Trust
اقرأ بالعربيةYour manuscript makes your review better. It never makes our models better.
Waraq gets better the way a good editor does: by refining its rules, its questions and its judgement. Not by feeding your paper into a model.
What we improve
The reviewer, not the model
- The deterministic rule set
- The DR rules that check structure, citations, statistics, reporting standards and journal guidelines. They are written and revised by people.
- Our prompts and question templates
- The instructions we give the models for each pass. Text we write; never text you wrote.
- Evaluation fixtures
- Built from public open-access papers, and from papers whose authors gave explicit written consent. Nothing else enters the fixture set.
- Routing and budgets
- Which model handles which pass, how many samples it takes, how much each review may cost.
- Manual audits
- A person compares our findings on one manuscript with a referee's read and records what we missed or got wrong. Under confidentiality; you can opt out.
What we never do
No training. No sharing beyond the review. No selling.
- Train on your manuscript
- We never train, fine-tune, distil or evaluate-for-training any language model on your manuscript, findings, questionnaire answers, chat or feedback. Ours or anyone else's.
- Share it for anything but your review
- Model providers receive sections of your text for one purpose: generating your review. Each is bound by a Data Processing Addendum and API terms that forbid training on it.
- Sell or advertise with it
- We do not sell your data, in the ordinary sense or in the sense used by US state privacy laws, and we do not share it for targeted advertising. No advertising pixels.
How your text travels
Four stops, each with a retention clock
From upload to review, this is where your manuscript goes and how long each stop keeps it.
- 01
Your file
You upload a .docx over TLS. It is stored on a server in the EU with access limited to named individuals over key-based SSH, and never made public.
Original kept 180 days after the last review activity. Reviewed file kept 365 days. Or until you delete the paper.
- 02
Our server (EU)
A virtual server in the European Union runs the rule engine, the workflow and the database. Nobody reads your paper as part of the normal service.
Server logs and job traces rotated and pruned within 90 days. Nightly backups, encrypted with a key held offline, kept 14 days.
- 03
Model providers, via gateway
Sections of your text leave through Cloudflare AI Gateway and are routed by OpenRouter to the host serving the chosen model. Payload logging at the gateway is off; only metadata (model, timing, tokens, cost) is recorded.
Providers may keep API inputs for up to 30 days for abuse monitoring. None may train on them.
- 04
Your review
Findings, a score, a reviewed .docx with tracked changes, and reports. They are yours to use, publish or share, without attribution.
Until you delete the paper or your account. Deletion is immediate on live systems and clears from backups within 14 days.
Who receives manuscript text
Every provider, bound by the same rule
The full sub-processor table, with locations, retention and what each one receives, is on the Data Processing Summary.
| Provider | Role | Training on your text |
|---|---|---|
| Cloudflare AI Gateway | Every model call passes through it; metadata only, payloads not logged | Not applicable: text is not stored there |
| OpenRouter | Routes each request to the model host | Prohibited by its DPA and API terms |
| DeepSeek V4 Pro hosts (CoreWeave, Sail Research, Phala) | Substance review | Prohibited; inputs may be retained briefly for abuse monitoring |
| OpenAI (GPT-5.6), served by OpenAI or Microsoft Azure | Hard-case and triage passes | Prohibited; inputs kept up to 30 days for abuse monitoring |
| Anthropic (Claude Haiku 4.5, Sonnet 4.5 fallback), served by Anthropic or Amazon Web Services (Bedrock) | Copy-edit lane; quality audits | Prohibited; retained per commercial terms, typically up to 30 days |
| Z.ai (GLM-4.7 Flash) | Structure extraction | Prohibited on API inputs |
Audits and opt-out
A person may read one paper. You can say no.
To check that reviews are accurate, a small number of Waraq staff, and the founder, may read one manuscript together with our findings for it and record an audit: what we missed, what we got wrong, a rating. This happens only for quality control, under confidentiality, and audit notes contain at most short quotations. Audit reads run in a Claude Code session, which sends the text to Anthropic under no-training terms.
Production access is limited to named individuals over key-based SSH, purpose-limited and logged. Telemetry labels are filtered so manuscript prose does not appear in dashboards or logs.
To exclude every paper on your account from audit reads, email privacy@waraq.io or support@waraq.io from your account email. We keep a list of opted-out accounts and exclude them from audits. Your reviews are unaffected.
The documents behind this page