CabdellThe open record of science.
Wallet
Theme
TestNet: articles here are for testing and carry no reputation on MainNet.

Privacy policy

This policy explains what personal data Cabdell's services handle, why, on what legal basis, who else receives it, how long it is kept and how you can exercise your rights. It covers this website, the Cabdell indexer and API, the IPFS gateway and node, the documentation site, browser notifications and the private test sandbox. The short version comes first (In short); a summary in Spanish is at the end (Resumen en español).

Cabdell is unusual in one respect: what you sign is written on a public blockchain and cannot be deleted by anyone, ourselves included. Please read What we can and cannot delete before you publish.

In short

QuestionAnswer
Who is responsiblepending, the operator of Cabdell. Contact: the contact address (pending)
What forIndexing and showing the open scholarly record you and others publish on the Algorand blockchain and IPFS; verifying ORCID iDs; computing public figures about scholarly work (reputation, Thread Score, the Peer-reviewed seal, juries); the browser notifications, Zenodo drafts and sandbox you ask for; handling notices and requests; security.
Legal basisLegitimate interest in an open, verifiable scholarly record; the Terms of use and the services you ask for; legal obligations for notices, orders and data-protection requests.
Who else receives dataEveryone, for what is public by design on the blockchain and IPFS; our host OVHcloud (France); the services we or your browser contact for a feature (Nodely, ORCID, OpenAlex, NFD, Zenodo, DataCite, push services, wallets, pinning services), some in the United States.
ProfilingYes: reputation, Thread Score, seal and jury eligibility are computed from the public record. No decision is solely automated. You can object.
Your rightsAccess, rectification, erasure, restriction, objection and portability, on the rights page; a complaint to the AEPD. What is on the blockchain cannot be deleted by anyone.
MoreThe full policy below.

Who is responsible

The controller of your personal data is:

  • Name: pending
  • Legal form: pending
  • Tax identification number (NIF): pending
  • Address: pending
  • E-mail: the contact address (pending)

You can write to us about your personal data at the contact address (pending) or through the rights page. We have not appointed a data protection officer; the same address reaches the person responsible.

What is public by design

Cabdell is an open system for publishing science. Each action you take (publishing, reviewing, commenting, voting, flagging, following, linking an ORCID iD, declaring a DOI, making a list public, answering as a juror) is a transaction signed by your wallet and recorded on the Algorand blockchain, a public ledger copied by computers around the world. Texts are stored on IPFS, a public storage network, and the blockchain keeps their fingerprint (CID).

  • Your address is a pseudonym: it is not your name. But anything that links it to you (an ORCID iD, an NFD name, your name in an article) links all of the address's activity to you, publicly and for good.
  • Everything recorded on the blockchain is public and permanent: the operator cannot change or remove it.
  • Short texts some actions write on the blockchain itself are public and permanent too: list and journal names, descriptions and policies, flag notes and jurors' reasons.

What we process, why, on what basis and for how long

1. The public record (addresses and actions)

  • Data: your address and what it did on Cabdell (publications and their versions, fields, co-authors you declared, reviews, comments, votes, flags, follows, mentions, public lists, ORCID and DOI declarations, juror answers), with dates; the short texts written on the blockchain.
  • Source: you, when you sign; and the Algorand blockchain, which our indexer reads (also for actions taken with other tools than this website).
  • Purpose: to index the open scholarly record and show it: the feed, article pages, profiles, search, the inbox and the notifications feed of every address, citations and the API.
  • Legal basis: our legitimate interest, and the public's, in an open and verifiable scholarly record (GDPR art. 6(1)(f)), which supports the freedoms of science, expression and information. In the balance we weighed that you choose what to publish, that an address carries no name unless you link one, that we add no tracking, and that you can object and ask us to stop showing something (below). For the actions you sign through this website, also the performance of the Terms of use you accept (art. 6(1)(b)).
  • Kept: on the blockchain, for ever (we cannot delete it). Our indexer's copy, for as long as the service runs; what we stop showing is masked everywhere, and our own copies are deleted where the case requires it.

2. Content on IPFS

  • Data: the articles, datasets, reviews and comments you publish, and anything personal in them.
  • Source: you; the IPFS network.
  • Purpose: to keep a second copy of every valid publication on our IPFS node, serve it through our gateway (ipfs.cabdell.press) and to other IPFS nodes, check it against its fingerprint, and keep its text for search.
  • Legal basis: legitimate interest in preserving and serving the open record (art. 6(1)(f)); the Terms of use for what you publish through this website (art. 6(1)(b)).
  • Kept: while the service runs. What we must stop showing is unpinned and removed from our node and our search.
  • Your responsibility: do not publish other people's personal data without a lawful basis, and publish health, genetic or other special-category data about research participants only when it is properly anonymised (see the Terms of use).

