Privacy Policy
Reservoir — A Product By HeyMIRA, Inc.
Effective date: June 11, 2026 Last updated: July 6, 2026
What changed in this version: added Section 4, "Google user data (Calendar and Gmail)", describing the optional Google Calendar and Gmail integrations, and updated Sections 1, 2, 7 and 8 accordingly.
This Privacy Policy explains how HeyMIRA, Inc., a Delaware corporation ("HeyMIRA", "we", "us"), collects, uses, and protects your personal data when you use Reservoir, available at reservoir.ac and app.reservoir.ac (the "Service").
Reservoir helps researchers store their career history once and re-project it into grant applications, manuscripts, and CVs. Because the documents you upload describe your professional life — and sometimes contain more than that — we have designed the Service, and this Policy, around minimising what we extract, retain, and expose.
For the purposes of the EU and UK General Data Protection Regulation ("GDPR"), HeyMIRA, Inc. is the data controller of your personal data processed through the Service.
Privacy contact: privacy@heymira.so Legal contact: legal@heymira.so Postal address: HeyMIRA, Inc., 2810 North Church Street, STE 88775, Wilmington, DE 19802, United States EU/EEA Representative: DataRep, The Cube, Monahan Road, Cork, T12 H1XY, Ireland · datarep.com/data-request
1. Data we collect
1.1 Account data
- Email address (used for magic-link authentication — we never store a password)
- Authentication metadata (sign-in timestamps, session tokens)
1.2 Profile data you provide
- Name, institutional affiliation(s), research group, ORCID iD, professional tagline, and similar career information you enter or confirm in your profile.
1.3 Documents you upload
You may upload documents such as CVs, employment contracts, grant justifications, publications, and teaching records. These documents may contain sensitive personal data — for example national identity numbers, dates of birth, salary figures, bank or social-security references — because that is how institutional paperwork is written.
Our handling of uploaded documents:
- Documents are stored encrypted at rest in the European Union (Frankfurt, Germany).
- Our extraction pipeline is explicitly instructed to exclude personal identifiers (national ID numbers, bank details, salary information, home addresses) from the career blocks it proposes. Blocks store professional merits only.
- Raw documents are never included in generated outputs (grant drafts, paper skeletons, CVs).
- You can delete any document or block at any time, individually or entirely. Deletion removes the document from storage; residual copies in encrypted backups are purged on the backup rotation cycle of up to 30 days.
1.4 Data imported from public sources
With your direction, the Service can retrieve publicly available professional information about you from ORCID and PubMed (e.g. your publication list). This data is only imported when you initiate the lookup, and every imported item is shown to you as a proposal that you accept or discard before it is stored.
1.5 Content you generate
Grant applications in progress, parsed call checklists, drafted sections, paper skeletons, and response-to-reviewers drafts you create within the Service.
1.6 Technical data
Standard server logs (IP address, browser type, timestamps) collected by our hosting infrastructure for security and reliability. We do not use advertising trackers, behavioral analytics, or third-party tracking pixels.
1.7 Google user data (optional)
If you choose to connect Google Calendar or Gmail, we access limited data from those services under your explicit consent, as described in detail in Section 4. If you never connect them, we collect nothing from Google.
2. How we use your data
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Providing the Service: storing your career blocks, generating drafts you request | Account, profile, documents, blocks, generated content | Performance of a contract (Art. 6(1)(b)) |
| Authentication via magic link email | Email address | Performance of a contract (Art. 6(1)(b)) |
| AI extraction and generation (see Section 3) | Document text, blocks, call documents you submit | Performance of a contract (Art. 6(1)(b)) |
| Optional Google Calendar and Gmail integrations (see Section 4) | Calendar events and certificate documents you confirm; OAuth tokens | Consent (Art. 6(1)(a)) — withdraw at any time by disconnecting |
| Security, abuse prevention, debugging | Technical data, logs | Legitimate interests (Art. 6(1)(f)) |
| Service communications (e.g. magic links, critical notices) | Email address | Performance of a contract (Art. 6(1)(b)) |
| Product announcements (optional) | Email address | Consent (Art. 6(1)(a)) — opt-out at any time |
We do not:
- sell your personal data;
- use your data for advertising;
- use your documents or career data to train AI models (ours or anyone else's);
- share your data with anyone except the subprocessors listed in Section 5, strictly to operate the Service.
