Security and data handling
What happens to a file you give us, product by product.
Written for the person at a research office, IT department or ethics board who has to sign off before a lab can use these tools. Every statement here describes what the code does today. The privacy policy is the legal document; this page is the plain summary. Last reviewed September 30, 2026.
By product
What each product does with your files
- Free tools that run in your browser
- Citation Generator, Reference Converter, the reference format pages, LaTeX Table Generator, Thesis Format Checker, Abstract Checker, the response letter template and the Submission Checklist run entirely in your browser. The text or PDF you give them never leaves your computer. Settings and checklist ticks are kept in your browser's local storage.
- Free tools that run on our server
- LaTeX to PDF, LaTeX Diff, LaTeX to Word, Word to LaTeX, Markdown to PDF, File to Markdown, PDF to Structured Data, PDF compression, BibTeX Builder, BibTeX Validator, Equation Renderer and the file-upload path of the Word Counter send your file over HTTPS to our backend on Modal. The file is processed in a temporary directory inside the container and discarded when the response is sent. No copy is written to durable storage or to logs. BibTeX Builder sends the DOI or arXiv ID you enter to CrossRef or arXiv; BibTeX Validator sends reference DOIs and titles to CrossRef and Semantic Scholar only when you tick those checks.
- Paper Review and the paid checks
- Paper Review, Anonymity Check, Citation Gap Analysis, Revision Review, Response to Reviewers and Resume Review run on Modal. The manuscript is sent to Anthropic's Claude API for analysis. Under Anthropic's commercial terms, inputs are retained for up to 30 days for abuse monitoring and are not used for model training. Reference titles and DOIs go to CrossRef, and the DOIs or titles of the references whose abstracts are checked against your claims go to OpenAlex and Semantic Scholar; nothing from your manuscript's own text goes to those three. The result waits in Modal storage until you open it. Purplelink deletes the manuscript, the review and the annotated PDF 30 minutes after the result is first opened, or after 24 hours if it never is. A scheduled job enforces the 24-hour limit. The Cover Letter tool receives your abstract and the journal name, not the manuscript.
- ModernTex
- A Mac app. Your documents stay on your Mac, and there is no account. The license key is checked offline against a public key built into the app; unlocking makes no server request. Once a day the app asks purplelink.llc for its update feed. That request carries the app's version and a channel token compiled into the app, and nothing from your documents. We count update downloads as totals per file. If you turn on ModernTex's optional AI features, they use your own AI account, not ours.
- Vitae
- A Mac app with a local database and no account. Purplelink cannot see your records. Once a day it checks purplelink.llc for a newer version and, unless you hide it, fetches the text of a small sidebar card; neither request carries an account, device identifier, cookie or library data. Citation lookups go to CrossRef, OpenAlex, Semantic Scholar, ORCID or Zotero only when you use those features, and your mailbox is read only if you connect one.
- Scholar Utility Belt
- A Chrome extension that runs on Google Scholar pages. It has no Purplelink server and no analytics; saved papers, notes and settings stay in the extension's storage in your browser. Lookups you turn on go straight from your browser to public scholarly services such as OpenAlex, CrossRef, Unpaywall and Semantic Scholar. The optional Pro tier is licensed through ExtensionPay.
- Payments
- Stripe takes payment on its own checkout page. Purplelink never sees card details and creates no account for you.
Subprocessors
Who handles the data, and what they see
Every third party that processes data for the research tools or this website, as listed in the privacy policy.
| Name | Purpose | Data it sees |
|---|---|---|
| Stripe | Payment processing, receipts, invoices, refunds | Email address and card details you enter on Stripe's checkout page; Purplelink never sees the card |
| Anthropic | Claude API runs the paid reviews and checks | Manuscript text and page images; retained up to 30 days for abuse monitoring, not used for training |
| Modal | Cloud platform the backend runs on | Files during processing; for paid reviews, the result until it is deleted on the schedule above |
| Netlify | Hosts this site, the checkout and payment-notice functions, and the ModernTex download store | IP addresses like any web host; waitlist emails; the Stripe session ID and email passing through the payment notice |
| Resend | Sends review-ready, download-link and follow-up emails | Your email address and the body of each email |
| CrossRef | Verifies that cited references exist | Titles and DOIs of references in your bibliography |
| OpenAlex | Fetches abstracts of cited references | DOIs or titles of the references checked; nothing from your manuscript text |
| Semantic Scholar | Fetches abstracts of cited references | DOIs or titles of the references checked; nothing from your manuscript text |
| ExtensionPay | Licenses Scholar Utility Belt Pro | A random per-install key and your IP address, only if you open its payment page |
| Google AdSense | Ads on the home page, free tools, guides and blog | Cookies and browsing data under Google's policy; not loaded on pages where you buy, upload or receive a paid result |
| Cloudflare Web Analytics | Aggregate page-view counts | Page views without cookies or fingerprinting; aggregate data kept up to six months |
Encryption
In transit and at rest
- In transit
- Every page, upload and download on purplelink.llc is served over HTTPS by Netlify, with HTTP Strict Transport Security set for one year, including subdomains. The backend on Modal is reached only over HTTPS.
- At rest on Modal
- Modal states that all user data on its platform is encrypted in transit and at rest. See Modal's security and privacy page.
- At rest on Netlify
- Netlify states that it encrypts data at rest and in transit within its infrastructure. See Netlify's security page.
Data classes
What to upload, and what not to
- Suitable for
- Unpublished manuscripts, preprints, drafts, theses.
- Not suitable for
- Identifiable patient or participant data, data under a data use agreement, export-controlled material. Purplelink is not a HIPAA business associate. De-identify before uploading.
Incidents and continuity
If something goes wrong
- Breach notice
- If a security incident affects your data, you will be told by email at the address on your receipt as soon as the facts are known.
- Who runs it
- Purplelink is one person, Benjamin Ampel. If he is unavailable, a review in progress still finishes: the pipeline runs on its own, and a scheduled job deletes the manuscript and result on the same 30-minute and 24-hour clock. Refunds are handled through Stripe; the 14-day refund window on paid tools applies.
For your IT or research office
Paperwork on request
A data processing addendum, the subprocessor list above, and a completed HECVAT Lite or your department's own vendor questionnaire are available on request: ben@purplelink.llc. A W-9 and supplier registration details are also available. Volume pricing and invoices are on the labs and departments page.