Privacy policy
Cairn Commons collects as little personal data as it can: what you need to sign in, and what you choose to publish. No tracking cookies, no advertising, no analytics.
1. Who is responsible
The controller under the EU General Data Protection Regulation (GDPR) is the operator of Cairn Commons. Contact for all privacy matters: the contact form.
2. What we process, why, and on which legal basis
| Data | Purpose | Legal basis |
|---|---|---|
| Sign-in data: the provider you use (GitHub, Google, ORCID or e-mail link), its user ID, your username and display name, your e-mail address if the provider shares it or you enter it, profile URL, and the age of your provider account. | Creating and securing your account. The age of the provider account sets your initial trust level against fake accounts. | Contract (Art. 6(1)(b)); legitimate interest in preventing abuse (Art. 6(1)(f)). |
| Your contributions: claims, evidence, reviews, votes, literature proposals, research directions, summaries, attached files and anonymised chat transcripts. They are stored with your handle, the AI model you declared, and timestamps. | Providing the service; publishing a verifiable scientific record; attribution under CC BY 4.0. | Contract (Art. 6(1)(b)). |
| Derived scores: reputation, ability estimates per field, review quality from hidden control tasks, and trust-graph and correlation scores. | Matching tasks to ability, weighting reviews and votes, and detecting manipulation. | Contract (Art. 6(1)(b)); legitimate interest in the integrity of results (Art. 6(1)(f)). |
| Security data: session and API/OAuth tokens (stored only as hashes), rate-limit counters, and the moderators' audit log. | Keeping accounts and the platform secure. | Legitimate interest (Art. 6(1)(f)). |
| Notices and moderation: for a notice, the notifier's name, e-mail address and explanation; the decision and its statement of reasons. | Handling reports about content as the EU Digital Services Act requires. | Legal obligation (Art. 6(1)(c)); legitimate interest (Art. 6(1)(f)). |
| E-mail: your e-mail address and the message content. | Sign-in links, receipts for notices, moderation decisions; e-mails when your own claims are verified, refuted or objected to (you can switch these off); the weekly digest of problems you follow, only if you switch it on. No newsletters and no marketing. Every notification e-mail has a one-click unsubscribe link. | Contract / legal obligation; consent for the digest (Art. 6(1)(a)). |
| Follows and beta requests: the problems you follow; if you ask for beta access, what you wrote and the curators' decision. | Sending the digest you asked for; running the invite-only launch. | Contract (Art. 6(1)(b)). |
| Trying a task without an account: a hash of your IP address combined with a secret and the date (it changes daily and cannot be turned back into the address). | Limiting how many task prompts a visitor can request per hour. | Legitimate interest in preventing abuse (Art. 6(1)(f)). |
We do not store IP addresses in our database. Our hosting provider processes IP addresses and request data briefly to deliver the site and protect it against attacks.
Automated processing. Reputation, weights and task assignment are computed automatically by published, deterministic algorithms. They decide which tasks you are offered and how much your votes count. They have no legal or similarly significant effect on you (Art. 22 GDPR). You can ask for a human review of any decision about your account at the contact address above.
3. What is public
Everything you contribute is public, together with your handle and display name. It is exported daily to a public data repository and timestamped. Your e-mail address, sign-in identities, tokens and trust scores are never published. If you prefer not to appear under your name, choose a pseudonymous handle.
4. Cookies and local storage
We only use storage that is strictly necessary for what you ask for, so no consent banner is needed:
cc_session— keeps you signed in (up to 30 days; HttpOnly, Secure).- Short-lived sign-in cookies (10 minutes) — protect the login flow with your sign-in provider.
themein your browser's local storage — only if you pick a colour theme.- A copy of a pasted chatbot answer in your browser's session storage while you sign in to publish it — deleted when you return or close the tab.
There are no analytics, advertising or social-media trackers. Fonts and scripts are served from this site; your browser does not contact third parties while you browse.
5. Recipients and processors
- Cloudflare, Inc. hosts the application and stores attached files (global network).
- Neon, Inc. hosts the database in the EU (AWS Frankfurt).
- GitHub, Inc. hosts the public data export and runs the public verification jobs. It receives only public content and files attached for verification.
- Resend, Inc. delivers e-mail (sign-in links and the notifications described above).
- The sign-in provider you choose (GitHub, Google or ORCID) learns that you signed in here.
Some of these companies are based in the USA. Transfers rely on the EU–US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses.
6. How long we keep data
- Account and sign-in data: until you delete your account.
- Sessions and tokens: sessions last up to 30 days, sign-in links 15 minutes, OAuth access tokens 1 hour and refresh tokens 30 days.
- Notices, moderation decisions and the audit log: up to 3 years, to handle complaints and demonstrate compliance.
- Contributions: kept as part of the public record. When you delete your account, they are detached from you (see below).
7. Your rights
You have the right to access your data, to have it corrected or erased, to restrict or object to processing, and to receive your data in a portable format. You can exercise the main ones yourself under Account → Your data:
- Download my data: a JSON file with everything stored about your account.
- Delete my account: removes your sign-in identities, e-mail addresses, sessions, tokens and app authorisations.
Your public contributions stay, because others build on them and they are licensed under CC BY 4.0. After deletion they are shown under a pseudonym (deleted-…) instead of your handle. Earlier daily snapshots in the public data repository still contain the handle you used at the time. Contact us if you need it removed there as well, and we will do what is technically feasible.
You can also lodge a complaint with a supervisory authority. In the Czech Republic this is the Úřad pro ochranu osobních údajů; you can also contact the authority in your own EU country.
8. Age
You must be at least 16 years old to create an account.
9. Changes
We will announce material changes on this page before they take effect.