Privacy Notice
Who is the data controller?
The controller for this service is KONSİL. For any question, request or objection about how your data is processed: [email protected]
KONSİL is currently in closed beta. When the service moves to commercial release, the controller's full legal name, address and — where applicable — registry details will be published in this section.
What data do we process?
- Public scholarly data: name, ORCID iD printed in publication records, institution, publications and research topics. Sources: OpenAlex (CC0), Crossref, Europe PMC, PubMed/NCBI, DataCite and ClinicalTrials.gov; for technical work, additionally the public repository/model records of GitHub and Hugging Face (username, repository/model name and description).
- Contact details: the email a member provides in their own profile, or the corresponding-author address printed in publication metadata (presented as needing verification).
- Account and security: ORCID iD, name, email, profile and institution details; the time and text version of consent and terms acceptance; plan and organisation membership records. We store an irreversible scrypt hash, not the password itself.
- Research archive: the idea text, selected search settings, generated report, candidate outcome statuses and impact/evidence records added by the user for each completed search. These are shown only in the account owner's archive.
- Chat: participants, subject, messages and, where needed, a translation cache. Messages are encrypted at rest. This is not end-to-end encryption (translation happens on the server).
- Usage events: technical records such as "search started / finished / failed", "profile saved", "chat opened", kept to operate and secure the service. The text of your research idea is never written to these records (only a coarse length bucket); no candidate names, emails or free text are stored, and your identity appears only as an irreversible pseudonym. Details below.
First-party measurement
KONSİL uses no third-party advertising or analytics trackers, including Google Analytics. Product measurement runs on our own server; data is not used for advertising or sold. Limited transfers to the infrastructure and AI providers described below do take place where needed to operate the service.
- Idea text is not written to the technical event log. Event records contain only a rough character-count range. The idea and report for a completed search are retained in your account archive so that you can reopen them.
- No cookies for measurement. Visitors are distinguished by an irreversible, daily pseudonym; the IP address itself is not stored and the pseudonym expires the next day, so tracking across days is technically impossible. (The session cookie that keeps you signed in is a separate, strictly necessary function and is not used for measurement.)
- Member pseudonym: your ORCID iD appears in event records only as an irreversible pseudonym. When you delete your account these event records are deleted too.
- Retention: event records are deleted automatically after 180 days by default.
- Legal basis: operating the service, fixing faults, preventing abuse and controlling cost (legitimate interests / performance of a contract). There is no profiling and no advertising purpose.
External service providers
- Anthropic API: your research idea and the profile and public scholarly records needed for AI pre-assessment and matching are processed; the relevant chat message is processed when translation is requested. Use of inputs and outputs for model training and their retention periods are governed by the provider's current terms: model training ↗ · data retention ↗.
- Resend: for transactional email such as verification, password, closed beta and organisation invitations, we transfer the recipient address; for an invitation, the name; and a single-use code or link. Research ideas and report content are not put in email.
- Scholarly data sources: OpenAlex, PubMed/NCBI, Crossref, Europe PMC, DataCite, ClinicalTrials.gov, and — for technical work — GitHub and Hugging Face may receive the query, ORCID iD or publication identifier needed for a lookup. Europe PMC receives only a publication identifier (DOI/PMID); the limitations section the authors wrote themselves is taken from the article's open-access full text and quoted verbatim in the report. No user data is sent.
- Site infrastructure: Cloudflare and Google Fonts used on the site may receive standard connection data such as your IP address and browser information when serving a request.
Purpose and legal basis
Purpose: to make research collaboration easier. For members, identity data (ORCID iD, name) is processed because it is necessary to enter into and perform the membership relationship (GDPR Art. 6(1)(b); KVKK Art. 5/2-c). Showing your profile to other members in the collaboration pool rests on explicit consent, recorded with a timestamp and withdrawable at any time. For non-members compiled from public scholarly records, the basis is legitimate interests. Data is never used for advertising or profiling, and is never sold.
Why is membership tied to ORCID?
