Privacy
ResearchOS is built so that we could not read your research even if we wanted to. This page says exactly what is stored, where, and who can see it. Last updated: August 2026.
This website
- No client-side analytics, no trackers, no cookies, no third-party scripts. The site is static files served from our own server.
- The web server keeps standard technical logs (IP address, page requested, timestamp, browser signature) for security, debugging, and anonymous usage statistics — page views, visitor counts and download counts are computed from these logs on the server, using one-way hashes that are never stored. Logs rotate away within 14 days; only anonymous aggregates (counts) are kept. Nothing about you leaves our server.
The apps
- Your research data — runs, logbook, notes, references, PDFs, papers — lives on your own machine, in open formats (Markdown, BibTeX, SQLite, JSON). It is never sent anywhere unless you enable sync.
- The apps contain no analytics and no telemetry. Bug reports are emails you write yourself.
- The AI assistant runs only when you use it. With an API key you provide (Anthropic, OpenAI, Google, or Mistral), prompts go directly from your machine to the provider you chose — never through our servers. If you explicitly select the optional hosted "ResearchOS" provider instead, those questions are relayed through our server to the model and immediately discarded — never stored, never logged. That is the one exception to the ciphertext-only rule, and it happens only when you choose it. On every plan, any element of your workspace can be individually excluded from the AI.
Sync (optional)
If you enable sync, your data is end-to-end encrypted before it leaves your device. Your passphrase derives encryption keys (argon2id + libsodium) that never leave your devices.
- What the server stores: your email address, a hashed password, device names, encrypted key material it cannot open, and your synced data as ciphertext — plus sizes and timestamps needed to make sync work. If your account belongs to a lab, the server also stores the lab's organization metadata: lab and team names, membership and roles.
- What the server can never see: the content of your notes, runs, PDFs, messages — anything. This is enforced by the protocol, and our test suite includes a check that dumps the server database and searches it for known plaintext. The only exception is the optional hosted AI provider described above, which relays only the questions you explicitly send it.
- Direct messages and group chats are end-to-end encrypted spaces whose keys exist only on the participants' devices. Nobody else can read them — not the server, and not your lab: there is no organization key, and lab admins see only metadata plus what members explicitly publish.
- Lab expertise profiles (research interests and hand-picked references, shown in a lab's directory) are opt-in publications: empty by default, written by you, stored readable on the server precisely because you chose to publish them, and editable or clearable at any time. Nothing is ever published from your library automatically.
- The beta sync server is hosted in France (OVH). You can also run your own server — the design means even your own server never sees plaintext.
- If you lose your passphrase, only your recovery code can restore access. We cannot read or reset your data for you.
Deleting your data
- Local data: yours to delete, like any other files on your machine.
- Account deletion (in the app, or on request) permanently removes your account, devices, encrypted data and blobs from the sync server.
Emails to beta@tramea.org or contact@tramea.org are used only to answer you and manage your beta access. No newsletters unless you ask for them, and your address is never shared.
ResearchOS is operated under the Tramea name by its
founder; a formal legal entity is being established for the public
launch, and this page will be completed with the usual legal
identifiers at that point. Privacy questions:
contact@tramea.org.