Rectoly — Privacy Policy
Last updated August 19, 2026
Hawk Eye ("we," "us") develops Rectoly, an iPad app for reading, annotating, and syncing academic PDFs with reference managers including Mendeley Reference Manager and Zotero. This policy explains what information Rectoly collects, why, and how it is handled.
Information we collect
Your Mendeley account connection. When you sign in with Mendeley, Rectoly requests an OAuth access token to read and sync your library, documents, and annotations. This token is stored in your device's Keychain and is never sent to our servers — Rectoly talks directly to Mendeley's own API.
Your Zotero account connection. When you sign in with Zotero, Rectoly requests a Zotero API key to read and sync your library, documents, and annotations. This key is stored in your device's Keychain and is never sent to our servers — Rectoly talks directly to Zotero's own API.
Your documents and annotations. PDFs you open, along with highlights, underlines, sticky notes, and any handwritten ink you add, are stored on your device. If you enable iCloud backup, this data — and, if you separately opt in, your handwriting — is backed up to your own iCloud account via Apple's CloudKit. We do not have access to this data; it is encrypted and scoped to your Apple ID.
Crash and error reports. Rectoly uses Sentry to automatically report crashes and errors so we can fix bugs. These reports are configured to exclude personal information: no default user identifier or IP address is collected, and document titles, file paths, email addresses, authentication tokens, and annotation text are stripped before a report is sent.
Anonymous usage analytics. Rectoly uses TelemetryDeck to collect anonymous, aggregated usage signals — for example, which screens are opened, whether onboarding was completed, or whether a sync succeeded or failed (as a general reason category, not raw error text). These signals never include document titles, file paths, email addresses, or annotation content, and are not tied to your identity.
Purchases. Subscriptions and one-time purchases are handled entirely by Apple through StoreKit. We receive confirmation that a purchase was made; Rectoly does not collect or store your payment details. Apple's own privacy policy governs that data.
What we don't do
- We do not sell your data.
- We do not run advertising or ad-tracking SDKs.
- We do not read the content of your documents or annotations ourselves — they remain on your device and, if you enable it, in your own iCloud account.
Third-party services
- Mendeley (Elsevier) — your reference library and document sync
- Zotero (Corporation for Digital Scholarship) — your reference library and document sync
- Apple iCloud / CloudKit — optional backup, governed by your Apple ID
- Sentry — crash and error reporting
- TelemetryDeck — anonymous product analytics
- Apple StoreKit — purchases and subscriptions
Each of these operates under its own privacy policy, which we encourage you to review.
Data retention and deletion
Your documents, annotations, and handwriting remain on your device until you delete them or delete the app. If iCloud backup is enabled, you can turn it off in Rectoly's settings, or remove the app's iCloud data from your device's Settings app. Disconnecting your Mendeley or Zotero account removes the locally stored access token or API key immediately.
Children's privacy
Rectoly is not directed at children under 13, and we do not knowingly collect information from them.
Changes to this policy
We may update this policy as the app changes. Material changes will be reflected here with an updated date.
Contact
Questions about this policy: rectoly.app@gmail.com