Legal
Privacy policy
Carbonyz collects very little, and this page says exactly what and why. If anything here reads as vague, that is a fault worth reporting.
Who is responsible
Carbonyz is an independent research project. It is not a registered company and takes no money from anyone, which is worth stating plainly: there is no commercial interest in your data behind any of what follows.
CarbonyzVienna, Austria
info@carbonyz.com
Write to that address for anything in this policy, including requests to see or delete your data, and someone will answer. If you need the identity of the responsible party in writing — to make a complaint, or to exercise a right under the GDPR — ask, and it will be given to you.
Reading the site without an account
Nothing is stored about you. The knowledge base pages are prerendered files served from a CDN. There is no analytics service, no tracking pixel, no advertising network, and no cookie set before you sign in.
The hosting provider processes technical connection data, including your IP address, in order to deliver the page and to defend against attacks. Carbonyz keeps no log of its own and stores no IP address anywhere in its database.
If you create an account
Signing up stores:
- Your email address, and a password hash if you set a password. Passwords are never stored in a readable form and cannot be read by anyone running the site.
- A username, which is public and appears on everything you post.
- Anything you choose to add to your profile: display name, affiliation, research area, a short biography, an avatar image, a website, an ORCID iD, a Google Scholar link. All of it is optional and all of it is public. Leave a field blank and nothing is stored for it.
- The date the account was created, and whether it has been marked as a verified researcher.
If you sign in with Google, Google tells Carbonyz your email address and confirms the sign-in. Carbonyz does not receive your Google password and does not gain access to any other part of your Google account.
If you take part
- Discussions. Posts, comments and the time they were written are public. If you choose anonymous posting, readers see Anonymous instead of your profile, but the account behind the post is still kept for editing, export and moderation. Votes are stored against your account but are never shown to anyone else, including moderators: scores are public, who cast them is not.
- Reports. If you report something, the report and your account are visible to moderators so a decision can be attributed. Moderator actions are written to an audit log.
- Corrections, paper submissions and claim checks. What you submit, and your account, are visible to you and to moderators. Corrections and papers are not public while under review. Claim checks start private and may become public after review; if you chose anonymous submission, public readers see Anonymous rather than your profile.
- Bookmarks. Private. No one else can read your saved list, moderators included. There is no database rule that would permit it.
- The page assistant. Your question and the assistant’s answer are stored against your account so you can find the conversation again, along with a daily count used to enforce the usage limit.
The page assistant and where your question goes
When you ask a question about a page, the text of that page, its reference list and your question are sent to a third-party AI provider that generates the answer. That provider is currently outside the European Union.
Depending on the plan in use, such a provider may retain submitted text and may use it to improve their own systems. Treat anything you type into the assistant as leaving Carbonyz. Do not put unpublished results, personal information or anything confidential into it.
Cookies
Carbonyz sets cookies only after you sign in, and only to keep you signed in. They are strictly necessary for a function you asked for, which is why there is no consent banner. Sign out and they are cleared. There are no analytics, preference-profiling or advertising cookies of any kind.
Who else processes your data
Carbonyz runs on services operated by other companies. Each one handles data only as needed to run the site:
- A hosting and content-delivery provider, which serves the pages and processes connection data.
- A database and authentication provider. The Carbonyz database is hosted in the provider’s Frankfurt region, so account and discussion data is stored in the European Union.
- An email provider, which sends sign-in and confirmation emails and therefore handles your email address.
- Google, if and only if you choose to sign in with Google.
- A third-party AI provider, as described above, and only when you use the assistant.
Some of these companies are based outside the European Union, so using the site involves an international transfer of data. Where that happens it relies on the standard contractual clauses those providers publish.
Why it is lawful to store this
- Your account and anything you post: necessary to provide the service you signed up for (GDPR Art. 6(1)(b)).
- Moderation records, the audit log and rate limits: legitimate interest in keeping a research community usable and defensible (Art. 6(1)(f)).
- Optional profile fields: your consent, given by filling them in (Art. 6(1)(a)). Clear a field and the consent is withdrawn.
How long it is kept
Account and profile data is kept until you delete the account. Assistant conversations are kept until you delete them. Moderation records are kept while the account exists, because a removal decision that cannot be reviewed is not a decision anyone can appeal.
Deleting a post or comment replaces its text and leaves a marker in the thread. This is deliberate: comments hang off one another, so removing the row itself would delete other people’s replies. The words you wrote are genuinely overwritten, not hidden.
Your rights
Under the GDPR you can ask for a copy of your data, ask for it to be corrected or deleted, object to processing, ask for it to be restricted, and ask for it in a portable form (Art. 15 to 21). Two of those are buttons rather than requests: account settings will hand you a JSON file of everything stored about you, and will delete the account outright. For anything else, write to the address above. There is no charge and no form to fill in.
You can delete your account yourself, at any time, from account settings. It happens immediately and cannot be undone: your email address, password, profile, avatar, votes, bookmarks and assistant history are deleted outright. Posts and comments you wrote stay by default, shown as written by a deleted account, and you can choose to have their text removed as well. The rows themselves survive either way, because deleting them would take other people’s replies with them.
If you are unhappy with how a request was handled you can complain to the Austrian data protection authority, the Datenschutzbehörde, or to the authority where you live.
Changes
Carbonyz is early and this policy will change as the site grows. Any change that affects what is collected or who processes it will be reflected here with a new date. See also the terms of use and the Impressum.