CORTEXA

Privacy Policy

Last updated August 16, 2026.

Cortexa is a free, open-access research paper search engine, built and operated by Ansh Kansagra. This page explains what data Cortexa collects, why, who it's shared with, and how you can control or delete it. Cortexa doesn't sell data, doesn't run ads, and doesn't share your data with anyone beyond the service providers listed below that Cortexa relies on to operate.

What Cortexa collects

  • Account data. If you register, Cortexa stores your email and a securely hashed password (handled by Supabase Auth — Cortexa never sees or stores your plaintext password). If you sign in with Google instead, Cortexa receives your name, email, and profile picture from Google.
  • Profile fields you choose to add. Affiliation, bio, research interests, social links, and similar fields on your Profile page — all optional, all editable or removable at any time.
  • Usage data tied to your account. Saved papers, collections, saved searches, search history, and citation-style/display preferences — used to make the product work (showing your saved papers back to you) and to personalize defaults.
  • Feedback submissions. The message you write on the feedback page, plus an email address if you choose to provide one (not required — anonymous feedback is supported).
  • API keys. If you generate a developer API key, Cortexa stores a one-way cryptographic hash of it, never the key itself, plus its creation and last-used timestamps.
  • Basic visitor analytics.Aggregate, privacy-preserving page-view analytics via Vercel Analytics — this doesn't use tracking cookies or build individual visitor profiles.
  • IP address, briefly. Used only to enforce rate limits against abuse (e.g. scraping). Not stored long-term or tied to your account.

The research papers themselves — titles, abstracts, authors, categories — are public metadata drawn from arXiv, CrossRef, OpenAlex, CORE, Semantic Scholar, and Zenodo. That's not personal data about you; it's the content the search engine indexes.

Service providers Cortexa relies on

Cortexa is a small, independently-run project built on established infrastructure providers rather than custom servers. Each of the following processes data only to provide their respective piece of the service, under their own privacy terms:

  • Supabase — database, authentication, and password/session handling.
  • Vercel — hosting, and aggregate analytics.
  • Upstash — short-lived rate-limit counters keyed by IP address.
  • Resend— delivery of saved-search digest emails, if you've opted into them.
  • Google— only if you choose "Sign in with Google" instead of an email/password account.

Cookies

Cortexa uses one essential cookie to keep you signed in (managed by Supabase Auth). There are no third-party advertising or tracking cookies.

The public API and MCP connector

Cortexa's read-only public API and Claude connector (Model Context Protocol server) expose the same public paper data available through search on the site — no account or personal data is required to use them, and they don't collect anything beyond the same abuse-prevention rate limiting described above.

Deleting your data

You can delete your account at any time from Settings. This permanently removes your account, saved papers, collections, saved searches, search history, and API keys. It can't be undone.

Children's privacy

Cortexa isn't directed at children and doesn't knowingly collect data from anyone under 13.

Changes to this policy

If this policy changes, the "Last updated" date at the top of this page will change too. Material changes will be noted here directly — there's no separate mailing list this gets announced through.

Contact

Questions about this policy or your data — reach out via the feedback page or email anshkansagra2004@gmail.com.