Skip to content
RefBytes A–Z Databases Start a trial
Menu
08

What RefBytes A-Z stores and what it never does.

Privacy

This describes what RefBytes A-Z stores. Each library's public page has its own patron-facing privacy statement at /privacy.

Patrons

No accounts, names, or card numbers. We count clicks and detail views per database, and searches that returned nothing. A scrambled session value prevents double-counting a repeated search and is deleted after 7 days. IP addresses are not stored. There are no advertising or third-party tracking scripts. If a patron reports a problem, their message and optional email go to library staff and nowhere else.

On plans with smart search, the words a patron types in the search box are sent to OpenAI, with nothing that identifies them, to work out their meaning. Under OpenAI's API terms they are not used for training. Searches that look like an email address or a card or phone number are never sent, and a library can switch smart search off under Settings → Public page; its public privacy page says so while it is on.

Library staff

Staff accounts hold a name, email, and hashed password, with optional two-factor authentication and passkeys. Every change made in the admin is written to an activity log with the staff member's name.

RefBytes sometimes emails staff tips and product news. We keep a copy of each one sent and note when it is opened and when a link in it is clicked. Every one has an unsubscribe link, and you can turn them off or back on under Settings → Profile. Account email such as password resets, renewal reminders, and proxy alerts is not affected.

Your data is yours

Everything can be exported at any time as CSV, including internal notes, vendors, and paperwork metadata. If a library leaves, they take everything.