Skip to the text
Scholaris

What happens to your data, provider by provider

Where your documents are stored, which AI provider reads what, what is sent to the open bibliographic databases, how your keys are encrypted and what is deleted when you delete.

Reviewed on This page as Markdown

The main thing

Your documents are yours. We do not train models on them. To read them, transcribe them and search them, Scholaris sends pages, audio and queries to AI providers, and this page says which ones, what for and what is stored where. If you work with material that must not leave your computer, the home version keeps everything on your disk, although it still needs a provider to read pages.

There are no third-party analytics and no ads on the site. The only cookies are the session ones (Clerk) and one that remembers you are in the demo.

Where each thing is stored

Everything lives on Cloudflare, in Scholaris's account:

WhatWhere
Your account, your API keys (hash only), settings, usage, invitations and access logD1, Cloudflare's database
Originals and page imagesR2, Cloudflare's object storage, under a folder of your own
Your read library (text, anchors, records, index)A Durable Object of your own, with its SQLite database, just for you
VectorsCloudflare Vectorize, in a namespace of your own
The sessionClerk, which handles sign-in (email and name) and payments

What each provider reads

ProviderWhat it receivesWhat for
Google Gemini (paid API)Page images, audio, the address of YouTube videos, passages and queriesReading pages (Gemini 3.8 Flash and 3.5 Flash-Lite), transcribing (Gemini Transcribe), vectors (Gemini Embedding 2), drafting answers and extracting entities
Cloudflare Workers AIAudio, images of easy pages and textTranscribing with Whisper, fallback and economy reader, fallback vectors and reranker
OpenRouter (with Mistral OCR)Pages the previous readers could not read; text to draft if Gemini failsFallback reader and writer
TypeSafe (Jev)Query and passage pairs, claims and passages, page-number candidatesReranking results, judging citations and settling doubtful folios

These providers get just what each task needs and are used through their paid or business APIs. Their terms (not ours) say how long they keep data and whether they use it for anything else; for instance, the Gemini API's paid terms exclude using requests to improve their products, while allowing them to be kept for a limited time to detect abuse. If that is not enough for you, use the home version with your own keys or with InferBox.

What is sent to open bibliographic databases

To complete and check each document's record, Scholaris asks Crossref, OpenAlex, Open Library, Wikidata, Wikipedia, arXiv, DataCite and, as a last resort, Google Books. What is sent is the title, the authors, the ISBN or the DOI, never the text. To link entities, each entity's name is sent to Wikidata. Requests identify themselves as "Scholaris/2" with the site's address.

Your own keys

You can add your own Gemini, OpenRouter, TypeSafe, Mistral, Voyage, Cohere, Jina or ZeroEntropy keys so your library uses your accounts. They are stored encrypted with AES-256-GCM, with a key derived per user, and are only used if you switch them on.

Deleting

  • Deleting a document also deletes everything derived from it: pages, vectors, images.
  • Deleting your search history, or pausing it.
  • Exporting everything as a ZIP before you leave.
  • Deleting your account: your keys, settings, usage, invitations, notifications and shared links are deleted; your library is emptied; vectors and files are purged in the background. A row with your identifier remains, marked as deleted, with no email or name, so it cannot be reused. The exception: if someone copied a document from a library you shared with them, their copy remains theirs.

Contact

For anything about your data, jl@joseluissaorin.com.