Privacy Policy
Version 1.7 · Effective date: 15 July 2026
Scinova Group LLP ("ReadNTag", "we", "us", "our") provides the ReadNTag reference-management service at readntag.com, including the web app; our browser extensions (such as for Chrome, Firefox, Safari, and Edge); any mobile or desktop applications; any add-ins or add-ons for third-party tools (such as Microsoft Office or Google Workspace); the conference and opportunity listings; and any other apps, integrations, features, and related tools we make available from time to time (together, the "Service"). Not all of these are available at any given time; this definition covers them where and when we offer them. This Privacy Policy explains what personal data we collect, why, how we protect it, and the rights you have under Singapore's Personal Data Protection Act 2012 ("PDPA") and, where applicable, the EU/UK GDPR.
1. Who we are
Scinova Group LLP (UEN T23LL1363K) is a Singapore Limited Liability Partnership at 60 Paya Lebar Road, #06-28 Paya Lebar Square, Singapore 409051. We are the data controller for personal data processed through the Service.
Our Data Protection Officer can be reached at dpo@readntag.com.
2. What we collect
- Account data: your email address, display name, and a securely hashed password (we never store your password in plain text). If you sign in with a third-party provider in future, we receive the basic profile that provider shares.
- Your content: the references, PDFs and other files you upload or capture, together with the metadata and everything you create, generate, organise or edit using the Service's tools, including but not limited to topics, projects, highlights, notes, snaps, citations, matrices, screening decisions, reading lists, boards, planner entries, saved searches and feed views, and any similar content you produce through features we add over time.
- Usage data: events needed to run, secure and improve the Service, for example logins, paper views, exports, storage used, and the other interaction events generated as you use the Service's features (such as the items you open, the actions you take, and the tools and features you use), together with session records (sign-in time and duration), the IP address and browser/user-agent of your requests, and the approximate location (such as country or region) derived from your IP address. We process these first-party usage records on our own servers, with no third party involved, both to operate the Service and to understand how it is used (our "first-party product analytics"). Some records (such as logins, uploads and bandwidth) are necessary to run, secure and bill the Service. The rest are used for first-party product analytics on the legitimate-interest basis described in Section 4, and you can opt out of that analytics use at any time in Settings, under Privacy & cookies (we still keep the records necessary to operate and secure the Service).
- How you found us (signup attribution): when you register or join the waitlist, we record coarse, first-party attribution: the source that referred you (for example a link from a social network, or a campaign tag in the web address) and your approximate country. We use this on the legitimate-interest basis in Section 4 to understand where our users come from and improve our outreach. It holds no precise location and involves no third-party tracker. Our funnel counts (how many people began signing up from a given source) are anonymous: we do not store the email of anyone who starts but does not complete signup.
- Analytics data (optional, consent-based): if you accept optional analytics, our analytics provider PostHog records how you use the Service (such as pages viewed and features used) to give us richer insight. This is separate from our first-party analytics, is off unless you accept it, and you can withdraw consent at any time. See our Cookie Notice and Section 6 below.
- Browser-extension data: the extension stores, on your device only, the address of your ReadNTag backend and an access token you paste in. When you clip a page, it sends that page's bibliographic metadata (such as DOI, title, authors) to your ReadNTag backend.
- Payment data: payments for paid plans are handled by our payment processor (Stripe). We do not store full card numbers; we keep only limited billing records.
- Waitlist / pre-launch signup: if you ask to be notified about ReadNTag (for example from a coming-soon page) or if signups are temporarily full when you register, we store the email address you provide, together with the coarse source that referred you and your approximate country (see "How you found us" above), so we can invite you when a place opens. You can remove your waitlist entry at any time (see Section 9).
3. How we use your data
We use personal data to: create and secure your account; store and display your library and annotations; provide features you ask for (capture, enrichment, citation, export, sharing); maintain, debug and improve the Service; prevent abuse and fraud; comply with law; notify you when a waitlist place opens if you asked to be added to our waitlist; and, where you have agreed, send you service or marketing communications (which you can opt out of at any time).
We do not train AI models on your content. We do not use your uploaded documents, annotations, notes, or other content you create to train artificial-intelligence or machine-learning models, and we will not do so without first asking for your consent. If we later introduce AI-assisted features, we will describe in this Policy what is processed and on what basis before you use them.
4. Legal basis / consent
Under the PDPA, we collect, use and disclose your personal data with your consent and for the purposes notified in this Policy. Where the GDPR applies, we rely on: performance of our contract with you (to provide the Service), our legitimate interests (to secure and improve the Service), your consent (e.g. optional third-party analytics or marketing), and legal obligations.
Our legitimate interests include first-party product analytics: measuring how the Service is used, on our own servers and with no third party involved, so that we can improve it. We have weighed this against your interests and rights, keep the data first-party and free of advertising, minimise what we record, and offer an opt-out in Settings, under Privacy & cookies. Optional third-party analytics (PostHog) relies on your consent, not on legitimate interest, and is off until you accept it.
5. Third-party enrichment (what leaves our servers)
To enrich references, the Service may query public scholarly APIs such as Crossref, OpenAlex, Unpaywall and PubMed/arXiv. Only identifiers you already have (such as a DOI or title) are sent; we do not send your account details or private notes. These lookups are server-to-server and degrade silently if a provider is unavailable.
6. Sharing & sub-processors
We do not sell your personal data. We use a small number of trusted service providers ("sub-processors") to operate the Service, each under a data processing agreement and only for the purposes described here. Our current sub-processors are:
- Amazon Web Services (AWS) for cloud hosting, database and file storage, in the United States.
