Demonstration only. Corollary is a non-commercial research demo — no warranty, no support, not for commercial use or clinical decisions. Read the disclaimer

Legal

Privacy Policy

Last updated 7 September 2026

This notice explains what Kernel Science SRL does with personal data when you use Corollary, a non-commercial research demonstration. It is written to meet Articles 13 and 14 of the GDPR.

1. Who is responsible

The controller for the processing described here is Kernel Science SRL, whose details appear at the foot of this page. We have not appointed a Data Protection Officer; we are not required to, because we do not carry out large-scale monitoring or process special-category data as a core activity.

For any privacy matter, including a request to exercise your rights, write to privacy@corollary-labs.com.

2. What we collect, why, and on what basis

Account data — your email address, and the display name and avatar your identity provider returns if you sign in through Google. Collected to create and secure your account. Legal basis: performance of a contract (art. 6(1)(b)) — we cannot give you an account without it.

Run and job metadata — which model you ran, when, how long it took, what it cost in credits, whether it succeeded, and the inputs you supplied. Collected so a run is reproducible, so the credit ledger is auditable, and so a failure can be diagnosed. Legal basis: performance of a contract (art. 6(1)(b)) for the service itself, and legitimate interests (art. 6(1)(f)) in operating and securing the platform.

Agent conversations and artifacts — the questions you ask the research agent, the tool results behind its answers, and files it produces (structures, figures, generated data). Stored so a thread can be resumed and a later turn can reason about earlier ones. Legal basis: performance of a contract (art. 6(1)(b)).

Abuse-prevention data — a salted, irreversible hash of the network origin an anonymous allowance was claimed from. We do not store the address itself. Legal basis: legitimate interests (art. 6(1)(f)) in preventing a free demonstration from being exhausted by automated abuse.

Analytics and session replay — only if you accept the analytics banner. See section 4.

Support correspondence — what you write to us, kept so we can answer and refer back. Legal basis: legitimate interests (art. 6(1)(f)).

Do not submit personal data, patient data, human subject data, identifiable genomic data or anything held under a confidentiality obligation. Corollary is a demonstration and is not built, assessed or contracted to process special-category data under Article 9, and you should assume it is not a suitable place for it.

3. What stays on your device

Structure coordinates and other large outputs from a model run are kept in your browser's local storage, not on our servers. A predicted PDB file can be several megabytes and is always re-derivable from its source, so there is no reason for us to hold it.

The exception is the research agent: when it folds a protein, draws a molecule or produces a figure, that file is stored on our servers so the conversation can still show it when you return.

Signed out, the platform works in full and your job history stays local to your device.

4. Cookies, analytics and session replay

Strictly necessary storage — the sign-in session and the security tokens that protect form submissions — is set without consent because the service cannot function without it and the law exempts it.

Everything else is opt-in. We use PostHog to understand how the demonstration is used and to find what is broken. It sets cookies, records page views and clicks, and captures session replays — a reconstruction of what happened on screen — together with browser console output and network timings, so a failed run can be diagnosed from what actually occurred rather than from a guess.

None of it starts until you accept the banner. If you reject it, or if your browser sends Global Privacy Control or Do Not Track, nothing is initialised: no cookie is written and no replay is begun. You can change your mind at any time from the Cookie Policy, and withdrawing is as easy as giving consent.

Every form field and input is masked before it leaves your browser: replays show that you typed, never what you typed. Sequences, structures, questions to the agent and API keys are not captured.

Legal basis: your consent (art. 6(1)(a)), and consent under the ePrivacy rules for the storage itself. PostHog acts as our processor.

