This privacy policy explains how Scholardemia.com collects, uses, shares, and protects personal data when you use the Scholardemia.com website and application, including our journal publishing, learning, events, careers, and collaboration features.
1. Who We Are (Data Controller)
The data controller is Scholardemia.com, whose registered office is 16 Holloway Lane, Minster Lovell, Oxfordshire OX29 0AU, United Kingdom (company registration number 10531557). For any privacy question or to exercise your rights, contact admin@scholardemia.com. This address is also our designated point of contact for regulators and authorities.
2. Data We Collect
- Account and profile data: name, email address, username, optional phone number (verified by SMS code), profile and cover images, and profile details you choose to add (biography, career history, education, research keywords).
- Content you create: documents, posts, comments, messages, journal submissions and peer reviews, news articles, project and task data, bookmarks and notes, and files you upload (images, video, audio, documents).
- Learning and events data: course enrollments, submissions, progress and review data, event registrations, check-ins, and related preferences (such as travel or dietary preferences you provide for an event).
- Career data: candidate profiles, job applications, and saved jobs or searches, where you use the careers features.
- Trial, subscription, and payment data:Premium and Teams & Labs trial or preview status and expiry, subscription interval and status, cancellation or lapse dates, Stripe customer and subscription identifiers, and records of purchases, invoices, refunds, and payment status. No-card trials do not collect a card. When payment is offered, card details are collected directly by Stripe and never touch our servers.
- Usage and device data: pages visited, actions taken, browser and device metadata, and security logs.
- Communication preferences: notification settings, newsletter subscriptions, and records of the consent you give us.
Please do not submit sensitive personal data or special-category data (for example health information, precise accessibility needs, political opinions, religious beliefs, ethnicity, trade union membership, genetic or biometric data, or information about sex life or sexual orientation) unless it is necessary for the feature you are using or the context in which you provide it. Where you choose to include such data in content, files, event preferences, accessibility requests, profile or career material, or journal/research submissions, we process it only as needed to provide the requested feature, protect users, comply with legal obligations, or support legal claims where applicable.
3. Data Collected from Google
If you connect your Google Calendar, we access:
- Calendar availability ("busy"/"free") via
https://www.googleapis.com/auth/calendar.freebusy - Calendar event metadata (titles, times, attendees, locations) via
https://www.googleapis.com/auth/calendar.events
We use this data to:
- Check availability: we call the Free/Busy endpoint to gray-out occupied slots in our scheduler UI, preventing double-booking without exposing event details.
- Synchronize events: we read your existing events so our app mirrors your schedule.
- Manage events: we create, update, and delete events when you book, reschedule, or cancel webinars or meetings in Scholardemia.com, and can request Google Meet links for newly created events.
- Keep calendars in sync: we periodically call the Calendar API to fetch updates made directly in Google Calendar.
Scholardemia.com's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell, rent, or share Google user data with third parties, and we do not use it for advertising.
4. Data from Social and Third-Party Logins
| Provider | OAuth Scopes | Data Retrieved | Purpose |
|---|---|---|---|
| openid profile email | Name, email, profile picture | User authentication and account linking | |
| public_profile email | Name, email | User authentication and account linking | |
| r_liteprofile r_emailaddress | Name, email | User authentication and account linking | |
| ORCID | /authenticate | ORCID iD, name | Researcher identity and publication linking |
We only read the profile data listed above; we do not post to your social accounts. If you connect Zotero or Mendeley, we access your reference library only to provide the citation features you request.
