Skip to content

Your manuscript makes your review better. It never makes our models better.

Waraq gets better the way a good editor does: by refining its rules, its questions and its judgement. Not by feeding your paper into a model.

What we improve

The reviewer, not the model

01
The deterministic rule set
The DR rules that check structure, citations, statistics, reporting standards and journal guidelines. They are written and revised by people.
02
Our prompts and question templates
The instructions we give the models for each pass. Text we write; never text you wrote.
03
Evaluation fixtures
Built from public open-access papers, and from papers whose authors gave explicit written consent. Nothing else enters the fixture set.
04
Routing and budgets
Which model handles which pass, how many samples it takes, how much each review may cost.
05
Manual audits
A person compares our findings on one manuscript with a referee's read and records what we missed or got wrong. Under confidentiality; you can opt out.

What we never do

No training. No sharing beyond the review. No selling.

Train on your manuscript
We never train, fine-tune, distil or evaluate-for-training any language model on your manuscript, findings, questionnaire answers, chat or feedback. Ours or anyone else's.
Share it for anything but your review
Model providers receive sections of your text for one purpose: generating your review. Each is bound by a Data Processing Addendum and API terms that forbid training on it.
Sell or advertise with it
We do not sell your data, in the ordinary sense or in the sense used by US state privacy laws, and we do not share it for targeted advertising. No advertising pixels.

How your text travels

Four stops, each with a retention clock

From upload to review, this is where your manuscript goes and how long each stop keeps it.

  1. 01

    Your file

    You upload a .docx over TLS. It is stored on a server in the EU with access limited to named individuals over key-based SSH, and never made public.

    Original kept 180 days after the last review activity. Reviewed file kept 365 days. Or until you delete the paper.

  2. 02

    Our server (EU)

    A virtual server in the European Union runs the rule engine, the workflow and the database. Nobody reads your paper as part of the normal service.

    Server logs and job traces rotated and pruned within 90 days. Nightly backups, encrypted with a key held offline, kept 14 days.

  3. 03

    Model providers, via gateway

    Sections of your text leave through Cloudflare AI Gateway and are routed by OpenRouter to the host serving the chosen model. Payload logging at the gateway is off; only metadata (model, timing, tokens, cost) is recorded.

    Providers may keep API inputs for up to 30 days for abuse monitoring. None may train on them.

  4. 04

    Your review

    Findings, a score, a reviewed .docx with tracked changes, and reports. They are yours to use, publish or share, without attribution.

    Until you delete the paper or your account. Deletion is immediate on live systems and clears from backups within 14 days.

Who receives manuscript text

Every provider, bound by the same rule

The full sub-processor table, with locations, retention and what each one receives, is on the Data Processing Summary.

ProviderRoleTraining on your text
Cloudflare AI GatewayEvery model call passes through it; metadata only, payloads not loggedNot applicable: text is not stored there
OpenRouterRoutes each request to the model hostProhibited by its DPA and API terms
DeepSeek V4 Pro hosts (CoreWeave, Sail Research, Phala)Substance reviewProhibited; inputs may be retained briefly for abuse monitoring
OpenAI (GPT-5.6), served by OpenAI or Microsoft AzureHard-case and triage passesProhibited; inputs kept up to 30 days for abuse monitoring
Anthropic (Claude Haiku 4.5, Sonnet 4.5 fallback), served by Anthropic or Amazon Web Services (Bedrock)Copy-edit lane; quality auditsProhibited; retained per commercial terms, typically up to 30 days
Z.ai (GLM-4.7 Flash)Structure extractionProhibited on API inputs

Audits and opt-out

A person may read one paper. You can say no.

To check that reviews are accurate, a small number of Waraq staff, and the founder, may read one manuscript together with our findings for it and record an audit: what we missed, what we got wrong, a rating. This happens only for quality control, under confidentiality, and audit notes contain at most short quotations. Audit reads run in a Claude Code session, which sends the text to Anthropic under no-training terms.

Production access is limited to named individuals over key-based SSH, purpose-limited and logged. Telemetry labels are filtered so manuscript prose does not appear in dashboards or logs.

To exclude every paper on your account from audit reads, email privacy@waraq.io or support@waraq.io from your account email. We keep a list of opted-out accounts and exclude them from audits. Your reviews are unaffected.