Language

Research Quality Lab · Privacy & Data Practices

Privacy Policy

This Privacy Policy explains how Research Quality Lab (RQL) collects, uses, stores, protects, and shares information when you use the RQL platform, services, workspaces, Network features, contact-discovery tools, and related research-support services.

Last updated: 2026-05-13
No sale of personal dataRQL does not sell personal data or Google Contacts data.
Google access is optionalGoogle Contacts is connected only when a user chooses to authorize it.
Read-only contact accessRQL does not request permission to edit or delete Google Contacts.
User-controlled sharingUsers decide whether to connect with or invite discovered contacts.

1. About RQL

Research Quality Lab (RQL) is a research-support platform providing AI-assisted manuscript review, post-publication review, academic polishing, translation support, human reviewer workflows, certificates, journal workspace tools, institutional services, scholarly collaboration, Network features, contact discovery, and related research-support services.

RQL may provide both free and paid services. Paid services may be purchased directly, through service credits, through institutional access, or through subscription plans where applicable.

This Privacy Policy applies to information processed through those services and through your RQL account.

2. Information We Collect

Depending on the features you use, RQL may collect and process the following categories of information:

  • Account information: name, email address, username, password hash, profile details, affiliation, qualification, ORCID, language, skills, and uploaded profile photo where provided.
  • Uploaded documents: manuscripts, PDFs, DOCX files, CVs, reviewer profile documents, revised files, and other attachments submitted through the platform.
  • Extracted and processed content: text and related document information extracted or processed to provide AI review, polishing, translation, scoring, certificate, or other requested services.
  • Review workflow data: AI review outputs, Paper Quality Score information, Post-Publication Review records, reviewer comments, reviewer offers, revision notes, review status, and workflow timestamps.
  • Profile and reputation information: badges, certificates, ratings, endorsements, reviewer activity, public profile information, and collaboration history.
  • Contact-discovery information: where you choose to use contact discovery, RQL may process contact names and email addresses obtained from an authorized Google account or from a CSV/vCard file that you upload. Additional details about Google data are provided in Section 5.
  • Payment and entitlement information: payment references, transaction status, purchased services, credit purchases, credit balances, credit transfers, subscription status, subscription entitlements, service access, and certificate entitlements. Full payment-card details are handled by the applicable payment provider and are not stored by RQL as card data.
  • Communication data: email notifications, reviewer invitations, Network invitations, referral invitations, thread messages, support requests, workflow messages, and notification records.
  • Usage and security information: timestamps, page views, IP-related usage signals, abuse-prevention checks, error logs, and device or browser-related technical information.

3. How We Use Information

RQL uses information where necessary to provide, maintain, secure, and improve the platform and the services requested by users.

  • To provide AI-assisted review, post-publication review, polishing, translation, scoring, and certificate services.
  • To operate user dashboards, public profiles, reviewer-board listings, journal workspaces, institutional workspaces, Network features, contact discovery, and collaboration workflows.
  • To identify whether a contact selected through contact discovery already has an RQL account and to support user-initiated connection or invitation actions.
  • To process payments, credits, subscriptions, service entitlements, refunds, and billing records.
  • To provide access to services purchased directly, through credits, through institutional arrangements, or through eligible subscription plans.
  • To send service emails, reviewer invitations, user-selected Network or referral invitations, notifications, payment updates, subscription updates, and workflow alerts.
  • To prevent abuse, spam, duplicate submissions, unauthorized access, and other misuse of the platform.
  • To maintain platform reliability, troubleshoot errors, protect security, and develop and improve research-support features.

4. AI Processing

When you request an AI-assisted service, information necessary to perform that service may be processed by an AI provider used by RQL.

Depending on the service, this may include manuscript or abstract text, title, review type, language preference, document type, and related information required to generate the requested result.

Important: RQL uses AI processing to provide requested services. You should only upload documents and information that you are authorized to process through the platform.

