← Blog

Guide18 min read

How to protect a research idea from being scooped

Afraid of being scooped? You can't own an idea, but you can show what you had and when. Preprints, preregistration, notebooks and timestamps compared.

You cannot own a research idea, but you can keep dated evidence of what you had and when, and decide how much of it to make public. In practice that means keeping dated versions, sharing early with people you trust, preregistering when the design is set and posting a preprint when the manuscript is ready. If the work might be patentable, speak to your technology-transfer office before anything goes public.

This guide compares the usual options by what each one actually shows, what it makes public and who can check it. Every policy quoted below was checked on 9 October 2026, on the provider's own pages or, where a page blocked automated access, on its Internet Archive copy, noted in the sources.

Can someone steal my research idea?

In law, an idea on its own is hard to protect. The US Copyright Office puts it plainly: "Copyright does not protect ideas, concepts, systems, or methods of doing something." Copyright covers your text and figures, not the thought behind them. Patents cover inventions, under strict conditions that we come to below.

Research ethics goes further than the law. The European Code of Conduct for Research Integrity (ALLEA, revised 2023) defines plagiarism as "using other people's work or ideas without giving proper credit to the original source". The US Office of Research Integrity also names ideas in its definition. Under these codes, taking an idea without credit is misconduct even where it is not a legal wrong.

What those codes cannot do is settle, after the fact, who had the idea first. That comes down to evidence. Often the real risk is not theft at all but parallel work: two groups reach the same question at the same time. Journals know this, and some have written policies for it. Either way, the useful question is the same: what record would let you show, calmly and specifically, what you had and when?

What does it mean to be scooped?

You are scooped when another group publishes the same or a very similar result before you do. The editors of PLOS Biology define it, loosely, as "when two independent groups studying the same system produce the same or similar results, and one group publishes their work first" (PLOS Biology, 2018). Despite the word, it describes parallel work, not theft. The cost is that the second paper can look less new: many journals, the editors note, "will reject it citing lack of novelty".

The penalty is real, but may be smaller than feared. Ryan Hill and Carolyn Stein used Protein Data Bank records to study priority races in structural biology. They found that "scooped teams are less likely to publish in top journals and receive 21 percent fewer citations" (Journal of Political Economy, 2025). A survey in the same study found that structural biologists overestimated both their chance of being scooped and what it would cost them (UC Berkeley Haas). "It's meaningful, but it's not devastating," Stein told Berkeley Haas. Some journals now consider scooped work on its merits, as the section on preprints below shows.

What actually establishes priority in science?

No registry awards scientific priority. Ronald Vale and Anthony Hyman, writing in eLife in 2016, describe it as "guided by the culture and practices within a scientific community". It can take years to settle and is "often most visible in the form of citations". They list four things a disclosure needs: the data with an interpretation, full methods, a widely recognised and stable venue, and "a time stamp to indicate when the work was disclosed".

Patents work differently, and mostly by filing date. Under the European Patent Convention, when two people make the same invention independently, the right goes to whoever filed the earliest application (Article 60(2)). The US has used a first-inventor-to-file system for applications filed since 16 March 2013. A dated notebook will not win a patent race on its own.

That leaves a dated record with a modest but real job. It is evidence that a specific version existed by a certain date, and of who signed or sent it. It is not a ruling on who deserves the credit, and none of the options below proves ownership or legal priority.

Preprint, preregistration, notebook or timestamp: what each one shows

Policies as stated on each provider's own pages, checked 9 October 2026.

OptionWhat it showsWhat it makes publicWho can check itLimits
Preprint (arXiv, bioRxiv)A manuscript existed by its posting date, under the listed authors; each version is keptThe whole manuscript, permanentlyAnyoneNeeds a substantive manuscript; screened, not peer reviewed; cannot be removed once posted; counts as public disclosure for patents
Public preregistration (OSF, AsPredicted)Your hypotheses, design and analysis plan existed by the submission dateThe planAnyoneRecords a plan, not results; cannot be edited afterwards, only updated or withdrawn
Embargoed or private preregistrationThe same, once revealed; OSF keeps the original submission dateNothing until the embargo ends (OSF, up to four years) or an author makes it public (AsPredicted)You and the people you add; everyone once it is publicYou rely on the registry's own records for the date; an OSF embargo has an end date you set
Data or code archive with a DOI (Zenodo)A deposit existed by its publication date; every version gets its own DOITitle, authors and description always; files can be public, embargoed or restrictedAnyone for the description; files as you allowThe description is public even when files are not; withdrawal is exceptional and leaves a tombstone page
Dated lab notebook (paper or electronic)What you did and thought, entry by entry, in orderNothingYou, your group, your institution, and anyone you show it toDates you control are easy to question; weight comes from bound pages, witnesses or an electronic notebook that timestamps entries; the records may belong to your institution
Email to a supervisor or colleagueA named person received a specific version on a dateNothing beyond the recipientsYou and the recipients; their copy sits outside your controlDepends on mail records and the recipient's goodwill; for patentable work, sharing may need a confidentiality agreement
Independent timestamp of a private file (OpenTimestamps)A file with exactly these bytes existed by the time of a Bitcoin blockOnly a fingerprint (hash), sent to the timestamp servers; not the fileAnyone you give the file and the .ots proof; the reference client checks against your own Bitcoin nodeSays nothing about who wrote it or whether it is right; keep the exact file, as one changed byte breaks the match; confirmation takes a few hours
Papex recordWho signed which exact version, and that it existed by a timestamped dateOnly a salted fingerprint, until you choose to share the version with people you invite or publish itYou and the people you invite; the .ots proof checks with any OpenTimestamps tool, without PapexNot proof of ownership, priority, originality, validity or a person's identity; shows only what you put in it

