Privacy policy
This policy explains what personal data Cabdell's services handle, why, on what legal basis, who else receives it, how long it is kept and how you can exercise your rights. It covers this website, the Cabdell indexer and API, the IPFS gateway and node, the documentation site, browser notifications and the private test sandbox. The short version comes first (In short); a summary in Spanish is at the end (Resumen en español).
Cabdell is unusual in one respect: what you sign is written on a public blockchain and cannot be deleted by anyone, ourselves included. Please read What we can and cannot delete before you publish.
In short
| Question | Answer |
|---|---|
| Who is responsible | pending, the operator of Cabdell. Contact: the contact address (pending) |
| What for | Indexing and showing the open scholarly record you and others publish on the Algorand blockchain and IPFS; verifying ORCID iDs; computing public figures about scholarly work (reputation, Thread Score, the Peer-reviewed seal, juries); the browser notifications, Zenodo drafts and sandbox you ask for; handling notices and requests; security. |
| Legal basis | Legitimate interest in an open, verifiable scholarly record; the Terms of use and the services you ask for; legal obligations for notices, orders and data-protection requests. |
| Who else receives data | Everyone, for what is public by design on the blockchain and IPFS; our host OVHcloud (France); the services we or your browser contact for a feature (Nodely, ORCID, OpenAlex, NFD, Zenodo, DataCite, push services, wallets, pinning services), some in the United States. |
| Profiling | Yes: reputation, Thread Score, seal and jury eligibility are computed from the public record. No decision is solely automated. You can object. |
| Your rights | Access, rectification, erasure, restriction, objection and portability, on the rights page; a complaint to the AEPD. What is on the blockchain cannot be deleted by anyone. |
| More | The full policy below. |
Who is responsible
The controller of your personal data is:
- Name: pending
- Legal form: pending
- Tax identification number (NIF): pending
- Address: pending
- E-mail: the contact address (pending)
You can write to us about your personal data at the contact address (pending) or through the rights page. We have not appointed a data protection officer; the same address reaches the person responsible.
What is public by design
Cabdell is an open system for publishing science. Each action you take (publishing, reviewing, commenting, voting, flagging, following, linking an ORCID iD, declaring a DOI, making a list public, answering as a juror) is a transaction signed by your wallet and recorded on the Algorand blockchain, a public ledger copied by computers around the world. Texts are stored on IPFS, a public storage network, and the blockchain keeps their fingerprint (CID).
- Your address is a pseudonym: it is not your name. But anything that links it to you (an ORCID iD, an NFD name, your name in an article) links all of the address's activity to you, publicly and for good.
- Everything recorded on the blockchain is public and permanent: the operator cannot change or remove it.
- Short texts some actions write on the blockchain itself are public and permanent too: list and journal names, descriptions and policies, flag notes and jurors' reasons.
What we process, why, on what basis and for how long
1. The public record (addresses and actions)
- Data: your address and what it did on Cabdell (publications and their versions, fields, co-authors you declared, reviews, comments, votes, flags, follows, mentions, public lists, ORCID and DOI declarations, juror answers), with dates; the short texts written on the blockchain.
- Source: you, when you sign; and the Algorand blockchain, which our indexer reads (also for actions taken with other tools than this website).
- Purpose: to index the open scholarly record and show it: the feed, article pages, profiles, search, the inbox and the notifications feed of every address, citations and the API.
- Legal basis: our legitimate interest, and the public's, in an open and verifiable scholarly record (GDPR art. 6(1)(f)), which supports the freedoms of science, expression and information. In the balance we weighed that you choose what to publish, that an address carries no name unless you link one, that we add no tracking, and that you can object and ask us to stop showing something (below). For the actions you sign through this website, also the performance of the Terms of use you accept (art. 6(1)(b)).
- Kept: on the blockchain, for ever (we cannot delete it). Our indexer's copy, for as long as the service runs; what we stop showing is masked everywhere, and our own copies are deleted where the case requires it.
2. Content on IPFS
- Data: the articles, datasets, reviews and comments you publish, and anything personal in them.
- Source: you; the IPFS network.
- Purpose: to keep a second copy of every valid publication on our IPFS node, serve it through our gateway
(
ipfs.cabdell.press) and to other IPFS nodes, check it against its fingerprint, and keep its text for search. - Legal basis: legitimate interest in preserving and serving the open record (art. 6(1)(f)); the Terms of use for what you publish through this website (art. 6(1)(b)).