AI-generated results are provided as research-support outputs. Users remain responsible for reviewing, verifying, and appropriately using the resulting material.

Google API disclosure

5. Google Contacts and OAuth Data

RQL provides optional Google Contacts integration for its Network and Referral Contact Discovery features. RQL accesses Google user data only after an authenticated RQL user chooses to connect a Google account and grants permission through Google's OAuth consent process.

Google data RQL accesses

RQL requests the following read-only Google OAuth scopes:

https://www.googleapis.com/auth/contacts.readonly

Used to read contact names and email addresses from the user's Google Contacts so RQL can display relevant contacts for Network and Referral Contact Discovery.

https://www.googleapis.com/auth/contacts.other.readonly

Used to read names and email addresses from Google's Other Contacts so a user can discover people they have previously interacted with who may not be stored in their primary Google Contacts list.

RQL does not request Google Contacts permission to create, modify, or delete contacts.

How RQL uses Google Contacts data

  • To display contact names and email addresses to the authenticated user within RQL's contact-discovery interface.
  • To compare contact email addresses with RQL accounts so the interface can distinguish existing RQL members from contacts who may be eligible for an invitation.
  • To allow the user to select whether to initiate an RQL connection request or send an invitation through an RQL workflow.

RQL does not automatically invite all discovered contacts. The user chooses which eligible contacts, if any, to invite.

Storage and retention of Google data

Google contact lists are fetched for contact discovery and are not stored by RQL as a permanent address-book database. RQL may retain encrypted OAuth credentials or tokens needed to maintain the user's authorized Google connection until the connection is disconnected, revoked, expires, becomes invalid, or is otherwise removed.

If a user chooses to send an RQL Network or referral invitation, RQL may retain the selected email address and invitation-related records as part of the resulting RQL workflow, including invitation status, timestamps, referral attribution where applicable, and security or abuse-prevention records.

CSV and vCard contact imports

RQL may also allow users to upload CSV or vCard contact files. Original uploaded contact-file bytes are not retained as a permanent address-book file for contact discovery. Parsed contact information may be held temporarily in protected cache storage to provide the discovery session and is cleared automatically after the configured temporary retention period or when the user selects the clear-import option.

Sharing, advertising, and Limited Use

RQL does not sell Google Contacts data and does not use Google Contacts data for advertising. RQL does not use Google Contacts data to train generalized AI models.

RQL's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Disconnecting Google Contacts

Users may disconnect Google Contacts through the RQL contact-discovery interface. Disconnecting removes RQL's stored Google OAuth authorization credentials for that connection. A user may also revoke RQL access through the security or connected-app settings provided by their Google Account.

User control: Google Contacts access is optional. Disconnecting Google Contacts does not delete ordinary RQL account records, previously completed RQL Network connections, or invitation records that resulted from actions the user intentionally performed.

6. Document Privacy and Public Visibility

Uploaded full manuscripts are not public by default.

Public visibility may apply to information that you intentionally publish or submit to a public-facing workflow. Depending on the feature, this may include paper titles, abstracts, public paper pages, reviewer-board listings, public profile information, selected certificate metadata, collaboration opportunities, or other information you choose to make available.

For Post-Publication Review and reviewer workflows, certain metadata may be displayed where the relevant workflow requires or permits publication. This may include a title, abstract, review type, paper link, Paper Quality Score status, or reviewer-board status.

Users should review the visibility controls and workflow requirements before publishing or listing research materials.

7. Reviewer and Collaboration Data

If you volunteer to review, collaborate, respond to an academic opportunity, participate in RQL Network activity, or participate in another user-initiated workflow, information from your profile may be made available to the request owner or authorized workspace users.

Depending on the workflow, this may include your name, email address, affiliation, qualification, expertise, academic profile link, CV/profile document, reviewer or collaboration message, and application status.

Public display of reviewer or collaboration information depends on the applicable platform settings, profile visibility, and workflow.