3. AI processing
Reservoir uses Anthropic's Claude models, via Anthropic's commercial API, to:
- extract proposed career blocks from documents you upload;
- parse grant call documents into structured checklists;
- generate draft text from your stored blocks when you request it.
What this means for your data:
- Document text is sent to Anthropic's API only when you trigger an action (upload extraction, call parsing, draft generation).
- Under Anthropic's commercial terms, API inputs and outputs are not used to train Anthropic's models.
- Every AI output is a proposal: nothing is stored as part of your career record until you review and confirm it. The system is instructed never to invent facts, citations, or numbers, and to flag gaps with visible placeholders rather than fabricating content.
4. Google user data (Calendar and Gmail)
Reservoir offers optional integrations with Google Calendar and Gmail. They exist for one purpose: helping you capture certifiable career activities that already live in your calendar and inbox (talks, courses, committee work, peer review, teaching) so they can become confirmed blocks and documents in your Reservoir, and helping you keep track of application deadlines. This section explains exactly what we access, what we store, and what we never store.
4.1 Separate connections, revocable at any time
- Calendar and Gmail are independent, opt-in connections managed from Settings. Connecting one never grants access to the other, and neither is required to use Reservoir.
- Before you connect each service, the app shows you exactly what will be accessed and why, and Google shows you its own consent screen listing the requested permissions.
- You can disconnect either integration at any time in Settings. Disconnecting deletes the Google access and refresh tokens from our systems. You can also revoke Reservoir's access directly from your Google Account at myaccount.google.com/permissions.
- Disconnecting does not delete the blocks or documents you previously confirmed; they remain yours, and you can delete them individually or entirely at any time, like any other content (see Section 8, Your rights).
4.2 Google Calendar
What we access and why. With your consent, we read your calendar events to detect activities that may be certifiable career merits and propose them to you as blocks, and, when you ask, we create calendar events for grant application deadlines you are tracking in Reservoir.
What we store. Only what you confirm: a calendar-derived proposal becomes a stored block or record when you accept it, exactly like every other proposal in Reservoir. For events Reservoir creates on your behalf, we also store the event identifier so we can update or remove that event if you ask us to.
What we never store. A copy of your calendar, the attendees or guest lists of your events, or the content of events you did not confirm. Unconfirmed event data is processed transiently to generate proposals and then discarded.
4.3 Gmail (read-only)
What we access and why. With your consent, we run a narrow, bounded search of your mailbox for messages likely to contain certificates of your professional activity (for example, attendance, teaching or review certificates institutions send by email). When a candidate attachment is found, we extract it and show it to you as a proposed document.
What we store. Only the certificate documents you confirm. A confirmed certificate is stored exactly like a document you uploaded yourself (see Section 1.3) and follows the same protections, retention and deletion rules.
What we never store. Raw email bodies, attachments you did not confirm, sender or recipient lists, or any copy of your mailbox. Email content is processed transiently to generate the proposal and then discarded. Reservoir cannot send, delete or modify your email with this permission; it is read-only.
Other people in your mailbox. Your inbox inevitably contains information about other people. We only extract the certificate documents you confirm, we never build profiles of your correspondents, and we never store correspondence.
4.4 Limited Use disclosure
Reservoir's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
In particular, and notwithstanding anything else in this Policy, we:
- use Google user data only to provide or improve the user-facing features described in this section, with your consent;
- do not transfer Google user data to third parties, except to the subprocessors listed in Section 5 as strictly necessary to provide these features, as required by law, or as part of a merger or acquisition with prior notice to you;
- never use or transfer Google user data for advertising (including retargeted, personalised or interest-based advertising), never use it to determine creditworthiness or for lending purposes, and never sell it to data brokers or information resellers;
- do not allow humans to read Google user data, unless (a) we first obtained your affirmative agreement to view specific messages or items, (b) it is necessary for security purposes such as investigating abuse, (c) it is necessary to comply with applicable law, or (d) the data has been aggregated and anonymised and is used for internal operations.
4.5 Google user data and AI
We do not retain or use data obtained through Google APIs, whether raw, aggregated, anonymised or derived, to develop, improve or train generalised or non-personalised AI or machine learning models, whether ours or anyone else's.
