Privacy Policy
1. Introduction
ResearchArk ("we", "our", or "us"), operated by Mycel UG (haftungsbeschränkt), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services (collectively, the "Service"). It also describes your choices regarding use, access, and correction of your personal information.
2. Information We Collect
We collect the following types of information:
- Personal Information: This includes your name, email address, institution affiliation, and any other information you provide directly to us, such as when you create an account, contact us, or participate in surveys.
- Usage Data: We automatically collect limited technical information about your interaction with our Service. This may include your IP address and user agent string (which contains browser information), collected primarily for security purposes such as rate limiting and abuse prevention.
- Research Information: We collect information related to your research interests, funding history, publications, collaboration preferences, network connections, and other research-related activities that you choose to provide.
- AI Interaction Data: We collect and process your interactions with our AI services including ArkAssist conversations, search queries, document uploads, and generated content to improve our services and provide personalized assistance.
- Collaboration Data: Information about your research spheres, team memberships, project collaborations, and network connections within the platform.
- Document Content: Content of documents you upload for analysis, processing, or contextual search enhancement.
- Identity and Standardization Data: Information processed through our ArkID system, which manages authentication and issues standardized identifiers (ARKI, ARKU, ARKP, ARKO, ARKD, ARKF) for use within the ecosystem. The availability of specific identifier types may vary as the system continues to develop.
- Cookies and Similar Technologies: We use cookies to support essential platform functions such as locale preferences and authentication sessions. See Section 7 for more details.
3. How We Use Your Information
We use your information for the following purposes:
- Provide and Improve our Services: To operate, maintain, and improve our Service, including developing new features and functionalities.
- Personalize your Experience: To tailor the content and information we may send or display to you, offer location customization, and personalized help and instructions.
- Communicate with You: To respond to your inquiries, send you service-related notices (e.g., account verification, changes/updates to features of the Service, technical and security notices), and provide customer support.
- Analyze Usage Patterns: To understand how users interact with our Service, monitor usage trends, and improve the overall user experience.
- AI Services and Machine Learning: To operate AI-assisted features such as proposal writing, search enhancement, and research intelligence, we send relevant content (such as your queries and document excerpts) to third-party AI providers including Google (Gemini API), OpenAI, and Anthropic (Claude API). These providers process data in real time to generate responses and do not use your data for model training. They may retain prompts and responses for limited periods (up to 30–55 days) solely for safety and abuse monitoring. We have configured all AI services to minimize data retention and have opted out of any data sharing for model training where such options are available.
- Research Collaboration: To facilitate research networking, team formation, and collaborative project development through ArkSphere and related services.
- Document Processing: To analyze uploaded documents for contextual search, proposal generation, and research insights.
- Research and Development: To conduct research and analysis to improve our algorithms and develop new AI-native features.
- Marketing and Promotions: With your consent, we may send you emails about new features, products, services, and other information we think may be of interest to you. You can opt-out of these communications at any time.
- Legal Compliance: To comply with applicable laws, regulations, legal processes, or governmental requests.
Lawful Bases (GDPR)
We process personal data under the following lawful bases, as applicable:
- Contract performance (e.g., providing the Service you requested)
- Legitimate interests (e.g., securing the Service and preventing abuse)
- Consent (e.g., first‑party analytics and performance measurement, and marketing communications via double opt‑in)
- Legal obligation (e.g., compliance with accounting and tax laws)
4. Data Sharing and Disclosure
We may share your information in the following circumstances:
- Service Providers: We may share your information with third-party service providers who assist us in operating our Service, such as hosting providers, payment processors, analytics providers, and email service providers. These providers are contractually obligated to protect your information and only use it for the purposes we specify.
- Research Institutions and Funding Bodies: We do not currently share your personal data directly with external research institutions or funding bodies. If such sharing is introduced in the future, it will only occur with your explicit, informed consent and this policy will be updated accordingly.
- Legal Authorities: We may disclose your information to legal authorities if required by law, such as in response to a subpoena, court order, or other legal process.
- Business Transfers: If ResearchArk is involved in a merger, acquisition, sale of assets, or other business transaction, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website of any change in ownership or uses of your personal information, as well as any choices you may have regarding your personal information.
- With Your Consent: We may share your information with other third parties with your explicit consent.
- Aggregated or Anonymized Data: We may share aggregated or anonymized data that does not directly identify you with third parties for research, analysis, or other purposes.
5. Data Security
We implement industry-standard security measures to protect your data from unauthorized access, use, or disclosure. These measures include encryption, access controls, firewalls, and regular security audits. However, no method of transmission over the Internet or method of electronic storage is 100% secure. Therefore, while we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.
6. Your Rights
You have the following rights regarding your personal information:
- Access: You can request access to the personal information we hold about you.
- Correction: You can request that we correct any inaccurate or incomplete personal information.
- Deletion: You can request that we delete your personal information, subject to certain exceptions (e.g., we may need to retain certain information for legal compliance).
- Objection: You can object to the processing of your personal information in certain circumstances.
- Restriction: You can request that we restrict the processing of your personal information in certain circumstances.
- Data Portability: You can request to receive a copy of your personal information in a structured, commonly used, and machine-readable format.
- Withdraw Consent: If we are processing your personal information based on your consent, you can withdraw your consent at any time.
