How your data and privacy work
Where your research actually lives, what touches our servers and when, how shared work is protected, what the cloud costs and why, and what a lab can publish. The plain-English version, honest throughout, including the parts where our server can read something.
Local by default
Your research lives in a folder on your own computer. ResearchOS reads and writes that folder directly through your browser, and there is no database we control holding your work. A free ResearchOS account is your identity, the way other researchers find you and you find them. It is not where your data is stored, not even on a paid lab plan.
Almost everything you do never leaves your laptop. The cloud is a thin path you open only when you ask. Click through the four steps below to see it.
Your work lives on your own computer
Every experiment, note, and result sits in a folder on your own machine. The browser reads and writes that folder directly. Nothing uploads to us.
There's no ResearchOS database holding your folder. Close the app and your data stays right where it is.
The only three things that leave
Local-first does not mean isolated. Three actions open the thin path, and we are honest about which ones our server can read. Each one moves only what you choose, never the whole folder.
Co-edit live, just the one doc
When two people edit the same note live, only that one shared document streams to our relay so each change reaches the other person right away. Everyone has their own named cursor, and the rest of your folder never moves.
Ask the AI, and only what it reads goes
BeakerBot runs on your machine. When you ask it to work with your data, only the note or table it reads travels through our server to the AI provider, and the answer returns. Nothing else from your folder goes along for the ride.
Three ways to share
There are three sharing modes, not two. Receiving anything is always free. Sending a copy or hosting live collaboration is a paid feature, and only the one-time copy is end-to-end encrypted.
- Live co-editing among members
- Only the shared doc syncs
- PI oversight, audit-logged
- Live co-editing with an outside user
- Their copy stays in sync, revocable
- Encrypted in transit and at rest, relay merges
- A one-time copy to anyone
- Free to receive, paid to send
- End-to-end, we cannot read it
Hot, cold, and local storage
The document you co-edit right now sits in a fast store that costs more. Backups and published files sit in a cheap durable store. Everything else is free, on your own disk.
That is roughly a thirteenfold price gap between the hot and cold tiers. Live collaboration needs the fast store, so that is the part a paid plan pays for. Almost everything else is free or has no marginal cost.
A free second copy from your university
Most universities already pay for Google Drive, OneDrive, or Box. Because a ResearchOS folder is just plain files, you can keep it inside that sync drive for an automatic second copy of your raw data at no extra cost to you or to us. The whole lab can even work out of the same synced folder.
Your version history rides along, because it is just files in the folder. ResearchOS writes the history into a per-record log inside your own folder, so it works offline, it is backed up with the rest of the folder, and none of it lands on a ResearchOS server.
Why it stays affordable
Both the low cost and the strong privacy come from the same place. Because your data is local, free accounts cost us almost nothing, and we never charge to store research we do not hold.
You mainly pay for live collaboration, the one part with a real per-use cost. Storage is sold at roughly what it costs us, not as a markup to profit from. We do not make money holding your data. The honest, full breakdown of the model is on How it stays free.
A spending brake
Cloud usage has a built-in safety valve. If cloud cost ever nears the budget set for an account, a brake pauses cloud writes until we lift it by hand, so spending never silently resumes. Your local work keeps running and nothing is lost.
Lab-head search, without moving the data lab tier
On the lab tier, a lab head can search the whole lab without bulk-copying everyone's data. Each member's sync writes one tiny, lab-key-encrypted index of titles and previews, so a lab head can search the whole lab instantly. The lab head reads only those tiny encrypted indexes, never everyone's files.
Big files stay with their owner. A large data table or sequence is not pushed to the index. The lab head sees that it exists, then requests it, the owning member approves, and only then does the full content upload. The request is visible to the member, there is no silent decline, and every lab-head read is audit-logged to the member's own log.
Local workspace, published page
Your private workspace stays local. The one place where ResearchOS deliberately puts something in the cloud is when you choose to publish. A public web address has to live online, so a page or dataset you publish is hosted in the cloud on purpose.
Your lab's own web home coming with lab sites
A lab is getting a public page at your-lab.research-os.com, with a custom domain as a later add-on. The headline use is a companion page for a paper, a citable landing page that can carry the paper's figures and a live, interactive dataset viewer, frozen on publish so the link never changes under a reader. There will be three ways to build it, so it fits any comfort level.
A no-code builder for data, omics, and genomes coming with lab sites
The built-in builder is the recommended default for most labs. The direction is a drop-in widget canvas, a data table, an omics heatmap, and a genome browser whose chromosomes open on the sequence pages, so a supplement page can carry live, interactive figures rather than flat images.
Where to go next
For the audit-grade version of the local-first claim, including how to watch the network yourself in DevTools, read the Security page. For the account tiers and what each one unlocks, see Account tiers. For the funding model in full, see How it stays free.