Inc. — a Quebec, Canada corporation
Privacy questions and requests: info@littview.com (person in charge of the
protection of personal information)
Support: support@littview.com
Postal address available on request.