5. How We Use Data and Our Legal Bases
| Purpose | Data involved | Legal basis | Typical retention |
|---|---|---|---|
| Account, authentication, profiles, publishing, learning, events, careers, and collaboration | Account, profile, content, learning, event, career, and workspace data | Performance of our contract with you | Life of account or content, subject to deletion and retention rules in section 10 |
| Trials, subscriptions, renewals, cancellation, payments, receipts, refunds, accounting, and tax records | Trial and subscription state, expiry and cancellation dates, purchase records, Stripe identifiers, invoice and refund records | Performance of contract and legal obligation | Financial records retained for the statutory period described in section 10 |
| Service communications and notifications you enable | Email address, phone number, push token, notification preferences, message metadata | Performance of contract and our legitimate interest in operating the service | Life of account or preference, plus suppression records needed to honor opt-outs |
| Newsletters and marketing | Email address, subscription preferences, consent and unsubscribe records | Consent, which you can withdraw via unsubscribe links or settings | While subscribed, plus records needed to evidence consent or honor opt-outs |
| Security, fraud and abuse prevention, moderation, and legal requests | Usage/device data, security logs, reports, moderation records, account and content metadata | Legitimate interests and legal obligations | As long as needed for security, compliance, dispute, and legal-record purposes |
| Journal peer review and editorial integrity | Submissions, reviewer assignments, reviews, editorial decisions, related communications | Legitimate interests of Scholardemia, participating journals, authors, and reviewers | Per journal archival policy and deletion rules, with reviewer anonymity protected where applicable |
| Optional AI features you invoke | Content you select or type for the AI request; encrypted user API key metadata where saved | Performance of contract for requested features; consent or legitimate interests where required by context | We do not retain provider responses beyond the content you save; saved API keys remain until removed or account deletion |
6. AI Features
Scholardemia includes optional AI writing and assistance features. When you actively invoke an AI feature, the content you select or type for that request is sent to an AI provider to generate the response. If you have saved your own API key in settings, the request goes to the provider you chose (OpenAI, Anthropic, Google, DeepSeek, or Perplexity) using your key; otherwise certain features use a platform-managed provider key. Your saved API keys are stored encrypted and are never shared with other users.
We do not send your content to AI providers except when you use an AI feature, and we do not use your content to train AI models. AI providers process the submitted content under their own terms; consult the relevant provider's privacy documentation before submitting sensitive material.
7. Service Providers, Processors, and Connected Third-Party Services
We do not sell or rent your personal data. We share data with service providers and connected third-party services only as needed to operate Scholardemia or provide integrations you choose. Where we engage a provider as our processor, we use contracts that restrict their use of your data. Where you connect a third-party service or use your own provider API key, that service may also handle data under its own terms.
| Provider | Role | Purpose | Data involved | Location |
|---|---|---|---|---|
| Stripe | Payment service provider; may act as an independent controller for regulated payment activity | Payment processing for Premium, Teams & Labs, events, and courses when paid checkout is available | Name, email, subscription or purchase details; card data goes directly to Stripe | US/EU |
| Postmark (ActiveCampaign) | Processor | Transactional email and newsletters | Email address, message content, delivery metadata | US |
| Twilio | Processor | SMS verification codes and SMS notifications you enable | Phone number, message content | US |
| Google Firebase | Processor | Push notifications you enable | Device push token, notification content | US |
| Cloudflare R2 | Processor | Storage of uploaded files and media | Files you upload and associated metadata | Global (US entity) |
| AI providers (OpenAI, Anthropic, Google, DeepSeek, Perplexity) | Processor where platform-managed; user-authorized third-party service where you use your own key | AI features, only when you invoke them (see section 6) | Content you submit to the AI feature | US |
| Plausible Analytics | Processor | Cookieless, aggregate analytics on some public event pages | Aggregate page statistics; no cookies, no cross-site identifiers | EU |
| Google Calendar / Zotero / Mendeley | User-authorized connected third-party service | Integrations you choose to connect (see sections 3–4) | Data exchanged with the service you connected | US/EU |
Content you choose to publish (for example public profiles, posts, published articles, or public event pages) is visible to others according to the visibility settings you select. Workspaces, journals, and labs you join can see the content and profile information you contribute there.
Public content may be indexed by search engines or copied, cached, or archived by third parties outside our control. Deleting public content or your account removes or disassociates it from Scholardemia according to this policy, but it may not remove copies already controlled by search engines, recipients, or other third-party services.
