Privacy Policy
1. Who we are
This policy explains how Papex Labs Ltd ("Papex", "we", "us") handles personal data when you use papex.org and its related APIs and tools. We are the data controller for the personal data described here.
Papex Labs Ltd is a company registered in England and Wales under company number 17438789, with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. For any privacy question or request, write to privacy@papex.org.
2. Data we collect
Account. Your name, email address and the identifier of your sign-in account. Your account also receives a Papex ID.
Profile. Handle, photo, bio, website and links, ORCID iD if you link one, and institutional affiliations with how they were checked (for example, an institutional email check). We check an institutional email with our sign-in provider when needed; we do not keep a separate copy of it.
Wallets and delegation. Wallet addresses you use to sign, and the permissions you give to delegate keys (address, scope, expiry and app label). Delegate private keys stay on your device; we do not receive them.
Records and files. Drafts, records, files, sources, notes, checkpoints and the names of authors and contributors you list. Co-authors without a Papex account are stored by name, and by email only if you invite them.
Signing and consent. When you sign a record or accept a legal statement, we keep the signature, the text you accepted, the time, and in many cases your IP address and browser user agent. This is our evidence of what was agreed.
Community. Comments, challenges, acknowledgements and reports you submit.
Email. Your notification preferences and time zone, and delivery status for the emails we send you. We do not keep the bodies of sent emails in our delivery log.
Technical data. Request identifiers in our logs, short-lived counters for rate limits, and aggregate view counts. We do not use advertising or cross-site tracking.
Data we receive from others.
- Other researchers may name you as an author or contributor on their records, or invite you by email to confirm it. You can decline an invitation. A name already signed into a published version cannot be removed from it (see section 7).
- Our sign-in provider gives us your name, email address and account identifier when you create an account, and tells us when an account is deleted.
- ORCID confirms your ORCID iD when you link it.
- Your institution's email system is used only to confirm that you control an institutional address.
What you must provide. An account needs a name and an email address, and signing needs a wallet. Everything else in your profile is optional.
Automated decisions. We make no decisions about you based solely on automated processing that have legal or similarly significant effects. Automated checks (such as malware scanning of uploaded files) can stop a file from being published; a person can review the result.
3. What is public
Papex exists to make research records public when you choose to publish. The following can be seen by anyone:
- your public profile: name, handle, Papex ID, photo, bio, links, ORCID iD and affiliations;
- published records, including author and contributor names, affiliations as signed, files, sources and stated tools;
- the signer's Papex ID, wallet address and signature on each published version, and its receipts;
- comments, challenges and acknowledgements, including a challenger's wallet address.
Your email address, drafts, private notes, private checkpoints, reports and the identity of reporters are not public.
4. Why we use your data
- To provide Papex (performance of our contract with you): accounts, records, signing, publishing, sharing, verification and email you ask for.
- To keep Papex safe and reliable (our legitimate interests): security, abuse prevention, moderation, fixing problems and keeping the record verifiable.
- To keep evidence and meet legal duties (legal obligation and legitimate interests): consent and signing records, responses to lawful requests.
- With your consent: optional features that say so when you turn them on. You can withdraw consent at any time.
We do not sell personal data.
5. Service providers
We use these providers to run Papex. They process data for us under their own security and privacy terms:
- Clerk: sign-in and account management.
- Render: application hosting and database (Frankfurt, EU).
- Cloudflare: file storage and delivery of the website.
- Resend: sending email.
- Coinbase: embedded wallet, if you use it.
- ORCID: linking your ORCID iD, if you choose to.
Some features send data to outside services only as needed:
- Timestamps: OpenTimestamps calendars receive a record's hash, never its content. The hash is anchored in the public Bitcoin blockchain.
- Reference lookups: identifiers such as DOIs are sent to public registries (for example Crossref, DataCite, arXiv and PubMed) to fetch metadata.
- AI features: if Papex offers a feature that sends your content to an AI provider, we will say so and ask you first.
We may disclose data when the law requires it, to protect people or the service, or as part of a merger or transfer of the service with notice to you.
6. International transfers
Some providers process data outside the United Kingdom and the European Economic Area, for example in the United States. Where the law requires, these transfers rely on an adequacy decision or on safeguards such as the UK International Data Transfer Addendum or the EU standard contractual clauses.
7. What cannot be erased
Signatures, hashes and timestamps are designed to be permanent. Once you sign and publish a version, the names, Papex ID, wallet address and affiliations in that signed version cannot be changed or removed from it, and a timestamp anchored in Bitcoin cannot be undone. Please check what a version contains before you sign it.
8. How long we keep data
- Account and profile data: while your account exists.
- Drafts and private content: until you delete them or your account.
- Account event logs from our sign-in provider: 30 days.
- Published records, receipts and signatures: as long as Papex runs, including after withdrawal for the parts that remain.
- Consent and signing records: as long as they may be needed to establish or defend legal claims.
- Other data: only as long as needed for the purposes above.
Copies in our hosting provider's backups are overwritten as the backups rotate.
9. Deleting your account
You can delete your account at any time in your account settings. You can also ask us by writing to privacy@papex.org.
We erase your account with our sign-in provider, your profile, drafts, records you never published and their files, private notes, checkpoints, share links, delegate permissions, wallet links, affiliations and email preferences.
We anonymise what other people's content depends on: your profile becomes "Deleted account", your comments and challenges stay under that name, and reports you made stay without saying who made them.
We keep published records as signed, with their receipts and public files. They are part of the public scientific record that others cite, and the names in a signed version cannot be changed (see section 7). You can withdraw published records before you delete your account, where Papex offers withdrawal. We also keep consent and signing records as evidence, without your IP address or browser details.
10. Your rights
Under the UK General Data Protection Regulation and the Data Protection Act 2018, and where they apply to you, the EU General Data Protection Regulation and Türkiye's Personal Data Protection Law (KVKK), you may have the right to:
- learn whether we process your data and get a copy of it;
- correct inaccurate data;
- have your data erased, or restrict or object to its processing;
- receive your data in a portable format;
- withdraw consent at any time.
Write to privacy@papex.org. We may need to confirm your identity, and we reply within one month. Some rights are limited for signed and published records, as explained in sections 7 and 9.
You can complain to the UK Information Commissioner's Office (ico.org.uk), to the data protection authority where you live, or, in Türkiye, to the Personal Data Protection Authority (KVKK).
11. Cookies and local storage
We use only the cookies needed for sign-in and sessions, set by our sign-in provider. Your browser's local storage keeps preferences such as appearance, unsaved drafts and recovery copies on your device. We use no advertising cookies and no third-party analytics.
12. Security
We protect data with encryption in transit, access controls, private file storage and audit logs. No system is perfectly secure. If you find a vulnerability, please write to security@papex.org.
13. Children
Papex is not for people under 18. We do not knowingly collect their data.
14. Changes
We may update this policy. For material changes, we will give notice by email or in the app before they take effect.
15. Contact
- Email: privacy@papex.org
- Post: Papex Labs Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom