Privacy Policy
Last updated: 5 August 2026
The short version:
- We don't use marketing or tracking cookies. Only strictly necessary ones.
- We use AI to help select and summarise scientific articles. Some content may be AI-generated.
- We store standard server logs for security and performance.
- If you create an account, we store your email, a hashed password (or your Google profile), your reading lists and your newsletter preferences. A reading list stays private unless you choose to publish it.
- Questions? Email us at [email protected].
1. Who We Are
Marginalia (readmarginalia.com) is operated by 4xxi Software Ltd. (“we”, “us”, “our”). For the purposes of UK data protection law, we are the data controller.
Contact: [email protected]
2. What We Do
Marginalia is a platform that displays curated collections and digests of scientific and academic articles. We use content from publicly available academic databases for scientific and educational purposes, presenting it in structured, expert-annotated formats.
3. What Data We Collect
We collect minimal data.
Account data. We operate our own accounts. When you register with an email address and password, we store your email address, your name (if you provide one), a cryptographic hash of your password (never the password itself), whether your email address has been verified, and the role assigned to your account (reader, expert or administrator). If you sign in with Google instead, Google sends us your name, email address and profile picture. This is used for authentication, account management, and to deliver newsletter emails if you subscribe to updates.
Session and security data. When you sign in, we store a session record containing a session token, the IP address and browser user agent the session was created from, and its expiry time. We also keep short-lived records of one-time email verification codes and password-reset links, and rate-limiting counters that protect the sign-in endpoints from abuse.
Reading lists and saved items. If you save papers or books, we store the lists you create (name, icon, description) and the items in them. Lists are private by default. If you choose to share a list, we generate an unguessable link that makes that list — its name, description and items — readable by anyone who has the link, until you make it private again. We do not publish your name alongside a shared list unless you have put it there yourself.
Paper suggestions. If you suggest a paper or book for an expert collection, we store the identifier you submitted (DOI or ISBN), the collection it was suggested for, and your account reference. The curator of that collection is notified by email and can see that a suggestion was made by you.
Expert and editorial activity. If your account has expert or administrator rights, we additionally store the content you produce in that capacity — annotations, collections, digests, retriever configurations and newsletters — together with your authorship of it. Published expert annotations appear publicly with your expert profile.
Subscription preferences. If you subscribe to newsletter updates, we store your subscription preferences (topics and collections you follow). You can unsubscribe at any time using the links in every newsletter email or by managing your subscriptions on the Website.
Server logs. When you visit Marginalia, our hosting provider automatically collects standard server log data. This may include your IP address, browser type, operating system, referring URL, pages visited, and timestamps. This data is collected for security, performance monitoring, and error diagnosis. Server logs are retained for up to one year.
Strictly necessary cookies. We use only cookies that are essential for the website to function (e.g., session management, security tokens). We do not use marketing cookies, advertising cookies, analytics cookies, or any third-party tracking cookies.
Marketing attribution.When you arrive at our website via a marketing link (e.g. from an email campaign or advertisement), we store the UTM parameters from the URL (source, medium, campaign, content, and term) along with the referring website address in your browser's localStorage (as betterauth_utm). This data is transferred to your account record when you sign up, and is then removed from localStorage. We use this data solely to understand which marketing channels bring users to our service. It is not shared with third parties and is not used for cross-site tracking.
Voluntary correspondence. If you contact us by email, we will process the personal data you provide (such as your name and email address) for the purpose of responding to your enquiry.
4. How We Use Your Data
We process personal data on the following lawful bases under UK GDPR:
- Legitimate interests (Article 6(1)(f)): server logs, session data and rate-limiting counters for website security, abuse prevention and performance; application logs for error diagnosis; marketing attribution data to understand which channels bring users to the service.
- Consent (Article 6(1)(a)): if you voluntarily contact us, your correspondence is processed on the basis of your consent to communicate with us.
- Contract performance (Article 6(1)(b)): operating your account, keeping your reading lists, sharing a list when you ask us to, passing a paper suggestion to the relevant curator, and delivering newsletter emails based on your subscription preferences.
We do not sell, rent, or share your personal data with third parties for marketing purposes.
