1. Scope and core principle

This policy applies to SciTuu.com and its wet lab tools, Experiment Workspace, Data Inbox, Instrument Inbox, MCP endpoint, account features and optional online integrations. Deterministic calculations and ordinary browser-local workspace operations are designed to run in your browser. Experiment content is transmitted only when you deliberately use a connected feature such as AI assistance, email delivery, an external lookup or an approved connector write.

2. Information processed in your browser

SciTuu may store preferences and working data in browser storage, including language and theme, favorites and recent tools, saved stocks and instrument profiles, mapping templates, workflow progress, QC rules, and the current Experiment Packet. Instrument watch-folder handles and imported files remain under browser and operating-system controls. Local Bridge and instrument import workflows process files locally by default unless you explicitly export, email or transmit them.

Clearing site data in your browser may remove these local records. A private/incognito window or a different device will not automatically share them.

3. Account and authentication data

If you create an account, we process your name, email address, account status, quota settings and timestamps needed to operate the service. Email-password accounts store a derived password hash and salt, not the original password. Session tokens and MCP bearer tokens are stored as cryptographic hashes.

If you sign in with Google or GitHub, SciTuu receives the provider subject identifier, verified email address and limited profile information needed to create or link your SciTuu account. We do not receive your Google or GitHub password, and provider access tokens are not retained after sign-in completes.

4. Abuse prevention and usage analytics

Anonymous beta access is limited by IP. The service stores only a secret-salted hash derived from the IP address for quota enforcement; it is not intended to recover the original IP. For registered users, usage counters may be associated with the member account.

We may record privacy-minimized operational metadata such as service or tool identifier, event type, success status, duration, response status, quota remaining, export format and file size. If you allow optional analytics, we also record page visits, referral and campaign parameters, session-level engagement, and approximate country, region or city information supplied by our hosting provider. We use this information to understand site adoption and improve the product. We do not intentionally place experiment inputs, result payloads, uploaded file contents or email attachments into product analytics events.

5. Optional online features

  • AI assistance: When you submit a Lab Agent or Bench Copilot request, the message, recent conversation context and any lab profile you explicitly choose to include are sent to the configured SciTuu.ai service and its configured AI provider.
  • Email delivery: When you press Send, the selected result or Experiment Packet, recipient, subject and optional message are processed to deliver email through Resend.
  • External lookups: PubChem, protocols.io and similar services are contacted only when you initiate the corresponding lookup or import. Their own privacy terms apply.
  • Connectors and webhooks: Data is sent to a third-party LIMS, ELN, object store or webhook only after you configure the destination and approve the write. Credentials entered for a connector should be treated as sensitive and are used for the requested connection.

6. Cookies and browser storage

SciTuu uses a secure, HttpOnly, SameSite=Lax session cookie for signed-in sessions and short-lived secure cookies for OAuth state and PKCE validation. Browser localStorage is used for the local preferences and workspace information described above, including your analytics preference. Essential authentication and security storage is required for the corresponding features. Optional page analytics is activated only after you select “Allow analytics”; choosing “Essential only” keeps it disabled.

7. Sharing and service providers

We do not sell personal information. Information is shared only as needed to operate requested features, protect the service, comply with law, or complete a user-approved integration. Relevant service providers may include Cloudflare for hosting, security, data storage and edge functions; Resend for email delivery; Google and GitHub for authentication; configured AI providers for optional AI requests; and scientific data services selected by the user.

8. Retention and security

Account, identity, session, token, quota, usage and synchronization records are retained for as long as reasonably needed to provide the service, enforce security and quotas, investigate failures and meet legal obligations. Expired sessions and revoked tokens may remain in security records for a limited period. Browser-local records remain until you remove them or clear site data. We use reasonable technical measures, but no internet service can guarantee absolute security.

9. Your choices and requests

You can avoid an account and use browser-local tools within anonymous beta limits, decline optional AI and lookup features, remove local browser data, revoke an MCP token, sign out, or choose not to approve an external write. To request access, correction or deletion of account information, contact support@scituu.com. We may need to verify the request.

10. Research and sensitive data

SciTuu is intended for research use. Do not submit patient-identifiable clinical data, regulated health information, secrets, or data you lack authority to process. Your institution's policies, consent terms, data-processing requirements and laboratory SOPs remain your responsibility.

11. Changes

We may update this policy as the service changes. The date above identifies the current version. Material changes will be reflected on this page.