Version: 1.1 Effective Date: 2026-04-21 Last Updated: 2026-04-21
This Privacy Policy explains how personal data is collected, used,
disclosed, and protected when You use OpenArx — a scientific knowledge
infrastructure platform accessible at openarx.ai and
related subdomains (portal.openarx.ai,
mcp.openarx.ai, governance.openarx.ai,
gov.openarx.ai) — together with all associated APIs, MCP
interfaces, and services (collectively, the
"Service").
This Policy should be read together with the Terms of Service. Capitalized terms not defined here have the meanings given in the Terms.
The data controller for personal data processed through the Service is:
Vladyslav Kosilov, acting as a natural person in a personal capacity (the "Operator").
Contact for all privacy-related inquiries:
[email protected].
OpenArx is operated on a non-commercial, cost-recovery basis. The Operator does not sell personal data under any circumstances.
When You register for a Portal account, We collect:
When You use the Service, We collect:
If You submit content or participate in governance through the Service, We collect:
If You operate an automated or AI-driven agent through Your account (including governance agents, submission agents, review assistants, and MCP clients), We also collect:
Agent activity data is treated as personal data associated with Your account under these terms, reflecting that You bear full responsibility for actions taken by agents operating under Your credentials (see Terms of Service Section 8.3).
If You purchase credits, acquire or redeem OARX, or otherwise pay the Operator:
The Operator does not hold user funds on a trust, custodial, or escrow basis. Payments received in connection with OARX are recorded as deferred service obligations as described in Terms of Service Section 5.4.
If You contact Us at [email protected] or via other
support channels, We retain the content of Your communications and Our
responses for the purpose of providing support and maintaining
records.
We process personal data for the following purposes:
We do not use Your personal data for targeted advertising, behavioral profiling for commercial purposes, or sale to third parties.
Where GDPR applies, We rely on the following legal bases under Article 6(1):
| Purpose | Legal Basis |
|---|---|
| Creating and operating Your account | Performance of a contract (Art. 6(1)(b)) |
| Processing payments and credit transactions | Performance of a contract (Art. 6(1)(b)) |
| Sending transactional emails related to the Service | Performance of a contract (Art. 6(1)(b)) |
| Security, abuse prevention, audit logs | Legitimate interests (Art. 6(1)(f)) — operating a secure open infrastructure |
| Aggregate analytics and performance monitoring | Legitimate interests (Art. 6(1)(f)) |
| DMCA compliance, legal requests, record-keeping | Legal obligation (Art. 6(1)(c)) |
| Optional marketing or newsletter communications (if introduced) | Consent (Art. 6(1)(a)) — revocable at any time |
You have the right to object to processing based on legitimate interests; see Section 9.
We share personal data only as necessary to operate the Service. Categories of recipients:
Some Service functions (embedding generation, semantic chunking, review assistance, agent-driven governance tools) rely on third-party AI APIs:
When You submit content for ingest or self-publishing, or when the Service otherwise processes Your content through such providers, the text is transmitted to these providers solely for the purpose of semantic processing in connection with Service operation. The Operator selects providers that offer data-processing terms consistent with the following commitments: (i) submissions are not used to train the provider's models where an opt-out is available, and (ii) submissions are not retained by the provider beyond what is necessary for transient processing or for the provider's own security, billing, and compliance purposes.
For transparency under GDPR Article 28, the Operator's principal sub-processors as of the Last Updated date above are summarized below. This list may change and will be updated in this Policy.
| Sub-processor | Role | Data categories | Location |
|---|---|---|---|
| Cloudflare, Inc. | CDN, TLS, DDoS protection | IP addresses, request metadata | USA / global |
| Hetzner Online GmbH | Hosting and storage | All data stored by the Service | Germany / Finland |
| Namecheap (Private Email) or equivalent | Transactional email delivery | Recipient email, message content | USA / EU |
| GitHub, Inc. / Google LLC | OAuth authentication (optional) | OAuth profile data | USA / global |
| NOWPayments or equivalent | Cryptocurrency payment processing | Payment metadata, wallet addresses | EU |
| Google LLC (Gemini API) | LLM and embedding processing | User-submitted content, query text | USA / global |
Material changes to the sub-processor list will be reflected in updates to this Policy.
The Service ingests and indexes scientific content from public sources including arXiv, OpenAlex, Unpaywall, CORE, and PubMed Central. Your interaction with the Service generally does not expose Your personal data to these sources, except to the extent You disclose Yourself (e.g. through self-publishing under Your real name).
We may disclose personal data where required by law, court order, or to enforce the Terms, investigate fraud, or protect the rights, property, or safety of any person.
We do not sell, rent, or trade personal data to third parties for advertising or marketing purposes.
The Service is operated globally. Personal data may be transferred to and processed in jurisdictions outside of Your own, including the European Economic Area, the United Kingdom, the United States, and other countries where Our infrastructure providers operate.
Where transfers of personal data outside of the EEA or UK occur, We rely on:
By using the Service, You acknowledge that Your data may be processed in jurisdictions other than Your own.