3. ORCID iD verification

  • Data: when an address declares an ORCID iD, our indexer reads the public ORCID record to check that it lists the address's Cabdell profile. For verified iDs only, it keeps the names, websites, countries and current employers shown publicly on the record, and shows the name. E-mail addresses are neither stored nor shown.
  • Source: ORCID (art. 14 GDPR: this data does not come from you directly).
  • Purpose: to show who stands behind an address when that person chose to link an iD; to find conflicts of interest for the Peer-reviewed seal and the juries (for example the same employer).
  • Legal basis: legitimate interest (art. 6(1)(f)), started by your own declaration.
  • Kept: re-read regularly (often in the first two days, then weekly); deleted when the iD is unlinked, stops being verified, or your data is withheld at your request.
  • Recipient: ORCID, Inc. (United States) receives the iDs our server asks about.

4. OpenAlex citation data

  • Data: for a verified ORCID iD, the counts of works and citations OpenAlex holds, by year and field; for a reviewer and the authors of an article, how many works they wrote together.
  • Source: OpenAlex (art. 14).
  • Purpose: to show citation counts on profiles, to judge expertise for the seal and the juries, and to find conflicts of interest from co-authorship.
  • Legal basis: legitimate interest (art. 6(1)(f)).
  • Kept: rechecked weekly or monthly; deleted with the ORCID data above.
  • Recipient: OpenAlex (OurResearch, United States) receives the iDs our server asks about.

5. Figures about people: profiling

The indexer computes, from the public record, figures that evaluate people's scholarly work (GDPR art. 4(4)):

  • reputation per field and the weight of votes (set by the contract itself, from the votes others gave);
  • the Thread Score, a citation percentile of a person's articles;
  • whether a review counts toward the Peer-reviewed seal (expertise, conflicts of interest from employers, co-authorship and earlier support, a verified ORCID iD);
  • who qualifies for a jury, and the random draw of jurors.

Each rule is published with its numbers in the About page and the documentation, and anyone can recompute every result. Legal basis: legitimate interest (art. 6(1)(f)). Consequences: these figures help readers find reviewed and cited work and decide who may sit on a jury; they say nothing about a person's worth and are not meant for hiring or funding decisions. No decision based solely on automated processing with legal or similarly significant effects is taken (art. 22): disputes are decided by people, a jury and governance.

You can object (art. 21). On your own profile you can sign an objection note asking this service not to show your Thread Score and reputation figures and not to draw you for juries. The objection note is itself a public record on the blockchain (it says only which objections you made). Reputation stays in the contract, which uses it for the weight of your votes; we cannot change that.

6. Names and pictures from NFD

  • Data: the .algo name and avatar that the owner of an address chose on NFD (Non-Fungible Domains).
  • Purpose: to show names instead of bare addresses. Our server asks NFD, so your browser never contacts it.
  • Legal basis: legitimate interest (art. 6(1)(f)); the owner published the name.
  • Kept: in our server's memory, for up to 30 minutes.
  • Recipient: TxnLab, Inc. (United States), which runs NFD, receives the addresses our server asks about.

7. Browser notifications

  • Data: when you turn notifications on: the push address your browser gives (at Google, Mozilla, Microsoft or Apple), its two encryption keys, the network, the address you receive notifications for, the kinds you chose, and the dates of creation and of the last delivery.
  • Purpose: to send you the notifications you asked for, encrypted end to end.
  • Legal basis: a service you ask for (art. 6(1)(b)).
  • Kept: until you turn them off; deleted at once when the push service says the address is gone, after repeated failures, or after 12 months without a successful delivery.
  • Recipients: your browser's push service (Google, Mozilla, Microsoft or Apple, mostly in the United States), which sees an encrypted message and when it is sent. Notifications are derived from public data, so anyone can subscribe to the notifications of any address.

8. Zenodo drafts

  • Data: when you ask for a DOI, the article's files and metadata (titles, the authors' names and ORCID iDs) go to your own Zenodo account, with a permission you give on Zenodo.
  • Legal basis: a service you ask for (art. 6(1)(b)).
  • Kept: the permission lives only in a sealed cookie in your browser, for at most an hour; our server keeps nothing. Zenodo keeps the draft under its own terms.
  • Recipient: Zenodo, run by CERN (an international organisation in Switzerland); DataCite registers the DOIs.

