Privacy policy
ResearchOS is built so that your work lives on your own computer, not on ours. Your notes, experiments, methods, images, and attachments are saved in a folder you pick on your own machine. Optional sharing and hosted features can send data off your device. You sign in to ResearchOS so we know who you are and other researchers can find you, and that account identifies you for these services. This page explains what stays local, what optional features send off your device, and which hosted data we can read.
Effective September 16, 2026. ResearchOS is free and open-source software written by researchers at the University of Wisconsin-Madison. If anything here is unclear, write to gnickles@wisc.edu.
The short version
- Your research, meaning your notes, experiments, methods, images, and attachments, lives in a folder you pick on your own machine. Local-only work is not uploaded to our servers. Optional hosted features have separate data flows described below.
- Signing in creates an account record on our servers. Choosing to publish a directory profile lets other researchers find you. It holds a salted hash of your verified email, your public keys, an encrypted backup of your key, and any account profile you save, rather than your local notebook. An account profile can include your handle, name, affiliation, avatar, biography and links. Public directory listing is a separate choice. Some account settings are stored in an encrypted blob. Your light, dark, or system theme preference is stored separately in readable form so it can apply when you sign in, before you unlock your notebook.
- A few features are hosted by design, so their content does sit on our servers. If you use Check-ins, its goals, meeting notes, and ratings are kept in readable form, because a mentor and a mentee need to see the same record from different computers. Photos and notes you send from the phone Companion pass through a relay that holds them only until your laptop picks them up, then deletes them.
- When you send work to someone outside your folder, it travels end-to-end encrypted through a relay that cannot read it and deletes it on a short timer. Live real-time collaboration works differently, it keeps a synced copy of the shared document on our servers so edits appear instantly, and that copy is not end-to-end encrypted.
- We do not sell your data or run advertising. Publishing and other connected features send content when you choose to use them.
Your local notebook
When you open ResearchOS you pick a folder on your computer, and the app reads and writes your notes, experiments, methods, images, and attachments directly to that folder. Local-only work stays on your machine unless you choose a feature that shares or uploads it. You can open the folder in Finder or Explorer at any time and see every file sitting there. Quit the app and your data stays exactly where it is.
Because of this design there is no server-side copy of your work for the core experience. Your account is an identity, not storage, and the hosted data flows below exist for specific features you choose to use. For the full technical account, see the security page.
Optional AI, backups, and publishing
BeakerBot AI. When you use hosted AI, your messages and the research context included for that request pass through the ResearchOS AI service to the configured model provider. That context can include tool results and attachments you provide. The provider needs this content to generate its response. Using an open-weight model does not mean the request stays on your computer. AI is optional.
Backups and your own storage provider. If you put your notebook or an exported backup in a cloud-synced folder, that provider can upload the files under your settings with it. Copying files into that folder is not confirmation that a cloud upload has completed. The encrypted identity-key backup stored by ResearchOS is separate from a backup of your notebook contents.
Lab websites and published work. Creating a hosted site sends its draft content to ResearchOS. Publishing makes the selected page and its published figures, tables, or datasets publicly available. Hosted assets are uploaded to the site storage service. Your unpublished local notebook does not become public just because you publish a page.
Signing in with Google, GitHub, Microsoft, LinkedIn, or ORCID
To create your account you prove you control an email address. You can do that with a one-time code we email you, or by signing in with Google, GitHub, Microsoft, LinkedIn, or ORCID. When you use Google, GitHub, Microsoft, or LinkedIn, we receive your verified email address and your name from them, and we use them for two things only.
- The verified email is turned into the salted hash described above, so the address itself is not retained in the directory.
- Your name can be saved with your account profile and settings. Publishing a searchable directory profile is a separate choice.
We request the minimum scope needed to read your email and basic profile. We do not request permission to post, read your contacts, or access anything else, and we never take any action on those accounts on your behalf. Your session is kept in a signed cookie on your device, not in a server-side session table.
ORCID works a little differently. ORCID does not share an email address with us. We receive your ORCID iD, which is already a public identifier, and store it as-is so a later ORCID sign-in can find your account. We then ask you for an email address and confirm it with a one-time code. Because a future ORCID sign-in has to look that address up again, we keep it encrypted at rest under a key we hold, so unlike the other providers we can recover the address itself. It is still never published, never searchable, and never used for marketing.