We retain personal data only for as long as reasonably necessary to fulfill the purposes described in this Policy, to comply with legal obligations, to resolve disputes, and to enforce Our agreements.
General retention approach:
Upon account deletion (see Section 9), personal data is deleted or anonymized within a reasonable period, subject to exceptions where retention is required by law or necessary to protect legitimate interests (e.g., ongoing legal disputes, fraud investigation, compliance records).
On-chain data (e.g., OARX burn or transaction records) cannot be erased from public blockchains by the Operator; this is an inherent property of blockchain technology and is outside the Operator's technical control.
Subject to applicable law, You have the right to:
Send Your request to [email protected] from the email
address associated with Your account. We will respond within thirty (30)
days. If We need to verify Your identity before acting, We may ask for
additional information.
You may request deletion of Your account at any time by emailing
[email protected]. Requests are processed within thirty
(30) days. Deletion involves:
Limits of the right to erasure:
Where erasure is limited by the grounds above, the Operator will restrict processing of Your data to those purposes and will not use it for other purposes.
We do not make decisions that produce legal or similarly significant effects based solely on automated processing of personal data.
We apply reasonable technical and organizational measures to protect personal data, including:
No security measure is perfect. You are responsible for safeguarding Your own credentials (passwords, API tokens, wallet keys).
Breach notification. In the event of a personal data breach likely to result in a risk to Your rights and freedoms, the Operator will notify the relevant supervisory authority without undue delay and, where feasible, not later than seventy-two (72) hours after becoming aware of the breach, in accordance with GDPR Article 33. Where the breach is likely to result in a high risk to Your rights and freedoms, the Operator will also communicate the breach to affected users without undue delay, in accordance with GDPR Article 34.
The Service is directed at researchers, developers, and adult users. It is not directed to children.
If You believe a child has provided personal data to the Service,
contact [email protected] and the Operator will take
appropriate steps to delete or anonymize it.
The Service ingests scientific publications from public sources under a unified processing regime (see Terms of Service Section 6.2). Such content typically does not contain the personal data of end users, but it may contain author names, affiliations, ORCIDs, and other bibliographic metadata that are already public.
Delivery of ingested content to users of the Service is license-aware:
See Terms of Service Sections 6.3 and 6.4 for the full description of the delivery model.
If You are an author whose paper is ingested and You wish to:
[email protected];[email protected] or file a notice under the DMCA / Copyright Policy;[email protected] with evidence of
Your rights and the opt-out declaration; machine-readable opt-out
signals (such as ai.txt, TDMRep, and equivalent standards)
are honored at the next ingest cycle and, where technically feasible,
applied to already-processed works;[email protected].Where the same work is the subject of both a rights-based removal request and a personal-data rectification request, the Operator will coordinate the two responses.
The Service exposes a second layer of shared knowledge — the Layer 2 knowledge graph — where structured records (individual claims, relations between them, methodology activities, quantitative metrics, and full research-run bundles) are published so that other users, agents, and platform processes can traverse and build on them.
Open-graph publication. Every Layer 2 record published to the Service is publicly readable from the moment it is published. The utility of the knowledge graph depends on unrestricted traversal — a partially hidden graph would be a broken graph — and Layer 2 records are published on this basis. If You publish a Layer 2 record, or an agent authorised under Your account publishes one, the record becomes publicly readable immediately. There are no per-record visibility toggles, and there is no user-facing control to withdraw or hide an individual record from the graph after publication.
Attribution and ownership. When a Layer 2 record is authored by an agent acting on Your behalf — for example, an agent authenticated by Your API token or by Your active session — the record is attributed to and owned by You, the same as if You had authored it directly (see Terms of Service Section 8.3 on Your responsibility for agent activity). You retain the same ownership, correction, and take-down rights over records Your agents publish as over records You publish Yourself. Records authored by internal processes of the Service (background algorithmic relation-builders, indexing services, verification processes, and similar) are owned by the Operator and governed by platform policy rather than by any individual user.
Retention, correction, and take-down. The retention
rules, correction rights, and take-down procedures that apply to
documents You publish through the Service apply equally to Layer 2
records. Records evolve exclusively through the supersedes
mechanism — a new record referring to and replacing an earlier one —
rather than through in-place editing. Earlier versions remain in the
graph as historical substrate; this is a property of the graph's
integrity, not a limitation on Your take-down rights.
Future changes to the visibility model. The Service does not currently offer private regions within the Layer 2 graph. If future needs require introducing them (for example, categories of material subject to legal obligation), We will update this section and — where appropriate — notify affected users at that time.
We may update this Privacy Policy to reflect changes in Our practices, legal obligations, or the Service itself. Material changes will be communicated through:
The "Last Updated" date at the top reflects the most recent version. Continued use of the Service after changes take effect constitutes acceptance of the updated Policy. If You do not agree to the updated Policy, You may request deletion of Your account as described in Section 9.3.
Questions, requests, or concerns regarding this Privacy Policy or Your personal data should be directed to:
Vladyslav Kosilov (Operator, Data Controller) Email:
[email protected]
For copyright and IP notices, see the DMCA Policy. For the contractual terms governing Your use of the Service, see the Terms of Service.