Rectoly — Privacy Policy
Last updated October 7, 2026
Hawk Eye ("we," "us") develops Rectoly, an app for iPad, iPhone, Mac, Android, Windows, and Linux for reading, annotating, and syncing academic PDFs with reference managers including Mendeley Reference Manager and Zotero. This policy explains what information Rectoly collects, why, and how it is handled.
Information we collect
Your Mendeley account connection. When you sign in with Mendeley, Rectoly requests an OAuth access token to read and sync your library, documents, and annotations. The token is stored securely on your device — in the Keychain on iPad, iPhone, and Mac, in encrypted app storage on Android, encrypted with Windows Data Protection (DPAPI) on Windows, and, on Linux, encrypted with AES-GCM using a random key kept in the app's data folder, in a file that only your user account can read — and Rectoly reads and syncs your library directly with Mendeley's own API. Mendeley issues tokens only with a secret that belongs to Rectoly, and we keep that secret on our server rather than in the app. So when you sign in, and about once an hour while you stay signed in, the app sends the sign-in code or renewal token to our server, which adds the secret, forwards the request to Mendeley, and passes Mendeley's reply — your new tokens — straight back to the app. The access token is also sent to our licence server (described below) so that it can ask Mendeley for your profile ID and confirm which account you are signed in to. Our servers use these tokens only for those steps and never store or log them; to avoid repeating the same lookup, the licence server keeps a one-way hash of the token in memory for up to five minutes.
Your Zotero account connection. When you sign in with Zotero, Rectoly requests a Zotero API key to read and sync your library, documents, and annotations. The key is stored securely on your device, and Rectoly talks directly to Zotero's own API. Zotero's sign-in must be signed with a secret that belongs to Rectoly, which we keep on our server rather than in the app, so the two sign-in steps go through our server, and Zotero's final reply — which contains your new API key, your Zotero user ID, and your username — passes through our server on its way back to the app. From version 4.0.0 of Rectoly for iPad and iPhone, the key is also sent to our licence server (described below), so that one purchase covers Rectoly on every operating system. It is sent for one purpose: to confirm which Zotero account is signed in. (Only the account ID, the receipt, and the dates — nothing from your library.) Rectoly sends it when it checks your purchase, and again when you buy, restore a purchase, or switch accounts. We do not use it to read your library, your papers, your annotations, or your notes. Our server asks Zotero only which account the key belongs to. So that it need not ask again, it keeps that answer — and only that answer — in memory for five minutes, matched by a hashed form of the key. It never stores or logs the key itself. Signing out of Zotero in Rectoly stops the key being sent; you can revoke the key at any time in your Zotero account settings; and you can ask us to delete your licence record (see "Data retention and deletion" below).
Server logs. Our sign-in relay, licence server, and update check run on Google Cloud (Firebase). Like most web services, they automatically log each request: the time, your IP address, the address requested, the app name and version, and whether the request succeeded. Log entries about purchases can also contain your account ID and order number. They never contain tokens, API keys, or anything from your documents. We use the logs to run the service, fix problems, and prevent abuse; to limit how often one address can call the sign-in relay, it also counts recent requests per IP address in memory. The logs are deleted automatically after 30 days. The doorbell signalling for requests from outside (described below) is not logged at all.
Your licence record. So that a purchase made on one platform also unlocks Rectoly on another, our licence server keeps a small record for your Mendeley or Zotero account. It holds your Mendeley profile ID or Zotero user ID; the store receipt or purchase token for your purchase — or, for a purchase on our website, the Paddle transaction and customer IDs, the amount and currency paid, the purchase date, and whether the order has been refunded; the IDs of your other accounts that share the purchase (a purchase may be shared only among up to three accounts that belong to you); whether a free trial has started and when, including a start date the app reports from your device; the date and app version of your most recent check on each platform; and a short log of when a purchase or trial was applied. It contains no name, no email address, and nothing from your documents. When you buy through the App Store or Google Play, the app may attach an identifier derived from your account ID to the purchase so that it can be matched to your account; Apple and Google receive that derived identifier, not the ID itself. On Windows and Linux, and on the Mac version sold on our website, the app also keeps a copy of your licence on the device, signed by our server and containing your Mendeley profile ID or Zotero user ID, so that it keeps working offline.
Your documents and annotations. PDFs you open, along with highlights, underlines, sticky notes, and any handwritten ink you add, are stored on your device. Highlights and notes sync to your own Mendeley or Zotero account, and handwriting travels in a file attached to the document in that same account, so that it reaches your other devices. None of it reaches us unless you choose to send it to us (see "Support and diagnostics" below). To name a PDF or fill in its details, Rectoly may look up its DOI, arXiv ID, or a title taken from the PDF in the public Crossref and arXiv catalogues; these requests go directly from your device to those services, and you can turn online lookup off in Rectoly's settings. On iPad, iPhone, and Mac, if you enable iCloud backup, this data — and, if you separately opt in, your handwriting — is backed up to your own iCloud account via Apple's CloudKit. We do not have access to this data; it is encrypted and scoped to your Apple ID. The Android, Windows, and Linux apps have no iCloud backup. On Android, the system's own backup to your Google account may include some of the app's settings and lists, such as the titles of papers in your library; your sign-in credentials are excluded from it.
