What happens to your data, provider by provider
Where your documents are stored, which AI provider reads what, what is sent to the open bibliographic databases, how your keys are encrypted and what is deleted when you delete.
Reviewed on This page as Markdown
The main thing
Your documents are yours. We do not train models on them. To read them, transcribe them and search them, Scholaris sends pages, audio and queries to AI providers, and this page says which ones, what for and what is stored where. If you work with material that must not leave your computer, the home version keeps everything on your disk, although it still needs a provider to read pages.
There are no third-party analytics and no ads on the site. The only cookies are the session ones (Clerk) and one that remembers you are in the demo.
Where each thing is stored
Everything lives on Cloudflare, in Scholaris's account:
| What | Where |
|---|---|
| Your account, your API keys (hash only), settings, usage, invitations and access log | D1, Cloudflare's database |
| Originals and page images | R2, Cloudflare's object storage, under a folder of your own |
| Your read library (text, anchors, records, index) | A Durable Object of your own, with its SQLite database, just for you |
| Vectors | Cloudflare Vectorize, in a namespace of your own |
| The session | Clerk, which handles sign-in (email and name) and payments |
What each provider reads
| Provider | What it receives | What for |
|---|---|---|
| Google Gemini (paid API) | Page images, audio, the address of YouTube videos, passages and queries | Reading pages (Gemini 3.8 Flash and 3.5 Flash-Lite), transcribing (Gemini Transcribe), vectors (Gemini Embedding 2), drafting answers and extracting entities |
| Cloudflare Workers AI | Audio, images of easy pages and text | Transcribing with Whisper, fallback and economy reader, fallback vectors and reranker |
| OpenRouter (with Mistral OCR) | Pages the previous readers could not read; text to draft if Gemini fails | Fallback reader and writer |
| TypeSafe (Jev) | Query and passage pairs, claims and passages, page-number candidates | Reranking results, judging citations and settling doubtful folios |
These providers get just what each task needs and are used through their paid or business APIs. Their terms (not ours) say how long they keep data and whether they use it for anything else; for instance, the Gemini API's paid terms exclude using requests to improve their products, while allowing them to be kept for a limited time to detect abuse. If that is not enough for you, use the home version with your own keys or, in its offline mode, with no provider at all: the models run on your machine or your network and no request goes out to the internet.
What is sent to open bibliographic databases
To complete and check each document's record, Scholaris asks Crossref, OpenAlex, Open Library, Wikidata, Wikipedia, arXiv, DataCite and, as a last resort, Google Books. What is sent is the title, the authors, the ISBN or the DOI, never the text. To link entities, each entity's name is sent to Wikidata. Requests identify themselves as "Scholaris/2" with the site's address. In the offline mode of the home version these lookups are off unless you turn them on.
Your own keys
You can add your own Gemini, OpenRouter, TypeSafe, Mistral, Voyage, Cohere, Jina or ZeroEntropy keys so your library uses your accounts. They are stored encrypted with AES-256-GCM, with a key derived per user, and are only used if you switch them on.
Deleting
- Deleting a document also deletes everything derived from it: pages, vectors, images.
- Deleting your search history, or pausing it.
- Exporting everything as a ZIP before you leave.
- Deleting your account: your keys, settings, usage, invitations, notifications and shared links are deleted; your library is emptied; vectors and files are purged in the background. A row with your identifier remains, marked as deleted, with no email or name, so it cannot be reused. The exception: if someone copied a document from a library you shared with them, their copy remains theirs.
Contact
For anything about your data, jl@joseluissaorin.com.