Skip to the content
Browse the library

Privacy

Describes the software as deployed on 21 September 2026.

Who holds the data

The service is operated by ReactionLens. Questions about personal data go to privacy@reactionlens.com.

Accounts during the beta

Sign-up and sign-in are closed while ReactionLens is in beta. Until they open, the parts of this page about accounts, workspaces and invitations describe how the service will handle them. For a visitor today, what applies is what your browser stores, the visit data sent to Google Analytics, and the structures you look up or enter.

What an account stores

  • Your email address, your name, and your password as an Argon2 hash — the password itself is never stored.
  • Your experience mode and what you said you came here to do, if you answered.
  • One record per sign-in: when it happened, the IP address the request came from, and the user-agent string your browser sent. You can see and end every one of these under Settings.
  • An audit trail of security-relevant actions: registering, signing in, inviting people, and refusals by the safety policy.

What your work stores

  • Projects, and the molecules, reactions and saved routes you put in them.
  • Structures you submit to the engines: prediction requests, design seeds, and calculation inputs, together with their results. Calculation geometries and logs are kept as files in this deployment’s own file storage.
  • One usage record per engine call — which workspace, which kind of call, when — used to count the workspace against its allowance.
  • For each invitation you send: the invited person’s email address, the role offered, and when the invitation expires.

Your projects and what is in them, your calculations, your invitations and your workspace’s usage are visible to that workspace’s members and to nobody else.

Two things are shared more widely, and are worth knowing before you enter anything confidential.

Molecules and reactions go into a shared record. A structure you draw, search for or add to a project, and a reaction you enter, are stored once, in the record every user of the service searches. Other users can find them, a molecule can be listed among similar structures on other pages, and a molecule with a name has its own page on this public website. The shared record holds the chemistry itself — never who entered it or which project it belongs to.

Predictions are not tied to an account. A prediction is stored with its inputs and results under a long random identifier, and is not attached to your account or your workspace. Anyone who has its link can open it.

Do not enter a structure or a reaction you need to keep confidential.

What the browser stores

Your theme, mode, panel sizes, recently viewed items and the workspace you last chose are kept in this browser’s local storage, not on the server. The session cookie is HTTP-only and same-site.

This site uses Google Analytics to count visits and see which pages and tools people use. It sets analytics cookies and sends Google the page you are on, your approximate location derived from your IP address, and details of your browser and device. It sets no advertising cookies.

What is sent is deliberately narrowed. Invitation links carry a secret token in the address, and that token is replaced before anything leaves the page. Identifiers for projects, reactions and molecules are collapsed to a placeholder, and the part of the address after a question mark — where a structure you are working on can appear — is never sent at all.

You can block Google Analytics with a browser extension or Google’s own opt-out add-on, and the site works the same without it.

Where data goes

Outside services receive data in two cases.

  • Public chemistry databases are asked for a molecule’s name, identifiers and published properties. What you type into molecule search, and the structures you enter — as a name, formula, SMILES, InChI or InChIKey — are sent to them. The request comes from this service’s server rather than your browser, and nothing identifying you goes with it.
  • Google Analytics, run by Google LLC in the United States, receives the visit data described above.

Invitation emails are sent through a mail server the operator configures. None is configured on this deployment, so an invitation link is shown to the person who created it, to pass on themselves.

Everything else — accounts, projects, results and files — is kept in this deployment’s own database and file storage, on a server run by ReactionLens. There is no outside database, email service, error tracker or advertising network.

How long it is kept

Your account, projects and results are kept until you delete them. Deleting your account under Settings removes the account, its sign-in records, your personal workspace and everything in it, and the records of your calculations. An account that owns a workspace other people are in cannot be deleted until that workspace has a new owner. Sessions expire on their own.

Some things outlast the account:

  • the security audit trail, which records actions such as signing in or inviting someone rather than the content of your work. Its entries are kept after the account is deleted, no longer attached to it, and an invitation’s entry keeps the invited email address;
  • calculation files in file storage, which are not yet removed with the account — ask for them to be deleted, as described below;
  • predictions, which were never attached to the account;
  • molecules and reactions in the shared record.

This deployment keeps no backups, so nothing that is deleted survives in one.

Google Analytics keeps its data for the retention period set in the operator’s Google Analytics account.

Your rights

You can ask for a copy of the personal data held about you, and have it corrected or deleted. Some of this you can do yourself under Settings: changing your password, seeing and ending your sign-ins, and deleting your account.

For anything else — a copy of your data, or deleting what outlasts an account — write to privacy@reactionlens.com. Requests are answered within one month. If you are not satisfied with the answer, you can complain to the data-protection authority where you live.