Privacy Notice
Who is the data controller?
The controller for this service is KONSİL. For any question, request or objection about how your data is processed: [email protected]
KONSİL is currently in closed beta. When the service moves to commercial release, the controller's full legal name, address and — where applicable — registry details will be published in this section.
What data do we process?
- Public scholarly data: name, ORCID iD printed in publication records, institution, publications and research topics. Sources: OpenAlex (CC0), Crossref, Europe PMC, PubMed/NCBI, DataCite and ClinicalTrials.gov.
- Contact details: the email a member provides in their own profile, or the corresponding-author address printed in publication metadata (presented as needing verification).
- Account and security: ORCID iD, name, email, profile and institution details; the time and text version of consent and terms acceptance; plan and organisation membership records. We store an irreversible scrypt hash, not the password itself.
- Research archive: the idea text, selected search settings, generated report, candidate outcome statuses and impact/evidence records added by the user for each completed search. These are shown only in the account owner's archive.
- Chat: participants, subject, messages and, where needed, a translation cache. Messages are encrypted at rest. This is not end-to-end encryption (translation happens on the server).
- Usage events: technical records such as "search started / finished / failed", "profile saved", "chat opened", kept to operate and secure the service. The text of your research idea is never written to these records (only a coarse length bucket); no candidate names, emails or free text are stored, and your identity appears only as an irreversible pseudonym. Details below.
First-party measurement
KONSİL uses no third-party advertising or analytics trackers, including Google Analytics. Product measurement runs on our own server; data is not used for advertising or sold. Limited transfers to the infrastructure and AI providers described below do take place where needed to operate the service.
- Idea text is not written to the technical event log. Event records contain only a rough character-count range. The idea and report for a completed search are retained in your account archive so that you can reopen them.
- No cookies for measurement. Visitors are distinguished by an irreversible, daily pseudonym; the IP address itself is not stored and the pseudonym expires the next day, so tracking across days is technically impossible. (The session cookie that keeps you signed in is a separate, strictly necessary function and is not used for measurement.)
- Member pseudonym: your ORCID iD appears in event records only as an irreversible pseudonym. When you delete your account these event records are deleted too.
- Retention: event records are deleted automatically after 180 days by default.
- Legal basis: operating the service, fixing faults, preventing abuse and controlling cost (legitimate interests / performance of a contract). There is no profiling and no advertising purpose.
External service providers
- Anthropic API: your research idea and the profile and public scholarly records needed for AI pre-assessment and matching are processed; the relevant chat message is processed when translation is requested. Use of inputs and outputs for model training and their retention periods are governed by the provider's current terms: model training ↗ · data retention ↗.
- Resend: for transactional email such as verification, password, closed beta and organisation invitations, we transfer the recipient address; for an invitation, the name; and a single-use code or link. Research ideas and report content are not put in email.
- Scholarly data sources: OpenAlex, PubMed/NCBI, Crossref, Europe PMC, DataCite and ClinicalTrials.gov may receive the query, ORCID iD or publication identifier needed for a lookup. Europe PMC receives only a publication identifier (DOI/PMID); the limitations section the authors wrote themselves is taken from the article's open-access full text and quoted verbatim in the report. No user data is sent.
- Site infrastructure: Cloudflare and Google Fonts used on the site may receive standard connection data such as your IP address and browser information when serving a request.
Purpose and legal basis
Purpose: to make research collaboration easier. For members, identity data (ORCID iD, name) is processed because it is necessary to enter into and perform the membership relationship (GDPR Art. 6(1)(b); KVKK Art. 5/2-c). Showing your profile to other members in the collaboration pool rests on explicit consent, recorded with a timestamp and withdrawable at any time. For non-members compiled from public scholarly records, the basis is legitimate interests. Data is never used for advertising or profiling, and is never sold.
Why is membership tied to ORCID?
A KONSİL account is tied to an ORCID iD; matching connects the identity declared by the user with public publication records.
- Identity: your ORCID iD rests on your own declaration; ownership is not verified. Only the works you select and confirm yourself are linked to your profile.
- Sign-in security: the closed-beta invitation code and a local password you set with KONSİL are used; the plaintext password is not stored. KONSİL does not request read or write access to your ORCID account.
- Equal access: an ORCID record is free and open to everyone (orcid.org/register), so the requirement excludes no one permanently.
Running a search requires a signed-in account. A researcher who receives a personal chat invitation may join that particular chat through its invitation link without opening an account.
Retention
Caches containing personal data are kept for a limited period (60 days by default) and then refetched from the source, so deletions and updates at the source are reflected. Technical usage events are deleted automatically after 180 days by default. Your profile, research archive, outcome and impact records are retained until you delete your account or the relevant search. If a participant deletes their account, chat messages are retained for the other participants' conversation history but the deleted account's ORCID link is removed.
Your rights
You have the right to be informed, to rectification, to object and to erasure. Members can additionally delete their account permanently from the account page: the profile, the search archive and the technical event records are erased; chat messages are retained for the integrity of the other person's conversation but are unlinked from your account. KONSİL may send transactional email for account verification, passwords and invitations; it does not send collaboration outreach to a candidate researcher on your behalf. Novelty and feasibility outputs are an AI pre-assessment, not a systematic review. For membership terms see the Terms of Use ↗.
🚫 Remove me
If you do not want to appear in results, enter your ORCID iD, full name or OpenAlex identifier — you will no longer be shown in searches.