G.O.A.T Peer
HomeWhat we checkAbout usPricing
Sign in Get started
Legal

Privacy Policy

What we collect, why, who else sees it, and how to make us delete it.

Version 2026-07-31 · Effective 31 July 2026

This policy explains how GoatPeer, LLC (“GoatPeer”, “we”) handles information when you use G.O.A.T Peer at goatpeer.com. It forms part of the Terms of Service.

The short version. What you upload is usually somebody's unpublished manuscript, and we treat it that way. We do not sell your data, we do not advertise, we do not use your uploads to train our models, and we do not show your material to other users. Uploads are encrypted in transit and at rest, kept until you delete them, and — only on plans whose AI checks you actually run — sent to a third-party AI provider to perform that check. You can delete any analysis, or your whole account, whenever you like.

1.Who is responsible

GoatPeer, LLC is the controller of the personal data described here. Contact us about anything in this policy at [email protected].

2.What we collect

CategoryWhat it isWhere it comes from
AccountUsername, password (stored only as a salted hash, never in readable form). If you use third-party sign-in: your email address, name and profile picture URL.You, or the identity provider when you choose that sign-in
UploadsThe figures, images, PDFs, manuscripts and code you submit for analysis, plus anything they happen to contain.You
ResultsDetection output, evidence crops, thumbnails, reports and the notes you write.Generated by the Service
Usage & technicalIP address, request times and paths, browser user agent, error logs, and counts of analyses and AI tokens used (for quotas and billing).Automatically, when you use the Service
SupportSupport tickets and any messages you send us.You
PaymentYour customer and subscription identifiers, plan, and billing status. We never receive or store your card number — the payment processor handles card data directly.The payment processor

We do not use advertising trackers, third-party analytics, or social-media pixels. We set only the cookies in clause 8.

Please do not upload personal or sensitive data. The Service is designed for scientific figures and manuscripts, not for identifiable patient data, protected health information, biometric or government identifiers, or the special categories of data defined by the GDPR. See clause 5 of the Terms.

3.Why we use it, and our legal basis

PurposeData usedLegal basis (GDPR)
Run the analysis you asked for and show you resultsUploads, results Performance of a contract
Keep your account, history and notesAccount, results Performance of a contract
Take payment and manage subscriptionsAccount, payment Performance of a contract
Send service email (welcome, analysis finished, support replies)Account Performance of a contract
Keep the Service secure; prevent abuse, fraud and brute-force attacks Usage & technicalLegitimate interests
Fix bugs, and understand aggregate load and reliabilityUsage & technical Legitimate interests
Comply with law and enforce our TermsAs necessary Legal obligation / legitimate interests

We do not carry out automated decision-making that produces legal or similarly significant effects about you. Detection results describe uploaded images, not people, and a result is a screening signal that a human evaluates — see clause 3 of the Terms.

4.Who else sees your data

We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not disclose your uploads to other users. We use the following categories of service provider (“sub-processors”), each under contract and only to run the Service:

Category of recipientWhat it doesWhat it can see
Hosting and storage providerRuns the servers and stores the data (United States)Everything stored, as encrypted data at rest
Network and security providerDNS, TLS, and protection at the network edgeRequest metadata and traffic in transit
Payment processorPayments and subscriptions Your email, card data (directly, never via us), billing records
Identity providerOptional third-party sign-in, if you choose it That you signed in; your verified email, name and picture come to us
AI model providerThe language- and vision-model checks, on plans that include themThe specific figure images and article text sent for a check you ran
Email providerSending service email Your email address and the message

We will tell you which specific companies sit behind these categories if you ask — write to [email protected].

4.1 About the AI checks

This is the disclosure most worth reading. On plans that include AI features, running one of those checks sends the relevant figure images and article text to a third-party AI model provider for processing, where it is handled under that provider's terms for the service. The pixel-forensics detector does not do this — it runs entirely on our own infrastructure. The free Alpine plan runs no AI checks at all, so nothing you upload on Alpine is sent to an AI provider.

4.2 Legal disclosure

We may disclose information if we are legally required to, or where we believe in good faith it is necessary to comply with law, enforce our Terms, or protect the rights, safety or property of anyone. Where we are permitted to tell you about such a demand, we will.

4.3 Business transfer

If GoatPeer is involved in a merger, acquisition or sale of assets, your information may transfer as part of it. We will give notice before your information becomes subject to a materially different privacy policy.

5.How long we keep it

  • Uploads and results — kept until you delete the analysis or your account. Deleting an analysis removes its stored files and evidence images.
  • The file you submitted — the working copy is removed from the analysis machine as soon as processing finishes.
  • Account records — kept while your account is open, and deleted within 30 days of account deletion.
  • Operational logs — typically 30–90 days.
  • Billing records — retained as long as tax and accounting law requires (usually seven years). These are transaction records, not your uploads.
  • Backups — deleted material may persist in encrypted backups for a short period before being overwritten.

6.How we protect it

Traffic is encrypted with TLS. Stored objects are encrypted at rest with per-object keys. Passwords are salted and hashed, never recoverable. The database is not exposed to the internet: nothing listens on a public port, administrative access is restricted to a single address, and the operator console is behind a second, independent authentication layer. Access to production is limited to people who need it. Credential endpoints are rate-limited against brute force.

No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal data we will notify you and any regulator as the law requires.

7.Your rights and choices

Whoever and wherever you are, you can:

  • See and export your analyses from your dashboard;
  • Delete any analysis, which removes its stored files;
  • Delete your account — email [email protected] and we will erase it and its contents within 30 days;
  • Opt out of non-essential email using the unsubscribe link. Transactional messages about your account and billing continue while your account is open.

7.1 If you are in the EEA or the UK

You have the right to access, rectify, erase, restrict and object to processing, and the right to data portability, under the GDPR. Where processing rests on consent you may withdraw it at any time. You may also complain to your local supervisory authority, though we would rather you told us first.

7.2 If you are in California

Under the CCPA/CPRA you may request the categories and specific pieces of personal information we hold, request deletion or correction, and not be discriminated against for exercising those rights. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of — but you are welcome to ask.

7.3 How to exercise a right

Email [email protected] from the address on your account, or from the account itself. We respond within 30 days (45 days for CCPA requests, extendable where the law allows). We may need to verify your identity before acting, and cannot act on a request that would expose someone else's data.

8.Cookies

We use two cookies, both strictly necessary, and no others:

  • session — keeps you signed in. Signed, HTTP-only, and marked Secure in production.
  • goatpeer_csrf — protects forms against cross-site request forgery.

Because both are strictly necessary for a service you asked for, no consent banner is required. We set no advertising, analytics or tracking cookies.

9.International transfers

We operate in the United States, and our providers process data there. If you use the Service from outside the US, you understand that your information is transferred to and processed in the US, where data-protection law differs from your own. Where required for EEA or UK data, transfers rely on the European Commission's Standard Contractual Clauses or another lawful mechanism operated by the provider concerned.

10.Children

The Service is not for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us personal data, write to [email protected] and we will delete it.

11.Changes to this policy

We may update this policy; the version and effective date at the top change when we do. For material changes we will give notice by email or in the Service before they take effect.

12.Contact

GoatPeer, LLC — [email protected]
Privacy requests, access requests and deletion requests all go to the same address.

G.O.A.T Peer
Set in Newsreader & IBM Plex Mono
How it worksWhat we checkPricingAbout usTermsPrivacySign in
© 2026 G.O.A.T Peer · by AlCybr