Datenschutzerklärung für Locus – External Papers
Locus – External Papers von LocusAI
Privacy Notice for Locus – External Papers
Last updated 21 September 2026
This notice covers the browser extension and the Locus service it saves papers into. Where something applies to only one of them, it says so.
Locus – External Papers is a browser extension with one purpose: to save a research paper you are already reading into your Locus library, without downloading it and uploading it again by hand. It works on any article page, open access or otherwise. Where a paper is behind a subscription, the download runs inside your own browser tab using the access you already hold, so your institution's entitlement applies exactly as it would if you clicked the publisher's own download link. Locus holds no credentials at any publisher and circumvents no access control.
The extension does nothing on a publisher's site until you click its toolbar icon. It observes no browsing and runs on no page by itself. When you do click it, it reads only the page you clicked on: the title and DOI from the citation metadata publishers embed for search engines, the links that look like the PDF, and the page address, which is saved with the paper so you can get back to where it came from. It also checks the start of the visible text for phrases such as "Get access", so it can warn you the article looks paywalled before you try; that text is examined on the page and discarded, and only the yes-or-no answer reaches the popup.
When you install the extension, it opens a page describing all of this and asks you to accept or decline before it does anything at all. Declining leaves it installed and idle, and you can accept later from its popup.
The extension collects only what those functions need: the PDF you choose to save, its title, DOI and page address, and the project you file it under. Your Locus sign-in and the email address of your account are stored on your own machine so that it knows which account to add papers to.
Your Locus sign-in, your email address, the record of whether you accepted the notice shown when the extension was installed, and the last project you added to are kept in the extension's own local storage on your computer and are never synced to another device. Disconnect in the popup erases all of it, and removing the extension erases it with it. The Locus web application records usage events; the extension does not, and it contains no analytics, tracking or advertising code of any kind.
When you press Add, the paper travels to two hosts, both visible in your browser's network log. www.joinlocus.ai is the Locus API, which returns your project list, issues a signed upload link, and records the import. The PDF itself is uploaded directly to our Supabase project at supabase.co, the storage behind that API, because our host limits how large a file may pass through the API. Supabase is also where your sign-in is renewed about once an hour.
The extension asks for the following, and uses each only as described. activeTab and scripting let it read the article page you clicked on and run the download inside that tab, so that your own access applies; nothing runs before the click. “storage” holds the items described above. Permission for joinlocus.ai lets it reach your Locus library and lets the popup see which Locus project you have open in another tab so the picker can default to it; no other tab or address is read. Permission for all sites is optional and is never requested at install. When you press Add, the extension asks only for the specific sites that the PDF links on that page point to, usually the publisher you are already reading and sometimes a separate download server. Declining costs you one fallback download path and nothing else.
The extension contains one content script. It runs only on joinlocus.ai/extension/connect, a page on our own site, and its only job is to carry your Locus sign-in from that page into the extension. There is no content script on any publisher site. No remote code is loaded or executed, and there are no third-party libraries.
The extension never collects your browsing history or records which pages you visit, and never downloads in bulk or crawls: one paper, on the page you are looking at, per click. Your institutional credentials and publisher cookies are used by your own browser to fetch the PDF and never reach us.
The rest of this notice describes the Locus service that the extension saves into. The extension itself talks only to joinlocus.ai and to our Supabase project, and plays no part in the AI features, payments or sign-up checks below. A paper you add with it becomes an ordinary paper in your library, so once it is there, everything that follows applies to it.
Locus uses AI models from OpenAI to read papers. Your papers are not used to train or improve OpenAI's models, data sent through OpenAI's API is excluded from model training by default, and we have not opted in to sharing it. OpenAI keeps what we send for up to 30 days so that it can detect abuse of its service, then deletes it; it is not used for anything else in that time. When you use a feature that needs a model, we send the relevant text of that paper to OpenAI, along with your question where there is one. That happens when Locus suggests tags, extracts citation details, answers a question about a paper, finds claims in your draft that need support, recommends related work, or explains a highlight or figure. We send the paper's text. We do not send your name, your email, or your other papers. If you upload a manuscript that is not yet published, all of the above applies to it in full; if that is not acceptable for a particular document, do not add it to Locus. Answers, tags and summaries are generated by a model and can be wrong. Locus shows you the sentence in the paper behind each answer so that you can check it, and nothing a model produces should be relied on without reading the source.
