Last updated: 2026-03-20
RefDesk ("we", "our") is committed to protecting user privacy. This Privacy Policy explains what data we collect, how we use it, who we share it with, and what your rights are. This policy applies to all use of the RefDesk platform at refdesk.com.
We use your information for the following purposes:
Legal basis for processing (GDPR Article 6):
We do not sell your personal information. We do not use your research content to train our own AI models.
Automated Decision-Making (GDPR Article 22):
RefDesk does not make automated decisions that produce legal or similarly significant effects on you. Framework selection uses deterministic logic (a decision tree), and AI content is an assistive tool only — all final decisions rest with you.
🔒 Zero Data Retention Guarantee
We strictly utilize the paid, enterprise tier of the Google Gemini API to process your research queries. Under these specific commercial terms, Google explicitly guarantees a Zero Data Retention policy for AI training. This means your inputs, research ideas, and generated outputs are NOT used to train Google's foundation models, nor are they used to train any of RefDesk's internal systems. Your intellectual property remains 100% yours and is securely processed solely to generate your requested outputs.
Important to know:
We share information only with the following parties and for the stated purposes:
| Service | Purpose | Data type | Location |
|---|---|---|---|
| Supabase | Storage & auth | Account & project data | Ireland (EU) |
| Google Gemini | AI processing | Conversation content | US / Global |
| Paddle | Payments | Email, billing details | United Kingdom |
| NCBI | MeSH lookup | Search terms only | United States |
| OpenAlex | Scoping search | Search queries only | United States |
| Vercel | Hosting | Technical data (IP, browser) | Global CDN |
We do not sell, rent, or share your personal information with third parties for marketing purposes.
RefDesk uses cookies for the following purposes:
We do not use marketing cookies or third-party tracking cookies for advertising. We do not use Google Analytics or similar tracking tools.
We retain your information as follows:
After account deletion, all personal data will be removed within 30 days, except where retention is required by law.
We take reasonable measures to protect your information:
Despite these measures, no method of internet transmission is 100% secure. We cannot guarantee absolute security.
System data is stored on Supabase servers in Ireland (EU). AI conversation content is processed by Google Gemini on servers that may be located outside your region of residence. Payments are processed by Paddle in accordance with Paddle's terms.
We maintain Data Processing Agreements (DPAs) with all our service providers, including Supabase, Google, Paddle, and Vercel. Data transfers outside the European Economic Area are conducted under Standard Contractual Clauses (SCCs) and in compliance with GDPR and the Israeli Privacy Protection Law.
EU Representative (GDPR Article 27):
RefDesk is operated by Shai Tamam from Israel. As the service processes data of EU residents, we are in the process of appointing an EU representative in accordance with Article 27 of the GDPR. Until the appointment is finalized, you may contact us directly at refdeskshaitamam@gmail.com for any data protection inquiries.
Under applicable privacy laws (including GDPR and the Israeli Privacy Protection Law), you have the following rights:
You can exercise most of these rights directly from your Settings page (data export, account deletion, AI consent toggle). For additional requests, contact us at refdeskshaitamam@gmail.com. We will respond within 30 days.
RefDesk is not intended for users under 18. We do not knowingly collect information from minors. If we learn that we have collected information from a minor, we will delete it immediately. If you believe a minor has provided us with personal information, please contact us.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
To exercise these rights, contact us at refdeskshaitamam@gmail.com. We will acknowledge receipt within 10 business days and respond substantively within 45 calendar days.
We may update this Privacy Policy from time to time. Material changes will be posted on the website and registered users will be notified via email. The last update date appears at the top of this document. Continued use of the service after changes are posted constitutes acceptance of the updated policy.
For questions about this Privacy Policy or to exercise your rights, contact us:
Email: refdeskshaitamam@gmail.com
For Israeli residents: You may contact the Israel Privacy Protection Authority at www.gov.il/privacy.
For EU residents: If you are not satisfied with how your inquiry was handled, you have the right to file a complaint with the data protection supervisory authority in your country.