Three details in that table matter more than they look.

Public is permanent. arXiv says that "articles that have been announced and made public cannot be completely removed", and it keeps every earlier version public. bioRxiv's policy is that "papers cannot be removed"; a withdrawal adds a notice and the original stays in the article history. OSF registrations can never be edited or deleted, only withdrawn, and a withdrawn one still shows its title, contributors and creation date.

An archive's description is public. Zenodo's help pages say "the metadata is always publicly accessible", even when the files are restricted or under embargo. If the title and abstract give the idea away, restricting the files will not keep it private.

Dates you control carry little weight on their own. A file's "modified" date comes from your own computer, and git lets anyone "override the author date used in the commit". That does not make your notes worthless. It means their weight comes from something outside your control: a witness, a recipient's inbox, an institutional notebook or an independent timestamp.

Is a preprint enough to protect my idea?

A preprint is the clearest public, dated disclosure most researchers have. arXiv dates each submission from the moment the final "Submit Article" step is completed (submission guide) and keeps all earlier versions available. bioRxiv posts revisions under the same DOI, with the original version still accessible. Both screen what they post; neither is peer review.

But a preprint is for a paper, not a bare idea. arXiv's moderators may decline "submissions that do not contain original or substantive research, including course projects, research proposals". If what you have is a question and a plan, a preprint is not yet the right tool; a preregistration or a private dated record is.

Some journals have written down how they treat parallel work, and some tie it to preprints. PLOS protects a study from being considered scooped by closely related work published, or preprints posted, after you submit. It applies this "retroactively for up to six months prior to the date of submission", or longer at the journal's discretion if you posted a preprint of the same version in that time. EMBO Press says your work "is considered irrespective of other papers published after preprint posting or submission". Check your target journal's own policy before you rely on it.

Should I preregister to establish priority?

A preregistration records a plan: hypotheses, design and analysis, fixed before the data come in. That makes it a dated record of the idea in its most concrete early form. On OSF, the registration's creation date is the date you submit it, whenever the other admins approve it, and the registration cannot be edited afterwards.

You do not have to show your hand to do it. OSF lets you embargo a registration for up to four years; until then, outside viewers see a "page not found" notice, and you can end the embargo early. AsPredicted keeps a preregistration private "until an author makes it public", and its PDFs are time-stamped with a unique URL for verification.

The limit is the flip side of the strength. A preregistration records what you planned, not what you found, and while it is private the date rests on the registry's own records.

Will a preprint or a talk affect a patent?

It can, and the rules differ by country. Under the European Patent Convention, the state of the art is "everything made available to the public by means of a written or oral description, by use, or in any other way" before the filing date (Article 54). The exceptions are narrow: within six months before filing, a disclosure that was "an evident abuse" against the applicant, or a display at certain officially recognised international exhibitions (Article 55). The UK IPO's guidance is short: "You may not be able to patent your invention if it becomes public knowledge."

The US is more forgiving of an inventor's own disclosures. A disclosure made one year or less before the effective filing date, by the inventor, is not prior art under 35 U.S.C. 102(b)(1)(A) (MPEP 2152). That year does not carry over to a European application.

Under that wording, a preprint, poster, conference abstract or talk can each be a disclosure. If there is any chance the work is patentable, talk to your institution's technology-transfer office or a patent attorney before any of them. The UK IPO also notes that if you discuss an invention with anyone apart from a patent attorney, you may need a non-disclosure agreement. This is general information, not legal advice.

Patentable work also needs stricter notes. The NIH's guidelines for its intramural researchers (ninth edition, 2025) ask that each entry be signed and dated and periodically witnessed by someone familiar with the work who is not a co-inventor. Electronic notebooks used for this purpose should have "the ability to timestamp entries and record signatures".

Can ChatGPT, Claude or Gemini steal my research idea?

