Privacy

What SciFlow collects, why, and how to get it back or delete it.

Last updated 16 August 2026 · sciflow.eu

The short version

You can read the entire feed without an account and without accepting anything. SciFlow stores no IP addresses, sets no advertising cookies, and never sells or shares personal data. If you create an account, the only identifying things held are your email address and your name.

If you do not have an account

Nothing about you is stored in the database. Three things happen anyway:

WhatWhere it goes
Google Analytics — which papers get opened, searches run, filters applied, share buttons used, and whether a feed was subscribed to Google. Until you accept the banner this runs cookieless, with no identifier stored on your device. Accepting sets a _ga cookie. Declining keeps it cookieless. Either way you can be counted; the choice controls the cookie.
Web server log — the page requested, time, status, and browser user-agent Our server, deleted after 14 days. No IP addresses and no query strings are recorded, so what you type into the search box does not appear in it.
Your browser's local storage — theme, your cookie choice, and whether panels are open Stays on your device. Never sent to us. Clearing site data removes it.

If you have an account

All of the above, plus these rows in our database:

DataWhy
Email addressTo sign you in, to send a password reset if you ask for one, and — only if you switch it on — to send the weekly digest. Never sold, never shared, and never used for marketing.
First and last nameTo address you in the interface.
Institution (optional)To understand who the tool is for. You may leave it blank and nothing changes.
PasswordStored only as an Argon2 hash. We cannot read it.
Papers you have read, and whenTo dim them in the feed so a second pass shows only what is new.
Bookmarks and notesBecause you saved them.
Saved filter setsBecause you named them, and to count what has arrived since you last looked.
Session tokensTo keep you signed in for 30 days.
Whether each saved set is in your weekly digestSo the digest knows what to include. Off for every set unless you turn it on.
The date you agreed to receive the digestThis is our record that you opted in. Cleared the moment you unsubscribe.
An unsubscribe tokenA random string that lets the unsubscribe link in an email work without signing in. Created only when you opt in. It can do nothing except stop the emails.

The weekly digest

It is off unless you switch it on, per saved set, and you are asked to agree before the first one is enabled. It arrives on Tuesdays at 07:00 UTC, lists what is new in the sets you chose, and is not sent at all in a week with nothing new.

Every message carries a link that unsubscribes you without signing in, and you can switch sets off in SETS at any time. Unsubscribing clears our record of your consent as well as switching off every set. Your account, bookmarks and saved sets are untouched by it — it only stops the email.

Your reading history is the most revealing thing here. It is used only to drive read-state and unread counts in your own account. It is never profiled, never sold, never sent to Google, and never used to advertise to you. No account identifier is sent to Analytics, so activity there cannot be connected to your account by us or by Google.

Your rights

Under the GDPR you can access, correct, export or delete your data. Two of these are buttons rather than requests — open ACCOUNT while signed in:

For anything else — correcting a name, or a question about the above — email sciflow.adm@gmail.com. You also have the right to complain to your national data protection authority.

Legal basis and retention

Who else is involved

Paper metadata comes from Europe PMC, bioRxiv and Crossref. That is public bibliographic information about publications, not about you.

← back to the flow