Skip to content

Legal

Privacy Policy

Last updated:

The short version

  • You upload a manuscript; we run rule checks and AI passes on it to produce a review. That is the only reason we touch your text.
  • Your manuscript is never used to train any AI model, ours or anyone else's. Every provider that receives it is bound to the same rule.
  • Sections of your text go to language models through Cloudflare AI Gateway and OpenRouter, only to generate your review. We do not sell your data or advertise with it.
  • Delete any paper, or your whole account, at any time. Deletion is immediate on live systems and clears from backups within 14 days.
  • A small team may read a manuscript to audit review quality; email privacy@waraq.io to opt out. No advertising trackers. Adults (18+) only.

1. Who we are

Waraq ("we", "us") is an AI-assisted pre-submission manuscript review service at waraq.io and app.waraq.io, operated by Alurood Alilmiyya Company for Education, a limited liability company registered in the Kingdom of Saudi Arabia (Commercial Registration 7037878365), at 4309 King Abdullah Al Saud Road, Al Raed, Riyadh. We are the controller of the personal data described here. Contact: privacy@waraq.io (or support@waraq.io).

This policy covers the website, the application, our API and our emails. Waraq is for researchers and other adults; it is not directed at anyone under 18, and we delete any account we learn belongs to a minor.

2. What we collect

  • Account data. Your email address (used for one-time sign-in codes; we store no passwords), plan and subscription status, a Polar customer reference, and any profile details you add. Anonymous trial accounts are deleted after 30 days of inactivity unless you sign in.
  • Your manuscript and what we derive from it. The .docx you upload, the text we extract, the reviewed .docx, findings, score, edits and reports, and your upload questionnaire answers. The in-app assistant also keeps a short summary of each finished review (score, edit count, top finding titles) that contains no manuscript text.
  • Usage and technical data. Server logs (IP address, user agent, timestamps, request paths), job traces, error reports and product-analytics events, including in-app session replays with all typed input masked (Section 8).
  • Billing data. Polar Software Inc., as merchant of record, collects payment details, billing address and tax information directly. We never see card numbers; we receive subscription status, product, amounts and a customer reference.
  • Communications. Emails you send us, in-app feedback, and delivery metadata for emails we send you.

We do not collect special-category data on purpose. If your manuscript contains such data (for example patient-level information), you are responsible for having the right to share it with us and our processors (Terms, Section 6).

3. Why we process it

PurposeLegal basis
Run your review; accounts, sign-in and security; billing and quotas; transactional email; assistant memoryPerformance of a contract (legitimate interest for security; legal obligation for billing records)
Product newsletterConsent (opt-in; one-click unsubscribe)
Quality audits (Section 7); analytics and error monitoring; preventing abuse; answering legal requestsLegitimate interest (you can object), or consent where your local law requires it; legal obligation

We do not sell personal data, in the ordinary sense or in the sense used by US state privacy laws, and we do not share it for targeted advertising.

4. AI processing and model training

No training, ever. We do not use your manuscript, the extracted text, the findings, the reviewed file, your questionnaire answers or your feedback to train, fine-tune, distil or otherwise improve any machine-learning model, ours or a third party's.

Our providers are bound to the same rule. Every provider that receives manuscript text does so under a published Data Processing Addendum and API terms that prohibit training on customer inputs. If a provider cannot give that assurance, we stop routing text to it. Each provider and the basis of its assurance is listed at /legal/data-processing.

What the models receive. Sections of your manuscript, with our instructions, leave our server through Cloudflare AI Gateway and are routed by OpenRouter to the host serving the chosen model. Models in use today: DeepSeek V4 Pro (substance review), OpenAI GPT-5.6 (hard-case and triage passes), Anthropic Claude Haiku 4.5 (copy-edit lane, Claude Sonnet 4.5 as fallback) and Z.ai GLM-4.7 Flash (structure extraction). Depending on capacity, the GPT-5.6 calls may be served by Microsoft Azure and the Claude calls by Amazon Web Services (Bedrock), each under API terms with no training on inputs and abuse-monitoring retention of at most 30 days. We may change models; the current list is always in the Data Processing Summary.

Provider-side logging. Cloudflare AI Gateway records only request metadata (model, timing, tokens, cost); payload logging is switched off, so the text itself is not stored there. Model providers may keep API inputs for up to 30 days for abuse monitoring; none may train on them.

Automated outputs. The score, findings and suggested edits are automated and advisory; they have no legal or similarly significant effect on you.

5. How long we keep data

DataKept for
Original uploaded .docx180 days after the last review activity, or until you delete the paper. Results stay visible; the original can no longer be re-reviewed or downloaded
Reviewed .docx (all variants)365 days after the review finished, or until you delete the paper. Score and findings stay visible
Findings, score, reports, edits, assistant memory, account dataUntil you delete the paper or account
Anonymous trial accounts30 days of inactivity, then the account and its files are deleted
Billing records (held by Polar)As required by tax law, typically 7 to 10 years
Server and container logs, and job traces (self-hosted Langfuse)Rotated and pruned within 90 days
Nightly backups (encrypted with a key held offline)14 days

The 180-, 365- and 30-day limits run in a nightly automated sweep that never touches a review in progress.

