Last updated 19 September 2026
Privacy policy
ResearchTogether is a desktop app that keeps your work in folders on your Mac, plus an optional Community website for sharing. This page says what each part stores and who processes it.
The desktop app keeps your work on your Mac
Projects are ordinary folders you choose. Accounts, settings, conversations, drafts and learning notes live in the app's own data folder on your computer. The app sends no usage analytics or crash reports to us.
When you connect an AI model, the text you send in a conversation and the files or selections you include go to that provider (OpenAI, Anthropic's Claude or OpenAI's Codex) under its own terms. Your API key or provider sign-in is stored encrypted on your Mac and is never sent to us.
What Community stores when you sign in
Community sign-in uses Google. We keep the account identifier Google returns and the name on the account, which becomes your display name. We do not store your Google password, and we do not keep your email address in the Community database. You can change your display name and bio in your profile.
What you publish
Projects you share, the files in the versions you publish, discussion messages, data requests and responses, contributions, your profile name and bio, and the projects you follow are stored on our servers. New projects are private to the people you invite until you make them public. Public projects and profiles can be read by anyone, including people without an account, and can be downloaded into other people's copies of the app.
Research in the browser
If you add an OpenAI API key for browser research, it is stored encrypted on our servers and only the last four characters are ever shown back to you. Browser conversations are stored with your account. Requests to OpenAI are sent without asking OpenAI to retain them.
Cookies
The website sets one session cookie after you sign in, valid for 30 days, and a short-lived cookie that lasts ten minutes during the Google sign-in step. There are no advertising or analytics cookies.
Who processes the data
The website runs on Vercel, the database is PostgreSQL hosted by Supabase, files are stored in Amazon Web Services S3, and sign-in is handled by Google. Each acts as a processor for the data described above. We do not sell personal data or share it with advertisers.
Keeping and deleting data
Community data stays until you delete it or ask us to. Deleting a project removes it from Community; copies other people already downloaded stay with them. To delete your account and everything attached to it, email us from the address you would like us to reply to. Desktop data is yours to delete by removing the app's data folder and your project folders.
Children and changes
ResearchTogether is not directed at children under 13. When this policy changes, the new version appears here with a new date.
Questions go to skyler@hivemindresearch.com.