9. Notices, data-protection requests and messages

  • Data: what you send us through the notice form, the rights page or by e-mail: your name and e-mail address (optional for notices of child sexual abuse material), the item and your explanation; for a rights request, the address or ORCID iD concerned and the proof that it is yours (a signed message, never a transaction).
  • Purpose: to handle notices of illegal content and orders, to answer data-protection requests, to keep a record of what we decided, and to defend against claims.
  • Legal basis: legal obligations (art. 6(1)(c)): the Digital Services Act (arts. 9-18), Regulation (EU) 2021/784 on terrorist content, and GDPR arts. 12-22; and legitimate interest in keeping proof (art. 6(1)(f)).
  • Kept: two years from receipt, then deleted.
  • Recipients: authorities, when the law requires it (for example the police for child sexual abuse material). We do not tell the person whose content is concerned who sent a notice, unless the law requires it or you agree.

10. The private test sandbox

  • Data: for invited testers: the name the operator gave the invitation, a log of the test tools used (visible to all testers) and problem reports (text, page, technical context, without keys).
  • Legal basis: the invitation you accepted (art. 6(1)(b)) and legitimate interest in testing (art. 6(1)(f)).
  • Kept: the action log and problem reports for six months, and they are deleted when the sandbox is reset. Nothing from the sandbox goes to IPFS or to the public networks.

11. Technical data and security

  • We keep no access log. Our servers do not record the pages you visit.
  • Your IP address is held in our server's memory, for at most an hour, to limit abusive request rates, and never written to disk for that purpose (the forms do not store it either).
  • The error logs of our containers may contain an IP address or a page address when a request fails. Each container keeps at most 3 files of 10 MB, overwritten as they fill.
  • Content-security reports your browser may send us keep only the rule, the blocked origin and the page's path.
  • Your searches go to our indexer, which answers them and does not keep them (a request that fails may leave its address in the error log above).
  • Legal basis: legitimate interest in the security of the service (art. 6(1)(f), recital 49).

Who else receives data

  • OVHcloud hosts our server in France, as our processor under a data-processing agreement (art. 28).
  • Independent services that receive data in the cases described above, each under its own privacy policy: Nodely (Algorand access, Poland), ORCID (United States), OpenAlex (United States), TxnLab/NFD (United States), Zenodo/CERN (Switzerland) and DataCite (Germany), and the push services of browsers.
  • Services your own browser contacts when you use a feature, not our server:
    • with a connected wallet: Nodely's Algorand API (it receives your IP address and your address), your wallet app and its connection service (Pera, Defly, Lute, WalletConnect); the Pera and Defly connection windows may load fonts from Google;
    • when you publish: the pinning service you chose (Pinata, Filebase or your own IPFS node), under your own contract with it, and the public IPFS gateway trustless-gateway.link.
  • Everyone, for what is public by design: the blockchain and IPFS are read by anyone, and our API is open.

Transfers outside the European Economic Area

Some recipients above are in the United States or are international organisations. Where a recipient is certified under the EU-US Data Privacy Framework, the transfer relies on the European Commission's adequacy decision of 10 July 2023; otherwise it relies on the safeguards the recipient offers, or is necessary for a service you asked for (art. 49(1)(b)). The Algorand blockchain and IPFS are global networks: what you publish there is copied worldwide by design.

How long we keep data

DataKept
Blockchain records, public texts on the blockchainfor ever: nobody can delete them
Our copies of the public record and contentwhile the service runs; removed when we must stop showing them
ORCID and OpenAlex datawhile the iD is linked and verified
NFD names and picturesup to 30 minutes, in memory
Browser-notification subscriptionsuntil turned off, or 12 months without a successful delivery
Notices, rights requests and their answers2 years from receipt
Sandbox action log and problem reports6 months, and deleted when the sandbox is reset
Terrorist content we removea protected copy for 6 months (Regulation (EU) 2021/784, art. 6), then deleted
Container error logs3 files of 10 MB per container, overwritten as they fill
Access logsnone are kept

What we can and cannot delete

We canWe cannot
Stop showing something on our website, API and gateway, and in searchChange or delete anything recorded on the blockchain
Unpin and delete it from our IPFS node, and refuse to serve it to other nodesDelete copies kept by other IPFS nodes, your pinning service, Zenodo or other websites
Delete our copies of ORCID and OpenAlex data, and stop showing names and picturesChange what ORCID, NFD or Zenodo publish themselves
Stop showing your figures and leave you out of juries when you objectChange the reputation the contract holds

So: treat everything you sign as public and permanent, and try things first on TestNet.

