ARXIVIX Privacy Policy
Effective date: 2026-09-11
ARXIVIX is operated by POPVOX Inc., a Delaware corporation headquartered in California. This policy explains how we handle information when you use our research, document, monitoring, and publishing services.
Contact us at legal@popvox.com, or write to POPVOX Inc., 274 Redwood Shores Pky 222, Redwood City, CA 94065.
Information we collect
Account and workspace information. We collect your name, email address, password in hashed form, timezone, login information, workspace and organization details, membership roles, and invitations. Workspace administrators can manage membership and access to workspace information.
Content and research activity. We process files you upload, URLs and sources you select, fetched source material, project information, annotations, metadata, search queries, questions, saved conversations, answers, citations, and alert instructions. Processing can create text extracted from documents, page records, summaries, structured fields, and search indexes. Your material and public sources may contain information about other people.
Support and onboarding. We collect survey responses, feedback, support messages, the page associated with a report, and information needed to investigate and respond.
Billing information. If you buy a paid service, our payment processor collects payment details. We retain the billing contact, transaction and subscription identifiers, purchased plan, payment status, and financial records needed to administer the purchase. ARXIVIX does not store full payment-card numbers or card security codes.
Technical and usage information. We collect session information, IP addresses, browser information, request and error information, and records of actions such as searches, uploads, questions, and feature use. Some of these records are linked to an account or project. We use them to operate the service, diagnose problems, prevent abuse, and understand which features need improvement.
How we use information
We use information to create and secure accounts; provide document extraction, search, monitoring, answers, alerts, and publishing; administer payments; answer support requests; diagnose and improve product reliability and usability; enforce our terms; and comply with legal obligations.
External AI processing is part of the service. Content in private projects, as well as public projects, may be sent to the processing providers used by ARXIVIX for features such as optical character recognition, search embeddings, and relevance ranking. The amount and type of material sent depend on the feature. The How ARXIVIX Uses AI page identifies the processing services and models enabled for the deployment you use.
We do not train AI models on your content. POPVOX does not use your documents, extracted text, questions, answers, or other submitted content to train or fine-tune AI models. We require providers processing that content for ARXIVIX to operate under contractual terms and applicable settings that prohibit such training. Creating a search index for your library is processing for the service, not model training.
Providers may retain information temporarily for service delivery, security, abuse prevention, or legal compliance under their applicable terms. A no-training commitment is not a promise that a provider retains no data. Provider retention information is described with the applicable service on the How ARXIVIX Uses AI page.
We do not sell personal information or share it for cross-context behavioral advertising. We do not use private content for advertising, public demonstrations, or general product research unrelated to a documented support, reliability, security, or legal need.
Who can access information
Your workspace. People with appropriate workspace permissions can access its projects and content. A private project is not restricted to the individual who uploaded each document. If an organization supplies your account, its administrators may control access, retention, and membership.
Our service providers. Providers may process information to supply hosting, database and file storage, backups, document processing, email, payments, and operational support. We limit access to the purpose of the service and use appropriate contracts and controls. A payment provider may also process certain information for its own legal, payment-network, and fraud-prevention responsibilities, as described in its privacy notice.
Authorized staff. Staff may access private content only when needed to fulfill a support request, investigate a specific service failure, protect security, investigate abuse, or meet a legal obligation. Access is limited to authorized personnel, recorded, and limited to the information needed. Staff may not browse private libraries out of curiosity or use their contents for model training. Service providers may separately conduct limited security or legally required review under their terms.
Public recipients. When an authorized user confirms publication, selected information becomes accessible through the public interfaces enabled for that project, including widgets, feeds, and compatible AI tools. Adding documents to a public project requires confirmation; a watcher can publish future items automatically only after that behavior is disclosed and confirmed. Disabling public full text also disables excerpts, source-derived summaries, and content-based public answers, leaving permitted metadata. Public recipients may copy information, and we cannot retrieve copies they independently made before access was removed.
Legal and business circumstances. We may disclose information to respond to valid legal demands, protect people and the service, investigate rights complaints, or complete a business transfer with appropriate confidentiality protections. Where lawful and appropriate, we notify affected users. A business transfer does not itself authorize training on your content.
