Skip to content

Legal

Privacy Policy

What we collect, why we use it, where it lives, and the rights you have over it.

Last updated: [[DATE]]

In plain English: We collect what we need to run Littview and nothing we sell. That's your account details, the research content you put into your projects (references, PDFs, annotations, decisions, extracted data), a record of your activity and AI usage, and basic billing status — your card details are handled by Paddle and never reach us. When you use an AI feature, the relevant paper text and your project's criteria are sent to OpenAI to generate the suggestion, and OpenAI does not use that content to train its models. We use a small set of trusted providers to host, email, measure and bill, all listed below. We keep your data while your account is open, and delete it when you ask. You can access, correct, export or delete your data by emailing info@littview.com.


1. Who we are

Littview Inc., a corporation constituted under the laws of Quebec, Canada (NEQ [[NEQ]]), is the data controller — in Quebec terms, the enterprise responsible — for the personal information described in this policy.

  • Person in charge of the protection of personal information (privacy officer): the President of Littview Inc., reachable at info@littview.com
  • General and support contact: support@littview.com
  • Postal address available on request.

We're subject to Quebec's Act respecting the protection of personal information in the private sector (as modernised by Law 25) and to Canada's PIPEDA. Where you're in the EEA or the UK, we also apply the GDPR standards described here.

2. What this policy covers

This policy covers the Littview marketing website (littview.com) and the Littview application (app.littview.com). It does not cover third-party websites we link to, or the publishers, databases and reference managers you obtain papers from.

A note on roles. For your account, billing and usage data, we're the controller. For the research content you upload — which is normally published literature and its bibliographic metadata, but which you control — we handle it on your instructions to provide the Service. If your institution needs a Data Processing Agreement covering that content, contact us at info@littview.com and we'll provide one.

3. Where your data comes from

Almost all of it comes from you: what you type, upload and do in the app. Some comes from Google if you choose to sign in with it (§4a), some from Paddle when you buy (§4d), and some is generated automatically as you use the Service (§4c, §4e, §4f).

4. What we collect

(a) Account data

Your email address, display name and nickname, avatar image if you upload one, your password in hashed form (we never store it in readable form), and authentication identifiers. If you use Sign in with Google, Google gives us your email address, name, and profile picture — we don't receive your Google password, and we don't get access to your Google account beyond that basic profile.

(b) Your research content

Everything you put into a project: reference libraries imported from BibTeX, RIS, PubMed MEDLINE or EndNote XML files; uploaded PDFs; PDF annotations and highlights; inclusion/exclusion criteria; screening decisions, votes, notes and conflict resolutions; data-extraction templates and the extracted data; project settings, tags and generated report text.

This content is normally published academic literature and its metadata — but it can contain personal data about third parties (author names and affiliations in citations, and anything you type into a note). See §9.

(c) Usage and activity data

Which projects you belong to, what you did in them and when (imports, screening decisions, extraction submissions, report generations), your assignments, and AI usage events — which AI feature was used, by whom, for which project, when, and how many credits it consumed. Project owners can see this per-member AI usage for their own projects, because AI usage is billed to the owner (Terms §5).

(d) Billing data

From Paddle we receive and store your subscription status, plan, billing cycle, renewal date, and Paddle's own subscription and customer identifiers, plus your credit balances and a ledger of credit purchases and spends. We do not receive or store your card number, CVC, or bank details — those go to Paddle directly (Terms §6). Paddle also processes your billing address and tax status, as its own controller, to calculate tax.

(e) Technical and log data

IP address, browser and device type, pages requested, timestamps and error information — produced automatically by our hosting, database, authentication and security layers, and used to run and defend the Service.

(f) Analytics, error reports and session recordings

We use PostHog (EU Cloud) to understand how the Service is used and to diagnose bugs. This covers page views, a small set of product events (project created, references imported, screening decision recorded, extraction submitted, report generated, checkout completed), uncaught application errors with technical context, and session recordings.

Analytics runs only if you accept it — see §13. Until you accept, nothing analytics-related is loaded and nothing is stored on your device.

