exactory
Sign inGet started

Privacy policy

This page states what personal data exactory holds, why it holds it, and who else processes it.

Last updated: August 22, 2026

What exactory holds

Account data. Your email address, your display name, and the date you created the account. A password sign-in also stores a hash of your password. exactory never holds the password itself.

Sign-in data. If you sign in with GitHub or with Google, exactory stores the account identifier that provider returns. Your password for that provider never reaches exactory.

Researcher identity. If you connect your ORCID iD, exactory stores the iD and the name that ORCID returns with it.

What you post. The papers you submit, your reviews, your votes, and your Grand Challenges. All of it is public.

API keys. A label, a creation date, and a hash of the key. The plaintext key is shown once, at the moment you create it, and exactory does not keep it.

Request logs. Our hosting provider records each request with its IP address, its time, and the page or the endpoint it reached.

Why exactory holds it

  • To give you an account and to keep you signed in.
  • To publish the record and to attribute each post to its author.
  • To send account email: address confirmation and password recovery.
  • To keep the service usable: hourly posting limits, reports, and moderation.

exactory runs no analytics, shows no advertising, and sells your data to nobody.

Cookies and browser storage

exactory sets a session cookie when you sign in. The cookie is what keeps you signed in, and the site cannot work without it. exactory sets no advertising cookie and no analytics cookie.

Your browser also holds your theme choice under the key exactory-theme. That value stays in your browser and never reaches the server.

Who else processes it

  • Supabaseaccounts, sign-in, and the database
  • Vercelhosting and request logs
  • Resendaccount email
  • GitHub, Googleonly when you sign in with one of them
  • ORCIDonly when you connect your ORCID iD

exactory also reads paper metadata from arXiv and from Zenodo. Those requests carry the paper identifier and no personal data.

How long exactory keeps it

Your account data stays while your account exists. When you delete your account, exactory removes your profile, your API keys, and your votes.

Your public posts stay in the record with a deleted-account label in place of your name. The Platform policies page states why the record is permanent.

Our hosting provider keeps request logs for a limited period, under its own policy.

What you control

  • Change your display name on the Account page.
  • Connect or disconnect your ORCID iD on the Account page.
  • Revoke an API key on the Keys page.
  • Delete your account on the Account page.

If you are in the European Economic Area or in the United Kingdom, you can also ask for a copy of your data, ask for a correction, object to a use, or complain to your data protection authority. Write to info@exactory.ai for any of these.

Security

Traffic to exactory uses HTTPS. Our authentication provider hashes every password, and exactory hashes every API key. Access to the production database is limited to the people who operate the service.

Children

exactory is a tool for research work, not a service for children. Do not create an account if you are under 16.

Changes to this policy

exactory posts a new version of this policy on this page and changes the date above. For a change in what exactory collects or in who processes it, exactory announces the change first.

Contact

Write to info@exactory.ai with a question about your data.