scid.ai Privacy Policy
Edition dated 19 July 2026 · effective 19 July 2026
1. Controller and scope
1.1. The personal-data controller is ARTICLE LLC (ООО «АРТИКЛ», the “Operator”). Privacy requests may be sent to info@scid.ai.
1.2. This Policy applies to the scid.ai website and workspace, accounts, public pages, search, AI chat and documents, library, favourites, graphs, digests, email and Telegram interactions, payments and support.
1.3. The Policy reflects Russian Federal Law No. 152-FZ on Personal Data, Federal Law No. 149-FZ on Information, Information Technologies and Information Protection, and other applicable Russian requirements.
1.4. External websites, publishers, scientific databases, payment systems, Telegram and other services process data under their own policies when the User visits them or creates a separate account.
2. Categories of data
2.1. The data processed depends on the selected features and may include:
- account and profile: email, name or alias, language, settings, login methods, account and organisation identifiers, email-verification status and consents;
- technical data: IP address, date and time, browser, device, operating system, referrer, event logs, cookies and session identifiers;
- research activity: search terms, DOI and SCID requests, filters, opened works, selected sources and clusters, graph-node actions, history and task parameters;
- AI interaction: messages, instructions, chat context, selected mode, responses, intermediate and final documents, source references and technical task-execution details;
- library and files: file name, type, size, metadata and uploaded-file content, extracted text, indexing output and sources selected for chat;
- favourites and collaboration: saved works, groups, notes, digest topics, import history, public links and access settings;
- community: posts, comments, attachments, reports and moderation records;
- credits and payments: plan, credit balance and ledger entries, selected product, amount and currency, payment status, transaction identifier, renewal, cancellation, refund or payment error; the Operator does not receive full card details;
- communications: notification subscriptions, digest topics, delivery and unsubscribe events, Telegram identifiers and messages, support requests and attachments.
2.2. scid.ai is not designed to intentionally collect biometric data or special categories of personal data. Such information should not be placed in prompts or files without necessity and a valid legal basis.
2.3. A User who submits another person's data must have a lawful basis and must not use scid.ai to infringe that person's rights.
3. Purposes of processing
3.1. Data is processed to:
- register and authenticate Users, restore access, and maintain profiles and organisations;
- find and display scientific material, resolve DOI routes, build graphs and save history;
- prepare AI answers, comparisons, reviews, reports, articles and other selected documents;
- store files, extract and index text, support download and use files as research sources;
- operate favourites, groups, sharing links, topics and personalised digests;
- process reports and provide topic-focused moderation;
- measure actual use, maintain credit balances, process plans or top-ups, confirm payments and service subscriptions;
- send required service messages and, with separate consent, news and offers;
- provide support, diagnose failures, prevent abuse, protect accounts and comply with law.
3.2. The Operator does not sell personal data or provide it to third parties for their independent advertising.
4. Legal grounds
4.1. Depending on the purpose, processing relies on one or more of the following:
- the data subject's consent where required;
- steps requested by the User and performance of the Terms of Use, Public Offer or another agreement;
- the Operator's legal duties and exercise of rights granted by law;
- lawful processing of data made public by the data subject;
- other grounds expressly provided by Russian law.
4.2. Consent to marketing is requested separately. Withdrawal does not prevent account, security, payment, legal-document or requested-feature messages.
5. AI processing, files and research requests
5.1. To complete a task, scid.ai may send a model provider the prompt, necessary context, excerpts from selected sources and technical parameters. Only the amount needed for that processing stage is submitted.
5.2. An uploaded file may be stored in object storage, checked, processed for text extraction, measured, indexed and split into excerpts for search or AI chat.
5.3. Users should not upload secrets, passwords, bank details, medical records, trade secrets or other sensitive information unless the task requires it and the User has ensured a legal basis and appropriate protection.
5.4. AI features prepare research materials and are not intended to make decisions on behalf of the Operator that produce legal effects for the User.
6. Public materials and links
6.1. A post, comment or other material marked public may be available to an indefinite audience and indexed by search engines.
6.2. A shared chat, document, favourites group or digest link may open the relevant material to anyone who receives the link. The User must review its contents before sharing.
6.3. Disabling a public link prevents later access through scid.ai but cannot remove copies lawfully saved by other people before access was disabled.
7. Data recipients and processors
7.1. To the extent required, data may be processed by providers supporting:
- hosting, databases, object storage, backups, monitoring and information security;
- AI models, search, text extraction and other computational functions;
- email, Telegram, support, authentication through a selected external provider;
- payments, fiscal receipts and banking operations, including YooKassa where it is identified in checkout;
- lawful public-authority requests and protection of Operator or third-party rights.
7.2. The Operator selects processors with regard to data type, enters into required arrangements and limits processing to the stated purposes within its authority and legal obligations.
8. Data localisation and international transfers
8.1. When collecting Russian citizens' personal data online, the Operator follows localisation requirements in the cases and to the extent required by Russian law.
8.2. Certain AI, email, authentication, Telegram and other providers may operate outside Russia. International transfers are made only where an applicable basis exists and required legal procedures have been completed.
9. Retention and deletion
9.1. Data is kept no longer than required for its purpose, agreement performance, security, dispute handling and mandatory legal retention.
9.2. Unless a longer period is required by law, security, dispute handling or protection of rights, the following indicative periods apply:
- technical and access logs are generally retained for up to 12 months;
- plan, credit-balance, payment-status, activation, renewal, cancellation and refund records are retained for the relevant relationship and generally for up to 5 years after it ends;
- marketing-consent and unsubscribe records are retained while the consent applies and generally for up to 3 years after withdrawal;
- digest topics and history, search queries, graph settings, selected clusters and AI or document-task history are retained while the account or feature is used and generally for up to 24 months after the last meaningful interaction;
- posts, comments, attachments and related moderation records are retained while the material is published and generally for up to 12 months after deletion;
- support requests and service correspondence are generally retained for up to 3 years after correspondence ends;
- Telegram metadata and thematic-moderation records are generally retained for up to 12 months after the last meaningful interaction.
9.3. Once the purpose is achieved or a valid request is received, data is deleted, anonymised or destroyed unless further retention is required by law or to protect legal rights.
9.4. Removing an account or file from the active interface may not instantly remove it from technical backups. Backup copies leave circulation under the applicable retention cycle and are not used for ordinary operations.
11. Data-subject rights
11.1. A data subject may request information about processing and access to data, seek correction, blocking or deletion where grounds exist, withdraw consent, and complain to Roskomnadzor or a court.
11.2. Requests may be sent to info@scid.ai with the subject “Personal data”. To protect the account, the Operator may request reasonable identity and authority verification.
11.3. A response is provided within the period and procedure required by applicable law. If a request cannot be fulfilled in full, the Operator provides the legal basis for the restriction.
11.4. Marketing messages may be unsubscribed from at any time using the link in an email or account settings. Unsubscribing does not affect service messages about security, payments, the account, legal documents or a feature requested by the User.
12. Security and Policy amendments
12.1. The Operator uses legal, organisational and technical measures proportionate to the data and risks, including access controls, authentication, logging, backups, software updates, processor oversight and incident response.
12.2. The Policy may be updated when law, features or processing change. A new edition is published before new processing begins where required by law.
ARTICLE LLC (ООО «АРТИКЛ»)
PSRN 1257800042004 · TIN 7804715019 · KPP 780401001
9 Marshal Blyukher Avenue, building 2, litera A, apartment 521, Saint Petersburg, 195197, Russian Federation
Email: info@scid.ai
This English translation is provided for convenience. The Russian version prevails for interpretation under Russian law.