To exercise these rights, please contact us at info@researchark.eu. We will respond to your request within a reasonable timeframe.
Data Retention
We retain personal data only as long as necessary for the purposes described above or as required by law. Typical retention periods:
- Account data and profile: retained while your account is active; deleted upon erasure request subject to a short safety window
- Activity logs and security events: retained for up to 12 months unless longer is required for security or legal compliance
- Consent-gated analytics (page views, Web Vitals, product events): raw events retained for up to 12 months, moving to 30 days once anonymised aggregation is verified; anonymised aggregates may be kept longer for product trends
- Marketing preferences and consent logs: retained to honor your choices and demonstrate compliance (up to 5 years)
7. Cookies and Tracking Technologies
We use a limited number of first‑party cookies that are essential for the operation of our Service:
- Locale preference cookie (
NEXT_LOCALE): Stores your language preference so the platform displays content in your chosen language. This is a functional cookie that does not track your behavior. - Authentication cookies: Session cookies used to keep you signed in after login. These are necessary for the Service to function and are managed by our authentication provider.
- Cookie‑consent preference (
cookie_consent): Remembers whether you allowed optional analytics so we can honour your choice. It records only your preference and no advertising data.
With your consent, we use privacy‑friendly, first‑party analytics to measure how the Service is used and performs. These are self‑hosted by ResearchArk — we do not use Google Analytics, advertising cookies, or third‑party cross‑site tracking cookies, and no analytics run until you accept them. When you are signed in, some usage and performance data is associated with your account so we can understand how features are used by plan type and can locate and delete the analytics linked to you when you exercise your data‑subject rights. You can change your choice at any time via “Cookie Settings”. See our Cookie Policy for exactly what is measured and for how long. You can manage cookies through your browser settings; however, disabling essential cookies may prevent the Service from functioning properly.
8. International Data Transfers
Your information may be transferred to, and processed in, countries other than the country in which you are resident. These countries may have data protection laws that are different from the laws of your country. We take appropriate safeguards to ensure that your personal information remains protected in accordance with this Privacy Policy, including relying on standard contractual clauses approved by the European Commission.
Service Providers and Sub‑processors
We use third-party service providers to operate the Service. These providers process data under their own terms of service with data protection provisions. Our core service providers include:
Infrastructure and Authentication:
- Firebase (Google LLC, USA): User authentication and session management
- Stripe (Stripe Inc., USA): Payment processing via hosted checkout (card details are never processed by ResearchArk directly)
Research Identity:
- ORCID (ORCID Inc., USA): Researcher identity verification via OAuth. With your authorization, we retrieve your public ORCID profile data (name, affiliations, publications) to enrich your ResearchArk profile. No data is sent from ResearchArk to ORCID.
AI Service Providers (for AI-assisted features):
- Google (Gemini API, Paid Tier 3): Prompts and responses are retained for up to 55 days for abuse monitoring only and are not used for model training. Zero Data Retention is available upon request for enterprise customers.
- OpenAI (API): Prompts and responses are retained for up to 30 days for abuse monitoring only and are not used for model training. We have opted out of data sharing for model improvement.
- Anthropic (Claude API): Prompts and responses are retained for up to 30 days for safety monitoring only and are not used for model training.
For transfers to the United States, these providers operate under their respective data protection terms, which include commitments consistent with GDPR requirements. We select providers that offer API terms with no-training guarantees and minimal data retention. A complete list of service providers is available on request at info@researchark.eu.
9. Children's Privacy
Our Service is designed for use by researchers, academics, and professionals, and is not intended for individuals under the age of 16. While we do not implement age verification at the point of registration, we do not knowingly collect personal information from children under 16. If we become aware that a user is under 16, we will take steps to delete their information and close their account. If you are a parent or guardian and believe your child has created an account, please contact us at info@researchark.eu.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically for any changes.
11. Contact Us
If you have any questions about this Privacy Policy, please contact us at info@researchark.eu.
For more information on how we comply with data protection regulations, please see our GDPR Compliance Statement.
Data Protection Officer (DPO)
If you have questions or concerns regarding our data protection practices, you can contact our Data Protection Officer at: dpo@researchark.eu
12. Automated Decision-Making and Profiling
We may use automated decision-making and profiling to:
- Provide personalized funding recommendations
- Suggest research collaborators and partners
- Optimize search results based on your research profile
- Generate AI-assisted proposal content
You have the right to object to automated decision-making and request human review of any automated decisions that significantly affect you. Contact us at info@researchark.eu to exercise this right.
13. Third-Party Integrations
Our Service may integrate with third-party platforms and services. When you connect your account to third-party services, we may access and process data from those services in accordance with their terms and your authorization. We are not responsible for the privacy practices of third-party services.
14. Business Transfers and Corporate Changes
In the event of a merger, acquisition, reorganization, or sale of assets, your personal information may be transferred to the acquiring entity. We will provide notice of any such transfer and any choices you may have regarding your personal information.
ResearchArk is a product of Mycel UG (haftungsbeschränkt), Kollwitzstraße 76, 10435 Berlin, Germany.
Company Website: https://mycel-ai.de
Have questions about our legal documents? Contact us for clarification.
Navigate across policies instantly from the legal submenu without reloading document text.