Privacy notice
Last updated: 5 October 2026
Map of Ideas is operated by Mikołaj Mielewczyk, who is responsible for the personal data described here. Correspondence address: Tulipanowa 16, 83-333 Chmielno, Poland. For privacy requests, contact contact@mapofideas.com.
What we store and why
- Your account: email address, account identifier, authentication records and access permissions. Supabase manages passwords and sessions.
- Your research workspace: saved papers, reading choices, paper visits recorded when you open a source through the app, Atlases, ideas, followed interests and saved findings. These let us restore your work and produce the suggestions you request.
- Analyses: questions, selected papers, model requests, results and progress. We keep these so you can return to results without repeating the computation.
- Operations and support: request times, service errors, inference usage, credit reservations and problem reports. These support reliability, abuse prevention and cost control. Hosting providers also process connection information, including IP addresses.
Workspace records are linked to an account identifier. This avoids repeating your email throughout the app, but it does not make your saved work anonymous: the identifier can be linked to your sign-in account. Providing an email and authentication information is necessary for an account; saving papers, ideas and questions is your choice.
We process account and workspace data to provide the service you request (GDPR Article 6(1)(b)). Security, diagnostics and cost control rely on our legitimate interests in operating and protecting the service (Article 6(1)(f)). Legal obligations, where applicable, rely on Article 6(1)(c). We do not sell your personal data or use private ideas and questions to train our models.
Sharing a research map
Creating a read-only share link stores a separate snapshot of the papers, connections, ideas and findings you select. Anyone with that link can view it without an account. Notes are excluded unless you explicitly include them; account details, reading status and activity history are not shared.
Editing or deleting the original workspace content does not change a shared snapshot. You can revoke its link in Atlas → Share → Your active share links. Revoking removes the stored snapshot and stops future access through that link; deleting your account also removes its shared snapshots. Copies another person has already saved cannot be recalled, and recovery copies follow the retention periods below.
Where your data goes
- Supabase: accounts and saved workspace data, with the primary database in Ireland.
- Hetzner: the application backend, paper catalogue, vectors, analysis records and recovery copies, hosted in Germany.
- Cloudflare: website hosting, traffic routing and access protection across its global network, including Cloudflare Access where access restrictions apply.
- Runpod: model inference. When you request an AI analysis, the relevant question or idea and paper passages are sent to its GPU workers. Current workers can run outside the EEA, including Canada; inference is not restricted to the EU. We do not send your account email as part of model prompts.
- Resend: account and operational email delivery, and research digests when you opt in. It receives the destination address and message content, including the names of the followed ideas or collections referenced in your digest.
- Research providers: arXiv, Semantic Scholar and OpenAlex receive the searches or paper identifiers needed for their respective lookups. External paper links take you to sites with their own privacy policies.
- Project mailbox: messages you send to our contact address are handled through Hetzner-hosted email in Germany.
Providers may use international infrastructure and subprocessors. Their applicable processing terms describe safeguards such as standard contractual clauses: Supabase, Cloudflare, Runpod and Resend. An EU database location does not mean every part of the service is processed only within the EU.
Payments
Paid subscriptions are unavailable and no payments are collected. When paid subscriptions become available, Paddle will handle purchase and payment information as the seller under its own privacy notice.
We plan to retain the subscription, payment status and billing period needed to manage your access, credits, cancellation and refunds. Payment-card details will be entered with Paddle rather than stored by Map of Ideas.
Retention and deletion
Saved workspace content and analysis history remain available while you keep your account, unless you remove them using the available controls. Account deletion removes your private workspace and analysis data after active work has been stopped. Public paper records and cost records stripped of account details can remain. We retain a minimal deletion record to prevent older backups or late jobs from recreating deleted account data.
We retain three successful daily application backups and seven rotating server backups. Server backups can contain older application copies. With uninterrupted daily rotation, deleted data may remain in these recovery copies for approximately ten days. If backups fail, the last successful copy is retained until recovery is restored. Deletion records must be reapplied before a restored service is reopened.
Temporary citation and map-position caches expire or are evicted when their storage budget is reached. Our server journal is limited to 30 days; rotated system log files can remain for approximately five weeks. Cloudflare Workers logs are retained for up to seven days, depending on the plan. Resend states a 30-day retention period for email and log data on its standard plans. Provider security records and messages in a recipient’s mailbox follow their own retention policies.
Questions, usage records and support reports can be retained with your account for troubleshooting. If a specific dispute or legal obligation requires longer retention, only the relevant records are kept for that purpose. Recovery and provider copies are not erased immediately when you delete a live record.
Storage on your device
We use essential browser storage for sign-in, pending edits, workspace recovery, graph positions and display preferences. We do not currently use advertising trackers or optional marketing analytics. Signing out ends the session but may leave local preferences and recovery copies on that device. Clear this site’s browser data when leaving a shared device.
Your choices and rights
Research emails are off until you choose to receive them. In Updates → Email preferences, choose their frequency and which followed interests to include. You can withdraw this consent at any time there or through the unsubscribe link in each digest. We retain your preferences and a record of delivered papers to avoid sending duplicates.
You can edit saved work, unfollow interests, export your account data and request account deletion through Account → Your data & account. You can also contact us to request access, correction, erasure, restriction or portability, or to object to processing based on legitimate interests. We may need to verify that the request comes from the account holder.
You can complain to Poland’s Urząd Ochrony Danych Osobowych or your local supervisory authority. Research suggestions and model scores help you explore papers; they do not make decisions about you with legal or similarly significant effects.
What to avoid sharing
Submit only information you are entitled to share. Do not put passwords, patient records or other sensitive personal information into research prompts. AI results can be wrong; check the cited sources before relying on them.