We may also disclose information where required by law — for example in response to a valid subpoena, court order, or other legal process — or to protect the rights, property, and safety of Scholardemia.com, our users, or the public.
8. International Transfers
Some of the service providers and connected third-party services above are located in, or store data in, the United States or other countries outside the UK and European Economic Area. Where Scholardemia transfers personal data outside the UK or the European Economic Area, we rely on appropriate safeguards: the UK Extension to the EU–US Data Privacy Framework where the provider is certified, or standard contractual clauses / the UK International Data Transfer Addendum included in the relevant data processing agreement where available. User-authorized integrations and user-supplied AI provider keys may involve transfers under that third-party service's own terms.
9. Cookies
We set only cookies that are strictly necessary to operate the service:
| Cookie | Purpose | Category |
|---|---|---|
| better-auth.session_token | Keeps you signed in (set with the Secure attribute over HTTPS) | Strictly necessary |
| sch-csrf-token | Security: protects forms and API requests against forgery | Strictly necessary |
| scholardemia.beta_access | Records that you have claimed access during the beta period | Strictly necessary |
Interface preferences (such as theme) are stored locally in your browser. We do not set advertising or cross-site tracking cookies. Some public event pages use Plausible Analytics, which is cookieless and collects only aggregate statistics. Because we do not track you across sites, the app does not respond to "Do Not Track" signals.
10. Data Retention
| Data | Retention |
|---|---|
| Account, profile, and content data | For as long as your account exists; removed when you delete it (see section 12) |
| Financial and transaction records | 6 years from the end of the relevant financial year (UK tax and company law) |
| Consent and communication-preference records | While the subscription or preference is active, plus as long as needed to evidence compliance |
| Unsubscribe suppression records | Kept so we can continue honoring your opt-out |
| Data export bundles | Download link expires after 7 days |
| Security logs and backups | Rotated on a rolling basis over a limited period |
11. Security
- Data is encrypted in transit (HTTPS/TLS).
- Saved AI provider API keys are stored encrypted at rest.
- Access to personal data is limited to authorized personnel who need it to operate the service, and we maintain technical and organizational measures appropriate to the risk.
12. Your Rights, Data Export, and Account Deletion
Under UK and EU data protection law you have the right to:
- Access your data and receive a copy in a portable format
- Rectify inaccurate data
- Request deletion ("right to be forgotten")
- Restrict or object to processing
- Withdraw consent at any time (for processing based on consent)
- Complain to a supervisory authority
You can export a copy of your data and delete your account yourself from your account settings (Settings → Privacy), or contact admin@scholardemia.com. Requests are addressed within one month, free of charge.
When you delete your account: your account record, profile, and personal data are permanently removed from our production database, your active sessions are revoked, and content you authored is deleted or disassociated from you. Personal files that are not needed by surviving shared, institutional, or legally retained content — including personal media and previous data-export bundles — are deleted from object storage. Files retained with surviving content are disassociated from your account and their personal uploader attribution is removed. We delete or de-link payment-provider customer records where supported, while the payment provider may retain records it is legally required or permitted to keep for tax, accounting, fraud-prevention, security, or regulatory compliance. We retain financial and transaction records for the statutory period described in section 10 with your account link removed, keep minimal newsletter suppression records so your opt-outs keep being honoured, and retain consent history only in anonymised (hashed) form. Residual copies may persist in access-restricted off-host database backups for up to 35 days; erasure propagates as those backups rotate.
Where fulfilling a request would reveal personal data about another person — for example, the identity of an anonymous peer reviewer — we may withhold that information to the extent permitted by law.
If you are unhappy with how we handle your data, you can complain to the UK Information Commissioner's Office (ico.org.uk) or, if you are in the EU, to your local supervisory authority.
13. Children
Scholardemia is intended for adults in the academic and professional community. It is not directed at children under 16, and we do not knowingly collect personal data from them.
14. Policy Updates
We will notify users of material changes to this policy on this page and, for significant changes, via in-app notice or email. For any questions or concerns, please contact admin@scholardemia.com.