Your rights

You have the right to:

  • access the personal data we hold about you and receive a copy;
  • rectification of inaccurate data (on the blockchain, a later record can correct an earlier one; off it, we correct our copies);
  • erasure, including, under article 94 of the Spanish data-protection law (LOPDGDD), of data you supplied for publication, at your simple request, and of data you supplied while a minor; for the blockchain, erasure means that we stop showing the data and delete our own copies;
  • restriction of processing while a question is settled;
  • object to processing based on legitimate interest, including the profiling above (art. 21);
  • portability of the data you gave us for a service you asked for (browser notifications);
  • not to be subject to a decision based solely on automated processing (art. 22).

How: use the rights page or write to the contact address (pending). To be sure a request about an address comes from its owner, we ask you to sign a short message with your wallet: it is not a transaction and nothing is recorded on the blockchain. If your wallet cannot sign messages, we agree another proof with you (for example through your ORCID record). We answer within one month, or within three months for complex requests, telling you within the first month. It costs nothing.

Complaints: you can complain to the Spanish data-protection authority, the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es, or to the authority of the EU country where you live or work. We would be glad to try to solve the problem first.

Cookies and storage in your browser

Cabdell uses no advertising, analytics or tracking cookies, and no third-party cookies. What it stores in your browser is needed for a service you ask for, or a choice you made, so no consent banner is needed (Spanish LSSI, art. 22.2). You can delete all of it by clearing this site's data in your browser.

Cookies

NameWhat forHow long
ariadne_networksends / to the network you chose1 year
ariadne_sandboxaccess to the private sandbox (invited testers only)the browser session, or 180 days if you ask to stay signed in
ariadne_zenodo_stateprotects the Zenodo sign-in10 minutes
ariadne_zenodo_<network>the Zenodo permission, sealedat most 1 hour
ariadne_legal_adminthe operator's own sign-in to the administration of notices12 hours

Browser storage (local storage and session storage)

  • Your preferences: theme, network, citation format, bibliography order, comment order, preview and welcome settings (ariadne.theme, ariadne.network, ariadne.cite.default, ariadne.bibliography.sort, ariadne.comments.order, ariadne.preview, ariadne.welcome.hidden).
  • What you create or ask for: private lists (ariadne.lists.<network>), co-author invitations you declined, which notifications you have read and what you have seen from people you follow, your acceptance of the Terms of use (ariadne.terms), and your pinning key (ariadne.pin.key: for the tab only, unless you tick "Remember on this device").
  • Your wallet connection: kept by the wallet libraries (@txnlab/use-wallet:v5, walletconnect, PeraWallet.Wallet, DeflyWallet.Wallet and similar).
  • Kept automatically, on your device only: your last 8 searches (ariadne.search.recent; "Forget recent searches" clears them) and where you stopped reading an article, for 90 days (ariadne.reading.<network>.<id>).
  • For the tab only: temporary state of claims, notices, the sandbox, and whether the Terms of use were already offered when your wallet connected (ariadne.terms.asked).
  • Sandbox only: the test accounts and their keys.
  • Offline use: a service worker and its cache keep the offline page and the site's own files, nothing personal.

The documentation site keeps only your theme (starlight-theme) and the state of its menu (sl-sidebar-state).

Children

Cabdell is not meant for children. You must be at least 16 to use it to sign anything. If you published data while you were a minor, you can ask us at any time to stop showing it and to delete our copies, and we will do so without delay (LOPDGDD art. 94.3).

Security

We protect our servers with encrypted connections, restricted access, limits on requests and a policy that keeps uploaded files from running as part of this site. We never see your wallet's private key. If a breach put your rights at risk, we would tell the AEPD within 72 hours and you without undue delay.

Changes

We will publish any change to this policy on this page, with its date, and announce significant changes on the site before they apply.

Last updated: 8 October 2026.

Política de privacidad: resumen en español

La política completa está en inglés, arriba. Si necesita alguna parte en español, escríbanos a la dirección de contacto (pendiente) y se la enviaremos.