Google user data is processed by our AI subprocessor (Anthropic, see Section 3) only to provide the specific feature you requested, for example extracting a certificate you asked Reservoir to look for. Under Anthropic's commercial terms, API inputs and outputs are not used to train Anthropic's models. As everywhere in Reservoir, the output is a proposal that you confirm or discard.
4.6 Legal basis, storage and retention
- Legal basis: your consent (GDPR Art. 6(1)(a)), given when you connect each service. You can withdraw it at any time by disconnecting, without affecting the lawfulness of prior processing.
- Storage: items you confirm are stored encrypted at rest in the European Union, like all your Reservoir data. International transfers to subprocessors are covered in Section 6.
- Retention: OAuth tokens are deleted when you disconnect or delete your account; unconfirmed Google data is never retained; confirmed items follow Section 7 (Retention).
- No new subprocessors: these integrations do not add any subprocessor. Google acts as a data source you direct us to read, not as a processor on our behalf.
5. Subprocessors
We use a small number of service providers to operate Reservoir:
| Provider | Purpose | Location of processing |
|---|---|---|
| Supabase | Database, file storage, authentication | EU (Frankfurt, Germany) |
| Vercel | Application hosting and delivery | EU/US (edge network) |
| Anthropic | AI extraction and generation (Claude API) | United States |
| Resend | Transactional email (magic links) | United States |
| Stripe | Payment processing (if/when you subscribe to a paid plan) | United States |
Each provider processes data only under contract with us and only as needed to provide its service.
6. International transfers
Your documents and career data are stored in the European Union. Some subprocessors (Anthropic, Resend, Vercel, Stripe) process data in the United States. Where personal data is transferred outside the EU/EEA or UK, we rely on appropriate safeguards: the EU–U.S. Data Privacy Framework where the provider is certified, and/or Standard Contractual Clauses approved by the European Commission. You may request details of the safeguards applicable to a specific transfer via privacy@heymira.so.
7. Retention
Reservoir is built to be your long-term career record, so by default we keep your data for as long as you want it kept:
- Account, profile, blocks, documents, and generated content: retained indefinitely while your account exists. We never auto-delete or expire your career data.
- You decide when data goes. Delete any document, block, draft, or your entire account at any time; deleted items are removed from production systems immediately and from encrypted backups within 30 days.
- Account deletion: request it at any time by emailing privacy@heymira.so (in-app deletion is coming). All your data is deleted within 30 days, except records we must retain to comply with legal obligations (e.g. billing records, kept 7 years).
- Server logs: retained for up to 90 days.
- Google integration data: OAuth tokens for Google Calendar and Gmail are stored encrypted and deleted when you disconnect the integration or delete your account. Calendar events and email content that you did not confirm are processed transiently and never retained. Items you confirmed (blocks, certificate documents) follow the standard rules above.
8. Your rights
If you are in the EU/EEA, UK, or another jurisdiction with similar protections, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate data (and Reservoir's review-and-confirm design lets you do this directly for all career content);
- Erase your data ("right to be forgotten");
- Restrict or object to certain processing;
- Portability — receive your data in a structured, machine-readable format. Reservoir's core function is exporting your data (docx, copy-paste text), and we will additionally provide a structured export of your blocks on request;
- Withdraw consent where processing is based on consent;
- Lodge a complaint with your supervisory authority (in Spain, the Agencia Española de Protección de Datos, www.aepd.es).
To exercise any of these rights, contact privacy@heymira.so. We respond within one month.
9. Security
- All data encrypted in transit (TLS) and at rest.
- Database access is governed by row-level security: your data is queryable only by your authenticated account.
- Passwordless authentication (magic links) eliminates password-database risk.
- The Claude API key and all AI calls are confined to server-side code; no AI credentials or raw document content are exposed to the browser beyond what you are viewing.
No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and the competent authority as required by law.
10. Children
Reservoir is a professional tool for researchers and is not directed at anyone under 18. We do not knowingly collect data from minors.
11. Changes to this policy
We may update this Policy as the Service evolves. For material changes we will notify you by email or in-app notice before the changes take effect. The "Last updated" date above reflects the current version.
Reservoir — A Product By HeyMIRA, Inc.