When you add a paper to Locus, we store the PDF, the text we extract from it, and whatever you create from it such as flashcards, highlights, tags, and the answers Locus gives you. You keep every right you had in those papers; Locus claims none. We do not publish them, share them between accounts, or make them searchable by anyone else. Most research papers are copyrighted by their publishers or authors rather than by the person who downloaded them, and you are responsible for having the right to upload each paper you add: normally a copy obtained through your institution's subscription, an open-access copy, or your own work. Locus cannot see what you are entitled to and does not check. Deleting a paper deletes the stored PDF and everything derived from it.
Locus is built on services run by other companies. Each receives only what it needs, and none of them may use your data for their own purposes. Supabase, in the United States, stores your account, your PDFs, extracted text, flashcards, tags and usage records. OpenAI processes the text of a paper when a feature needs a model to read it, as described above. Vercel hosts the website and receives the ordinary technical records of any web request, including your IP address. Stripe handles payment if you subscribe; your card details go directly to Stripe and never reach us, and we hold only the identifiers Stripe gives us to recognise your subscription. hCaptcha is shown when you create an account or sign in, to keep automated signups out. OpenAlex, Unpaywall, Europe PMC, PubMed Central and doi.org are public scholarly databases: we send a paper's title, DOI or PubMed identifier to identify it, find its citations, and check whether a free version exists. We do not send them your identity, your library, or anything you have written. Requests to Unpaywall include our contact address, which their service requires. We do not sell your data, share it with advertisers, or use it to build a profile of you.
We keep what is in your account for as long as your account exists. Papers are never deleted because a subscription lapsed. In such a case your account moves to the Free plan and your data stays. Deleting your account removes your stored PDFs and then the account itself, and everything tied to it goes with it: papers, flashcards, highlights, tags, saved references and usage records. That is immediate and cannot be undone. Two things outlive it. Our database provider keeps routine backups, in which deleted data persists until those backups rotate and are overwritten; it is not used for anything else in the meantime. And if you have ever paid, Stripe keeps transaction records for as long as tax law requires. Those are Stripe's records, not ours to delete.
Whatever jurisdiction you are in, you can see what we hold: your papers, flashcards and tags are visible in the app, and for anything else you can ask. You can correct it: your name and email are editable under Personal Info. You can delete it: any paper from the paper itself, or your whole account under Privacy, both taking effect immediately. You can turn off usage tracking in the same place. If you are in the United Kingdom, the European Union or the EEA, you also have the right to object to our processing of your data, to ask us to restrict it, to ask for a copy of it in a machine-readable form, and to complain to your data protection authority. To exercise any of these, email support@joinlocus.ai. We will respond within 30 days.
Everything travels over HTTPS. Your papers are stored with access rules that scope every row and every file to the account that owns it. Passwords are handled by our authentication provider and are never stored by us in a form we could read. No service is perfectly secure; if a breach affects your data we will tell you and tell the relevant authority where the law requires it. Locus sets the cookies it needs to keep you signed in, and hCaptcha sets its own when you create an account or sign in. We use no advertising cookies and no third-party analytics trackers. Usage measurement happens in our own database, and you can switch it off. Locus is for researchers and is not directed at children; we do not knowingly collect data from anyone under 16, and if you believe a child has created an account, email us and we will remove it. We will update this policy as Locus changes, and the date at the top says when it last changed. If a change materially affects how we handle your data, we will tell you before it takes effect.
Locus is operated by Haoyu Wang, who is the data controller for the personal data described in this policy. For any question about this policy, about your data, or to exercise any of the rights above, email support@joinlocus.ai. If you need a postal address for a formal data protection request, ask and we will provide one.