Privacy
Public browsing
Searching the directory needs no account. Searches and the filters you choose are sent to the server to run the search. The app does not keep an account-linked search history. Server logs and any existing search caches may still contain request information.
To limit excessive requests, the app temporarily counts requests using a protected identifier derived from your network address. These counters stay in server memory, expire after their short limit window, and are not saved as account history. People using the same network may share a limit.
Optional AI explanations
Paid AI explanations are disabled in this release. If enabled in a future release, requesting one sends selected interests, skills, coursework, and preferences with public researcher information to the AI provider. Account addresses, private outreach notes, and Gmail contents are excluded from that explanation context.
Hosting and service providers
The hosted app runs on Railway. Account profiles, saved researchers, and outreach records are stored on the server. Encrypted managed backups and deletion receipts are stored separately in private Railway storage; the backup decryption key is kept outside that storage. Railway provides both the app hosting and backup storage.
Google handles sign-in and supplies your account identifier, email address, name, and profile image. Connecting Gmail is a separate optional permission; it is currently unavailable in the hosted release. Your sign-in does not by itself grant Gmail access.
Keeping and removing your data
Signing out ends your session; it does not delete your profile, saved researchers, or outreach records. We keep live account data until you choose Delete my account on the account page. Deletion removes your live profile, saved researchers, outreach records, sessions, stored Gmail credentials and account-linked pending connections. Signing in again creates an empty account. Your messages and drafts already in Gmail are unaffected.
We attempt to revoke Gmail access with Google. If Google cannot confirm revocation, local credentials are still removed and the deletion result directs you to your Google Account connections. A minimal receipt containing a hash of the account identifier and deletion time is retained to prevent accidentally restoring deleted account data.
New managed backups are encrypted and made daily. Managed backups and operational logs expire after 30 days, checked at server startup and hourly while the server is running. Expiry catches up after downtime. Managed logs contain event categories rather than request contents. An independent deletion ledger is kept without automatic expiry; operators must apply it before restoring a backup.
Historical manual backups, logs and review evidence remain outside this managed policy. Deletion does not erase those older copies, browser data on other devices, or data held by Google or an AI provider. Historical copies need an explicit retention decision before public launch. Public researcher records are retained separately from account data.
When you sign in
Signing in stores your saved researchers, outreach records, profile, and any Gmail connection against your account. Your session is held in an HttpOnly cookie and expires after a fixed number of days.
Email handling
If you connect Gmail, the app requests permission to create drafts and to read message metadata so it can check whether your draft was sent or a reply arrived. Message bodies are never read, and no email is ever sent automatically.
Résumé import
Choosing a résumé sends its contents to our server for text extraction. The original file and extracted preview are not saved by the app or sent to an AI provider. Review and edit the suggestions before applying them. Only the skills, coursework, and experience you apply become part of your stored profile and its managed backups. The selected filename stays in this browser. Do not import details you want to keep private.
Public researcher data
Researcher names, titles, departments, and published contact details come from official university sources and are public information. We collect them to help you find a mentor, not to build a profile about you.
Questions and privacy requests
For questions about your data or help with a privacy request, email researchmentorfinder@gmail.com . Please do not include passwords, access tokens, or sensitive personal documents.