Skip to content

Privacy

What the product processes

This notice describes ArcXiv’s current data flows in plain language. It covers ArcXiv, not arXiv.org, linked papers, sign-in providers, or other third-party sites, which publish their own notices.

Information processed

  • Public browsing: requested URL, network and device information, timestamps, response and error information, search terms, and product interaction events may be processed in operational logs or analytics.
  • Account and sign-in: when you choose Google, GitHub, ORCID, or Hugging Face sign-in, ArcXiv receives the provider account identifier and available email, display name, and avatar. ArcXiv stores the linked profile and an ArcXiv session; the provider access token is used for the sign-in exchange rather than stored as an ArcXiv profile field.
  • Research workspace: saves, collections, notes, preferences, follows, reading or lesson progress, votes, questions, selected text, and generated answers may be stored when you use the corresponding feature.
  • Email: a weekly-digest subscription stores the address, confirmation and unsubscribe state, selected fields, delivery schedule, timezone, suppression state, and delivery history needed to operate the subscription.
  • Support: a message to the contact address contains the sender address and whatever details you choose to include.

Why it is used

ArcXiv processes this information to deliver requested pages and features; authenticate accounts; synchronize saved and learning state; select and send requested email; generate answers or learning material; prevent abuse; diagnose errors; understand performance and product use; and respond to correction, privacy, accessibility, security, or legal reports.

Public research-signal scores are designed to remain viewer-independent. Private activity and preferences may affect personalized ordering but should not change the public score. See the editorial and AI policy.

Processors and disclosures

Data may be processed by vendors that provide hosting, databases, search, authentication, email delivery, analytics, error monitoring, and model inference. The selected OAuth provider necessarily receives the sign-in request. Prompts, selected text, paper metadata, or source context needed for an AI feature may be sent to the model provider configured for that feature.

When enabled in a deployment, ArcXiv uses PostHog and Google Analytics for page, interaction, performance, feature-flag, survey, and error measurement. Signed-in analytics can be associated with an ArcXiv user identifier and profile fields. PostHog session replay may run when the relevant feature flag is enabled; inputs are configured to be masked, but sensitive information should not be entered into ArcXiv unnecessarily.

Information may also be disclosed when reasonably necessary to comply with law, protect users or the service, investigate abuse, or complete a service transition. This notice does not turn third-party content or an official arXiv record into ArcXiv-controlled data.

Cookies and browser storage

ArcXiv uses an HTTP-only session cookie after sign-in; the current session lifetime is up to 30 days. A short-lived OAuth state cookie protects the sign-in callback. Local storage and similar browser storage remember interface preferences, learning state, analytics identifiers, and whether the privacy notice has been dismissed. Analytics providers may set or read their own identifiers when configured.

Dismissing the on-site notice records that it was seen; it is not currently an analytics opt-out control. Browser privacy settings, storage deletion, and content blockers can limit client-side storage or analytics, though blocking essential storage can prevent sign-in or saved preferences from working.

Retention and source documents

Different records are kept for different operational needs. Session records expire; account, library, learning, question, subscription, delivery, security, and support records can remain while needed to provide the feature, preserve user choices such as unsubscribe or suppression, resolve disputes, and protect the service. ArcXiv does not publish a single retention period that applies to every record.

A PDF used for a full-paper research-signal job and its extracted body are processed transiently and are not retained after the job. Concise generated reasons, structural locators, model provenance, and job records may be retained. Paper metadata remains part of the public research corpus even if an ArcXiv account is deleted because it comes from the public arXiv record, not from that account.

Your choices and requests

  • Browse public records without creating an ArcXiv account.
  • Sign out to end the current server-side session and clear its cookie.
  • Use the unsubscribe link in every digest email to stop future delivery.
  • Clear site storage or use browser privacy controls for local data and analytics.
  • Ask to access, correct, or delete ArcXiv account information through the contact channel. Send the request from the account address when possible; identity verification may be required.

Applicable law may provide additional rights. ArcXiv cannot change or delete an official arXiv paper record; use arXiv’s own process for that source data.

Security and changes

ArcXiv uses access controls and separates public from authenticated application state, but no online service can promise absolute security. Do not send passwords, OAuth tokens, unpublished manuscripts, or unnecessary sensitive information through prompts or support email.

This notice should change when material product data flows change. No effective date or operator identity is asserted here without a verified public record. Questions about the current notice can be sent through the published contact route.