Privacy

ICSAC operates the submission and review infrastructure at icsacinstitute.org. This page documents what we collect, why, who we share it with, how long we keep it, and what you can ask us to do with it.

Last revised: October 1, 2026. Controller: The Institute for Complexity Science and Advanced Computing LLC, PO Box 15008, Fort Wayne, IN 46885, USA — [email protected]. Processing happens in the United States. We have not appointed an EU representative under GDPR Article 27; we rely on the Article 27(2) exemption for occasional, low-risk processing that involves no special categories of data.

What we collect

On submission: your ORCID, name, email, manuscript (PDF or DOI), and submission metadata — title, abstract, keywords, license, conflict-of-interest declaration, author list, ORCID-verified identity. If you declare a code or data archive, we record its link. If you tell us the paper is a revised version of one we returned, we record that earlier submission ID. If you tick the newsletter box, we record your email address and name, the time, and the version of the wording you agreed to.

On credential lookup (/verify): the credential ID you queried, your IP address (logged for rate limiting and abuse defense), and the timestamp.

On any page visit: standard web-server logs — IP, browser user agent, requested URL, timestamp. No third-party trackers. No advertising cookies. No analytics services.

Cookies: after you sign in with ORCID on a submission form or your response page, one session cookie holds your ORCID iD and name for 24 hours; it is HttpOnly and is cleared when you sign out. Cloudflare Turnstile (anti-bot) sets a short-lived verification cookie during form submission only.

On the submission status page: the state of a submission (received, in review, awaiting decision, completed) and its timestamps can be read by anyone who knows the submission ID. The decision itself is not shown there; it reaches you by email. When a paper is a revised version of an earlier submission by the same ORCID iD, the status pages of both show the two submission IDs.

On contribution: when you contribute via Stripe or (in future) GitHub Sponsors, the processor collects your payment details directly on its own hosted infrastructure — your card or bank information never touches ICSAC servers. From Stripe we receive transaction records (contributor name, email, billing country, amount, transaction ID) and, for recurring tiers, subscription status. From GitHub Sponsors, when active, we will receive the sponsor’s GitHub username and tier (unless your sponsorship is private).

Why

  • Submission processing — to fetch your manuscript, route it through the curation system, send you decisions and the curation record.
  • ORCID verification — to confirm you are who you say you are and prevent fabricated authorship.
  • Fraud and abuse defense — to detect prompt injection, jailbreaking, duplicate submissions, and other system-integrity attacks.
  • Rate limiting — to keep public endpoints reachable for everyone.
  • Publication and registration — when a paper is accepted, your name, ORCID iD and affiliation become part of the public record: the paper’s page here, its DOI registration at Crossref, and the archival copy at Zenodo.
  • Announcing accepted work — on the Institute’s website, social media, newsletters and print or broadcast materials. You can exclude any of these categories from your response page after acceptance, or by email at any time.
  • Newsletter — only if you ticked the box at submission: occasional news from the Institute and Persistence. Every issue will carry an unsubscribe link.

Legal bases (GDPR): handling your submission and sending you its results is performance of the contract you enter by submitting (Art. 6(1)(b)); publication, registration and announcement of accepted work rest on our legitimate interest in running an open scholarly record (Art. 6(1)(f)), with the exclusions above as your objection; archiving to Zenodo and the newsletter rest on the consent you give at submission (Art. 6(1)(a)), which you can withdraw at any time; fraud defence and rate limiting are legitimate interests.

Automated decisions: the AI review panel produces a recommendation. Every publication decision is made by the Institute’s curation team; no decision about you or your work is based solely on automated processing (GDPR Art. 22 does not apply). Before the panel sees a manuscript, author names, affiliations, emails and ORCID iDs are removed from the text, and the authors’ surnames are replaced wherever they appear, including in citations of their own work.

Who we share with

We do not sell, rent, trade, or share your data with third parties for marketing or any other purpose.

Operational disclosures:

  • Zenodo (CERN-operated): if your submission uses the upload route and you grant deposit consent, we deposit your manuscript to the ICSAC Zenodo community for permanent archiving.
  • Crossref (DOI registration agency): for accepted papers we register the title, abstract, your name, ORCID iD and affiliation, the licence and the reference list. Crossref metadata is public by design and redistributed to indexers such as OpenAlex.
  • AI model providers: the panel runs on third-party AI services in the United States. They receive the manuscript text with author identity removed, the citation report, extracts of any code or data archive you declared (its file list, the opening of its README, function names, and the lines that define the measures your paper names), and the review rubric — not your contact details.
  • Google Workspace: our email to you is sent from a Google-hosted mailbox and is subject to Google’s processing terms.
  • Crossref, DataCite, doi.org, arXiv and Semantic Scholar (during review): to verify your reference list we query these public registries with the titles, authors, years and identifiers of the works you cite. Nothing about you is sent.
  • Zenodo and GitHub (during review): if you declare a code or data archive hosted there, we download it once, read-only, to list its files and the lines the panel is shown. Nothing in it is run, and only that extract is kept with the review record.
  • CiteStamp: reference-list metadata (DOIs of the works you cite, not your data) is checked against the CiteStamp citation graph, a service operated by an affiliated company.
  • Cloudflare: routes requests to icsacinstitute.org as a CDN and handles Turnstile bot-detection on form submission. Cloudflare logs request metadata under its own privacy policy.
  • Stripe: processes one-time contributions and recurring Supporter/Sponsor tiers via its own hosted checkout (donate.stripe.com) and billing portal. Card and bank data are collected by Stripe, not by ICSAC. Stripe’s handling of payment information is governed by the Stripe Privacy Policy.
  • GitHub Sponsors (planned): when activated, will process GitHub-based recurring sponsorships. Governed by the GitHub Privacy Statement.

How long we keep it

  • Submission records and curation records: indefinite. The curation record is part of the public scholarly record; it does not get deleted on request unless required by law (see Your Rights below). Your contact details within a submission record are kept so we can correspond with you about that paper; they can be removed on request once the paper is published or withdrawn.
  • Your response to an acceptance (approve, exclusions, hold or withdraw): kept with the submission record as evidence of your instructions, with its timestamp.
  • The editorial audit log (submission ID, each step the system took, its timestamp, and the address a notice was drafted to): indefinite, as the record of what the Institute did with each submission.
  • Newsletter list: until you unsubscribe. The list is a log of sign-ups and unsubscribes, so your sign-up stays in it as the record of your consent; after an unsubscribe nothing is sent to that address, and on request we remove the address entirely.
  • Verification access logs: 90 days, then purged.
  • Web server logs: 30 days, then purged.

Your rights

If you are in the EU/EEA (GDPR) or California (CCPA), you have the right to:

  • Request a copy of the data we hold on you.
  • Request correction of inaccurate personal data.
  • Request deletion of personal data that is not part of the public curation record. (We will not delete published papers or their curation records on request — that would compromise the scientific record. Pre-publication withdrawal is a separate process — see Publication Ethics → Corrections, Updates, and Retractions.)
  • Withdraw consent for non-essential processing.
  • Object to processing based on our legitimate interests — for announcements, use the exclusions on your response page or email us.
  • Receive the data you gave us in a portable format.
  • Lodge a complaint with your national data protection authority if you are in the EU/EEA.

Email [email protected] with the request and your ORCID. We respond within 30 days.

Children

The submission system is not intended for use by anyone under 16. We do not knowingly collect data from children.

Changes

This policy may be revised. Material changes will be announced on /publication-ethics or sent to active submitters via email.