Privacy Policy

This Privacy Policy (the “Policy”) describes how Mosaic collects, uses, discloses, and safeguards personal information in connection with the Mosaic research workspace, the Mosaic Citations add-in for Microsoft Word, and the Mosaic Citations add-on for Google Docs (collectively, the “Services”). This Policy supplements and is incorporated into our Terms of Service. By accessing or using the Services, you acknowledge that you have read and understood this Policy.

1. Who We Are

The Services are operated by Mosaic Labs, LLC, a Maryland limited liability company (“Mosaic”, “we”, “us”, or “our”), located at 202 E University Pkwy, Baltimore, Maryland 21218, USA. For the purposes of the European Union and United Kingdom General Data Protection Regulation (“GDPR”), Mosaic is the controller of the personal information described in this Policy. For any privacy question or to exercise your rights, contact us at hello@joinmosaic.ai.

2. Information We Collect

We limit our collection of personal information to what is reasonably necessary and proportionate to provide and maintain the Services you request. We collect the following categories:

  • Account Information. Your name and email address and, where you authenticate through a third-party identity provider such as Google or Microsoft, the basic profile information that provider makes available to us.
  • Content and Materials. The research projects, notes, tasks, documents, and reference library you create, upload, or import, including papers, PDFs, document identifiers such as DOIs, and associated citation metadata.
  • Citation and Add-in Data. When you use the Mosaic Citations add-in or add-on, the sentence, claim, or text you select within your document, together with any search queries you submit, which we process in order to identify and verify sources on your behalf.
  • Google User Data. Where you sign in with Google or install the Mosaic Citations add-on for Google Docs, the Google user data described in Section 8: your basic Google profile information, and the content of the Google Docs documents in which you use the add-on.
  • Usage and Diagnostic Data. Information about how the Services are accessed and used, which we use to operate, secure, and improve the Services.
  • Technical Data. Standard log information, such as browser type, device information, and IP address, processed for security, reliability, and diagnostic purposes.

3. How We Use Your Information and Our Legal Bases

We process personal information for the following purposes:

  • to provide, operate, maintain, and secure the Services;
  • to locate, retrieve, and verify citations, to parse documents you import, and to generate AI-assisted output and suggestions;
  • to synchronize your library and projects between the web application and the add-in;
  • to detect, prevent, investigate, and address fraud, abuse, and security incidents; and
  • where permitted, to analyze and improve the Services.

Where the EU or UK GDPR applies, we rely on the following legal bases. We process your account information and store the content you create to perform our contract with you. We transmit document text, queries, and related content to the AI and search providers described in Section 5 in order to deliver the specific feature you have requested (performance of a contract). We process security and activity logs, and we take abuse-prevention and service-improvement measures, on the basis of our legitimate interest in keeping the Services secure, reliable, and improving over time. Where we use any non-essential cookies or analytics, we do so only with your consent. We do not sell your personal information, and we do not use your research content to train artificial-intelligence models. You may withdraw consent at any time where consent is the legal basis for processing.

4. Special-Category Data

The Services are not intended for the storage or processing of special-category personal data (such as data revealing health, racial or ethnic origin, religious beliefs, sexual orientation, or genetic or biometric data). You should not upload such data unless it is necessary for your research. Where your content nonetheless contains special-category data, we process it only at your instruction and only to provide the storage, retrieval, and AI-assistance features you request, relying on your explicit consent given at the time of upload. We do not use special-category data for any other purpose.

5. How We Share Your Information

We do not sell your personal information. We disclose information only as described in this Section.

  • Service Providers and Sub-processors. We engage third-party service providers to perform functions on our behalf and under our instructions, in the following categories: cloud hosting, database, and authentication infrastructure; artificial-intelligence and machine-learning processing (for example, language models and text-embedding services used to find and verify citations); search and information-retrieval services used to locate sources; document-parsing services used to process the files you import; transactional email; and logging and operational-monitoring services. These providers currently include Anthropic (AI-assisted answers and citation verification), Voyage AI (text embeddings), Cohere (search-result reranking), LlamaIndex (LlamaParse, document parsing), Supabase (database and authentication), Vercel (hosting), and Resend (transactional email, such as sign-in and account notices), together with our web-search provider. They act under data-processing agreements, process information only as necessary to provide their services to us, and are contractually required to maintain reasonable administrative, technical, and physical safeguards. We select these providers on terms that do not permit them to use the content we transmit through their APIs to train their models. A current list of our sub-processors is available on request at hello@joinmosaic.ai.
  • Public Academic Sources. To retrieve information about scholarly works, we query publicly available academic metadata services (such as Crossref, Unpaywall, OpenAlex, PubMed, and Semantic Scholar) using identifiers such as DOIs. These queries do not include your account information.
  • Authentication and Connected Services. Where you sign in with, or connect, a third-party account or service (such as Google or Microsoft), we exchange information with that provider as necessary to authenticate you and to enable the integration you have requested.
  • Legal and Protective Disclosures. We may disclose information where we believe in good faith that doing so is required by law or is reasonably necessary to protect the rights, property, or safety of Mosaic, our users, or others.
  • Business Transfers. In connection with a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.