Retention and deletion
The following periods are our ordinary retention limits. Where a shorter period is legally required, we follow it. A specific legal obligation, preservation requirement, or active security investigation may require a limited exception; we restrict those records to that purpose and review the need for continued retention.
| Information | Ordinary retention |
|---|---|
| Account information; originals; extracted text/pages; metadata; annotations; vectors; saved conversations and answers | While needed to provide your account and library. After deletion or account closure, remove from normal access promptly and complete deletion from active systems within 30 days of a valid request. |
| Backup copies of deleted information | Expire no later than 90 days after the deletion request. Restricted to disaster recovery and security; deletion instructions are reapplied before restored information is made available. |
| Temporary upload/OCR working files | Delete after processing; remove abandoned copies within 48 hours. Durable library files follow the content schedule above. |
| Raw search terms and questions copied into operational or diagnostic records | Up to 30 days. Questions deliberately saved in conversations follow the content schedule. |
| Identifiable usage events and routine security records | Up to 90 days; remove raw query text on the shorter schedule above. |
| Routine application/access logs | Up to 30 days. Necessary security evidence may follow the 90-day security schedule or a documented incident exception. |
| Staff access audit records | Up to one year; retain identifiers, purpose, and access details rather than copies of content. |
| Support, feedback, and survey records | Up to 24 months after resolution or last relevant interaction. Remove unnecessary content attachments earlier. |
| Minimal records of privacy requests and our responses | 24 months after completion, or longer where required by applicable law. |
| Minimal evidence of terms acceptance and subscription authorization | During the relationship and up to six years after it ends, subject to applicable recordkeeping requirements. These records do not include library contents. |
| Invoices and necessary accounting/tax records | Seven years after the relevant fiscal year ends, subject to applicable requirements. This financial-record period does not extend retention of documents, conversations, or usage records. |
Irreversibly deidentified aggregate statistics may be retained longer. We do not attempt to reidentify them or use content contained in them for model training.
Deleting an individual document also removes or redacts service-maintained derivatives and copied excerpts attributable to it within the active-system deletion period. Independent copies held by other users or public recipients, an original source website, and information independently required for legal or financial records may remain. We can explain the scope of a deletion request when you contact us.
Archiving a project retains its content. Deleting a watcher stops future monitoring; you must also choose to delete the collected items if that is what you intend. Removing an individual from an organization workspace does not automatically delete the organization's shared content. To close your account or request deletion that is not available through the interface, contact legal@popvox.com. We verify identity and authority proportionately before acting on sensitive requests.
Cookies and communications
We use essential cookies for sessions, security, and optional persistent sign-in. Product usage measurement is performed using service records; we do not currently use third-party advertising cookies. Browser settings can limit cookies, although disabling essential cookies may prevent account features from working.
We send account, security, billing, support, and service messages. You control configured alert emails. Optional promotional messages, if offered, have a separate choice and an unsubscribe method; acceptance of the service does not subscribe you to marketing.
Security and international processing
We use safeguards appropriate to the information and service, including access restrictions and security procedures. No service can guarantee that information will never be lost or accessed without authorization. Contact legal@popvox.com to report a security concern.
Processing locations depend on the hosting and processing providers enabled for the service and may include the United States and other countries. We identify those locations in our provider disclosures and use legally required transfer mechanisms where applicable. We do not promise that all information remains in one country unless a separate written agreement says so.
Your choices and rights
You can manage available sharing, alerts, and export controls in the service. Depending on your location and applicable law, you may have rights to access, correct, delete, or obtain a portable copy of personal information; object to or restrict processing; withdraw consent where consent is the legal basis; appeal certain decisions; and complain to a regulator. Contact legal@popvox.com. We respond within the applicable legal deadline and do not penalize you for exercising protected rights.
POPVOX determines the handling of account, billing, security, and service-administration information. For content an organization supplies and controls, we may act on that organization's instructions, including under a separately signed data processing agreement. We will direct requests to the responsible organization where appropriate while meeting our own obligations.
Where laws require a legal basis, we use the applicable basis for each purpose: necessary contract performance, legitimate interests assessed against your rights, legal obligations, or consent where required. The signup acknowledgment of service processing does not replace any separate consent or other lawful basis required for a particular category of information or purpose.
The service is for people aged 18 or older. Contact us if you believe a child has supplied account information so we can investigate and take appropriate action.
We will identify the effective date of material changes and provide advance notice when appropriate or legally required. Changes do not authorize retroactive model training on previously supplied content.