- Kept: while the service runs. What we must stop showing is unpinned and removed from our node and our search.
- Your responsibility: do not publish other people's personal data without a lawful basis, and publish health, genetic or other special-category data about research participants only when it is properly anonymised (see the Terms of use).
3. ORCID iD verification
- Data: when an address declares an ORCID iD, our indexer reads the public ORCID record to check that it lists the address's Cabdell profile. For verified iDs only, it keeps the names, websites, countries and current employers shown publicly on the record, and shows the name. E-mail addresses are neither stored nor shown.
- Source: ORCID (art. 14 GDPR: this data does not come from you directly).
- Purpose: to show who stands behind an address when that person chose to link an iD; to find conflicts of interest for the Peer-reviewed seal and the juries (for example the same employer).
- Legal basis: legitimate interest (art. 6(1)(f)), started by your own declaration.
- Kept: re-read regularly (often in the first two days, then weekly); deleted when the iD is unlinked, stops being verified, or your data is withheld at your request.
- Recipient: ORCID, Inc. (United States) receives the iDs our server asks about.
4. OpenAlex citation data
- Data: for a verified ORCID iD, the counts of works and citations OpenAlex holds, by year and field; for a reviewer and the authors of an article, how many works they wrote together.
- Source: OpenAlex (art. 14).
- Purpose: to show citation counts on profiles, to judge expertise for the seal and the juries, and to find conflicts of interest from co-authorship.
- Legal basis: legitimate interest (art. 6(1)(f)).
- Kept: rechecked weekly or monthly; deleted with the ORCID data above.
- Recipient: OpenAlex (OurResearch, United States) receives the iDs our server asks about.
5. Figures about people: profiling
The indexer computes, from the public record, figures that evaluate people's scholarly work (GDPR art. 4(4)):
- reputation per field and the weight of votes (set by the contract itself, from the votes others gave);
- the Thread Score, a citation percentile of a person's articles;
- whether a review counts toward the Peer-reviewed seal (expertise, conflicts of interest from employers, co-authorship and earlier support, a verified ORCID iD);
- who qualifies for a jury, and the random draw of jurors.
Each rule is published with its numbers in the About page and the documentation, and anyone can recompute every result. Legal basis: legitimate interest (art. 6(1)(f)). Consequences: these figures help readers find reviewed and cited work and decide who may sit on a jury; they say nothing about a person's worth and are not meant for hiring or funding decisions. No decision based solely on automated processing with legal or similarly significant effects is taken (art. 22): disputes are decided by people, a jury and governance.
You can object (art. 21). On your own profile you can sign an objection note asking this service not to show your Thread Score and reputation figures and not to draw you for juries. The objection note is itself a public record on the blockchain (it says only which objections you made). Reputation stays in the contract, which uses it for the weight of your votes; we cannot change that.
6. Names and pictures from NFD
- Data: the
.algoname and avatar that the owner of an address chose on NFD (Non-Fungible Domains). - Purpose: to show names instead of bare addresses. Our server asks NFD, so your browser never contacts it.
- Legal basis: legitimate interest (art. 6(1)(f)); the owner published the name.
- Kept: in our server's memory, for up to 30 minutes.
- Recipient: TxnLab, Inc. (United States), which runs NFD, receives the addresses our server asks about.
7. Browser notifications
- Data: when you turn notifications on: the push address your browser gives (at Google, Mozilla, Microsoft or Apple), its two encryption keys, the network, the address you receive notifications for, the kinds you chose, and the dates of creation and of the last delivery.
- Purpose: to send you the notifications you asked for, encrypted end to end.
- Legal basis: a service you ask for (art. 6(1)(b)).
- Kept: until you turn them off; deleted at once when the push service says the address is gone, after repeated failures, or after 12 months without a successful delivery.
- Recipients: your browser's push service (Google, Mozilla, Microsoft or Apple, mostly in the United States), which sees an encrypted message and when it is sent. Notifications are derived from public data, so anyone can subscribe to the notifications of any address.
8. Zenodo drafts
- Data: when you ask for a DOI, the article's files and metadata (titles, the authors' names and ORCID iDs) go to your own Zenodo account, with a permission you give on Zenodo.
- Legal basis: a service you ask for (art. 6(1)(b)).