About session recordings, specifically: we may record how you interact with the app — mouse movement, clicks, navigation and page content — so we can reproduce bugs and see where the interface confuses people. All input fields are masked, so what you type into forms is not captured. Recordings are stored by PostHog in the European Union. Analytics requests are routed through our own domain, so you may see them as requests to app.littview.com/lv/… — the processor is still PostHog.

When you're signed in, analytics events are associated with your account ID and email so we can support you and understand real workflows. Signed-out visitors are pseudonymous.

(g) Communications

Emails you send us and support tickets, so we can help you and keep a record of what was asked.

(h) What we deliberately do not collect

We don't collect special-category data by design, we don't buy data about you, we don't run advertising or advertising trackers, and we don't attach the contents of your forms to error reports.

The same processing happens wherever you are. The legal-basis column below is framed under the GDPR, because it's the most prescriptive of the regimes that apply to us; under Quebec's Law 25 and Canada's PIPEDA the same purposes are covered by the consent you give when you create an account and by the exceptions those laws provide for performing a contract, meeting a legal obligation, and protecting the security of the service.

What we doData usedLegal basis (GDPR)
Create and run your account; authenticate you(a) accountContract — Art. 6(1)(b)
Provide the review workflow: store and display your projects, references, PDFs, decisions and extractions(b) contentContract
Generate AI suggestions and report drafts when you invoke them(b) content, (c) usageContract
Meter and bill AI credits; enforce plan limits(c) usage, (d) billingContract
Take payment, renew subscriptions, issue invoices(d) billingContract; legal obligation for tax/accounting records
Send transactional email: reviewer invitations, project notifications, report-ready notices, security and billing notices(a) accountContract, and legitimate interests in operating the Service
Keep the Service secure: rate limiting, bot protection, abuse and fraud detection, audit logs(a), (c), (e)Legitimate interests (security); legal obligation where applicable
Diagnose errors and fix bugs(e), (f)Legitimate interests (a working product)
Measure product usage and improve the Service, including session recordings(f)Consent — asked before anything runs, withdrawable any time (§13)
Provide support(a), (g), and (b) only when you ask us to look at a specific projectContract / legitimate interests
Comply with law; establish, exercise or defend legal claimsas neededLegal obligation / legitimate interests
Send product or marketing email, if you opt in(a) accountConsent — withdrawable any time

On analytics and consent. Analytics and session recording run only after you accept them in our banner. Until then, nothing analytics-related is loaded and nothing is stored on your device — analytics is off by default. You can change your mind at any time (§13).

You have the right to object to anything we do on the basis of legitimate interests — see §12.

6. AI processing — the detail

When you use an AI feature, we send the following to our AI provider, OpenAI, over its API:

FeatureWhat is sent
AI screeningThe paper's title and abstract; your project's inclusion/exclusion criteria; a few already-decided papers from the project as examples. If you explicitly escalate a paper to full-text analysis, the extracted text of the PDF is also sent.
AI data extractionThe extracted text of the PDF, and your extraction template (fields, types, instructions).
AI conflict resolutionThe paper's metadata, the reviewers' votes, their notes and annotations, and the project criteria.
Methods / Results report draftingProject configuration and aggregated review data — criteria, screening setup, extraction template, screening counts, and extracted data across included papers.

What this means for you:

  • We do not send your account details, your colleagues' identities, or your billing data to the AI provider. Reviewer notes sent for conflict resolution are the content of the note, not a profile of the reviewer.
  • Your content is not used to train AI models — neither by us (Terms §10) nor, under its API terms, by our provider. Content sent through OpenAI's API is not used to train its models by default, and is retained by OpenAI only for a limited abuse-monitoring window before deletion.
  • Processing may occur outside your country, including in the United States — see §8.
  • AI processing only happens when you invoke it. We don't send your content to the AI provider in the background, and Free accounts have no AI features at all, so nothing is sent for them.

