Gradstep

Privacy

Private beta · last updated 6 October 2026

Gradstep is an iPhone and iPad app for reading machine-learning papers. This page explains what data the app and its servers handle during the private beta, who processes it, and the choices you have.

Your notes and conversations

Your saved conversations and notes are encrypted on your devices with keys that stay on your devices. Our servers store them only in encrypted form and cannot read them. A new device is approved from a device you are already signed in on, or with your recovery code. If you lose every device and your recovery code, we cannot recover that content.

AI answers

When you ask a question, the app sends your question, any passage you selected, earlier messages in that conversation and, for questions about a paper, the paper's text to Anthropic, whose Claude models write the answer. When a question needs the web, the searches Claude writes go to Tavily or, as a backup, Anthropic's search provider; search services see only the searches. Our servers pass this through without storing it. These providers process it under their own terms and may keep it for a limited time. You agree to this the first time you ask a question, and the answer is saved, encrypted, on your device.

Papers

When you add a paper, our servers fetch it (from arXiv or an open-access source) and convert it with Mathpix so equations and figures display properly. Papers whose license allows sharing may be converted once and reused for other readers. Other papers, and anything you upload, are converted privately for your account. Your library lists which papers you have added.

Your account

You sign in with Apple, Google or an email code. We keep your email address and the identifiers from these sign-in services to run your account. Sign-in codes are sent by email through Resend.

Purchases and credits

Plans and credit packs are sold through the App Store. Apple processes payment; we receive transaction details to add credits to your account and keep a record of credit use.

Reports and support

If you send a report from the app, we store its text and any screenshots you attach, privately, to investigate it.

What we don't do

Where data is processed

Our database and file storage run on Supabase in the United States (US West). Paper processing runs on Google Cloud in the United States (US West). This website is served by Cloudflare. The providers named above process data as described in each section.

Deleting your account

You can delete your account in the app (Settings → Account). We then delete your library, encrypted history, private papers, reports and sign-in details. Records needed for accounting, such as credit and usage totals, are kept without your account identity. Shared paper conversions that other readers use remain. Deleted data leaves our backups as they expire.

Contact

Questions about privacy: [email protected].