Privacy Policy
Last updated: August 2026
1. Introduction
Scauthor ("we", "our", or "us") operates scauthor.com and related services. This Privacy Policy explains what we collect, why we collect it, and your rights under privacy laws that may apply to you — including the EU/UK General Data Protection Regulation (GDPR), Malaysia's Personal Data Protection Act (PDPA), California's CCPA/CPRA, Canada's PIPEDA, and similar laws elsewhere.
Minimal data by design. Scauthor is a coordination platform, not a manuscript or data repository. We intentionally limit what we store to what collaboration requires.
2. What we store (and what we do not)
What we store
- Researcher profile — name, email, institution, field of study, short bio, avatar (optional), ORCID iD if linked, and contact preferences you choose.
- Brief paper summaries — listing title, teaser or abstract text, stage descriptions, tracker status, journal targets, and authorship metadata needed to coordinate a project. These are short text fields, not full manuscripts.
- Messages — text exchanged between matched researchers on Scauthor for coordination (timelines, roles, submission updates).
- Account & billing metadata — authentication identifiers (Firebase Auth), subscription plan/status when you pay, and transactional records from our payment provider.
- Essential technical logs — IP address, browser type, timestamps, and error logs for security and reliability. We do not use advertising or cross-site tracking cookies.
What we do not store
- Full manuscripts, PDFs, or preprints uploaded to Scauthor
- Raw datasets, lab notebooks, or large file attachments
- Your ORCID password (ORCID is used only for verification when you connect your iD)
- Full payment card numbers (handled by Stripe when billing is enabled)
Working documents should stay in your preferred tools (Overleaf, Google Docs, institutional storage). You may paste an external link in a listing or message after trust is established; Scauthor does not host those files.
3. How we use your information
- Provide the Service — tracker, Discover, messaging, authorship tools, journal and funding features.
- Recommend relevant papers based on profile fields and listing keywords you supply (not AI profiling of private content).
- Send transactional email — applications, authorship invites, reminders, billing receipts.
- Process subscriptions through Stripe when you upgrade.
- Protect the platform — fraud prevention, abuse detection, and security incident response.
We do not sell personal data. We do not use your messages or paper summaries for advertising. We do not train third-party AI models on your content.
4. Legal bases (GDPR / UK GDPR)
If you are in the EEA or UK, we process personal data on these bases:
- Contract — to provide the account and features you request.
- Legitimate interests — security, product improvement, and non-intrusive recommendations, balanced against your rights.
- Consent — where required (e.g. optional marketing email if we offer it).
- Legal obligation — tax, accounting, or lawful requests.
5. Data sharing
We do not sell personal data. We share data only with:
- Other users — according to product rules: public listing fields on Discover, profile details visible after a collaboration match, and contact information when you enable sharing.
- Service providers (processors) — Google Firebase (database, authentication), Vercel (hosting), Resend (transactional email), ORCID (identity verification when linked), and Stripe (payments). These providers process data on our instructions under contractual safeguards.
- Legal requirements — when required by law, court order, or to protect rights, safety, and integrity of the Service.
Some providers may process data outside your country. Where required, we rely on standard contractual clauses, adequacy decisions, or equivalent transfer mechanisms.
6. Data retention
We keep profile, listing summaries, and messages while your account is active and as needed to provide the Service. If you delete your account or request deletion, we remove personal data from active systems within 30 days, except where retention is required for legal, security, dispute, or backup purposes (backups are purged on a rolling schedule).
Billing records may be retained longer where tax or accounting law requires.
7. Your rights
Depending on where you live, you may have the right to:
- Access a copy of personal data we hold about you
- Correct inaccurate data
- Delete your account and associated data
- Restrict or object to certain processing
- Data portability (structured, commonly used format)
- Withdraw consent where processing is consent-based
- Opt out of "sale" or "sharing" under US state privacy laws (we do not sell data)
- Lodge a complaint with your local supervisory authority (e.g. PDPC Malaysia, ICO UK, EU DPA)
Update much of your profile in Settings. For other requests, email support@scauthor.com. We respond within the timeframe required by applicable law (typically 30 days).
8. Cookies & similar technologies
We use essential cookies (such as the Firebase session cookie) for authentication. We do not deploy third-party advertising cookies on the core application. Stripe may set cookies during checkout on their domain.
9. Security
We use HTTPS, access controls, and Firebase security rules. No internet transmission is 100% secure; please use a strong password and keep your session private on shared devices.
10. Children
Scauthor is not intended for users under 16. We do not knowingly collect data from children. Contact us if you believe a child has provided data and we will delete it.
11. Changes
We may update this policy. We will post the revised version with a new "Last updated" date and notify you of material changes via email or an in-app notice where appropriate.
12. Contact
Privacy questions or requests: support@scauthor.com
Scauthor — scauthor.com
See also our Terms of Service and Refund Policy.