Privacy Policy
What we collect
PubMed Tracker collects the minimum needed to run the free tier and, if you choose to use it, the Pro license system:
| Data | When | Why |
|---|---|---|
| Email address | Only if you start a Pro trial or purchase | To sign you in with a one-time code and check your license status. No password is ever stored. |
| Device ID (randomly generated, not tied to hardware identifiers) | Only after sign-in | To enforce the one-computer-at-a-time license and show your "Computer" list. |
| License status (free / trial / pro / expired / moved) | Continuously, for signed-in accounts | To unlock or lock Pro features. |
| Purchase & renewal events | When you buy or renew Pro | Sent to us by our payment processor to activate your license — we don't see your card details. |
What stays on your device
Everything about your actual research reading stays local, in your browser's own storage — never transmitted to us, never readable by us:
- Saved papers, PMIDs, titles, authors, and journal metadata
- Folders, tags, and personal notes
- Reading status (to read / reading / read) and your reading history/streak
- Saved search terms and alert results (Pro)
- Your settings, including any personal NCBI API key you add
Paper metadata (titles, authors, journals) is fetched directly from NCBI's public E-utilities API by your browser — that request goes straight from you to NCBI, not through our server.
How we use it
We use account and license data only to operate the product: verifying sign-in codes, checking whether your license is active, enforcing the single-device limit, and sending you license-related notifications (like a trial ending soon). We do not use this data for advertising, and we do not build behavioral profiles from it.
Third parties we rely on
- Payment processing — purchases are handled by our payment provider (Payhip). We receive confirmation that a purchase happened and the email it was made under; we never receive your card number.
- Email delivery — sign-in codes are sent through a transactional email provider. That provider sees the email address and the code, nothing else.
- Infrastructure — our backend runs on Cloudflare Workers and Cloudflare D1 (database). Cloudflare processes data on our behalf under its own security commitments; it does not use your data for its own purposes.
We do not sell, rent, or share your data with data brokers or advertisers.
Retention & deletion
Your account record (email, device list, license status) is kept for as long as your account is active. If you'd like your account and email deleted, contact us (see below) and we'll remove it — there's currently no self-service delete button in the extension, which we know is a gap and plan to close.
Local library data (papers, folders, notes) lives entirely in your browser and is deleted the moment you remove the extension or clear its storage — we have no copy to retain because we never received one.
Security
Sign-in uses a one-time emailed code rather than a password, so there's no password to leak. License state cached on your device is signed to resist casual tampering. Traffic between the extension and our server is encrypted (HTTPS). No system is perfectly secure, but we don't store anything more sensitive than an email address and a license flag.
Children's privacy
PubMed Tracker is a research tool not directed at children, and we don't knowingly collect data from anyone under 13. If you believe a child has created an account, contact us and we'll delete it.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete the data we hold about you. Since the only personal data we hold is your account email, device list, and license status, most requests are quick to fulfil — reach out and we'll handle it directly.
Changes to this policy
If this policy changes in a material way, we'll update the "Last updated" date above. Continued use of PubMed Tracker after a change means you accept the update.
Contact
Questions about this policy or your data: pubmedtracker@mybrowsertools.com