7. Who we share data with (sub-processors)

We don't sell your data and we don't share it for advertising. We use these providers to run the Service, each under a contract that limits them to our instructions:

ProviderWhat they do for usWhat they handleWhere
SupabaseDatabase, authentication and file storage — the primary home of your account and content(a) account, (b) content incl. PDFs, (c) usage, (e) logsCanada (ca-central-1)
CloudflareHosting and CDN for the app, plus Turnstile bot protection on sign-in forms(e) technical/log data, traffic metadataGlobal edge network
OpenAIAI features — screening, extraction, conflict resolution, report drafting(b) content submitted for AI processing (§6)United States
Paddle (Paddle.com Market Ltd)Merchant of Record — sells, charges, invoices, and remits taxPayment and billing data, as its own controllerEU / UK / US
Amazon Web Services (SES)Transactional email delivery, from noreply@littview.comRecipient email addresses and message contentCanada (ca-central-1)
PostHogProduct analytics, error tracking and session recordings — only after you consent (§4f, §13)(f) analytics dataEuropean Union
Google"Sign in with Google" (only if you choose it)Your email, name and profile picture, at sign-inGlobal

Your account and your research content are stored in Canada. Supabase hosts our database and file storage in the Canadian region, and our transactional email is sent from the Canadian AWS region. The routine flows outside Canada are two: OpenAI in the United States (content you submit to the AI features you invoke, §6) and PostHog in the European Union (analytics data, only if you've accepted analytics, §4f).

Not sub-processors, but worth naming: when you import from Zotero or look up open-access availability, data is fetched from those services at your request; we don't send them your content.

We may also disclose data if legally required (court order, valid legal process), to protect our rights, safety, or the security of the Service, or in connection with a merger, acquisition or sale of assets — in which case we'll notify you and the acquirer remains bound by this policy.

We keep this list current. Material additions are announced under §15.

8. International transfers

We're established in Quebec, Canada, and that's where your account and content are stored (§7). Some processing happens elsewhere — the United States (OpenAI, and parts of Cloudflare's and Paddle's infrastructure) and the European Union / UK (Paddle, and PostHog for analytics data).

  • If you're in the EEA or the UK: transfers of your data to us in Canada rely on the European Commission's adequacy decision for Canada (and its UK equivalent), which covers commercial organisations subject to PIPEDA — so no Standard Contractual Clauses are needed for the EU→Canada leg. Onward transfers to the United States rely on an appropriate safeguard: Standard Contractual Clauses, or the EU–US Data Privacy Framework where the recipient is certified.
  • If you're in Quebec: before sending personal information outside Quebec we assess whether it will receive adequate protection, taking account of the sensitivity of the information, the purpose, the protections in place and the legal framework where it's going — and the transfer is covered by a written agreement with the provider. This is what Law 25 requires, and we do it for each provider in §7.

You can ask us for details of the safeguard applying to a specific transfer at info@littview.com.

9. Personal data about other people

Two situations where you give us data about someone else:

  1. Inviting colleagues. When you invite a reviewer, you give us their email address and we email them an invitation from noreply@littview.com. Please invite only people who expect it. If you're invited and don't want an account, ignore the email — or write to us and we'll remove the record.
  2. Content that contains personal data. Bibliographic records contain author names and affiliations, and your notes may mention people. That's normal research use. You're responsible for having a lawful basis for any personal data you put into Littview, and for not uploading identifiable patient, participant or other special-category data without a specific agreement with us (Terms §9).

If you're an author whose personal data appears in someone's private research project and you want to exercise rights over it, contact us at info@littview.com — we'll route the request to the controller (the project owner) and support them in answering it.

10. How long we keep things

DataRetention
Account dataWhile your account exists, then deleted on closure or request (see below)
Your research content (references, PDFs, annotations, decisions, extractions, reports)While your account exists — we never delete project data because you downgraded to Free (Terms §7)
AI usage events and credit ledgerWhile your account exists, then 12 months — they're the record behind what you were charged
Billing records (invoices, payment status)6 years from the end of the tax year they relate to, as Canadian tax law requires
Technical and security logs30 days
Analytics events12 months
Session recordings30 days
Support emails24 months from last contact
BackupsDeleted content persists in encrypted backups until they age out — normally within 30 days

Deleting your account. Email info@littview.com from your account address and ask us to delete your account. We'll confirm your identity, give you a chance to export your work, and then delete your account and content within 30 days, except where we must keep billing and tax records (row 4 above) and except for backups aging out. Deletion is permanent.

