Papertrek

Privacy

Last updated: 21 August 2026

The short version

Papertrek holds your manuscripts, the account details needed to log you in and write to you, and a small amount of technical data that keeps the service working. It runs on a server in Germany. Nobody sees your work unless you share it. You can export everything or delete your account at any time, and deletion is immediate.

What’s stored

  • Your name and email address, so you can log in and we can write to you.
  • Your ORCID iD, if you sign in with ORCID or import from it.
  • The date the beta founder note was sent to you — stored so it can only ever be sent once. It is in your export and it goes when your account goes.
  • Which entries of your ORCID record we have already offered you, kept as ORCID’s own reference numbers for them — no titles, no DOIs. That is what lets the nightly sync leave a work you deleted deleted, instead of adding it back the next night. It goes when your account goes.
  • Everything you enter about your work: titles, abstracts, notes, co-authors, journals, submissions, reviewer notes, deadlines and links — and each work’s stage history, which the app records as you move it and you can edit or clear.
  • A session cookie, so you stay logged in — plus, stored with the session, the IP address and browser you signed in from. That is how a session can be told apart from an intruder and how abuse is rate-limited; it is kept while the session lives (up to 30 days) and is never used to profile you. No tracking cookies, no third-party analytics, no ad-tech.
  • Bug reports you send from inside the app: your message, the page you were on, your browser, the app version, and — if you reported a crash — its error reference. The operator reads these next to your name and email in order to answer them.
  • How you found us, if you register: when the link that brought you to the signup page carried a campaign tag (say, “reddit”) or came from another website, that tag and that site’s address are written once to your account at registration — alongside your answer, if you give one, to the one-question “How did you hear about Papertrek?” in the app. This is a single note made at signup, not tracking: nothing is stored on your device for it, nothing records your browsing, and it is never updated afterwards. Visitors who never register leave nothing.
  • Anonymous usage counters: how often a feature is used per day — one number per feature per day, nothing else. No user id, no account id, no IP address is stored with these counts, so they cannot be traced back to you. They exist to learn which features matter during the beta.
  • Anonymous visit statistics on the public pages (this site and the login screens — never the app you log into): a self-hosted, cookie-free analytics tool (Umami) on our own server records page views with referrer, browser, operating system, device type, screen size, language and approximate location (country and city, derived from the IP address — the IP itself is not stored). It stores nothing on your device, visitors are distinguished by a hash that changes daily, and the data never leaves our server.
  • Error logs. When something fails — a mail that will not send, an ORCID lookup that times out — the server writes a line about it, which can contain an email address or an ORCID iD. These are operational logs on our own machine, kept no longer than needed to fix the problem. There is no web access log: nothing records which IP address requested which page.

Why, and on what legal basis

  • Running the service— your account, your manuscripts, the calendar feed, sharing links, and the emails that make an account work (confirmation, password reset, deletion receipt): performance of our contract with you, Art. 6(1)(b) GDPR. Without this data there is no service; providing it is required to have an account.
  • Deadline reminders — also contract performance: they are a feature you switched on by creating a deadline, and you can delete the deadline or mark it done to stop them.
  • The beta founder note— the single message the operator sends during the open beta, in your first week, asking what to fix: our legitimate interest in learning what is wrong with the software while it is still being built, Art. 6(1)(f) GDPR. It is sent once per person and never again. You can object at any time under Art. 21 GDPR — the message says so and tells you how, and one reply is enough. Objecting costs nothing but the reply.
  • Session IP and browser, rate limiting, error logs, backups— our legitimate interest in keeping the service secure, available and recoverable, Art. 6(1)(f).
  • Anonymous counters and visit statistics— legitimate interest, Art. 6(1)(f), in knowing which features are used and whether anyone reads these pages. Neither can be traced to a person.
  • The signup-source note— legitimate interest, Art. 6(1)(f), in learning which of the handful of places we talk about Papertrek actually brings researchers here during the beta. It is ordinary account data: included in your export, deleted with your account.
  • Payments — contract performance and legal obligation, once anything is actually sold. Papertrek is free during the beta and no payment data is processed today.
  • No processing here relies on consent, so there is no consent to withdraw. No automated decision-making or profiling takes place.

