Privacy Policy

Last updated: January 15, 2026

Overview

PostScholar ("we," "our," or "us") operates an academic discussion platform for published research. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

We are committed to protecting your privacy and complying with applicable data protection laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

Information We Collect

Information You Provide

  • Account Information: When you register, we collect your email address, username, and password (stored as a cryptographic hash).
  • Profile Information: You may optionally provide a display name, bio, affiliation, location, website URL, Twitter handle, Google Scholar profile, and profile picture.
  • Content: We store discussions, comments, bookmarks, and other content you create on the platform.
  • ORCID Verification: If you verify as an author via ORCID, we store your ORCID iD and verification status for specific discussions.

Information Collected Automatically

  • Usage Data: We collect information about how you interact with the platform, including pages viewed, features used, and actions taken.
  • Device Information: We collect device type, browser type, IP address, and operating system.
  • Cookies: We use session cookies to keep you signed in. See "Cookies and Tracking" below for details.

Information from Third Parties

  • OAuth Providers: If you sign in via Google, GitHub, or ORCID, we receive basic profile information (name, email, profile picture) from those services.
  • Research Metadata: We fetch paper metadata from CrossRef, DataCite, and other academic APIs based on DOIs you provide.

How We Use Your Information

We use your information for the following purposes:

  • Provide the Service: To operate the platform, display your contributions, and enable discussions.
  • Authentication: To verify your identity and maintain your session.
  • Communication: To send you notifications, mentions, and service updates.
  • Moderation: To review reported content and enforce our Terms of Service.
  • Analytics: To understand usage patterns and improve the platform.
  • Legal Compliance: To comply with legal obligations and enforce our policies.

Sharing Your Information

Public Information

The following information is publicly visible to all users and visitors:

  • Your username and display name
  • Profile information you choose to add (bio, affiliation, website, etc.)
  • Discussions, comments, and other content you post
  • ORCID verification badges (only for discussions you verify)

Service Providers

We share data with third-party service providers who help us operate the platform:

  • Hosting: Render (infrastructure), Neon (database)
  • Email: Email service providers for transactional emails
  • Analytics: Aggregated usage analytics (no personal identifiers)

Legal Requirements

We may disclose your information if required by law, court order, or government request, or if necessary to protect the rights, property, or safety of PostScholar, our users, or others.

Business Transfers

If PostScholar is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you via email and/or a prominent notice on the platform before your data is transferred and becomes subject to a different privacy policy.

What We Do Not Do

We do not sell, rent, or trade your personal information to third parties for their marketing purposes.

Data Retention

We retain your information for as long as your account is active or as needed to provide services. Specific retention periods:

  • Account Data: Retained until you delete your account.
  • Content: Discussions and comments remain visible but are anonymized after account deletion.
  • Logs and Analytics: Retained for up to 90 days for security and debugging purposes.
  • Backups: Deleted data may persist in backups for up to 30 days before permanent deletion.

Your Rights

Depending on your location, you may have the following rights regarding your personal data:

GDPR Rights (EEA, UK, Switzerland)

  • Access: Request a copy of your personal data.
  • Rectification: Correct inaccurate or incomplete data.
  • Erasure: Request deletion of your account and personal data.
  • Restriction: Request limited processing of your data.
  • Portability: Receive your data in a structured, machine-readable format.
  • Object: Object to processing based on legitimate interests.
  • Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.

CCPA Rights (California)

  • Know: Request disclosure of personal information collected, used, and shared.
  • Delete: Request deletion of your personal information.
  • Opt-Out: Opt out of the "sale" of personal information (note: we do not sell personal information).
  • Non-Discrimination: You will not be discriminated against for exercising your rights.

How to Exercise Your Rights

To exercise any of these rights, please contact us at hello@postscholar.org or use the account deletion feature in your settings. We will respond within 30 days.

Cookies and Tracking

Session Cookie

We use a single httpOnly session cookie to keep you signed in. This cookie:

  • Is essential for platform functionality
  • Cannot be accessed by JavaScript (httpOnly flag)
  • Is transmitted only over HTTPS (secure flag)
  • Expires after 30 days of inactivity

No Third-Party Advertising Cookies

We do not use third-party advertising cookies, social media trackers, or cross-site tracking technologies.

Security

We implement industry-standard security measures to protect your data:

  • Encryption: All data transmitted over HTTPS; database connections use TLS.
  • Password Security: Passwords are hashed using bcrypt with per-user salts.
  • Access Controls: Database access is restricted to authorized personnel only.
  • Regular Updates: Dependencies and infrastructure are kept up to date.

While we strive to protect your data, no method of transmission or storage is 100% secure. If you discover a security vulnerability, please report it to hello@postscholar.org.

International Transfers

PostScholar is operated from the United States. If you are accessing the service from outside the U.S., your information will be transferred to, stored, and processed in the U.S.

For users in the EEA, UK, and Switzerland, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate protection for your data when transferred internationally.

Children's Privacy

PostScholar is not intended for users under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected data from a child under 13, we will delete it promptly.

If you believe we have inadvertently collected information from a child under 13, please contact us at hello@postscholar.org.

Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be noted on this page with an updated "Last updated" date. Continued use of the service after changes constitutes acceptance of the updated policy.

For significant changes that affect your rights, we will provide additional notice via email or a prominent platform notification.

Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

We will respond to all requests within 30 days, or as required by applicable law.

Terms of Service · ← Back to home