5. Newsletter Email Delivery
If you subscribe to newsletter updates, we use Resend (a US-based email delivery service) to send newsletter emails to your registered email address. Your email address and name are shared with Resend solely for the purpose of delivering these emails.
Resend processes your data as a data processor on our behalf. We do not use Resend's marketing or audience features. Each email is sent individually as a transactional message based on your explicit subscription.
Every newsletter email contains unsubscribe links. You may unsubscribe from individual topics or collections, or from all emails at once. Unsubscription is immediate and does not require authentication.
6. AI and Automated Processing
Marginalia uses artificial intelligence, specifically Large Language Models, as part of its editorial and content workflow. AI tools are used for:
- Monitoring and filtering scientific manuscripts from public databases.
- Generating summaries, data extractions, and assessments of scientific articles.
- Assisting with content preparation for collections and digests.
Some content published on the Website may be AI-generated or AI-assisted. Where possible, AI-generated content is reviewed by human expert curators, but this is not guaranteed for all content.
Where open access PDF files are available, we may download and extract text content to assist with automated annotation. Extracted text is sent to our AI provider for analysis.
AI is also used in automated filtering to determine which articles are selected or rejected for inclusion. This automated processing applies to publicly available bibliographic data and does not involve personal data of Website visitors.
We use third-party AI services to process article metadata and generate content: OpenAI (US-based) by default, and optionally OpenRouter (a US-based gateway to other model providers), Azure OpenAI, or a model we host ourselves. Which provider and model runs each editorial step is a configuration setting our administrators control and may change. Data sent to AI providers is limited to bibliographic information and article text — titles, abstracts, DOIs and, where available, open-access full text. No personal data of Website visitors is sent to AI providers.
7. Third-Party Data Sources
Article metadata displayed on Marginalia (such as titles, authors, abstracts, publication dates, and DOIs) is sourced from publicly available academic databases and APIs, including but not limited to:
- NASA Astrophysics Data System (ADS)
- OpenAlex
- arXiv
- CrossRef (for DOI lookups)
- Unpaywall (for open access PDF discovery)
- Google Books (for ISBN and book metadata lookups)
We use this content for academic and scientific purposes to display structured collections and digests. We do not host or redistribute full-text articles unless they are published under open access licences.
8. Other Recipients of Your Data
- Google — only if you choose to sign in with Google, in which case Google authenticates you and returns your name, email address and profile picture.
- Resend — our email provider, which receives email addresses and message content in order to deliver newsletters, account emails (verification codes, password-reset links) and curator notifications.
- Collection curators — if you suggest a paper for a collection, its curator receives an email identifying you as the person who suggested it.
- Anyone with a share link — if you publish one of your reading lists, its contents become readable by anyone holding the link until you make it private again.
- Our self-hosted log aggregation service — runs on our own infrastructure; no log data is sent to an external third party.
We do not sell your personal data and we do not use advertising or third-party analytics networks.
9. Data Transfers
Our website is hosted on infrastructure that may process data outside the United Kingdom or European Economic Area. In particular, our AI providers and our email provider (Resend) are based in the United States. Where data is transferred outside the UK or EEA, we rely on Standard Contractual Clauses or equivalent safeguards approved under UK GDPR; where a provider is certified under the UK Extension to the EU-US Data Privacy Framework, that certification may also apply.
10. Data Retention
Your account, reading lists, subscription preferences and suggestions are retained for as long as your account exists. You can delete individual lists and saved items at any time in the application, and you can make a shared list private again at any time.
To have your account and its personal data deleted, email us at [email protected]. Editorial content published under an expert profile (annotations, collections, digests) may be retained after account deletion as part of the public scientific record, with attribution removed on request where that is possible.
Server logs are retained for up to one year. Newsletter delivery records are retained for operational purposes.
11. Your Rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate personal data.
- Eraseyour personal data (“right to be forgotten”).
- Restrict processing of your personal data.
- Object to processing based on legitimate interests.
- Data portability where applicable.
- Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, contact us at [email protected]. We will respond within one month.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
12. Age Restriction
Marginalia is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from anyone under 18.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated “last modified” date.
14. Contact
For any privacy-related questions or requests:
Email: [email protected]