Privacy Policy
What we collect, why, and what we don't do
Effective: 4 September 2026 · Latently is operated by Blockworks Pte. Ltd., Singapore ("we").
Latently exists to make research papers comfortable to read. This policy explains what data we collect to do that, why, and what we don't do. We've kept it short because our data posture is genuinely simple: no ads, no third-party tracking, and we never sell your data.
What we collect
In short: your email, the papers you read and add, how far you've read them, and any PDFs you upload for your own reading.
You give us:
- Email address — when you join the waitlist, request alpha access, or send us a feature request on latently.app.
- Account details — when accounts exist: email and sign-in credentials. During the TestFlight alpha, Apple handles the invite identity.
- Papers you search for and add — your search queries and the papers you ask Latently to fetch and reformat. We keep a log of these requests (see "the request ledger" below).
- Files you upload — PDFs you bring yourself ("Bring Your Own PDF").
- Anything you email us.
Collected automatically when you use the app:
- Reading telemetry — per paper: your current position (so you can resume), how far you've reached, active reading time, number of sessions and resumes, and a derived reading-speed estimate. This is the heart of the product: it's what makes "continue where you left off" work, and in aggregate it tells us whether Latently actually gets papers read.
- Device and app basics — device model, OS version, app version.
- Server logs — IP address, timestamps, and requested resources, kept for security and debugging.
- Crash reports — via Apple (TestFlight/App Store), under your Apple device settings.
- Website page counts — latently.app uses Vercel Web Analytics, which counts page views without cookies or cross-site identifiers. It cannot follow you anywhere else.
We do not collect: advertising identifiers, location, contacts, or anything from third-party tracking SDKs — because we don't use any.
Why we collect it
In short: to run the service, to make it better, and to keep a record that papers are fetched at your request — nothing else.
| data | purpose |
|---|---|
| Alpha invitations, service announcements, replying to you. No marketing without your consent. | |
| Reading telemetry | Making resume/sync work across your devices; understanding, in aggregate, how the reading experience performs. |
| Search & add requests | Fetching the paper you asked for; the request ledger — we retain the record that each paper was fetched at a specific user's request, because that fact matters legally (it evidences that you, not we, selected the work). |
| Uploaded PDFs | Converting them into your private reading version. |
| Server logs, device info | Security, abuse prevention, debugging. |
Your uploaded files, specifically
In short: your PDFs are yours, are served only to you, and the raw file is deleted right after processing.
When you upload a PDF or add a paper that isn't openly licensed, the reading version we produce lives in your private locker and is served only to you. The raw PDF is used to produce that reading version and is then deleted from the processing machine — we don't keep it, and we never redistribute it to anyone else.
Where your data lives
In short: Singapore, with two named exceptions.
- Paper content, lockers, and reading telemetry are stored on our servers in Singapore.
- Waitlist/signup data is stored with Amazon Web Services in the Asia Pacific (Singapore) region.
- PDF processing may run on rented GPU infrastructure (RunPod) whose data centers may be outside Singapore. Only the file being processed transits there, for the duration of processing, after which it is deleted (see above).
- Apple processes TestFlight and crash data under its own terms.
Where personal data leaves Singapore, we take the steps the PDPA requires to ensure it remains comparably protected.
Who we share with
In short: infrastructure providers under contract, and nobody else unless the law compels us.
Our processors: Apple (app distribution, crash reports), AWS (signup backend), RunPod (PDF processing), Vercel (website hosting and cookieless page counts), and our email provider. We share what each needs to do its job, nothing more. We may disclose data if legally required, and we'd tell you unless prohibited. We do not sell or rent personal data, full stop.
How long we keep it
In short: while you use Latently, plus the minimums below.
- Account + telemetry: while your account is active, deleted within 30 days of account deletion.
- Waitlist emails: until launch or your unsubscribe, whichever comes first.
- The request ledger: retained 6 years even after account deletion, in de-identified-where-possible form, because it is our legal record of user-directed fetching.
- Raw uploaded PDFs: deleted immediately after processing (usually minutes).
- Server logs: 30 days.
Your rights
In short: ask us what we hold about you, ask us to fix it or delete it — privacy@latently.app.
Under Singapore's PDPA you may request access to and correction of your personal data, and withdraw consent (which may mean parts of the service stop working — resume, for instance, cannot work without a stored position). If you're in a jurisdiction that grants you additional rights (such as deletion or portability under the GDPR), we'll honor reasonable requests in that spirit regardless of where you are.
Write to privacy@latently.app — it reaches the person responsible for data protection at Blockworks Pte. Ltd. (our PDPA data protection officer). We reply within 14 days.
The small print that remains
- Cookies: latently.app doesn't use tracking cookies. The web reader stores your reading preferences (theme, text size) and offline copies of papers in your browser's local storage, on your device — that data never reaches us.
- Children: Latently is not directed at children under 13, and we don't knowingly collect their data.
- Changes: we'll post updates here; if a change is material, we'll email account holders before it takes effect.