Deleting is always available and immediate. Deleting a paper removes the source file, the reviewed files and every derived record from our live systems at once; deleting your account removes everything we hold about you. A copy can persist in encrypted backups for up to 14 days and is then gone. You can also email privacy@waraq.io; we complete deletion within 30 days.

6. Who we share data with (sub-processors)

We share personal data only with providers that help us run the service, under Data Processing Addenda that restrict them to our instructions. The full table, with locations and retention, is at /legal/data-processing.

  • Cloudflare, Inc.: DNS, edge network and DDoS protection; hosting for waraq.io and app.waraq.io; AI Gateway (metadata only is logged).
  • OpenRouter, Inc. routes model requests; DeepSeek V4 Pro hosts (CoreWeave, Sail Research, Phala), OpenAI, Anthropic and Z.ai receive manuscript text sections solely to generate your review; Microsoft Azure (OpenAI models via Azure) and Amazon Web Services (Anthropic models via Bedrock) may serve the same requests as alternate hosts, each with no training on inputs and abuse-monitoring retention of at most 30 days under its API terms. Anthropic PBC (Claude Code) also receives text during an audit (Section 7), under terms that do not permit training.
  • Contabo GmbH: the virtual server in the European Union that hosts our API, database, files, workflow engine and tracing.
  • Polar Software Inc. (merchant of record), Resend, Inc. (email) and PostHog, Inc. (analytics, session replay and error tracking on its US cloud through a first-party relay on our domains; it receives your account email as the user identifier).
  • Crossref, OpenAlex, Jina Reader, Firecrawl: reference metadata, retraction checks, journal lookups and public guideline pages. They receive only DOIs, reference titles and journal names; never manuscript text or personal data.

We may also disclose data if the law requires it, to protect our rights or users' safety, or to a successor in a merger or acquisition (with notice to you).

7. Confidentiality and quality audits

We treat your manuscript as confidential unpublished research. Nobody at Waraq reads it as part of the normal service, and it is never made public. Production access is limited to named individuals over key-based SSH, purpose-limited and logged.

To check that reviews are accurate, a small number of Waraq staff, and the founder working in a Claude Code session, may read one manuscript with our findings for it and record an audit (what we missed, what we got wrong, a rating). This happens only for quality control, under confidentiality. Audit notes contain at most short quotations.

Opt out. Email privacy@waraq.io from your account email. We keep a list of opted-out accounts and exclude them from audits, so no paper on your account is read. Your reviews are unaffected.

8. Cookies and analytics

A session cookie set at sign-in keeps you logged in for up to 30 days; it is strictly necessary and cannot be switched off.

PostHog helps us understand how the product is used and catch errors. It sets first-party cookies and local-storage keys (prefixed ph_) shared across waraq.io and app.waraq.io. In the app it may record session replays with all typed input masked; manuscript content is not captured as text. Data goes through a relay on our own domain to PostHog's US cloud. When you create an account, we send your account email to PostHog as the user identifier so events can be tied to your account. If you are in the EU, UK or Switzerland and prefer not to be measured, email privacy@waraq.io and we will exclude you; a standard tracker blocker also stops analytics without breaking the service.

No advertising pixels, no third-party marketing cookies.

9. International transfers

Our application server is in the European Union. Cloudflare serves traffic from its global edge. OpenRouter, the model providers, PostHog, Polar, Resend and Anthropic process data in the United States or other countries. Waraq is established in Saudi Arabia; the Saudi Personal Data Protection Law (PDPL) governs our own transfers and we apply the safeguards it requires. Where the GDPR, UK GDPR or Swiss law applies, transfers rely on the Standard Contractual Clauses in each processor's Data Processing Addendum, or on an adequacy decision.

10. Security

All traffic uses TLS. Sign-in uses one-time codes rather than passwords. Files are stored on a server in the European Union with access limited to named individuals over key-based SSH; backups are encrypted with a key held offline and kept for 14 days. No system is perfectly secure; if we learn of a breach affecting you, we will notify you and any regulator as the law requires.

11. Your rights

Depending on where you live (including under the Saudi PDPL, the GDPR/UK GDPR and US state laws such as the CCPA), you may have the right to access, correct, export, restrict or delete your personal data, to object to processing based on legitimate interests, to withdraw consent, and to complain to a supervisory authority. Deletion is self-service in the app; for anything else, email privacy@waraq.io. We respond within 30 days, may need to verify your identity first, and will not treat you differently for exercising your rights.

12. Changes

We may update this policy. For material changes we will email account holders at least 14 days before they take effect and show a notice in the app. Continued use after the effective date means you accept the changes; if you do not, delete your account before then.

13. Contact

Alurood Alilmiyya Company for Education (CR 7037878365), 4309 King Abdullah Al Saud Road, Al Raed, Riyadh, Kingdom of Saudi Arabia. Privacy: privacy@waraq.io (or support@waraq.io) · Support: support@waraq.io

We have not appointed a representative in the EU or UK. If we become required to appoint one, their details will appear here.