8. Payments, Credits, and Subscriptions

RQL may use supported third-party payment providers to process payments for services, credit packs, and subscription plans.

RQL's payment system may use Paddle for international payments and Flutterwave for supported African currencies and regional payment methods. The payment options presented to a user may depend on the service, currency, country, provider availability, and current configuration.

Payment providers may collect and process payment information according to their own terms and privacy policies. RQL does not store users' complete payment-card details.

RQL may retain payment references, transaction status, purchased amounts, credit balances, credit transfers, subscription status, service entitlements, refunds, and related accounting records for access control, support, fraud prevention, and service administration.

Subscription plans may provide platform access, service limits, credits, or other entitlements according to the applicable plan and the information presented to users at the time of purchase. Subscription benefits may be changed or expanded as RQL develops its subscription system, subject to the applicable terms and purchase information.

Service credits may also be purchased separately through available credit refill options. Credits and subscription entitlements are recorded in the RQL account associated with the transaction.

9. Data Sharing and Service Providers

RQL does not sell personal data.

RQL may share or transmit limited information where necessary to operate requested services or meet legal and security obligations.

Depending on the service, this may include sharing or processing with:

  • AI and language-processing providers;
  • payment processors;
  • email and notification providers;
  • hosting and infrastructure providers;
  • technical and security service providers;
  • authorized reviewers or collaborators where a user initiates the relevant workflow; and
  • legal, regulatory, or governmental authorities where required by applicable law.

Third-party service providers may process information according to their own applicable terms and privacy policies.

10. Data Retention

RQL may retain account information, review outputs, profile data, certificates, payment records, credit records, subscription records, and workflow information so that users can access services and records over time and so that RQL can maintain service continuity, accounting, security, and support.

Uploaded files may be retained for processing, user access, audit, support, or workflow continuity. Older or temporary files may be removed during maintenance, cleanup, or storage-management processes.

Contact-discovery results obtained from Google are not maintained as a permanent RQL address book. Temporary imported-contact cache data is cleared according to the applicable contact-discovery retention process. OAuth connection credentials may remain until disconnected, revoked, expired, invalidated, or otherwise removed.

Retention periods may vary according to the type of information, the service involved, operational requirements, and applicable legal obligations.

11. Security

RQL uses reasonable technical and organizational measures intended to protect user information against unauthorized access, loss, misuse, or alteration.

These measures may include secure password hashing, session controls, access controls, role-based permissions, encrypted storage for certain sensitive credentials, abuse-prevention checks, and restrictions around sensitive workflow areas.

Security limitation: No internet-based service can guarantee absolute security. Users should protect their login credentials and should not upload documents or data they are not authorized to process.

12. Your Choices

  • You may update available profile information through your account or dashboard.
  • You may choose whether to participate in public-facing reviewer, collaboration, Network, or paper-listing workflows where the applicable controls are available.
  • You may choose whether to connect Google Contacts and may disconnect that integration through RQL.
  • You may clear temporary CSV/vCard contact-discovery data using the available clear-import control.
  • You may review information before intentionally publishing or sharing research materials through an RQL workflow.
  • You may contact RQL regarding account, privacy, or data-support questions.

13. Children's and Unauthorized Use

RQL is designed for researchers, students, academic professionals, institutions, and other users engaged in research or scholarly activities. Users should provide information only where they have the appropriate authority and legal basis to do so.

Users are responsible for ensuring that manuscripts, research data, personal information, contact files, and other materials uploaded to RQL may lawfully be processed through the platform.

14. Changes to This Policy

RQL may update this Privacy Policy as the platform, services, integrations, payment systems, security practices, or legal requirements change.

The updated version will be made available through the RQL website with a revised "Last updated" date.

15. Contact

If you have questions about this Privacy Policy, your personal information, Google Contacts integration, account data, or privacy-related matters, please contact:

support@researchqlab.org