11. How we protect your data

  • Access control at the database level. Every table enforces row-level security, so a query can only ever return rows the signed-in user is entitled to. Permission checks that matter — project membership, ownership, plan limits, credit balances — are enforced on the server, not in the browser.
  • Encryption. Data is encrypted in transit (HTTPS/TLS everywhere) and at rest by our hosting provider.
  • Private file storage. Uploaded PDFs live in private buckets and are served through short-lived signed URLs; they are not publicly addressable.
  • Authentication hardening. Passwords are hashed, sign-in uses the PKCE OAuth flow, and sign-in forms are protected against automated abuse by Cloudflare Turnstile. A Content Security Policy is enforced on the app.
  • Least privilege and audit. Administrative operations are restricted and logged; production access is limited to those who need it.

No system is perfectly secure. If a confidentiality incident affects your personal information and presents a risk of serious injury, we'll notify you and the Commission d'accès à l'information du Québec, and any other authority the law requires, with reasonable promptness — and tell you plainly what happened and what to do. We keep a register of confidentiality incidents, as Quebec law requires.

12. Your rights

Depending on where you live, you have some or all of these rights:

  • Access — get a copy of the personal data we hold about you.
  • Rectification — correct anything inaccurate (you can edit most of it in the app yourself).
  • Erasure — have your data deleted (§10).
  • Portability — receive the personal information you gave us in a structured, commonly used technological format. In the app you can already export evidence tables to CSV and Methods and PRISMA sections to DOCX; for a full export, ask us.
  • Restriction and objection — including the right to object to processing based on legitimate interests.
  • Withdraw consent — where we rely on consent (for example marketing email), you can withdraw it at any time without affecting past processing.
  • No automated decision-making. We don't make decisions with legal or similarly significant effects about you by automated means. AI features suggest to you; they don't decide about you.

How to exercise them: email info@littview.com from your account address. We respond within 30 days. There's no charge unless a request is manifestly unfounded or excessive.

Complaints. Tell us first — we'd like the chance to fix it. You can also complain to the Commission d'accès à l'information du Québec (cai.gouv.qc.ca), to the Office of the Privacy Commissioner of Canada (priv.gc.ca), or to your own local data protection authority if you're outside Canada.

If you're in the United States. We do not sell your personal information, and we do not share it for cross-context behavioural advertising or targeted advertising. We don't run advertising at all. The access, correction, deletion and portability rights above are offered to everyone, wherever you live, and we won't treat you differently for exercising them.

13. Cookies and similar technologies

We use very little, and nothing for advertising. No advertising cookies, no cross-site trackers. Analytics items are stored on your device only after you accept them.

Cookie / storagePurposeCategory
lv_consentRemembers your analytics choiceStrictly necessary
Supabase authentication tokens (browser local storage)Keeps you signed inStrictly necessary
Cloudflare TurnstileBot protection on sign-in and sign-upStrictly necessary
Paddle checkout cookiesRuns the payment checkout — set only when you open checkout, on Paddle's domainStrictly necessary / payment
PostHog ph_* (cookie + local storage)Recognises a returning visitor for analyticsAnalytics — set only after you accept

Strictly necessary items can't be switched off — without them you can't sign in or pay, and consent isn't required for them under EU/UK or Quebec rules. Analytics items are off by default: nothing analytics-related is loaded or stored until you say yes — on our website via the consent banner, and in the app when we ask on your first signed-in visit. "Accept" and "Reject" are equally prominent, and you can change your choice at any time via the "Cookie settings" link in the website footer or in the app's Account settings.

14. Children

The Service is not directed at children and is not intended for anyone under 18. We don't knowingly collect data from children. If you believe a child has given us personal data, contact info@littview.com and we'll delete it.

15. Changes to this policy

We'll update this policy as the Service changes. For material changes — a new category of data, a new purpose, or a new sub-processor handling your content — we'll give notice by email and/or in the app 30 days before it takes effect, and we'll always update the "Last updated" date. Minor clarifications take effect on posting.

16. Contact

Littview Inc. — a Quebec, Canada corporation Privacy questions and requests: info@littview.com (person in charge of the protection of personal information) Support: support@littview.com Postal address available on request.