- Kept: the permission lives only in a sealed cookie in your browser, for at most an hour; our server keeps nothing. Zenodo keeps the draft under its own terms.
- Recipient: Zenodo, run by CERN (an international organisation in Switzerland); DataCite registers the DOIs.
9. Notices, data-protection requests and messages
- Data: what you send us through the notice form, the rights page or by e-mail: your name and e-mail address (optional for notices of child sexual abuse material), the item and your explanation; for a rights request, the address or ORCID iD concerned and the proof that it is yours (a signed message, never a transaction).
- Purpose: to handle notices of illegal content and orders, to answer data-protection requests, to keep a record of what we decided, and to defend against claims.
- Legal basis: legal obligations (art. 6(1)(c)): the Digital Services Act (arts. 9-18), Regulation (EU) 2021/784 on terrorist content, and GDPR arts. 12-22; and legitimate interest in keeping proof (art. 6(1)(f)).
- Kept: two years from receipt, then deleted.
- Recipients: authorities, when the law requires it (for example the police for child sexual abuse material). We do not tell the person whose content is concerned who sent a notice, unless the law requires it or you agree.
10. The private test sandbox
- Data: for invited testers: the name the operator gave the invitation, a log of the test tools used (visible to all testers) and problem reports (text, page, technical context, without keys).
- Legal basis: the invitation you accepted (art. 6(1)(b)) and legitimate interest in testing (art. 6(1)(f)).
- Kept: the action log and problem reports for six months, and they are deleted when the sandbox is reset. Nothing from the sandbox goes to IPFS or to the public networks.
11. Technical data and security
- We keep no access log. Our servers do not record the pages you visit.
- Your IP address is held in our server's memory, for at most an hour, to limit abusive request rates, and never written to disk for that purpose (the forms do not store it either).
- The error logs of our containers may contain an IP address or a page address when a request fails. Each container keeps at most 3 files of 10 MB, overwritten as they fill.
- Content-security reports your browser may send us keep only the rule, the blocked origin and the page's path.
- Your searches go to our indexer, which answers them and does not keep them (a request that fails may leave its address in the error log above).
- Legal basis: legitimate interest in the security of the service (art. 6(1)(f), recital 49).
Who else receives data
- OVHcloud hosts our server in France, as our processor under a data-processing agreement (art. 28).
- Independent services that receive data in the cases described above, each under its own privacy policy: Nodely (Algorand access, Poland), ORCID (United States), OpenAlex (United States), TxnLab/NFD (United States), Zenodo/CERN (Switzerland) and DataCite (Germany), and the push services of browsers.
- Services your own browser contacts when you use a feature, not our server:
- with a connected wallet: Nodely's Algorand API (it receives your IP address and your address), your wallet app and its connection service (Pera, Defly, Lute, WalletConnect); the Pera and Defly connection windows may load fonts from Google;
- when you publish: the pinning service you chose (Pinata, Filebase or your own IPFS node), under your own contract
with it, and the public IPFS gateway
trustless-gateway.link.
- Everyone, for what is public by design: the blockchain and IPFS are read by anyone, and our API is open.
Transfers outside the European Economic Area
Some recipients above are in the United States or are international organisations. Where a recipient is certified under the EU-US Data Privacy Framework, the transfer relies on the European Commission's adequacy decision of 10 July 2023; otherwise it relies on the safeguards the recipient offers, or is necessary for a service you asked for (art. 49(1)(b)). The Algorand blockchain and IPFS are global networks: what you publish there is copied worldwide by design.
How long we keep data
| Data | Kept |
|---|---|
| Blockchain records, public texts on the blockchain | for ever: nobody can delete them |
| Our copies of the public record and content | while the service runs; removed when we must stop showing them |
| ORCID and OpenAlex data | while the iD is linked and verified |
| NFD names and pictures | up to 30 minutes, in memory |
| Browser-notification subscriptions | until turned off, or 12 months without a successful delivery |
| Notices, rights requests and their answers | 2 years from receipt |
| Sandbox action log and problem reports | 6 months, and deleted when the sandbox is reset |
| Terrorist content we remove | a protected copy for 6 months (Regulation (EU) 2021/784, art. 6), then deleted |
| Container error logs | 3 files of 10 MB per container, overwritten as they fill |
| Access logs | none are kept |
What we can and cannot delete
| We can | We cannot |
|---|---|
| Stop showing something on our website, API and gateway, and in search | Change or delete anything recorded on the blockchain |
| Unpin and delete it from our IPFS node, and refuse to serve it to other nodes | Delete copies kept by other IPFS nodes, your pinning service, Zenodo or other websites |
| Delete our copies of ORCID and OpenAlex data, and stop showing names and pictures | Change what ORCID, NFD or Zenodo publish themselves |
| Stop showing your figures and leave you out of juries when you object | Change the reputation the contract holds |
So: treat everything you sign as public and permanent, and try things first on TestNet.