Who else sees it

Nobody sees your work unless you share it: your data is private to your account and isolated at the database level. These are the routes by which anything leaves the server.

  • Hosting.The application, its database and its backups run on servers operated by netcup GmbH (Germany) under an Art. 28 data processing agreement. Your data is stored in the EU.
  • Email. Papertrek sends you a confirmation link, password resets, a deletion receipt, and — if you have deadlines — a reminder digest. Those digests contain the titles of your deadlines and the manuscripts they belong to, so those titles travel through the mail servers of netcup GmbH (Germany, same agreement) to your mailbox. During the open beta you also get one personal note from the operator, about a day after you sign up, asking what he should fix; it contains nothing but your first name, it is sent once and never again, and replying to it writes to him directly. If you would rather not have it, one reply saying so is enough — the note itself says that too.
  • The contact form. What you write on /contact — your message and the address you give for a reply — is emailed to the operator and not stored anywhere else. Nothing about you is kept if you never write.
  • Crossref. When you fetch or import metadata we ask Crossref about a DOI. That request tells Crossref that a DOI was looked up, not who looked it up.
  • ORCID. When you import, we ask ORCID for the public works on your record. If you have connected your ORCID iD, we also do this automatically once a day so new publications appear on their own — without you present. That request contains your ORCID iD, so ORCID can see which researcher was looked up and when.
  • Payments. When Papertrek starts charging, subscriptions will be handled by Paddle.com Market Ltd as Merchant of Record. We never see or store card details. Nothing is sold during the beta, so no payment data is shared today.
  • Anyone you give a link to. See the next section — those are your decisions, and each is reversible.

Crossref and ORCID are based in the United States, and Paddle in the United Kingdom. What reaches them is narrow — a DOI, an ORCID iD, or (later) checkout details you enter yourself — and each is contacted because you asked for a feature that needs them.

What you can share, and how far it reaches

  • A work you mark public is readable by anyone holding its link. Turning sharing off kills the link immediately.
  • Your publication page at /u/your-name lists the works you have marked public, under your name. It is a public web page: search engines can index it if they find it. The embeddable version of the same list asks search engines not to.
  • A supervisor link shows anyone holding it the titles of all your works — including ones you have not made public — which stage each is in, and your open deadlines. It never shows your notes, reviewer comments or files. Delete it in Settings and it dies at once.
  • Your calendar feed needs no password and carries your deadline titles and the manuscript titles they belong to. If you subscribe to it in Google Calendar, Outlook or Apple Calendar, that provider fetches and stores those titles under your own account there. Treat the link as private; you can regenerate it in Settings, which kills the old one.

Co-authors and other people you record

Papertrek stores the co-authors you enter or import — usually a name, sometimes an ORCID iD — as part of your records. Some of it arrives from Crossref or ORCID metadata rather than from you. It is used only to describe your work, never to build a profile or to contact anyone. A co-author who finds themselves on a page of yours can write to the address below, and we will help you correct or remove the entry.

How long it is kept

  • Your account and everything in it: until you delete it.
  • Login sessions, with their IP address and browser: up to 30 days.
  • Bug reports: until you delete your account.
  • Anonymous counters and visit statistics: kept indefinitely — they contain no personal data to expire.
  • Encrypted backups: 14 days on the server, 90 days offsite, then deleted. They exist to survive a dead machine and are never opened to restore one account.

Your data, and your rights

Settings has a one-click JSON export — your account, works, submissions, rounds, deadlines, authors, journals, files, bug reports and sharing links — and account deletion. Deletion is permanent and immediate: there is no soft-delete, and no backup we will restore for you afterwards. Export first if you want a copy.

You have the right to access your data, to have it corrected, to have it deleted, to restrict or object to how it is used, and to take it elsewhere. Export and deletion are the two buttons in Settings. For anything else — including correcting your name or email address, which has no button yet — write to the address below and it will be done. You may also complain to a supervisory authority; for the operator that is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, though you may approach the authority where you live.

Who is responsible, and how to reach us

Papertrek is operated by Dr. Marian Sauter, Schlößlesgasse 3, 89077 Ulm, Germany — the controller in the sense of Art. 4(7) GDPR. Write to contact@papertrek.app about anything on this page; full details are in the imprint.