6. International Data Transfers

We and our service providers are located in the United States and may process information in countries other than the country in which you reside. Where we transfer the personal data of users in the European Union, the United Kingdom, or Switzerland to providers in the United States, we rely, for each provider, on the EU-US Data Privacy Framework where that provider holds an active certification, and otherwise on the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum. Details of the safeguard applicable to a given provider are available on request.

7. The Mosaic Citations Add-in for Word and Add-on for Google Docs

The add-in for Microsoft Word and the add-on for Google Docs operate only at your direction. When you select text and request sources, or enter text into the add-in or add-on, that text and your related queries are transmitted to Mosaic and to the service providers described in Section 5 for the sole purpose of identifying and verifying sources, and the results are returned to you for insertion. The add-in and add-on read your document only when you initiate an action and write to your document only when you choose to insert or update a citation or bibliography, or when you use a citation-management feature (such as changing citation style or refreshing your reference list) that you have turned on. We do not retain a copy of your document, and a Mosaic account is required. Where you use the add-on for Google Docs, the additional disclosures in Section 8 apply.

8. Google User Data

This Section describes how the Services access, use, store, and share Google user data, and applies whenever you sign in with Google or use the Mosaic Citations add-on for Google Docs.

Mosaic’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Mosaic’s use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

  • What we access. When you sign in with Google, we access your basic profile information (name, email address, and profile picture) to create and authenticate your account. When you use the add-on for Google Docs, or the document features of the Mosaic web app, we access the content of the documents you are working in or link to Mosaic through the Google Docs API (the https://www.googleapis.com/auth/documents scope). This lets Mosaic read the text you are writing, insert and update citations and bibliographies, and, when you ask our AI assistant, read a document to answer questions about it and draft, edit, or create document content on your behalf. When you ask Mosaic to create a Google Doc for you, we also use the Google Drive API (the https://www.googleapis.com/auth/drive.file scope) to create that document and to rename, organize, or delete documents that Mosaic itself created on your behalf; this per-file scope does not give Mosaic access to any other files in your Google Drive.
  • How we use it. We use Google user data only to provide the user-facing features you invoke: authenticating you, reading the text you select or the surrounding passage so we can find and verify sources, inserting citations and reference lists you choose to insert, keeping managed citations and your bibliography consistent when you change citation style or edit citations, and synchronizing the sources you cite with your Mosaic library. At your request, our AI assistant also reads the content of a Google Doc you have linked so it can answer questions about your writing, and it can draft new content that we create as a new Google Doc or append to an existing one, in every case only to deliver the specific feature you requested. We do not use Google user data for advertising, and we do not sell it or transfer it to data brokers or information resellers.
  • How we store it. We do not retain a copy of your Google Docs documents on our servers. We store the citation metadata needed to manage the citations you insert (such as which sources are cited in a document), and we store your Google authentication tokens encrypted. Document text processed to answer a request is used to deliver that request and is not retained as a stored copy of your document.
  • How we share it. Document text and queries are shared with the service providers described in Section 5 only as needed to deliver the specific feature you have requested, for example sending a selected passage to our AI provider to find a supporting source. These providers act under data-processing agreements and are not permitted to use this data to train their models. We do not transfer Google user data to any third party for advertising, credit or lending decisions, or resale.
  • Artificial intelligence. We do not use Google user data to develop, improve, or train generalized or foundational artificial-intelligence or machine-learning models, and we do not transfer Google user data to any third-party artificial-intelligence service that uses it to train its models. Google user data is transmitted to the AI providers described in Section 5 only to provide the feature you have requested, and never for model training. Our use of raw or derived user data received from Google Workspace APIs, including any processing by the artificial-intelligence features described in this Policy, complies with the Google API Services User Data Policy, including the Limited Use requirements.
  • Human access. Our personnel do not read Google user data except with your explicit permission (for example, when you ask us to help resolve a support issue), where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and anonymized for internal operations.
  • Retention, deletion, and revoking access. You can revoke Mosaic’s access to your Google account at any time from your Google Account security settings at myaccount.google.com/permissions, or by disconnecting Google inside Mosaic. When you revoke access or disconnect, we delete the associated Google authentication tokens promptly and any cached Google user data within 30 days. When you close your Mosaic account, Google user data is deleted on the schedule described in Section 10. You can also request deletion at any time by emailing hello@joinmosaic.ai.