Translating papers. Rectoly translates the paragraphs of the paper you are reading with a translation model that runs on the device (iPad, iPhone, Mac, Android, Windows and Linux). The text of your paragraphs is never sent to us or to any translation service. The model (about 2.5 GB) is downloaded from our distribution server (dl.rectoly.com, served through Cloudflare) when you first turn translation on; like any web service, Cloudflare processes your IP address for that download, but no account information is sent. On iPad, iPhone and Mac, for a language whose quality we have not yet measured (Hindi) and for use through the mainland-China App Store, Rectoly uses Apple’s Translation feature instead; that translation also happens on the device, and its language packs are downloaded from Apple. Translations are stored on the device. In Rectoly for Mendeley, so that your other devices can show the same translation, it is also saved as a file attached to that paper in your own Mendeley account (on by default; you can turn it off in Settings). In Rectoly for Zotero it is saved to your own Zotero storage only if you consent, and never to group libraries.
Letting a computer on your network translate. When you turn on “Translate for my phone and tablet” in Rectoly for Windows or Linux, that computer listens for connections on the network you choose and announces itself as “Rectoly on <computer name>” so devices on the same network can find it (off by default). Pairing happens with an on-screen QR code or a six-digit code; on iPad and iPhone the camera is used only while reading the QR code, and no image is kept. On Android the QR code is read by the Google Play services code scanner, and Rectoly itself has no camera permission. A paired device encrypts the paragraphs it wants translated with a key only those two machines hold, sends them to the computer, and the computer translates and answers. Paragraphs and translations never leave your home or office network. The pairing record (device name and key) is stored on each device, encrypted with DPAPI on Windows and, on Linux, encrypted with a key only your user account can read. On Android it is kept in the app’s private storage and left out of device backups.
Asking your computer from outside. When you turn on “Ask my PC from anywhere” on iPad, iPhone, Mac or Android and “Take requests” on the computer (both off by default), the device places a marker for each paragraph it wants translated — a short code derived from the text, not the text itself — as a file next to that paper in your own Mendeley or Zotero library. The computer translates from its own copy of the PDF and saves the translation to the same library. So that the computer can start promptly, the device sends a “doorbell” signal through our server (Google Cloud / Firebase). The signal is encrypted with a key only the paired machines hold and is addressed by a name derived from that key, which is not linked to any account, device or library ID; we cannot read its contents. A signal becomes unreadable after 15 minutes and is deleted automatically, normally within 24 hours. While “Take requests” is on, the computer checks our server for signals every 30 seconds. If you turn on “Wake my translating PC when a request comes” on another computer at home, that computer checks the same way and, when a signal arrives, sends a wake-up (Wake-on-LAN) signal inside your home network. Papers and translations never pass through our servers, and we do not log this signalling.
Crash and error reports. On iPad, iPhone, Mac, Windows, Linux, and Android, Rectoly uses Sentry to report crashes and errors automatically so we can fix bugs. A report contains technical details: the kind of error and where in the code it happened, the app version, the operating system and device model, and a short trail of recent technical events. The apps send no user identifier, IP address, or computer name, and they are set up to remove document titles, file paths, user names, email addresses, authentication tokens, annotation text, and the web addresses the app contacted before a report is sent. We use reports only to fix bugs. Reports are sent only after you have accepted the terms and while usage data sharing is on; turning that setting off in Rectoly stops crash reports as well as the analytics below.
Anonymous usage analytics. Rectoly uses TelemetryDeck to collect anonymous, aggregated usage signals — for example, which screens are opened, whether onboarding was completed, whether a sync succeeded or failed (as a general reason category, not raw error text), or whether in-app help such as tips, "what's new" cards, and guide pages was shown or opened. Each signal carries basic technical details such as the app version, the operating system version, the device model, and the language and region settings, and is linked only to an identifier for this installation that is hashed before it is sent; it is not tied to your account. These signals never include document titles, file paths, email addresses, or annotation content. Sharing is on by default, but nothing is sent until you have finished the welcome screens and accepted the terms, and you can turn it off at any time in Rectoly's settings.
Purchases. One-time purchases in the app stores are handled entirely by the store you bought from — Apple through StoreKit on iPad, iPhone, and Mac (App Store version), Google through Google Play Billing in the test version of the Android app that we distribute to testers through Google Play. We receive confirmation that a purchase was made; Rectoly does not collect or store your payment details. The store's own privacy policy governs that data.
