Privacy · privacy-2026-08-09-referrals
Privacy Policy
What Articlo collects, why it is used, who receives it, and how long it stays.
Last updated August 9, 2026
1. Who is responsible
Articlo, a United States company, is the controller and, where applicable, the “business” responsible for account, website, billing, support, security, first-party attribution, and other information described here. Our principal business address is 1717 E Morten Ave, Phoenix, Arizona 85020, United States.
When a university, laboratory, company, publisher, or other organization determines why personal information in Customer Content is processed, that organization is the controller or business and Articlo is its processor or service provider under the organizational data-processing terms incorporated into the Terms of Service.
2. Information we collect
- Account and authentication: email, password hash, one-time-code records, consent versions, session and security events.
- Customer Content: manuscript files or a Google Docs URL, journal choice, article type, figures, tables, references, author information, and generated outputs.
- Billing: plan, credits, transaction and subscription identifiers, status, amounts, and accounting records. Stripe—not Articlo—collects full payment-card details.
- Referrals and partner payouts: referral codes, a random browser identifier, link visits, referred purchases, discounts, rewards, commission amounts, program acceptance, and Stripe payout-account status. Stripe collects the identity, bank, and tax details needed for partner payouts.
- Support and requests: messages, journal requests, privacy requests, and related resolution records.
- Device and security: IP address, user agent, timestamps, rate-limit and access events. Manuscript text is excluded from application, analytics, and error logs.
- First-party attribution: referral source, campaign parameters, and click identifiers, excluding credentials and private URLs.
- Optional website measurement: after consent, public page path and title, referral/campaign source, device and browser information, coarse location derived by Google, funnel events, purchase value and currency, and a one-way transaction deduplication token.
Google measurement does not receive manuscripts, email addresses, private links, journal selections, account or payment identifiers, payment details, or public-page query strings. We obtain public journal guidance and scholarly metadata from publishers, Crossref, OpenAlex, DOAJ, and similar sources. It may include journal instructions plus names, professional affiliations, persistent identifiers, and other author information. We use it for the catalog, authoritative guidance, journal requests, and source attribution. Routine ingestion is restricted to journal-level data where author records are unnecessary.
3. Purposes and legal bases
Contract: creating and authenticating accounts; receiving and preparing manuscripts; delivering files, checklists, and reports; subscriptions, credits, cancellation, refunds; administering accepted referral and partner terms, rewards, and payouts; and requested support.
Legal obligations: tax and accounting records, legal process, consumer protection, sanctions, and legally required notices.
Legitimate interests: securing accounts and manuscripts; attributing eligible referrals; preventing referral fraud and abuse; diagnosing failures; reliability; transaction and consent evidence; legal claims; and journal-level catalog/source records. Our interests are protecting users and unpublished work, operating reliably, rewarding legitimate recommendations, preventing misuse, and documenting compliance. We assess whether individual rights override them.
Consent: optional Google Analytics and Google Ads conversion measurement, nonessential technologies, direct marketing, or another optional activity where law requires. Consent can be declined or withdrawn prospectively through Measurement settings in the footer.
For organizational Customer Content, we act on the customer’s documented instructions. The organization establishes the lawful basis and gives required notices.
Articlo does not generate or rewrite research content, verify reference validity, train or fine-tune generative-AI or cross-customer content models with Customer Content, or use manuscript substance for advertising profiles.
4. Providers and disclosures
Articlo uses providers for application infrastructure and delivery, encrypted data storage and managed data services, service communications, payments and billing, business administration, customer-directed document sharing or import, and consent-based website and advertising conversion measurement. Contracts and applicable law restrict their permitted processing. The current provider list and organizational processing terms are incorporated into the Terms of Service.
Google LLC provides Google Analytics and Google Ads conversion measurement after consent and processes restricted public-site and purchase measurement under its applicable terms and privacy notice. A provider may act independently for processing it determines is necessary for its own legal, regulatory, security, fraud-prevention, or platform obligations, under its own privacy notice. Articlo does not control a document platform’s independent processing when a customer chooses to supply a shared-document link.
Public journal sources may receive a journal name or public URL request, never a manuscript, account credential, or payment record. We may also disclose information to advisers, authorities, courts, transaction counterparties, or a successor as needed for law, security, claims, or a business transaction.
5. Analytics, attribution, and privacy signals
Google Analytics and Google Ads conversion measurement load only after you choose “Allow measurement.” Enhanced measurement, Google Signals, enhanced conversions, Customer Match, ad personalization, and retargeting are disabled. Advertising storage is used only after consent to connect an ad visit with a conversion. Articlo sends public paths without query strings, non-content funnel events, and—after a purchase—the value, currency, and a one-way deduplication token. Private account, paper, admin, result, and tokenized routes are excluded from page measurement; a completed checkout is reported only as /checkout/complete. Change or withdraw your choice through Measurement settings in the footer.