The encrypted relay for one-time sends
When you send a note, method, experiment, project, or sequence to someone outside your folder, ResearchOS encrypts it on your device before it ever leaves, then hands the encrypted bundle to a relay that simply holds it until the recipient picks it up. The relay stores only ciphertext. It has no keys, sees no filenames, and cannot read any of the contents.
Bundles auto-expire on a short timer (about 30 days) and are deleted when the recipient retrieves them, whichever comes first. The only metadata recorded is what is needed to route and expire a pending delivery. There is an abuse-report path so a recipient can flag unwanted content, and because the relay holds only encrypted bytes, we act on the account rather than the content we cannot see.
Live real-time collaboration works differently. When you co-edit a note or a shared notebook with someone live, the app keeps a synced copy of that document on our servers so every change reaches the other person right away. That copy is held in readable form, not end-to-end encrypted, so unlike a one-time send, our servers can read what you collaborate on there. Anything you do not put into a live shared document remains local unless you use another feature that sends it off your device, such as publishing or hosted AI.
Email we send
We send transactional email only, and all of it goes through Resend, our email provider. Here is the full list.
- The one-time code that confirms you control your address.
- An invitation when someone shares with you or invites you to collaborate, or when a lab head chooses to have us send their invitation to join the lab.
- Notifications to your own inbox, only for the categories you turn on under Settings, and only to the address you set there.
- A confirmation if you join the closed-beta waitlist or ask for a beta-tester code. We may write to that list about the beta, since that is what you joined it for.
We do not send marketing email, and we never add you to a list you did not join yourself.
Analytics
The hosted app uses Vercel Web Analytics and Speed Insights to understand page performance and rough traffic. These are privacy-respecting and do not use cross-site tracking cookies or build advertising profiles. They never have access to your research data or to anything else described on this page. If you run ResearchOS locally from source, even this is absent.
Deleting your data
Most of what you make in ResearchOS never reaches us, so most deletion is already in your own hands. A few things are hosted on our servers so a lab can share them across computers, and for those you can ask us to delete them. Here is the split.
On your own disk, delete it yourself. Your notes, experiments, methods, images, and attachments live in the folder you picked on your computer. Delete that folder the way you delete any file and it is gone. There is no server copy for us to remove, and you can revoke the app's access to the folder in your browser at any time.
On our servers, ask us. This is everything we can hold for you, and all of it is covered by a single request.
- Your account record. The salted hash of your verified email, your public keys, your encrypted key backup, any profile you chose to publish, and the sealed preferences blob if the app keeps one for you. If you signed in with ORCID, your ORCID iD and the encrypted copy of the email you confirmed. You can remove a published profile yourself at any time.
- Hosted Check-ins content. Goals, meeting notes, and ratings entered in Check-ins are kept on our servers in readable form, because a mentor and a mentee need to see the same record from different computers.
- Phone Companion captures in transit. Photos, scans, and notes you send from the phone Companion travel over an encrypted connection to a relay that holds them only until your laptop picks them up, then deletes them. So there is normally nothing waiting, but anything not yet picked up is included. The snapshots your laptop sends to the phone are sealed to the phone's own key and are removed when you unpair it.
- Pending shares. Encrypted bundles waiting for a recipient. These expire on their own within about 30 days regardless.
- Your waitlist or beta-tester entry. If you joined the closed-beta waitlist or asked for a beta-tester code, the address you entered, and the name if you gave one.
How to ask. Email hi@research-os.app from the address on your account with the subject line "Delete my data". Writing from the account address is how we confirm the request is really yours without asking you for anything else. We will complete the deletion within 30 days and confirm by reply. Billing records for a paid plan are kept only as long as tax law requires; everything else goes.
Your rights
You can request access to, correction of, or deletion of the limited directory data described above. Because local-only research stays on your machine, most of your data is already entirely in your own hands. The lawful basis for processing the account and sharing-directory data is providing the account and sharing features you asked for, together with your consent, and we minimize what we hold to the salted email hash, public keys, and whatever profile fields you choose to publish.
Children
ResearchOS is a tool for researchers and is not directed to children under 13, and we do not knowingly collect personal information from them.
Changes to this policy
If this policy changes in a meaningful way, we will update the effective date at the top and, where appropriate, note the change in the app. Because ResearchOS is open source, the full history of this page is visible in the public repository.
Contact
Questions about privacy or anything else covered here can go to gnickles@wisc.edu. Deletion requests go to hi@research-os.app as described under Deleting your data. ResearchOS is operated by ResearchOS LLC, a registered Wisconsin company.