Your rights
You have the right to:
- access the personal data we hold about you and receive a copy;
- rectification of inaccurate data (on the blockchain, a later record can correct an earlier one; off it, we correct our copies);
- erasure, including, under article 94 of the Spanish data-protection law (LOPDGDD), of data you supplied for publication, at your simple request, and of data you supplied while a minor; for the blockchain, erasure means that we stop showing the data and delete our own copies;
- restriction of processing while a question is settled;
- object to processing based on legitimate interest, including the profiling above (art. 21);
- portability of the data you gave us for a service you asked for (browser notifications);
- not to be subject to a decision based solely on automated processing (art. 22).
How: use the rights page or write to the contact address (pending). To be sure a request about an address comes from its owner, we ask you to sign a short message with your wallet: it is not a transaction and nothing is recorded on the blockchain. If your wallet cannot sign messages, we agree another proof with you (for example through your ORCID record). We answer within one month, or within three months for complex requests, telling you within the first month. It costs nothing.
Complaints: you can complain to the Spanish data-protection authority, the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es, or to the authority of the EU country where you live or work. We would be glad to try to solve the problem first.
Cookies and storage in your browser
Cabdell uses no advertising, analytics or tracking cookies, and no third-party cookies. What it stores in your browser is needed for a service you ask for, or a choice you made, so no consent banner is needed (Spanish LSSI, art. 22.2). You can delete all of it by clearing this site's data in your browser.
Cookies
| Name | What for | How long |
|---|---|---|
ariadne_network | sends / to the network you chose | 1 year |
ariadne_sandbox | access to the private sandbox (invited testers only) | the browser session, or 180 days if you ask to stay signed in |
ariadne_zenodo_state | protects the Zenodo sign-in | 10 minutes |
ariadne_zenodo_<network> | the Zenodo permission, sealed | at most 1 hour |
ariadne_legal_admin | the operator's own sign-in to the administration of notices | 12 hours |
Browser storage (local storage and session storage)
- Your preferences: theme, network, citation format, bibliography order, comment order, preview and welcome
settings (
ariadne.theme,ariadne.network,ariadne.cite.default,ariadne.bibliography.sort,ariadne.comments.order,ariadne.preview,ariadne.welcome.hidden). - What you create or ask for: private lists (
ariadne.lists.<network>), co-author invitations you declined, which notifications you have read and what you have seen from people you follow, your acceptance of the Terms of use (ariadne.terms), and your pinning key (ariadne.pin.key: for the tab only, unless you tick "Remember on this device"). - Your wallet connection: kept by the wallet libraries (
@txnlab/use-wallet:v5,walletconnect,PeraWallet.Wallet,DeflyWallet.Walletand similar). - Kept automatically, on your device only: your last 8 searches (
ariadne.search.recent; "Forget recent searches" clears them) and where you stopped reading an article, for 90 days (ariadne.reading.<network>.<id>). - For the tab only: temporary state of claims, notices, the sandbox, and whether the Terms of use were already
offered when your wallet connected (
ariadne.terms.asked). - Sandbox only: the test accounts and their keys.
- Offline use: a service worker and its cache keep the offline page and the site's own files, nothing personal.
The documentation site keeps only your theme (starlight-theme) and the state of its menu (sl-sidebar-state).
Children
Cabdell is not meant for children. You must be at least 16 to use it to sign anything. If you published data while you were a minor, you can ask us at any time to stop showing it and to delete our copies, and we will do so without delay (LOPDGDD art. 94.3).
Security
We protect our servers with encrypted connections, restricted access, limits on requests and a policy that keeps uploaded files from running as part of this site. We never see your wallet's private key. If a breach put your rights at risk, we would tell the AEPD within 72 hours and you without undue delay.
Changes
We will publish any change to this policy on this page, with its date, and announce significant changes on the site before they apply.
Last updated: 8 October 2026.