Google does not receive Customer Content, journal selections, names, email addresses, account identifiers, payment identifiers, or payment details. Articlo does not use measurement data to build advertising profiles or for cross-context behavioral advertising. First-party referral and campaign information is retained separately so Articlo can independently reconcile ad spend, purchases, and profitability.
We honor legally recognized opt-out signals, including Global Privacy Control, where applicable. A recognized signal keeps optional measurement off unless you affirmatively choose otherwise. Because we do not sell or share personal information or use it for targeted advertising, a signal does not otherwise change current processing.
6. Retention schedule
- Free-check source files: deleted from memory when the check completes or fails, no later than 24 hours. Manuscript text is not logged.
- Free-check results: 30 days or until deletion, whichever comes first.
- Abandoned unpaid uploads: deleted from active systems within 72 hours.
- Paid manuscripts and outputs: until you delete the package or close the account. After 24 months of inactivity, we may delete packages after at least 30 days’ notice and a download opportunity.
- Recovery backups: database metadata may remain in encrypted, access-restricted backups up to seven days through rotation. Manuscript files are stored separately and are not copied into those database backups.
- Account/authentication records: while active and 30 days after closure, except the limited records below.
- Terms, renewal, and consent evidence: at least three years or one year after the contract ends, whichever is longer.
- Payment, invoice, tax, referral rewards, and partner commissions: seven years, or longer if required.
- Referral-link visits and first-party attribution: 90 days. A referral reward record remains with the related transaction record after the visit expires.
- Support and journal requests: 24 months after closure, unless an active dispute or security investigation requires longer.
- Security and access logs: 90 days unless an event requires longer investigation or claim preservation.
- Optional measurement: Articlo-set measurement cookies expire within 90 days; Google Analytics user-level and event data is configured for two months, while standard aggregated reports and Google Ads conversion records may remain longer under Google’s applicable settings and retention terms.
- Legal holds: until the hold is no longer reasonably needed for law, process, fraud, security, or claims.
Delete individual packages from their paper page, or close the account from Account. Limited non-content identifiers may remain to preserve eligible re-target and referral entitlements.
7. Security and sensitive information
We maintain administrative, technical, and organizational safeguards reasonably designed against unauthorized access, loss, alteration, disclosure, or destruction. Verified current measures include TLS in transit; AES-256 encryption at rest for private object storage and backups; private storage permissions; email/password authentication with a short-lived one-time email code; secure, HTTP-only session cookies; expiring and revocable paper tokens; rate limiting; no-store and no-referrer controls on private pages; access-event monitoring; and encrypted rotating database backups with isolated restore verification.
Manuscript access is limited to personnel and providers who need it for authorized support, confirmed failure or security investigation, law, or another authorized function, subject to confidentiality and appropriate logging. No system is completely secure. We investigate incidents and notify customers, individuals, and authorities when law requires.
Do not upload the prohibited sensitive data listed in the Terms. Articlo is not a HIPAA business associate.
8. Privacy rights and appeals
Depending on location, you may request access, correction, deletion, portability, restriction, objection, consent withdrawal, or information about collection and disclosure. Submit the web request form or email privacy@getarticlo.com with subject “Privacy Request.” State the right and use the account email where possible. We may reasonably verify identity, account, residency, or authority and respond within the legally required time.
An authorized agent may act where law permits; we may require proof and direct verification. If denied in whole or part, appeal within 30 days by emailing the same address with subject “Privacy Appeal,” identifying the decision and added information. Someone not responsible for the initial decision will review it and respond in the required period, including regulator contact information where required. We do not discriminate for exercising a right.
9. International processing
Articlo is established in the United States. We and our providers may process information in the United States and other countries where they operate. For EEA transfers without adequacy, we use the European Commission Standard Contractual Clauses and supplementary safeguards where required. For UK restricted transfers, we use the applicable UK IDTA or UK Addendum. Request information or a redacted copy at privacy@getarticlo.com.
You may complain to the data-protection authority where you live, work, or believe a violation occurred. Articlo will complete the required EU/UK representative assessment and appoint a representative if applicable before intentionally marketing to or routinely accepting customers in those markets.
10. Children and policy changes
Articlo is for adults and is not directed to anyone under 18. Contact us if you believe a child submitted information.
We update this Policy when practices, providers, or legal duties change, revise the date and version, archive prior versions, and provide additional notice where required before a materially different use.
11. Contact
Privacy requests and complaints: privacy@getarticlo.com
Legal notices: legal@getarticlo.com
Security: security@getarticlo.com
Support: support@getarticlo.com
Postal address: Articlo, 1717 E Morten Ave, Phoenix, Arizona 85020, United States
Email is accepted for ordinary notices and requests. Formal service of legal process must be delivered in accordance with applicable law to the postal address above.