Legal
Privacy Policy
Effective 2 October 2026
1. Who is responsible
EldoNova+ Technologies operates Unisphere and is responsible for the personal information described here. Each journal's editors also use the information in their journal's submissions to run peer review. Contact us at privacy@unisphere.com.
2. What we collect
- Account: name, email address, affiliation, ORCID iD if you add it, and what you told us you'd like to do on Unisphere. Your password is stored only in a scrambled form we cannot read.
- Submissions: manuscripts, files, author lists with each author's name, email and affiliation, declarations, and the editorial history.
- Reviews: your review, your comments to the editor, and your conflict of interest declarations.
- Repository deposits: files and the descriptions, author names and affiliations you enter.
- Payments: invoice amounts, waiver claims (including the country you declare) and Stripe payment references. Not your card details.
- Technical: sign-in records and the IP address your requests come from, used to keep accounts secure.
3. How we use it, and why we may
- To provide the service you asked for (performing our agreement with you): your account, submissions, reviews, publication, payments and the emails and in-app notifications about them.
- To keep Unisphere safe (our legitimate interest): bot checks, preventing abuse, and investigating misconduct such as fabricated work or manipulated review.
- To keep the scholarly record (our legitimate interest, and the public interest in research): published articles and records stay available permanently.
- To meet legal obligations, such as keeping payment records for tax purposes.
4. Who can see what
- Editors of a journal see the submissions made to it, including author details, reviews and reviewer identities. An editor never sees this for a manuscript they wrote.
- Reviewers see the manuscript and its authors' names, not the cover letter or other reviewers' reports.
- Authors see reviews of their manuscript after a decision, without the reviewers' names.
- Everyone can see published articles and repository records, including the authors' names, affiliations and ORCID iDs shown with them.
- Our administrators can see account details to support and protect the service.
5. Services that process data for us
We use these providers to run Unisphere. They act on our instructions and may process data outside your country, including in the United States.
- Supabase: Hosts our database, sign-in system and file storage: your account, submissions, reviews and files.
- Cloudflare: Serves the website, and runs the Turnstile check on sign-in and sign-up that tells people from bots.
- Stripe: Takes article processing charge payments. Each payment goes directly to the journal's own Stripe account: the journal is the seller and holds the payment record (with your name, email and payment details) to handle refunds and tax. Card details go directly to Stripe; we receive only the payment outcome, the amount and our commission. Editors-in-chief also share their journal's business details with Stripe when they connect it.
- WSMailPro: Delivers our emails, so it receives your email address and the message content.
- Anthropic: Runs the AI editorial assistant, only for journals whose editors switch it on. It receives the manuscript PDF and its title and abstract, and does not use them to train its models.
- Google Fonts: Supplies the site's fonts. Your browser fetches them from Google, which sees your IP address.
- Have I Been Pwned: Checks whether a new password has appeared in a data breach. Only the first five characters of a scrambled (hashed) form of the password are sent, which cannot reveal it.
We do not sell or rent personal information, and we do not use advertising trackers.
6. How long we keep it
- Account information: while your account exists.
- Published articles and repository records: permanently, as part of the scholarly record.
- Unpublished submissions and reviews: while the journal needs them for its editorial record, and as long as your account exists.
- In-app notifications: deleted 180 days after you read them.
- Payment records: as long as tax law requires.
- Review invitation links: the secret part of the link is removed from our records once the email has been sent.
7. Your rights
Depending on where you live, you can ask us to:
- give you a copy of your personal information;
- correct it (you can change your name, affiliation and ORCID iD yourself in Settings);
- delete it, or restrict or object to how we use it;
- send it to you in a portable format.
Write to privacy@unisphere.com. We reply within 30 days. Deleting an account does not remove published articles or records, which stay credited to the names they were published under, and we keep what the law requires us to. If you are in the EU or UK you may also complain to your data protection authority. California residents have the right to know, delete and correct, and not to be discriminated against for using these rights; we do not sell or share personal information.
8. Security
Data is encrypted in transit and at rest by our hosting providers. Access is controlled in the database itself, so each person can read only what their role allows. Passwords must be at least 12 characters and are checked against known breaches.
10. Children
Unisphere is not intended for anyone under 16, and we don't knowingly collect their data.
11. Changes
We will post any change here with a new effective date, and ask you to review a material change the next time you sign in.
