Skip to content
Rounds
Privacy Terms Support

Privacy, in plain language

Your reading life is yours.

Rounds collects the minimum information needed to run accounts, resolve papers, and deliver your digest. Saved papers, notes, profile photos, library cookies, and reading habits stay on your device.

Effective July 10, 2026
On this page
Scope What we collect What stays on device How we use data Service providers Retention and deletion Your choices Security Contact

1. Scope

This Privacy Policy explains how Rounds ("Rounds," "we," "us," or "our") handles personal information through the Rounds iOS app, Share Extension, website, and related services.

Rounds is an educational literature-discovery service for orthopaedic surgeons, residents, and researchers. It is not a patient record system and is not intended to receive identifiable patient information.

The essential boundary

Rounds stores account data on its servers. Your saved-library list, personal notes, selected profile photo, institutional browser session, and reading-habit metrics stay on your device.

2. Information we collect

Account

Identity and profile

Name, email, sign-in provider identifier, profession, selected institution, email-verification status, account role, and subscription tier.

Reports

Paper reports and feedback

When you flag a paper, we store the article's DOI and title, the reason you chose from a fixed list, and a diagnostic reference. There is no free-text field. We also keep the limited feedback you choose to submit.

Security

Authentication

Hashed passwords for email accounts, hashed session tokens, and hashed short-lived verification or recovery codes. We do not store plaintext passwords or codes.

Operations

Limited service events

Search input type and outcome, error status, and moderation events. We do not store the DOI, article title, URL, or query text in analytics events.

Technical request information

Our hosting and security systems may process IP address, request time, route, device or browser information, and security signals to deliver the service, diagnose failures, and enforce rate limits. In-process rate-limit counters are temporary.

Information you send to support

If you contact us, we receive the email address and information you include. Do not send passwords, verification codes, institutional credentials, or patient-identifying information.

3. Information that stays on your device

The following information is stored locally by the app and is not uploaded to the Rounds social server:

  • saved-paper references and security-scoped pointers to PDFs you selected in Files;
  • personal notes and formatting;
  • your selected profile photo;
  • subspecialty, pathology, joint, level, cadence, and reading-goal preferences;
  • reading streak and completed-reading counts;
  • institutional sign-in cookies held in the shared WebKit browser store; and
  • temporary open-access PDF cache files and resolver results.
PDF ownership

Rounds does not store paywalled article PDFs. When you save a PDF, the Files picker places it in storage you control. Deleting a Rounds account or saved-library row does not delete your file from Files.

4. How we use information

  • create and secure your account;
  • link sign-in methods only when control of a verified email is established;
  • personalize the literature digest using preferences sent with a request;
  • resolve articles through open-access, publisher, or institutional-access services;
  • review the papers you report so links and content can be corrected;
  • prevent spam, credential leakage, patient-identifier disclosure, and abuse;
  • respond to support, privacy, and security requests; and
  • measure aggregate service reliability without recording article query text.

We do not sell personal information. We do not use article searches to build advertising profiles. Rounds does not provide medical advice.

5. Service providers and external services

We disclose information only as needed to operate the service, comply with law, protect people and systems, or complete a transaction you request.

  • Hosting and databases: Render hosts the API and Neon hosts separate social and editorial-content databases.
  • Email: Resend delivers verification, recovery, and service emails.
  • Authentication: Apple and Google verify identity when you choose those sign-in methods.
  • Article services: Third Iron/LibKey, Crossref, NCBI, Elsevier, DOI infrastructure, publishers, and your selected institution may receive an article identifier or link needed to resolve content.
  • Website delivery: Vercel serves the website, and Google Fonts may receive ordinary web-request information when fonts load.

Some providers may process information outside Canada, including in the United States, where it may be subject to local law.

We may disclose information if reasonably necessary to comply with law, respond to valid legal process, investigate abuse, protect rights or safety, or complete a corporate transaction subject to appropriate safeguards.

6. Retention and account deletion

We retain account information while your account is active and as needed to provide and secure the service. Sessions expire, verification and recovery codes are short-lived and single-use, and operational information is retained only as long as reasonably needed for its purpose or a legal obligation.

You can permanently delete your account inside the app under Profile → Delete account. Reauthentication is required. Deletion removes your profile, linked identities, password hash, sessions, verification records, paper reports, feedback, and account-linked analytics. Saved references, notes, and preferences are held on your device and are removed with them; PDFs you downloaded into your own Files storage are yours and are never touched.

The app also removes account-scoped saved references, notes, preferences, avatar, reminders, caches, library selection, and institutional website data from the device. PDFs you saved in Files remain under your control.

If Sign in with Apple cannot be revoked automatically, the app provides the manual Apple Settings path after deletion.

7. Your choices and privacy rights

Depending on where you live, you may have rights to access, correct, delete, or obtain information about our use of your personal information, and to withdraw consent subject to legal or contractual limits.

  • Edit your profile and digest preferences in the app.
  • Permanently delete your account in the app.
  • Report a paper from the reader when it is wrong, will not open, or is too slow.
  • Control notification permission in iOS Settings.
  • Contact us to request access, correction, or help with deletion.

We may need to verify your identity before completing a privacy request. We will not discriminate against you for exercising a privacy right.

8. Security, children, and changes

Security

We use safeguards appropriate to the information we handle, including encrypted network transport, hashed passwords and tokens, server-side provider verification, access controls, separate content and social databases, bounded inputs, and abuse controls. No system can guarantee absolute security.

Children

Rounds is intended for adults engaged in orthopaedic practice, training, or research. It is not directed to children under 18.

Changes

We may update this policy as the service changes. We will update the effective date and provide additional notice when a change materially affects your rights or how we use personal information.

Questions about privacy?

Contact Rounds with “Privacy” in the subject line. Please do not include passwords, verification codes, institutional credentials, or patient-identifying information.

Email privacy support Visit Support
Rounds
PrivacyTermsSupport

Rounds is an educational literature-discovery service. It does not provide medical advice and should not be used as the sole basis for a clinical decision.