5. Who we share it with

We do not sell personal data, and we do not share it for advertising. We use the following processors and sub-processors, each under a data processing agreement:

  • Vercel — application hosting, edge delivery and logs (United States, EU regions available).
  • Supabase — the database, authentication and file storage holding accounts, jobs, threads and the credit ledger.
  • Modal — the sandboxed compute that executes model runs and code, receiving the inputs of a run.
  • PostHog — product analytics and session replay, only where you have consented.
  • OpenAI and the Vercel AI Gateway (fronting Google and other model providers) — the language models behind the research agent, receiving your prompts and tool results.
  • NVIDIA (BioNeMo / NIM) and Hugging Face — managed model inference, receiving the inputs of the runs routed to them.
  • Resend — transactional email, receiving your address to send notifications.
  • Stripe — payment and subscription infrastructure. Retained in the codebase but not active: no payment is taken during the demonstration.

When you run a model on a third-party provider, your input is transmitted to that provider to execute the job and their terms apply to that transmission. When the agent queries a public scientific database — UniProt, the RCSB PDB, AlphaFold DB, ChEMBL, PubChem, Europe PMC and others — the request is made server-side from Corollary: those services receive the query text but not your identity.

We will disclose data where we are legally required to, and to establish or defend legal claims.

6. International transfers

Several of the processors above are established in the United States or process data there. Where personal data leaves the EEA, the transfer relies on the European Commission's Standard Contractual Clauses, on an adequacy decision where one covers the recipient, or on the EU–US Data Privacy Framework where the recipient is certified under it.

You can ask us for the details of the safeguards applying to a particular transfer at privacy@corollary-labs.com.

7. How long we keep it

  • Account data — for as long as the account exists, and deleted when you ask us to delete it.
  • Jobs, runs and ledger entries — for as long as the account exists, or until you delete the job. Ledger entries needed to show a balance was correctly calculated are kept for the life of the account.
  • Agent threads — until you delete the thread or the account.
  • Agent artifacts — deleted on a schedule after they are produced; they are always re-derivable from the run that made them.
  • Analytics and replays — retained by PostHog under its own retention schedule, which for replays is a matter of months rather than years.
  • Support email — up to two years from the last message.
  • Abuse-prevention hashes — for the period they bound, plus a short margin.

Because this is a demonstration, we may delete accounts and all stored data when it ends. Export anything you need to keep.

8. Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you, and receive a copy.
  • Have inaccurate data corrected.
  • Have your data erased.
  • Restrict or object to processing based on our legitimate interests, including on grounds relating to your particular situation.
  • Receive the data you gave us in a portable, machine-readable format.
  • Withdraw consent at any time, without affecting processing carried out before you withdrew it.
  • Not be subject to a decision based solely on automated processing producing legal or similarly significant effects — we make no such decisions.

To exercise any of these, write to privacy@corollary-labs.com. We will respond within one month, and will tell you if we need longer. We do not charge for this.

Account deletion is not yet self-service. Ask us and we will delete the account, which removes every row belonging to it — jobs, usage, threads, artifacts — by cascade, and we will confirm when it is done.

If you believe we have handled your data unlawfully you can complain to a supervisory authority, in particular Garante per la protezione dei dati personali, or to the authority in the EU country where you live or work.

9. Security

Data is encrypted in transit and at rest. Database access is constrained by row-level security so one account cannot read another's rows. Credentials for external providers are read server-side only and never reach the browser.

No system is perfectly secure, and this one is a demonstration rather than a hardened production service. Treat it accordingly, and do not store anything in it that you could not afford to lose or to have exposed.

Report a vulnerability to security@corollary-labs.com. We will not pursue legal action against good-faith security research that respects user privacy and does not degrade the service.

10. Children

Corollary is not directed at children and is not for anyone under 16, or under the age of digital consent in their country if that is higher. We do not knowingly collect data from children; tell us if you believe we have and we will delete it.

11. Changes

We will post changes to this notice here with an updated date. Where a change materially affects how we use data you have already given us, we will tell you before it takes effect and, where the change relies on consent, ask again.

Operator and contact

Kernel Science SRL

Via dei Salici 9/09

34151, Trieste (TS)

Italy

Company register: R.E.A.: TS-213649

VAT: P.IVA / C.F.: 01411320326