9. Cookies and Local Storage

We currently use only strictly necessary cookies and local storage to keep you signed in and to operate core features, including, for the add-in, an authentication token stored locally in your browser. These do not require consent, and we do not use third-party advertising cookies. If we introduce analytics or other non-essential cookies in the future, we will, for users in the EU and UK, request your consent through a banner that lets you accept or reject non-essential cookies equally easily before any such cookies are set, and we will update this Section accordingly.

10. Data Retention

We retain account information for as long as your account is active and for a short wind-down period of up to 30 days after you close it. We delete the research content associated with a closed account within 90 days of closure, except where we must retain it to comply with law. We retain security and activity logs for up to 90 days. Google user data is retained and deleted as described in Section 8, and revoking Google access does not require closing your account. Data transmitted to AI and search providers is retained by those providers in accordance with their own policies.

11. Your Privacy Rights

Depending on where you live, you may have the right to access, correct, delete, restrict, or port your personal information, to object to certain processing, and to rights concerning automated decision-making. Where we rely on consent, you may withdraw it at any time. To exercise any of these rights, email hello@joinmosaic.ai; we will respond within one month, which we may extend by two further months for complex requests, and we will tell you if we do. If you are in the EU or UK and believe we have not handled your data lawfully, you have the right to lodge a complaint with your local data protection authority; users in the United Kingdom may contact the Information Commissioner’s Office (ICO).

12. California Privacy Rights

This Section applies to California residents. In the preceding twelve months we have collected the following categories of personal information: identifiers (such as name and email); internet or network activity (such as log and usage data); professional or education-related information you provide; and the content you create or upload. We collect this information from you directly and from your use of the Services, and we use it for the business purposes described in this Policy. We do not sell your personal information, and we do not share it for cross-context behavioral advertising. California residents have the right to know and access, delete, and correct their personal information, to opt out of sale or sharing, to limit the use of sensitive personal information, and to be free from discrimination for exercising these rights. Because we do not sell or share personal information, no “Do Not Sell or Share” mechanism is required. To make a request, email hello@joinmosaic.ai; you may use an authorized agent, in which case we will verify the agent’s authority.

13. Maryland Residents

If you are a Maryland resident, we do not sell your personal data, we do not sell sensitive data under any circumstances, and we do not use your personal data for targeted advertising or for profiling that produces legal or similarly significant effects. We limit our collection of personal data to what is reasonably necessary and proportionate to provide or maintain the product or service you request.

14. Artificial Intelligence

Mosaic uses artificial intelligence to assist you, including for briefings, citation help, summaries, and search. We do not use your research content or Google user data to train artificial-intelligence models, and we do not permit our AI providers to use the content we transmit through their APIs to train theirs. Mosaic does not make legal or similarly significant decisions about you by solely automated means, and our AI features are designed to support, not replace, your own judgment.

15. Children’s Privacy

The Services are intended for users aged 16 and older and are not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us so that we may take appropriate action. Where you are located in the EU or UK, the digital-consent age may vary by country.

16. Data Security and Breach Notification

We maintain reasonable administrative, technical, and physical safeguards designed to protect your data, including encryption in transit and at rest, access controls, and least-privilege practices. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a data breach affecting your personal information occurs, we will notify affected users and the relevant authorities as required by applicable law, including the GDPR and the Maryland Personal Information Protection Act.

17. Changes to This Policy

We may amend this Policy from time to time. Material changes will be posted on this page with a revised “Last updated” date and, where required by law, communicated to you by email or within the Services.

18. Contact Us

For questions or requests regarding this Policy or your personal information, contact us at hello@joinmosaic.ai.