The short version
- This page lists every third party that touches your data, what it receives, where it runs, and how long it keeps it.
- Manuscript text leaves our server for one reason: to be sent, through Cloudflare AI Gateway and OpenRouter, to the language models that write your review. Nothing else receives it, except the audit read in Section 3.
- No one, including us, trains AI models on your manuscript. Every provider on this page is bound to that by its Data Processing Addendum and API terms.
- We do not sell your data.
1. Is my paper used to train AI?
No. Your manuscript, the text we extract from it, the findings, the reviewed file, your questionnaire answers and your feedback are never used to train, fine-tune, distil or evaluate-for-training any AI model, whether ours or a third party's. When we send sections of your text to a language model, it is only to generate your review, under a published Data Processing Addendum and commercial API terms that forbid the provider from training on the input. If a provider cannot give that assurance, we stop routing manuscript text to it. Providers may keep API inputs for a limited period for abuse monitoring (typically up to 30 days); the per-provider detail is below. Our rule library and scoring improve from aggregate statistics (for example how often a rule fires) and from audits of individual reviews conducted under confidentiality, not from feeding manuscripts into model training.
2. Sub-processors
| Sub-processor | Purpose | What it receives | Location | Retention on their side |
|---|---|---|---|---|
| Contabo GmbH (virtual server) | Hosts our API, PostgreSQL database, file storage volume, Temporal workflow engine and self-hosted Langfuse tracing | Everything we store (Privacy Policy, Section 2) | European Union | Our retention schedule applies; the host does not access data |
| Cloudflare, Inc. | DNS, edge network and DDoS protection for waraq.io, app.waraq.io and api.waraq.io; hosting of waraq.io and app.waraq.io on Cloudflare Workers; AI Gateway, through which every review model call passes | Traffic in transit; AI Gateway metadata only (model, timing, token counts, cost). Payload logging is switched off, so manuscript text is not stored at the gateway | Global edge; metadata in our Cloudflare account | Bound by Cloudflare's Data Processing Addendum |
| OpenRouter, Inc. | Routes each model request to the host serving the chosen model; reports usage and cost | Manuscript text sections plus our instructions; no account identity beyond an app name | United States | Bound by OpenRouter's Data Processing Addendum and API terms; no training on inputs |
| DeepSeek V4 Pro, served by CoreWeave, Sail Research or Phala (via OpenRouter) | Substance-review model | Manuscript text sections | United States or Singapore, depending on host | Per host terms; no training on inputs; inputs may be retained briefly for abuse monitoring |
| OpenAI, L.L.C. (GPT-5.6, via OpenRouter) | Hard-case and triage review passes | Manuscript text sections | United States | Bound by OpenAI's Data Processing Addendum; API inputs kept up to 30 days for abuse monitoring; not used for training |
| Microsoft Azure (Azure OpenAI Service, via OpenRouter) | Alternate host for the GPT-5.6 hard-case and triage passes when OpenRouter routes there | Manuscript text sections | United States | Per Azure OpenAI API terms: no training on inputs; abuse-monitoring retention of at most 30 days |
| Anthropic PBC (Claude Haiku 4.5 copy-edit lane, Claude Sonnet 4.5 fallback, via OpenRouter; Claude Code for audits) | Copy-edit review lane; quality audits | Manuscript text sections; for audits, the full plain text and our findings | United States | Bound by Anthropic's Data Processing Addendum; API inputs not used for training; retained per commercial terms (typically up to 30 days) |
| Amazon Web Services (Amazon Bedrock, via OpenRouter) | Alternate host for the Claude copy-edit lane when OpenRouter routes there | Manuscript text sections | United States | Per Amazon Bedrock API terms: no training on inputs; abuse-monitoring retention of at most 30 days |
| Z.ai / Zhipu AI (GLM-4.7 Flash, via OpenRouter) | Document structure and metadata extraction | Manuscript text sections | China / Singapore | Per provider API terms; no training on API inputs |
| Polar Software Inc. | Merchant of record: checkout, payment, tax, invoices, refunds, subscription management | Email, name, billing address, payment method, purchase history | United States (payments via Stripe) | Bound by Polar's Data Processing Addendum; billing records kept as required by tax and payment law (typically 7 to 10 years) |
| Resend, Inc. | Transactional email (sign-in codes, review-ready, billing reminders) and newsletter | Email address, subject, message body, delivery metadata | United States | Bound by Resend's Data Processing Addendum; message logs retained briefly for deliverability |
| PostHog, Inc. | Product analytics, session replay (inputs masked) and error tracking on waraq.io and app.waraq.io | Page views, clicks, feature events, masked session replays, error stack traces, device and coarse location data, sent via a first-party relay; and your account email, which our server sends as the user identifier so events can be tied to your account | United States (US cloud) | Bound by PostHog's Data Processing Addendum; EU/UK visitors can object by email and a tracker blocker stops collection |
| Crossref | Retraction and reference-metadata checks | DOIs and reference titles from your bibliography only; never manuscript body text | United States | Public API; queries logged in aggregate |
| OpenAlex (OurResearch) | Journal lookups to locate author guidelines | Journal names only | United States | Public API |
| Jina AI (Reader) and Firecrawl | Fetching public journal guideline pages | Public journal URLs only; no manuscript or personal data | United States / Germany | Not applicable |
Not in the loop. Google sign-in is not offered. No SMTP mailbox provider receives your email. Cloudflare R2 object storage and Cloudflare Vectorize are not in use; if we enable them, this table will be updated first. Semantic Scholar is not called.
Self-hosted components (on our own server, not third parties): PostgreSQL; Temporal (workflow engine; job payloads may contain manuscript-derived data while a review runs); Langfuse (tracing; model prompts and completions, which include manuscript text sections, stored with restricted access and pruned after 90 days); our rule engine; server and container logs, rotated and pruned within 90 days; and nightly backups, encrypted with a key held offline, kept for 14 days.
3. Internal access
Access to production data is limited to named individuals over key-based SSH, for operations, support you request, security and quality audits. During an audit, the founder or staff may read one manuscript together with its findings, in a Claude Code session (which sends the text to Anthropic's API under no-training terms), and record an audit rating. Audit notes contain at most short quotations. You can opt out of audit reads by emailing privacy@waraq.io; we keep a list of opted-out accounts and exclude them from audits. Telemetry labels are filtered so manuscript prose does not appear in dashboards or logs.
4. Retention summary
| Data | Retention |
|---|---|
Original .docx | 180 days after last review activity, or until you delete the paper |
Reviewed .docx (all variants) | 365 days after the review finished, or until you delete the paper |
| Findings, score, reports, assistant memory | Until you delete the paper or account |
| Anonymous trial accounts | 30 days of inactivity |
| Server and container logs, Langfuse traces | Rotated and pruned within 90 days |
| AI Gateway payload logs | Not collected (metadata only) |
| Nightly backups (encrypted with a key held offline) | 14 days |
The 180-, 365- and 30-day sweeps run nightly in our retention worker and never touch a review in progress. Self-service deletion of a paper or account takes effect immediately on live systems; a copy can persist in our encrypted backups for up to 14 days and is then gone. Requests by email are completed within 30 days.
5. Changes
We update this page when we add, replace or remove a sub-processor. Subscribers can ask to be notified of sub-processor changes by emailing privacy@waraq.io; institutional customers may request a signed Data Processing Agreement.
Contact: Alurood Alilmiyya Company for Education (CR 7037878365), 4309 King Abdullah Al Saud Road, Al Raed, Riyadh, Kingdom of Saudi Arabia · privacy@waraq.io (or support@waraq.io)