Purchases on our website. On Windows, Linux, and Android, and for the Mac version downloaded from our website, Rectoly is bought on our website through Paddle.com, which acts as the Merchant of Record for the order. Paddle collects the information needed to complete the purchase — such as your email address, country, and payment details — and handles it under Paddle's own privacy policy. Paddle notifies our licence server when a purchase is completed or refunded, and our server stores the details listed under "Your licence record" above. Through Paddle's seller dashboard we can also see the order details, including the email address you entered at checkout; we use them only to answer your support and refund requests. We never receive or store your card details.
Support and diagnostics. If you email us, we receive your email address and whatever you include, and use them only to answer you. Rectoly can also create a diagnostics file to help us look into a problem. It is never sent automatically — it reaches us only if you attach it to an email or share it yourself. Depending on the platform, it contains device and app details, your Rectoly settings, sync status, document IDs and counts, and the app's recent log, which can include error messages. On iPad, iPhone, and Mac it also contains the annotation files of your papers, including the text of your highlights and notes, and a list of your handwriting pages (not the drawings). It never contains your PDFs or your sign-in credentials. We use it only to resolve your request.
Our website. rectoly.com counts visits with Umami, an analytics service that uses no cookies and reports only aggregated statistics such as page views, referring sites, and browser, device, and country. The checkout page loads Paddle's payment script. If you sign up for launch news, your email address — together with the product you signed up for, the page language, and the campaign link that brought you, if any — is stored by our email provider MailerLite and used only to send you news about Rectoly; you can unsubscribe at any time.
What we don't do
- We do not sell your data.
- We do not send the text of your papers to us or to any translation service for translation — it happens on the device, or on a computer you paired yourself.
- We do not run advertising or ad-tracking SDKs.
- We do not read the content of your documents or annotations ourselves — they remain on your device, in your own reference manager account, and, if you enable it, in your own iCloud account, unless you send them to us for support.
Third-party services
- Mendeley (Elsevier) — your reference library and document sync
- Zotero (Corporation for Digital Scholarship) — your reference library and document sync
- Apple iCloud / CloudKit — optional backup on iPad, iPhone, and Mac, governed by your Apple ID
- Sentry — crash and error reporting on iPad, iPhone, Mac, Windows, Linux, and Android
- TelemetryDeck — anonymous product analytics
- Crossref and arXiv — looking up a paper's details when naming a PDF
- Apple Translation — on-device translation of some languages on iPad, iPhone and Mac (language packs downloaded from Apple)
- Google ML Kit — on-device handwriting and text recognition on Android, and reading the QR code when pairing for translation; the recognition models and the code scanner are downloaded from Google, and the SDK sends Google its own usage and diagnostic data
- Apple StoreKit — purchases on iPad, iPhone, and Mac (App Store version)
- Google Play Billing — purchases in the test version of the Android app on Google Play
- Paddle — purchases on our website for Windows, Mac, Linux, and Android (Merchant of Record)
- Cloudflare — serves our website, and distributes app updates and the translation model (dl.rectoly.com)
- Google Cloud (Firebase) — hosts our sign-in relay, licence server, the relay for away-from-home request signals, and their logs
- Umami and MailerLite — our website's visit statistics and launch-news emails
Each of these operates under its own privacy policy, which we encourage you to review.
Data retention and deletion
Your documents, annotations, and handwriting remain on your device until you delete them or delete the app. On Windows and Linux, the app's data folder stays after you uninstall the app, and on a Mac it can stay after you delete the app; deleting that folder removes them. If iCloud backup is enabled, you can turn it off in Rectoly's settings, or remove the app's iCloud data from your device's Settings app. Disconnecting your Mendeley or Zotero account removes the locally stored access token or API key immediately. Server logs are deleted automatically after 30 days.
Translations remain in the app’s data folder on the device (on Windows, the folder above) and, if you turned saving on, in your own Mendeley or Zotero library. The translation and request files in your library have names beginning “Rectoly translation (do not delete)” and can be deleted in Mendeley or Zotero; once you turn saving off, nothing further is written. Pairing can be removed in Settings on either machine. Doorbell signals become unreadable after 15 minutes and are deleted automatically, normally within 24 hours; because they are not linked to an account, we cannot identify them individually to delete them on request.
Your licence record is kept for as long as your purchase remains valid, so that you can restore it on a new device. To have it deleted, write to us at the address below from the email address on your Mendeley or Zotero account and we will remove it. Deleting the record does not refund a purchase, and you may need to restore the purchase again afterwards. Paddle keeps its own record of website orders, as tax law requires, under its own privacy policy. Emails and diagnostics files you send us are deleted on request.
Children's privacy
Rectoly is not directed at children under 13, and we do not knowingly collect information from them.
Changes to this policy
We may update this policy as the app changes. Material changes will be reflected here with an updated date.
Contact
Questions about this policy: [email protected]