01

The standard

The site may process ordinary request logs, privacy-oriented aggregate analytics, browser language and theme choices, Turnstile verification, and account, submission, message, or contact fields. D1 stores account identity, email-verification and single-use password-reset records, salted password hashes rather than readable passwords, private editorial metadata, workflow history, and messages. Private R2 storage holds immutable PDF manuscript versions up to 20 MB. Upload checks reject encrypted PDFs and detected active or embedded PDF content, but they are format checks and not an antivirus scan. Do not submit patient records, identifiable health data, or unpublished raw datasets. Contact messages pass through restricted internal email services and are not stored in the site’s D1 database.

Sources for this section: [1]

02

How it works in practice

Contributor access is limited to a verified account's own records; editorial access requires both Cloudflare Access and a separate verified administrator session. Secrets remain in Cloudflare secret storage, private manuscripts are served only as no-store downloads, and transport uses HTTPS. Closed declined or withdrawn submissions are de-identified after 24 months and their private manuscript objects and message text are removed, unless law, security, or an active integrity investigation requires limited retention. For published work, the accepted file is preserved in the version-specific Zenodo record before its private R2 copy is removed. Requests concerning access or deletion require identity verification and are logged without exposing the record publicly.

Sources for this section: [1]

Sources

  1. Data protection by design and by defaultEuropean Commission · 2024