Privacy Policy
What we collect, why, and the commitments we make to researchers.
Effective date: 21 August 2026
1. Who we are
Forefront is a research-intelligence tool for scientists and researchers. The data controller is Forefront Intelligence Ltd (registered in England and Wales, company number 16893923), at 124 City Road, London EC1V 2NX, United Kingdom. Forefront Intelligence Ltd is subject to UK data protection law, including the UK GDPR and the Data Protection Act 2018, and our supervisory authority is the Information Commissioner's Office (ICO).
For any privacy question or to exercise your rights, contact us at privacy@forefrontedge.com.
2. Our commitment to researchers
A scientist’s search history is their unpublished research direction. We have built the product around that. Specifically:
- We do not sell or rent your personal data, and we never will.
- We do not send your search queries, your questions, or the contents of your library to any third-party analytics service.
- We do not use your library, questions or uploaded documents to train AI models.
- We do not use advertising or marketing trackers, and we do not track you across other websites.
- We do not record your screen or session.
These are not aspirations; the sections below explain how each one is enforced in the way the product is built.
3. What we collect
Account data. When you create an account we store your email address, name, and (for password sign-in) a securely hashed password. If you sign in with Google we store the identifier Google returns, not your Google password.
Content you create. The research you save — followed topics, saved papers, projects, landscapes, and the questions you ask and answers you keep. This is the product; it is stored so we can show it back to you.
Guest activity. You can use much of the product without an account. When you first save or follow something as a guest, we create a guest record so your work persists, tied to your browser by a cookie (see the Cookie Policy). It holds no name, email or password.
Technical data. Standard server logs and error reports needed to run and secure the service. Our error-monitoring is configured to record the typeof page where a problem occurred (for example “a drug page”), never which specific entity you were viewing, and never your identity. Search queries in our internal logs are stored only as a one-way hash, never as readable text.
Usage analytics. We keep simple, aggregate counts — how many searches happen, how often a feature is used, error rates. These counts contain no identifier of any kind (no account id, no device id, no IP address) and no free text(no queries, no titles). They are stored as daily totals with nothing on your device, so they cannot be traced back to an individual. This is why we do not need to show you a cookie-consent banner for analytics — there is nothing personal to consent to.
4. Why we process it, and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Provide the research tools you use | Performance of a contract with you |
| Keep your saved research and show it back to you | Performance of a contract |
| Secure the service and prevent abuse | Our legitimate interests in a safe service |
| Understand aggregate product usage (non-personal) | Not personal data — no basis required |
| Send service and account emails | Performance of a contract |
| Take payment for paid plans | Performance of a contract |
The precise lawful bases will be confirmed on legal review under UK data protection law.
5. AI processing
When you ask a question or chat with a paper, we send the relevant text — your question and the paper content — to our AI provider, OpenAI, to generate the answer. Under OpenAI’s API terms this data is not used to train their models. We are additionally pursuing a zero-data-retention arrangement; until that is confirmed, OpenAI’s standard API retention applies. We never send your identity alongside this content.
6. Cookies
We use four cookies, all of them strictly necessary to run the service — no analytics or advertising cookies. The full list is in our Cookie Policy.
7. Who we share data with
We use a small set of service providers (“processors”) to run the service. Each is bound by a data-processing agreement and may only use your data to provide their service to us:
- Vercel — application hosting.
- Neon — database.
- Upstash — rate-limiting state (keys are hashed before storage).
- Sentry — error monitoring (configured to hold no user identity).
- Resend — sending service and account emails.
- OpenAI — AI question answering (see section 5).
- Stripe — payment processing. Stripe acts as an independent controller for parts of payment handling.
To find the research you are looking for we also query public research databases (such as OpenAlex, Europe PMC, ClinicalTrials.gov and public regulatory sources). These are outbound lookups of public information; we do not send them your personal data.
8. International transfers
Some of the providers above process data outside the United Kingdom. Where they do, the transfer is protected by an appropriate safeguard — such as the provider’s certification under a recognised adequacy framework, or Standard Contractual Clauses with a transfer risk assessment. The specific mechanism per provider is confirmed on legal review.
9. How long we keep it
We keep your account and saved research for as long as your account is active. Technical and diagnostic data is kept only as long as it is useful and is then deleted on a defined schedule. Aggregate usage counts contain no personal data. If you delete your account, we erase your personal data (see below).
10. Your rights
Depending on your location, you have the right to:
- access the personal data we hold about you;
- correct it if it is wrong;
- delete your account and personal data — deletion is real: we remove your data across our systems, cancel any subscription, and this propagates to our providers;
- export your data — you can download your library in standard formats (.bib, .ris, .csv) at any time;
- object to or restrict certain processing;
- complain to a supervisory authority (the Information Commissioner's Office (ICO)).
To exercise any of these, contact privacy@forefrontedge.com. We aim to respond within one month.
11. Security
Data is encrypted in transit and at rest, access is restricted to what is needed to run the service, and we maintain a process for handling any security incident. No system is perfectly secure, but we take proportionate measures to protect your data.
12. Changes to this policy
If we change this policy we will update the effective date above and, for material changes, tell you in the product or by email. Your continued use after a change means you accept the updated policy.