A chatbot does not claim your idea as its own. The question is what happens to what you type. Depending on the product, plan and settings, it may be stored, read by people working for the provider, or used to train future models. The providers' own pages (OpenAI, Anthropic, Google) said this on 9 October 2026:

ProductPersonal accountsWork, education and API
ChatGPTMay be used for training unless you turn off Improve the model for everyone (Settings > Data controls). OpenAI says it reviews conversations. Deleted chats are erased within 30 days, with exceptions.Not used for training by default. API data may be kept up to 30 days for abuse monitoring.
ClaudeYou choose, under Settings > Privacy. If you allow training, de-identified data may be kept up to five years. Staff see chats only for feedback you send or a policy review.Not used for training by default. API data deleted within 30 days, with exceptions.
GeminiKeep activity is on by default for adults: chats may be used to train AI models and are auto-deleted after 18 months unless you change it. Some are read by human reviewers and kept up to three years. With it off, chats are kept 72 hours.Workspace and Education: not reviewed or used for training outside your domain without permission. Free API: may be reviewed and used to improve products, except in the UK, EEA and Switzerland.

Rating a reply with thumbs up or down can send the whole conversation for training, even when training is otherwise off (OpenAI, Anthropic). Opting out does not reach back: Anthropic says your data "will still be included in model training that has already started and in models that have already been trained". Temporary or incognito chats are not used for training, but are still kept: up to 30 days on ChatGPT, 30 days on Claude, 72 hours on Gemini.

Settings change, so check your own account and, for a work account, your institution's agreement. In practice:

  • Use an institutional or business plan with training off for unpublished work, if you have one.
  • Do not paste what you are not allowed to share, such as patient data or a manuscript sent to you for review. If the work could be patentable, ask your technology-transfer office first. Google's own advice is not to enter "confidential information that you wouldn't want a reviewer to see".
  • Keep your own dated record of what you developed and what the AI contributed.

With Papex connected, the provider's terms still cover your chat; Papex receives only what the app sends in a tool call, not the conversation.

What to do this week

Most of the protection comes from habits that cost little.

  1. Write the idea down and keep each version. Save a new, dated file for each meaningful change instead of overwriting the last one. Note who did what, when, why and what comes next.
  2. Put an outside date on the versions that matter. Email the file to your supervisor or a collaborator, use your institution's electronic notebook, or timestamp the file with OpenTimestamps, where the hash is calculated in your browser. Keep the exact file you timestamped.
  3. Share early with people you trust. Conversations with a supervisor or close colleague are how a field learns who is working on what, and they leave their own trail of emails, slides and notes.
  4. Note any AI help as you go. If an AI tool shaped the idea, record which one and how; you will want it later for disclosing AI use and for citing it correctly.
  5. Preregister when the design is set. Use an embargo if you are not ready for the plan to be public.
  6. Post a preprint when the manuscript is ready, after checking your target journal's preprint and scooping policies.
  7. Pause before any public step if it could be patentable, and contact the technology-transfer office first.
  8. Check who owns your records. Your institution may have rules; the NIH's guidelines, for example, state that research records are the property of the NIH.

If you think you have already been scooped, gather your dated records before you do anything else, and talk to your supervisor. Parallel work can still be publishable: PLOS, for one, considers such studies and expects authors "to cite and discuss any papers that have scooped theirs". If you believe someone used your work without credit, your institution's research integrity office is the place to raise it.

Keeping a private, dated record as you go

Papex fits the gap between a private notebook and a public preprint. You write a hypothesis, finding or publication as a draft, which stays private while you work. When you sign, the signature links you to that exact version. A later edit becomes a new version with its own signature and date, and the earlier versions stay as they were.

At signing, only a salted fingerprint of the version leaves Papex, not the text. The fingerprint is timestamped with OpenTimestamps and anchored in Bitcoin: it is combined with other fingerprints and committed in a Bitcoin transaction, so the time of the block that holds it sets a date anyone can check. The proof (an .ots file) checks with any OpenTimestamps tool, without Papex, and you need no wallet or cryptocurrency. As an example of the mechanism, Papex Labs' educational record PXH-0BADXVXY7QM3 was signed at 11:18:33 UTC on 5 October 2026, and its fingerprint was confirmed in Bitcoin block 970009, with a block time of 11:26:56 UTC.

After signing, you choose: keep the version private, share it with people you invite, or publish it. If you develop the idea with an AI app such as Claude or ChatGPT, it can prepare a private draft with your permission, but only you can sign or publish.

The limits are those of any timestamp. A Papex record shows who signed which exact version and that it existed by a date. It does not prove ownership, priority in law, originality or that the work is right. What a Bitcoin timestamp proves explains the mechanism in more detail, and you can start a private record at papex.org.

Sources

Keep reading