Privacy
Critically Research LLC · effective 23 September 2026
The short version. We keep the account you made, the work you wrote, and copies of the pages you cited. We do not advertise, we do not sell anything about you, and we do not track you across other sites. The browser extension is built so that we never learn which pages you visit. It does not replace the document below, but nothing below contradicts it.
1Who is responsible
Critically Research LLC operates Critically and decides how the information described here is used. For anything in this document, write to privacy@critically.io.
2What we hold
Your account. An email address, a handle you chose, and anything you put on your profile — a display name, a short bio, an avatar, links. The email address exists so you can sign in and so we can tell you things about your own work.
What you write. Notes, notebooks, sections, citations, comments, and the sources you keep in your pool. Notes are private until you decide otherwise.
Copies of pages you cite. When anyone cites a web page, we fetch it and keep the text and a screenshot, and we re-check it afterwards so we can tell you if it changed. This is the point of the service rather than a side effect. Those copies are of publicly reachable pages, not of anything behind your login.
Ordinary technical records. Our hosts keep server logs, which include IP addresses, for security and for working out what broke. We do not build profiles from them.
3What we do not do
We do not show advertising, and there is no plan to. We do not sell or rent anything about you. There are no advertising pixels, social-network trackers or session recorders on these pages, so no other company is watching you use this site and nobody is recording what you type.
Two measurements, named. We count page views using Vercel Analytics, and we measure how long pages take to appear and respond using Vercel Speed Insights. Both are served from this domain, set no cookies, and cannot follow you to any other site. Between them they tell us that a page was viewed, roughly from where, on what kind of device, and how slow it was. The second exists because the first cannot answer “is this fast for the people actually using it”, and measuring that on our own machines had been giving us the wrong answer. Neither builds a profile of you and neither is linked to your account.
We do not use your work to train anybody's AI model, and we do not let anybody else do so through us.
4The browser extension
RE: has to know whether the page you are on has been cited. The obvious way to find that out — asking our server about every address you open — would be a live feed of your browsing history, so it is not what happens.
Instead we publish a list of short fingerprints of every page that has been cited, all of them together. The extension downloads that list about once an hour and checks it inside your browser. We are told nothing about where you go. We only receive an address when you deliberately act on a page — opening the panel to see what was said, or keeping a passage.
If you connect an account, the extension stores its sign-in token in your browser's own extension storage. Disconnecting it, or signing out on the website, ends that.
5The AI features
When you ask for a summary, a post or a script, the text you asked about is sent to Anthropic to produce it. Nothing that comes back is stored or attributed to you. Managed (student) accounts never reach a model at all, and a private notebook has to be opened up by its owner before anything in it can be sent.
6Who else sees it
Only the companies that run the machinery, each doing one job on our instructions:
- Supabase · Database, authentication and file storage · United States
- Vercel · Hosting the website · United States
- Fly.io · The service that archives cited pages · United States
- Resend · Sending email — sign-in links and notifications · United States
- Anthropic · The optional AI features, when you use one · United States
- Internet Archive · Fallback copy when a publisher blocks our archiver · United States
We will also hand something over if the law actually requires it. If we are ever compelled to do that about you, we will tell you unless we are forbidden from doing so.
7What other people can see
A public notebook, and the notes in it, are public — that is what public means, and search engines can index them. A private notebook is visible only to you and the people you have added.
One thing is permanently public once done: your handle on work you published. Publishing is one-way, and readers cannot be un-told what they saw.
Comments only exist inside private notebooks. Publishing a private notebook deletes its comments, and you are warned before that happens.
8How long we keep it
Your account and your work stay until you delete them. Deleting your account removes your profile, your private work, and your name from everything else.
Two things outlive that, deliberately. A note somebody else put on their board stays on it, without your name — see the Terms. And the archived copies of cited pages remain, because they are the public record that a claim rests on and they are not about you.
9What you can ask for
You can download everything you wrote, as one file, from your settings — you do not have to ask us. You can correct your profile at any time, and you can delete your account.
Depending on where you live you may also have the right to object to what we do, to ask us to restrict it, or to complain to a data protection authority. Write to privacy@critically.io and we will answer within 30 days.
10Cookies
We set cookies to keep you signed in, and your browser stores a few preferences locally — your theme, which view of a notebook you last used. That is all of it. Our page-view counting sets no cookies at all. There are no advertising or tracking cookies, which is why there is no banner asking you to accept any.
11Children
Ordinary accounts are for people aged 16 and over. Younger students can use Critically only through a managed account created by a school or organisation, which is walled off at the database: managed accounts cannot see public material, cannot reach the AI features, and cannot receive money.
If you believe a child has an ordinary account, tell us at privacy@critically.io and we will remove it.
12Where the data is
On servers in the United States. If you are in the United Kingdom or the European Economic Area, that is a transfer outside your region, and it is made under the standard contractual clauses our providers offer.
13Security, and being honest about it
Access to your work is enforced by the database itself rather than by the website asking nicely, which means a bug in a page cannot show somebody a note they are not allowed to read. Passwords are handled by our authentication provider and we never see them.
No system is perfect. If we ever discover a breach affecting you, we will tell you what happened and what to do about it, without waiting to have a comfortable story. Found a hole? Please write to security@critically.io — we will not threaten you for it.
14Changes
If we change something that matters, we will say so on this page and email you before it takes effect. Silently rewriting a privacy policy is the sort of thing this site exists to make harder.