Research Workbench

Privacy policy

Research Workbench is a research tool, and research depends on trust. This page says what personal data researchworkbench.space and the cloud workbench keep, why, for how long, who else sees it, and what you can ask for.

Last updated 5 October 2026.

Who is responsible

Research Workbench is run by Enrico Rossini, an individual, who is the controller of the personal data described here under the UK General Data Protection Regulation and the Data Protection Act 2018.

For anything about your data, write to privacy@researchworkbench.space.

The workbench on your own computer

The desktop workbench keeps your vault on your computer and sends us nothing: no account, no analytics, no telemetry. If you give it a key for an AI provider, it sends the text you ask it to work on to that provider, under your agreement with them. If you link it to a cloud account, it syncs the projects you choose, as described under the cloud workbench.

The browser extension sends nothing to us either; its own privacy policy sets out what it reads and keeps.

Your account on the website

When you create an account we keep:

  • your name, email address, university or institution, and department or field;
  • your password, only as a one-way hash, and any passkeys, authenticator app and recovery codes you add;
  • a display name, a profile picture and a phone number, if you add them;
  • when the account was created, whether the email address is confirmed, and failed sign-in attempts, to lock out guessing;
  • whether you asked to use the cloud workbench, and the answer.

We use them to run your account and sign you in, and to understand who the platform serves. The lawful basis is the contract with you: the account cannot work without them. None of this is shown publicly, except that a profile picture can be opened by anyone who has its address.

The forum

What you post in the forum is public, with your display name (your first name until you choose one) and your picture: anyone can read it. We also keep your votes, subscriptions, notifications, any reports you make, and the moderation record, to run the forum and keep it civil. Notification emails are on until you turn them off.

If you delete your account, your posts stay so that the conversations around them still make sense, but they are shown as by a former member and are no longer linked to you. To have a post removed, edit or delete it, or write to us.

Email and the mailing list

We send email about your account — confirmation links, sign-in links, password resets — and the forum notifications you ask for. These are part of running the account.

The mailing list is separate and only by your consent: an unticked box when you register. We keep your address, when you agreed and the words you agreed to. You can leave at any time, and leaving or deleting your account removes you from it.

The Contact us page

When you write to us through the Contact us page, we keep your name, your email address, what you chose it is about, your message and when you sent it, and which account it came from if you were signed in. We use them only to answer you. The site's administrators are emailed a copy when it arrives, and the message is deleted once it has been answered and nothing more needs it.

Cookies and analytics

Strictly necessary, and set without asking:

  • the sign-in cookie, which keeps you signed in for up to 14 days, and the cookies used during two-factor sign-in;
  • an anti-forgery cookie that protects the site's forms;
  • your choice of light or dark theme, for a year.

Google Analytics, only if you allow it. Until you choose Allow analytics in the banner, nothing from Google loads and no analytics cookie is set. If you allow it, Google sets its _ga cookies and receives how you use the site, including your IP address, as our processor. You can change your mind at any time with the analytics link at the foot of every page.

The cloud workbench

The cloud workbench is open by invitation. You sign in to it with your website account, which tells it your name, email address and workspace. It keeps what you put in it: your projects, documents, notes and references, the record of every AI call it makes (the prompt, the model and the answer), your settings, the devices you sync from, and your AI providers' keys, encrypted.

When you ask it to use an AI provider, it sends the text involved to that provider with your own key, so the provider handles it under your agreement with them. If you record other people in it, such as contacts for a study, you are responsible for having a lawful basis to do so.

If you turn on reminder emails on your cloud account page, the cloud workbench emails you on a morning when a deadline is due, listing each deadline's title, date and project or paper. It keeps the time zone your browser gives, so the email comes in your morning, and the day it last wrote, so it never writes twice. They are off unless you turn them on, and every email has a link that turns them off.

You can erase your whole cloud workspace yourself, from your account page there: your projects, files, search index and the record of every AI call, your keys and your settings. Deleting your website account does not do this, so erase the workspace first. The cloud workbench cannot yet export your data by itself; until it can, write to privacy@researchworkbench.space and it will be exported for you.

Who else sees it

We do not sell personal data or use it for advertising. It is seen only by:

  • our hosting provider, whose servers run the site, store its data and send its email;
  • Google, for analytics, only if you allow it;
  • the AI providers you choose, with your own keys, for the work you ask of them.

Where any of these handle data outside the UK, they do so under the safeguards UK law requires, such as an adequacy decision or the standard contractual clauses.

How long it is kept

  • Your account, until you delete it.
  • The mailing list entry, until you leave the list or delete your account.
  • A message sent through the Contact us page, until it has been answered and dealt with.
  • Forum posts, as described above, after which they are no longer linked to you.
  • The site's logs, which record errors and the emails sent but not your browsing, for 30 days.
  • The cloud workbench, until you ask for it to be erased.

Your rights

You can ask to see the personal data we hold about you, to correct it, to have it erased, to restrict or object to how it is used, and to have a copy to take elsewhere. Where we rely on your consent, you can withdraw it at any time.

Your account's personal data page downloads what the website holds about you and deletes your account. For anything else, write to privacy@researchworkbench.space; we answer within a month.

If you are not satisfied, you can complain to the Information Commissioner's Office at ico.org.uk.

Age, and changes to this policy

Accounts are for people aged 16 or over. If this policy changes, this page changes first, with its date; a change that matters to how your data is used is also emailed to you. The terms of use cover the rest of using the site.

Something went wrong. Reload the page to continue. Reload 🗙