Privacy and permanence
Cabdell is built so that the scientific record cannot be rewritten: nothing is deleted from the blockchain, and every action is a public, signed record. That is good for science and needs care from you. This page sums up what is public, what you can still change, and what stays private. The sources are the About page (“What runs outside the blockchain” and “Known limits”) and the code of the web app and the indexer.
In short
Section titled “In short”| Examples | |
|---|---|
| Public and permanent | everything recorded on the blockchain: publications and every version, reviews, comments, votes, flags, follows, public lists, ORCID and DOI declarations |
| Can be withdrawn or marked, but stays in the history | retraction, unfollowing, unlinking an ORCID iD, withdrawing a DOI, editing or deleting a public list |
| Copies you cannot recall | article files on IPFS, Cabdell’s second copy, copies others keep, Zenodo records |
| Only in your browser | private lists, your pinning key, the Zenodo permission, read marks, preferences |
| Seen by Cabdell’s server | your searches, the names it looks up for you, browser notification subscriptions, Zenodo drafts while you make them |
What is public and permanent
Section titled “What is public and permanent”The blockchain is a shared record that thousands of computers keep identical; once an action is written there, nobody can change or remove it, including the people who run Cabdell (see What is on the blockchain, and what is not). On Cabdell this covers:
- publications: every version of every article, its fields, type, co-authors and status;
- reviews and comments, with their recommendation, and the addresses they mention;
- votes, which can never be changed or withdrawn, and flags;
- reputation claims and co-authorship confirmations;
- follows: anyone can see who follows whom;
- public lists: every name, description, addition, removal and deletion;
- ORCID declarations: anyone can see which iD an address declared, and when;
- DOI declarations.
The texts themselves are on IPFS, and the blockchain keeps their fingerprint. Everything in a publication’s folder is
public and permanent, including comments in the source (<!-- ... -->) and every file in assets/. Check them
before you publish.
Your address is not your name, but anything that links the two (an ORCID iD, an NFD name, a signature in your text) links all of the address’s activity to you, publicly and for good. See Identity: addresses, names and ORCID.
Notifications are derived from this public data, so the indexer serves the notifications of any address to anyone.
What you can withdraw, hide or mark
Section titled “What you can withdraw, hide or mark”| You can | What changes | What stays |
|---|---|---|
| Retract an article (see New versions, amendments and retraction) | the article is marked retracted, everywhere | every version stays readable; a retraction is a visible status, not an erasure |
| Unfollow someone | they leave your inbox; the follow is marked inactive | the follow and the unfollow, on the blockchain |
| Unlink your ORCID iD | the iD, its name and the details read from ORCID disappear from your profile, and the indexer deletes what it had read from your record | the declaration, in the blockchain history |
| Object to figures about you | your Thread Score and reputation figures are no longer shown, and you are never drawn for a jury (below) | the objection itself, a public note on the blockchain |
| Hide a detail of your ORCID record | change its visibility on ORCID; your profile follows at the next check (weekly) | nothing on chain: these details are never written there |
| Withdraw a DOI | it disappears from the article | the declaration, on the blockchain; the Zenodo record, on Zenodo |
| Rename, empty or delete a public list | your profile shows the change | every earlier change, on the blockchain |
| Delete a private list | it is gone | nothing: it never left your browser |
| Turn off browser notifications | Cabdell’s server forgets that subscription | nothing |
What you cannot change: a vote, the list of co-authors declared when publishing, a published version, a review or a comment.
Copies you cannot recall
Section titled “Copies you cannot recall”A published article lives on IPFS, the storage network where a file is found by its fingerprint (see Storage: IPFS, pins and copies).
- Your pinning service (Filebase, Pinata or your own node) holds the copy you uploaded.
- Cabdell’s indexer keeps a second copy of every article it validates, and of every review and comment, and serves it through its gateway, https://ipfs.cabdell.press. After a retraction the content stays addressable.
- Anyone, a reader or an institution, can pin a copy; the article page even shows the command.
- A Zenodo record cannot be deleted once published, even if the article is later retracted on Cabdell; its description can still be edited (see Get a DOI with Zenodo).
So treat publishing as final: assume that every published file will stay available somewhere.
