Privacy Policy
Last updated October 1, 2026
TrialPath 2026 Clinical Research Services limitted ("we") runs Scintria and is responsible for your personal data. We process it in line with Uganda's Data Protection and Privacy Act, 2019 and, where they apply to you, the EU and UK General Data Protection Regulation. Contact: hello@scintria.com.
What we collect
- Account details: name, email address and sign-in information, including from Google if you choose Google sign-in.
- Research profile: country, institution, field, career stage, interests and keywords you choose to add.
- Your work: saved opportunities, saved papers, notes, projects, application statuses and drafts you create.
- Documents you upload: we extract and store their text so you can search and ask questions about them. The original file is not kept.
- Usage and technical data: features used, AI generation counts, and information such as browser type and IP address, used for security and reliability.
- Billing information: your plan and subscription status. Payment card details are handled by our payment provider and never reach our servers.
How we use it
To provide and secure the Service; to personalise funding alignment and drafts using the profile you provide; to apply plan limits; to process payments through our payment provider; to send service emails such as sign-in links and billing notices; and to improve Scintria using aggregated usage information.
We do not sell personal data, and we do not use your content to train AI models.
Legal bases
Where the GDPR applies, we rely on performance of our contract with you (running your account), legitimate interests (security, reliability and product improvement), consent where we ask for it (which you can withdraw), and legal obligations (tax and accounting records).
Who we share it with
We use these service providers to run Scintria:
- Supabase: database, authentication and storage.
- Vercel: hosting.
- OpenRouter and the AI model providers it routes to: generating drafts from the content you select. Requests are restricted to providers that do not store or train on prompts.
- Paddle: payments, as Merchant of Record. Paddle is an independent controller of the payment data it collects.
- Resend: service emails.
- Google: only if you choose Google sign-in.
- Public research databases (Grants.gov, NIH RePORTER, Europe PMC, OpenAlex, Crossref, ClinicalTrials.gov): searched with the terms you enter. ORCID: only when you import your own record.
- Your team: documents you share with a team are visible to its members.
International transfers
These providers may process data outside Uganda, including in the United States and the European Union. We rely on their contractual and technical safeguards for these transfers. We may also disclose data where the law requires it.
How long we keep it
We keep account data while your account is open. When you ask us to delete your account, we delete your personal data and content within 30 days, except records we must keep for legal, tax or accounting reasons.
Your rights
You can access, correct, export or delete your personal data, object to or restrict certain processing, and withdraw consent. You can edit your profile and remove saved items in Scintria at any time; for anything else, email hello@scintria.com. You can also complain to Uganda's Personal Data Protection Office or your local data protection authority.
Cookies
We use only essential cookies: to keep you signed in and to remember your language. We do not use advertising cookies.
Security
Your data is isolated to your account with row-level security in our database, sent over encrypted connections, and accessible only to authorised systems. No system is perfectly secure; tell us promptly at hello@scintria.com if you suspect a problem.
Children
Scintria is for adults. We do not knowingly collect data from anyone under 18.
Changes
We will post updates on this page and tell you about material changes before they take effect.