Información básica

PreguntaRespuesta
Responsablependiente, titular de Cabdell. Contacto: la dirección de contacto (pendiente)
FinalidadesIndexar y mostrar el registro científico abierto que usted y otros publican en la cadena de bloques Algorand y en IPFS; verificar identificadores ORCID; calcular cifras públicas sobre el trabajo científico (reputación, Thread Score, el sello Peer-reviewed, los jurados); las notificaciones del navegador, los borradores de Zenodo y el entorno de pruebas que usted solicite; tramitar notificaciones y solicitudes; seguridad.
LegitimaciónInterés legítimo en un registro científico abierto y verificable; las Condiciones de uso y los servicios que usted solicita; obligaciones legales para notificaciones, órdenes y solicitudes de protección de datos.
DestinatariosCualquier persona, en lo que es público por diseño en la cadena de bloques e IPFS; nuestro proveedor de alojamiento OVHcloud (Francia), como encargado del tratamiento; los servicios que nosotros o su navegador contactan para una función (Nodely, ORCID, OpenAlex, NFD, Zenodo, DataCite, servicios de notificaciones push, carteras, servicios de anclaje IPFS), algunos en Estados Unidos.
Elaboración de perfilesSí: la reputación, el Thread Score, el sello y la idoneidad para jurados se calculan a partir del registro público. Ninguna decisión es exclusivamente automatizada. Puede oponerse.
DerechosAcceso, rectificación, supresión, limitación, oposición y portabilidad, en la página de derechos; reclamación ante la AEPD. Lo registrado en la cadena de bloques no puede borrarlo nadie.

Lo esencial

  • Lo que firma es público y permanente. Cada acción (publicar, revisar, comentar, votar, señalar, seguir, vincular un ORCID, declarar un DOI, hacer pública una lista, responder como jurado) es una transacción firmada por su cartera y registrada en Algorand. Nadie puede cambiarla ni borrarla, tampoco nosotros. Su dirección es un seudónimo, pero todo lo que la vincule con usted (un ORCID, un nombre NFD, su nombre en un artículo) vincula públicamente y para siempre toda su actividad.
  • Lo que guardamos. Una copia del registro público y de los textos en nuestro indexador y nuestro nodo IPFS; para los ORCID verificados, los nombres, sitios web, países y empleadores públicos del registro ORCID (nunca los correos electrónicos) y los recuentos de OpenAlex, que borramos al desvincular el identificador; las suscripciones a notificaciones del navegador (hasta que las desactive, o 12 meses sin una entrega correcta); las notificaciones de contenidos y las solicitudes de derechos (2 años); en el entorno de pruebas, el registro de acciones y los informes de problemas (6 meses). No guardamos registros de acceso; su dirección IP solo se usa en memoria, como mucho una hora, para limitar abusos (los formularios tampoco la guardan).
  • Perfiles. La reputación, el Thread Score, el sello y la idoneidad para jurados son evaluaciones automáticas del trabajo científico con reglas públicas. Desde su propio perfil puede firmar una nota de oposición (artículo 21 del RGPD) para que este servicio no muestre su Thread Score ni sus cifras de reputación y no le sortee para jurados; la nota misma es pública.
  • Transferencias. Algunos destinatarios están en Estados Unidos (ORCID, OpenAlex, NFD, servicios de notificaciones push, Pinata, Filebase) o son organizaciones internacionales (Zenodo, del CERN). La cadena de bloques e IPFS son redes mundiales.
  • Cookies. Solo usamos cookies y almacenamiento del navegador necesarios para un servicio que usted pide o para recordar sus preferencias: no hay publicidad, analítica ni seguimiento, por lo que no se necesita banner de consentimiento (LSSI, art. 22.2). La lista completa está en la política en inglés.
  • Edad mínima: 16 años. Si publicó datos siendo menor de edad, puede pedirnos en cualquier momento que dejemos de mostrarlos y borremos nuestras copias (LOPDGDD, art. 94.3).

Lo que podemos y no podemos borrar

Podemos dejar de mostrar algo en nuestro sitio web, nuestra API, nuestra pasarela y la búsqueda, borrarlo de nuestro nodo IPFS, borrar nuestras copias de los datos de ORCID y OpenAlex y dejar de mostrar sus cifras si se opone. No podemos cambiar ni borrar nada de lo registrado en la cadena de bloques, ni las copias que conservan otros nodos IPFS, su servicio de anclaje, Zenodo u otros sitios web.

Cómo ejercer sus derechos

Use la página de derechos o escriba a la dirección de contacto (pendiente). Para comprobar que una solicitud sobre una dirección viene de su titular, le pedimos que firme un breve mensaje con su cartera: no es una transacción y no se registra nada en la cadena de bloques. Si su cartera no puede firmar mensajes, acordaremos con usted otra prueba (por ejemplo, a través de su registro ORCID). Contestamos en el plazo de un mes (tres para solicitudes complejas, avisándole en el primer mes), sin coste. El artículo 94 de la LOPDGDD le permite pedir la supresión de los datos que facilitó para su publicación, a su simple solicitud.

Si no queda satisfecho, puede reclamar ante la Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es.

Última actualización: 8 de octubre de 2026.

Download this policy (Markdown)