Skip to the content
Browse the library

Privacy

Describes the software as deployed on 21 September 2026.

Who holds the data

The service is operated by ReactionLens. Questions about personal data go to privacy@reactionlens.com.

Accounts during the beta

Sign-up and sign-in are closed while ReactionLens is in beta. Until they open, the parts of this page about accounts, workspaces and invitations describe how the service will handle them. For a visitor today, what applies is what your browser stores, the visit data sent to Google Analytics, and the structures you look up or enter.

What an account stores

  • Your email address, your name, and your password as an Argon2 hash — the password itself is never stored.
  • Your experience mode and what you said you came here to do, if you answered.
  • One record per sign-in: when it happened, the IP address the request came from, and the user-agent string your browser sent. You can see and end every one of these under Settings.
  • An audit trail of security-relevant actions: registering, signing in, inviting people, and refusals by the safety policy.

What your work stores

  • Projects, and the molecules, reactions and saved routes you put in them.
  • Structures you submit to the engines: prediction requests, design seeds, and calculation inputs, together with their results. Calculation geometries and logs are kept as files in this deployment’s own file storage.
  • One usage record per engine call — which workspace, which kind of call, when — used to count the workspace against its allowance.
  • For each invitation you send: the invited person’s email address, the role offered, and when the invitation expires.

Your projects and what is in them, your calculations, your invitations and your workspace’s usage are visible to that workspace’s members and to nobody else.

Two things are shared more widely, and are worth knowing before you enter anything confidential.

Molecules and reactions go into a shared record. A structure you draw, search for or add to a project, and a reaction you enter, are stored once, in the record every user of the service searches. Other users can find them, a molecule can be listed among similar structures on other pages, and a molecule with a name has its own page on this public website. The shared record holds the chemistry itself — never who entered it or which project it belongs to.

Predictions are not tied to an account. A prediction is stored with its inputs and results under a long random identifier, and is not attached to your account or your workspace. Anyone who has its link can open it.

Do not enter a structure or a reaction you need to keep confidential.

What the browser stores

Your theme, mode, panel sizes, recently viewed items, the workspace you last chose and your answer about analytics cookies are kept in this browser’s local storage, not on the server. The session cookie is HTTP-only and same-site.

This site uses Google Analytics to count visits and see which pages and tools people use. If your browser is set to a time zone in the UK or Europe, you are asked when you first visit, and until you allow it nothing is loaded: no analytics cookie is set and nothing is sent to Google. Elsewhere it runs unless you turn it off. The time zone is read in your browser and is not sent anywhere. When it runs, Google Analytics sets its cookies and receives the page you are on, your approximate location derived from your IP address, and details of your browser and device. It is never used for advertising.

What is sent is deliberately narrowed. Invitation links carry a secret token in the address, and that token is replaced before anything leaves the page. Identifiers for projects, reactions and molecules are collapsed to a placeholder, and the part of the address after a question mark — where a structure you are working on can appear — is never sent at all.

You can change your answer at any time with , here or at the foot of the library pages; withdrawing it removes the analytics cookies. Your answer is kept for a year, and then you are asked again. The site works the same whichever you choose.

Where data goes

Outside services receive data in two cases.

  • Public chemistry databases are asked for a molecule’s name, identifiers and published properties. What you type into molecule search, and the structures you enter — as a name, formula, SMILES, InChI or InChIKey — are sent to them. The request comes from this service’s server rather than your browser, and nothing identifying you goes with it.
  • Google Analytics, run by Google LLC in the United States, receives the visit data described above.

Invitation emails are sent through a mail server the operator configures. None is configured on this deployment, so an invitation link is shown to the person who created it, to pass on themselves.

Everything else — accounts, projects, results and files — is kept in this deployment’s own database and file storage, on a server run by ReactionLens. There is no outside database, email service, error tracker or advertising network.

How long it is kept

Your account, projects and results are kept until you delete them. Deleting your account under Settings removes the account, its sign-in records, your personal workspace and everything in it, and the records of your calculations. An account that owns a workspace other people are in cannot be deleted until that workspace has a new owner. Sessions expire on their own.

Some things outlast the account:

  • the security audit trail, which records actions such as signing in or inviting someone rather than the content of your work. Its entries are kept after the account is deleted, no longer attached to it, and an invitation’s entry keeps the invited email address;
  • calculation files in file storage, which are not yet removed with the account — ask for them to be deleted, as described below;
  • predictions, which were never attached to the account;
  • molecules and reactions in the shared record.

This deployment keeps no backups, so nothing that is deleted survives in one.

Google Analytics keeps its data for the retention period set in the operator’s Google Analytics account.

Your rights

You can ask for a copy of the personal data held about you, and have it corrected or deleted. Some of this you can do yourself under Settings: changing your password, seeing and ending your sign-ins, and deleting your account.

For anything else — a copy of your data, or deleting what outlasts an account — write to privacy@reactionlens.com. Requests are answered within one month. If you are not satisfied with the answer, you can complain to the data-protection authority where you live.