- Amazon Cognito (AWS) for account sign-in and authentication, in the United States.
- Amazon SES (AWS) for transactional email such as verification, password reset and notifications, in the United States.
- Stripe for payment processing for paid plans (United States and EU).
- PostHog for optional product analytics, only if you consent, processed on PostHog's US host (us.posthog.com). This is in addition to the first-party analytics we run on our own servers (Section 2); declining it does not limit your use of the Service.
- Sentry for error monitoring and crash diagnostics (United States). It receives technical error data such as stack traces and the request context when something goes wrong, which can incidentally include limited identifiers; it does not receive your uploaded documents or annotations.
We also disclose personal data to authorities where we are legally required to do so.
Business transfers. If we are involved in a merger, acquisition, financing, reorganisation, sale of assets, or a transfer of all or part of our business, your personal data may be transferred to the successor or acquirer as part of that transaction. We will require the recipient to continue to protect your personal data in a manner consistent with this Policy, and we will notify you of any such transfer and of any material change to how your data is handled.
User-initiated integrations. If you choose to connect an integration (for example, Microsoft OneNote via Microsoft Graph, Notion, or a custom webhook URL you provide), the Service sends the reference or note content you push to that third party at your request. Those third parties process the pushed content under their own terms and privacy policies, and they act as the controller of whatever you send them. You can disconnect an integration at any time in your settings.
Public reading lists you choose to share expose only bibliographic fields (title, authors, journal, DOI) of the papers in that list. They never expose your annotations, files, or account information, and only while the share link is active.
We maintain this sub-processor list as part of this Policy and will update it when our sub-processors change.
6a. Advertising and promotions
The Service may include ads and promotions, on free and paid plans alike. Where we show them, we make them relevant using information we already hold about you as a first party, such as the topics and tags in your library. We do not sell or share your personal data with advertisers, and we do not use third-party advertising or cross-site tracking cookies for this. Advertisers do not receive your personal data; we choose what to show using our own signals. This is separate from the optional product analytics described in Section 2, which we never use for advertising. If and when we offer personalized promotions, you will be able to turn off the personalization in your settings and still see non-personalized ones.
Some content, such as certain conference listings, may be sponsored, meaning a paid placement. We always label sponsored content clearly.
7. Where your data is stored (cross-border)
Your data is hosted in the United States. If we process or back up data outside Singapore, we ensure, as required by the PDPA's Transfer Limitation Obligation, that it receives a standard of protection comparable to the PDPA, through our providers' contractual commitments and our own security controls.
8. Retention
We keep your personal data for as long as your account is active and as needed to provide the Service. When you delete your account, it is deactivated immediately and then permanently erased after a 30-day recovery period. We keep your data during those 30 days only so that an accidental or unauthorized deletion can be reversed using the link we email you; you can also ask us to erase it sooner. After the recovery period we erase your content and personal data from our active systems, except where we must retain limited records to comply with law, resolve disputes, or enforce our agreements. Backups are purged on our routine backup cycle.
A waitlist email is kept only until you are invited to join or you ask us to remove it, whichever comes first. If you later create an account and then delete it, any waitlist entry for your email is removed as part of that erasure.
9. Your rights
You may, at any time:
- Access & correct your account data in Settings;
- Export your data. Download a copy of your references, annotations and account data at any time ("Export my data", a machine-readable file). You can also request a full export that additionally includes your original files (PDFs, attachments and snap images), which we prepare and email you a download link for. The full export is available once per billing cycle and counts toward your monthly download allowance; the metadata export above is always available. If your allowance is used up, or you need a complete copy sooner, contact support@readntag.com and we will provide it free of charge (these usage limits apply only to the self-service export and never restrict your right of access);
- Delete your account. Request full erasure ("Delete my account");
- Opt out of first-party analytics in Settings, under Privacy & cookies;
- Withdraw consent to optional processing (e.g. third-party analytics or marketing);
- Leave the waitlist. If you are only on our pre-launch waitlist (no account), remove your email at /waitlist/remove, or email us.
To exercise any right not available in-app, contact dpo@readntag.com. We respond within the timeframe required by law.
10. Security
We protect your data with encryption in transit (TLS) and at rest, access controls, hashed passwords, audit logging, and regular dependency and backup hygiene. No method of transmission or storage is ever completely secure, but we work to apply protections appropriate to the sensitivity of the data.
11. Cookies
We use strictly-necessary cookies and local storage for sign-in and your preferences; these always run. With your consent, we also set an analytics cookie via PostHog to measure how the Service is used. You can give or withdraw that consent at any time from the "Cookie preferences" link in the footer or in Settings, under Privacy & cookies. Our first-party product analytics does not rely on these optional cookies and has its own opt-out in the same place. See our Cookie Notice for full details.
12. Children
The Service is not directed to children under 13 (or the minimum age in your jurisdiction). Where the EU or UK GDPR applies, you must be at least 16, or the minimum digital-consent age set by your member state, to use the Service without the consent of a parent or guardian. We do not knowingly collect personal data from children below the applicable age. If you believe we have, contact dpo@readntag.com and we will delete it.
13. Changes
We may update this Policy. Material changes will be notified in-app or by email. The "Effective date" above reflects the latest version.
14. Contact & complaints
Questions or requests: dpo@readntag.com. If you are in Singapore and are not satisfied with our response, you may contact the Personal Data Protection Commission (PDPC).