Privacy
Last updated 9 October 2026
WHAT AN ACCOUNT KEEPS
Your username, and a way to sign in: a salted hash of your password (never the password itself), a passkey, or a sign-in from Google or Apple when those are switched on. A passkey stores a public key, not a fingerprint or a face. Linking Google or Apple stores that provider's id, and the email they send with it, beside the link.
An email address is optional. You can add a recovery address so a password reset can be mailed after you open the confirmation link. If you turn on the paper digest, the address you type for it is kept so the digest can be sent there, and only after you confirm it.
Your reading: the papers and books you add, the text of PDFs you drop in, how far you are through them, highlights, notes, projects, and bookmarked briefs. Your streak, the interests you chose, and the searches you make, which tune the explore feed. Papers other readers send you, the shared projects you are in and what is said in them, and the share links you make. The recall questions written about papers you finish, and whether you remembered them.
The waitlist keeps the email you join with, your place in line, and how many people arrived through your link. The link itself carries a short code, not your email.
If you share an invite link, zimmr keeps the referral code, which accounts signed up through it, and which of those have read a card.
All of it exists to run zimmr for you. None of it is sold, shown to advertisers, or used to follow you across other sites.
COOKIES
A cookie keeps you signed in. Someone without an account gets a guest session in that same cookie. Another cookie remembers that this device has signed in before, so the sign-in page opens on sign in. A referral link sets a cookie with the code, and that cookie is cleared when a new account is created. A passkey, or a Google or Apple sign-in, uses a short-lived cookie for that one attempt.
These cookies are essential: the site does not work properly without them. zimmr does not set advertising or analytics cookies. Page views, sign-ups, and the referral steps are counted in our own database, with no cookie and no analytics company.
WHERE IT IS KEPT
The library is stored in Upstash Redis. The site is served from a server zimmr runs.
WHO ELSE SEES IT
To write a brief, answer a question, or define a word, the paper's text or the word is sent to the language model that does it (z.ai). Ranking by meaning uses an embeddings service (Mistral, or another OpenAI-compatible embeddings host when that is how this copy of zimmr is configured). A scanned PDF's pages are sent as images to Mistral to be read. Reading a paper aloud can use a voice from Mistral or OpenAI when one is configured, and otherwise the phone's own voice, which stays on the device. Private mode writes briefs on the device instead. Searches go to PubMed, Europe PMC, OpenAlex, CORE, Crossref, and arXiv, definitions to Wiktionary and MeSH, and explore pictures come from Wikipedia. None of them is sent your username.
Other readers see what you choose to show them: your name, what you study, and what you are curious about on your profile; the papers you send them; and, in a shared project, the papers you add and what you say. A share link shows anyone who has it the paper's title and the opening of its brief, never its text or your notes. A shared week shows its numbers, its topics, and up to three titles. A shared project's invite link shows its name, who is in it, and its papers' titles.
For working out costs, the number of model calls each account makes is counted for 90 days. To see what brings readers back, zimmr notes which days you used it and which parts of it you have tried, and counts how often each kind of notification is opened. Those counts stay in the same database. They are not sent to an analytics company, and they are not used to follow you onto other sites.
PRIVATE MODE
With private mode on (Settings, then Private mode), PDFs you add stay in that browser only, with their progress and highlights. The server never has them. Briefs, answers, and definitions are written by a model on the device. Only a word you look up goes to the public dictionaries, without the sentence around it. Searching still asks the catalogues, and scanned PDFs cannot be added.
ON YOUR PHONE
In the phone app, the theme, the reading reminder, and which cards counted toward today's streak stay on the device. Those reminders are scheduled on the phone. If you turn on notifications in the browser, the subscription is kept with your account so a note can be sent. The app does not use the microphone, the camera, or the photo library.
DELETING IT
Settings, then Delete account, which is also described at /delete, asks for your password (or your username, if the account has none) and then signs you out. The account is closed: you cannot sign in, and your name is hidden from other readers. The account and what it kept are held for 30 days so it can be restored if you write to hello@zimmr.ai, and removed after that.
CONTACT
Privacy questions go to hello@zimmr.ai. The terms are on the terms page.