What this site stops showing, and when
Section titled “What this site stops showing, and when”Cabdell stops showing something on its own service in four cases only: an order of a court or an authority; a notice that shows the content to be manifestly illegal; content against the terms of use (spam, malware, phishing); a request about your own personal data. It can be an article, a review, a comment, a list or journal’s texts, a flag’s note, a juror’s reasons, a person’s names and ORCID data, or any file on IPFS. Then:
- the indexer no longer returns the text, the names or the CID, and deletes the copies of the texts it kept (for search, for instance);
- the Cabdell gateway answers “410 Gone”, and our IPFS node drops its copy and neither serves it to other nodes nor fetches it again. One exception, which the law requires: terrorist content is kept, encrypted and seen by nobody, for six months (for a review of the removal or the police), then deleted. Child sexual abuse material is kept nowhere;
- the website shows, in its place, a statement of the reasons: the ground, the facts and rule, that it applies to this service, since when, and how to contest it (write to the address on the contact page quoting the case’s number, or go to the courts). The author is told by a notification, unless an authority forbids it;
- the transparency report of each network (the Transparency link at the foot of every page) lists the case by its record and ground, never by its content or its CID, from its publication date. Cases of child sexual abuse material, terrorist content and personal data are only counted, by month and ground, so that the report never points to them. A private person who asked is never named.
The record on the blockchain does not change, and other services and anyone who keeps a copy may still show it. Disagreement is never a reason: it is answered with reviews, comments and flags. See Principles and commitments.
Objecting to figures about you
Section titled “Objecting to figures about you”Cabdell derives figures about people from the public record: reputation per field, the Thread Score, and whether someone qualifies for a jury. You can object to them (GDPR art. 21), item by item, with a note signed by your own address (a 0-ALGO payment to yourself, like a public list; the web app offers it on your profile):
ariadne/lists/<appId>:{"op":"objection","to":["thread","jury","reputation_display"],"on":true}thread: your Thread Score is no longer shown on your profile;reputation_display: your reputation figures are no longer shown on your profile or in the people search;jury: you are never put in a jury pool or drawn, from then on.
"on":false withdraws an objection; for each item, your latest note stands. The note itself is public and permanent,
like every note on the blockchain. Your reputation still exists on the blockchain and still weighs your votes: only its
display stops.
What stays in your browser
Section titled “What stays in your browser”These are kept in your browser’s storage on this site, never on Cabdell’s servers, and other devices do not have them. Clearing the site’s data removes them.
- Private lists (see Lists and bibliographies).
- Your storage setting: the Filebase or Pinata key, or your own IPFS node’s address; “Forget it” removes it.
- The Zenodo permission, in a sealed cookie that lasts at most an hour; “Disconnect Zenodo” removes it sooner.
- Which notifications you have read, and what you have already seen from the people you follow.
- Preferences: theme, citation format, bibliography order, comment order, the network you used last, and the wallet you connected.
- Your last 8 searches; “Forget recent searches” clears them.
Reading needs no wallet and no account: you can read and search everything without connecting anything.
What Cabdell’s server sees
Section titled “What Cabdell’s server sees”- Your searches. The search runs on Cabdell’s indexer, so the server receives what you search for.
- Names and pictures. Cabdell’s server asks NFD for the
.algonames and avatars of the addresses on a page and passes them to your browser, so your browser never contacts NFD. Names are kept in the server’s memory for up to 30 minutes. - Browser notifications. When you turn them on, the server keeps the push address your browser gave (at Google, Mozilla, Microsoft or Apple), its two keys, the network, the address you receive for and the kinds you chose. The messages travel encrypted end to end through that push service. Turning notifications off removes the subscription.
- Zenodo drafts. While you prepare a draft, the server uses the permission from your sealed cookie to create it in your Zenodo account; it does not keep the permission.
- ORCID and OpenAlex. For a declared ORCID iD, the indexer reads the public part of the ORCID record (names, websites, countries; never its e-mail addresses) and, once the iD is verified, its current employments and OpenAlex’s counts of the person’s works and citations. It reads only what the record shows to everyone, keeps and shows it only while the iD is verified, and deletes it when the iD is unlinked. An iD that is not verified is shown to nobody.
- Logs. No access log is kept. The servers’ own error messages are kept in rotating files (at most 30 MB per service, the oldest overwritten), with the visitor’s address cut to its network and without the browser’s description; the indexer never logs what is searched.
Cabdell never sees your wallet’s private key, and it has no advertising. Images from other websites are not embedded in articles but shown as links, because an external image can change, disappear or be used to follow readers.
Before you act, ask yourself
Section titled “Before you act, ask yourself”- Publishing: is every file and every source comment something you want public for ever?
- Linking an ORCID iD: are you happy for this address’s whole history to carry your name?
- Following, voting, making a list public: are you happy for anyone to see it?
- Publishing on Zenodo: the record will outlive any retraction.
Try things on TestNet first: it works exactly like MainNet, with free ALGO, though what you do there is public and permanent on TestNet too (see TestNet and MainNet).