Skip to main content

Privacy notice · current platform scope

Account metadata stays separate from research data.

This notice describes current authentication and project-operations metadata, plus the boundary for a planned collaboration intake that is not active. It does not authorize participant data to be stored here.

No participant-level data

Research records, linkage keys, controlled extracts, and sensitive free text remain outside this site.

No provider access tokens retained

ORCID or GitHub access tokens are used only to complete sign-in and are not stored by the application.

Retention decisions remain open

Final account, request-retention, deletion, and privacy-contact procedures still require project-owner approval.

01 · Authentication

What is stored when you sign in

  • Your selected provider: ORCID or GitHub.
  • The provider's stable subject identifier for your account.
  • Your display name and email address when the provider supplies it.
  • A hashed session record, issue and expiry timestamps, and short-lived OAuth transaction state needed to complete sign-in safely.
  • A project role and status only if the project team explicitly approves membership.

Authentication confirms identity. It does not provide repository, research-data, organisation, or project-team access.

02 · Collaboration requests

What would be stored only if collaboration intake opens

Collaboration intake is currently disabled. When a formally approved policy activates it, the request record will contain:

  • The signed-in account making the request.
  • The selected area of interest and the short note you submit.
  • Request status, a response intended for the requester, and creation, update, and decision timestamps.

Do not enter participant details, confidential project material, credentials, private links, or controlled research information in the request form.

03 · Essential cookies

Cookies used for sign-in and session security

  • A provider-specific OAuth-flow cookie is used for up to 10 minutes while sign-in completes.
  • A session cookie is used for up to 12 hours to keep a signed-in account authenticated.
  • These cookies are HTTP-only and SameSite=Lax; production cookies are also Secure.

These are essential authentication cookies, not permission to access project or research data. Expired OAuth transaction records and expired or revoked session records are removed by the next daily scheduled cleanup.

04 · Retention and deletion

Decisions still to be finalized

The project has not yet approved final retention periods for account metadata and collaboration requests, a user-facing deletion workflow, or a dedicated privacy contact. This notice will be updated when those decisions are recorded. Signing out ends the current browser session; it does not yet constitute an account or request deletion.