Privacy
Last updated 8 October 2026
WHAT AN ACCOUNT KEEPS
Your username, and a way to sign in: a salted hash of your password (never the password itself), a passkey, or a sign-in from Google or Apple. Your reading: the papers and books you add, the text of PDFs you drop in, how far you are through them, highlights, notes, projects, and bookmarked briefs. Your streak, the interests you chose, and the searches you make, which tune the explore feed. Papers other readers send you, the shared projects you are in and what is said in them, and the share links you make. The recall questions written about papers you finish, and whether you remembered them.
If you share an invite link, zimmr keeps the referral code, which accounts signed up through it, and which of those have read a card.
All of it exists to run zimmr for you. None of it is sold, shown to advertisers, or used to follow you across other sites.
COOKIES
A cookie keeps you signed in. Someone without an account gets a guest session in that same cookie. Another cookie remembers that this device has signed in before, so the sign-in page opens on sign in. A referral link sets a cookie with the code, and that cookie is cleared when a new account is created. A passkey, or a Google or Apple sign-in, uses a short-lived cookie for that one attempt.
These cookies are essential: the site does not work properly without them. zimmr does not set advertising or analytics cookies. Page views, sign-ups, and the referral steps are counted in our own database, with no cookie and no analytics company.
WHERE IT IS KEPT
The library is stored in Upstash Redis. The site is served from a server zimmr runs.
WHO ELSE SEES IT
To write a brief, answer a question, or define a word, the paper's text or the word is sent to the language model that does it (z.ai). Searches are sent to an embeddings service (Mistral) to rank results by meaning. A scanned PDF's pages are sent as images to Mistral to be read. Searches go to PubMed, Europe PMC, OpenAlex, CORE, Crossref, and arXiv, definitions to Wiktionary and MeSH, and explore pictures come from Wikipedia. None of them is sent your username.
Other readers see what you choose to show them: your name, what you study, and what you are curious about on your profile; the papers you send them; and, in a shared project, the papers you add and what you say. A share link shows anyone who has it the paper's title and the opening of its brief, never its text or your notes. A shared week shows its numbers, its topics, and up to three titles. A shared project's invite link shows its name, who is in it, and its papers' titles.
For working out costs, the number of model calls each account makes is counted for 90 days. To see what brings readers back, zimmr notes which days you used it and which parts of it you have tried, and counts how often each kind of notification is opened. Those counts stay in the same database.
PRIVATE MODE
With private mode on (Settings, then Private mode), PDFs you add stay in that browser only, with their progress and highlights. The server never has them. Briefs, answers, and definitions are written by a model on the device. Only a word you look up goes to the public dictionaries, without the sentence around it. Searching still asks the catalogues, and scanned PDFs cannot be added.
ON YOUR PHONE
In the phone app, the theme, the reading reminder, and which cards counted toward today's streak stay on the device. Those reminders are scheduled on the phone. If you turn on notifications in the browser, the subscription is kept with your account so a note can be sent.
DELETING IT
Settings, then Delete account, removes your account and everything kept under it, at once.
CONTACT
Privacy questions go to hello@zimmr.ai. The terms are on the terms page.