A KONSİL account is tied to an ORCID iD; matching connects the identity declared by the user with public publication records.
- Identity: your ORCID iD rests on your own declaration; ownership is not verified. Only the works you select and confirm yourself are linked to your profile.
- Sign-in security: the closed-beta invitation code and a local password you set with KONSİL are used; the plaintext password is not stored. KONSİL does not request read or write access to your ORCID account.
- Equal access: an ORCID record is free and open to everyone (orcid.org/register), so the requirement excludes no one permanently.
Running a search requires a signed-in account. A researcher who receives a personal chat invitation may join that particular chat through its invitation link without opening an account.
Retention
Caches containing personal data are kept for a limited period (60 days by default) and then refetched from the source, so deletions and updates at the source are reflected. Technical usage events are deleted automatically after 180 days by default. Your profile, research archive, outcome and impact records are retained until you delete your account or the relevant search. If a participant deletes their account, chat messages are retained for the other participants' conversation history but the deleted account's ORCID link is removed.
Recommendation measurement — separate, voluntary explicit consent
To improve its matching, KONSİL needs to measure which recommendation was shown and what was done with it. This measurement is off by default and runs only if you give separate, explicit consent; it is independent of the membership agreement and of the pool-visibility consent. Declining does not limit the service in any way — every feature continues to work exactly the same.
If you consent, what is recorded:
- The recommendation and its position: the recommendations shown to you, their engine rank and their on-screen rank, plus a view identifier issued each time a report is opened (so that opening the same report twice can be counted separately).
- Attributes of the recommendation: fit score, whether the candidate is a KONSİL member, whether they are at your institution, geographic proximity and whether that proximity was actually known, whether contact details were shown, seniority tier and how that tier was determined.
- Role information: the contribution family and subtype the candidate was proposed for (e.g. methods, domain expertise) — not as free text but coded from a predefined list, together with whether the role could be mapped onto that list at all.
- Context: version stamps for the engine, ranker and result schemas, and the domain pack used for the search. (The language of the search is part of the search record independently of measurement consent: it determines which language the report is produced in.)
- Actions — these three only: you opened the contact detail (and through which channel), you started a KONSİL chat, you reported an outcome status. Seeing a recommendation on screen additionally creates an exposure record; opening or dismissing a recommendation is not measured at present.
- Structured outcome reason: if you mark a recommendation as “not suitable”, the reason you choose is stored as a predefined code only — out of field, too senior, unreachable, already know them, other. Any free-text note you write is never copied into the measurement records; the note is kept only as part of the outcome mark in your own archive, visible to you alone, and is deleted with it when you delete your account.
What is never copied into the measurement tables: the candidate's name, e-mail, ORCID iD, institution, the text of your research idea, the rationale text of a recommendation, draft messages, chat content, or the free-text note you write when marking a recommendation as unsuitable.
How the candidate is identified — and why this is not “anonymous”: Instead of a raw identifier, the candidate is recorded under a pseudonymous token. The token is an HMAC computed with the server's secret key and is different for every search; the ORCID iD or name cannot be computed backwards from the token, a third party who obtained a token could not tell who it refers to, and records of the same researcher across different searches cannot be joined by comparing tokens.
Link to your archive: measurement records are linked to the search they belong to through the search's identifier in your archive — your idea text and report content are never copied into the measurement tables, but through this link the records can be read alongside your archived search and are deleted together with it when you delete your account.
The withdrawal ledger: when you withdraw consent, that decision is written to a separate ledger as a pseudonymous digest (SHA-256) of your ORCID iD together with the moment of the decision. The digest alone does not reveal your identity; it can, however, be compared against a known identity — the system can compute the digest of an ORCID iD it holds and match it against the ledger (that comparison is exactly how the protection works). Its sole purpose is to make sure your "not taking part" decision survives the restoration of an older backup: on every start-up the system consults this ledger and re-applies any withdrawal that a restore has resurrected. The digest is used only for this comparison. Retention: unlike the 180-day measurement data, this ledger entry is kept indefinitely — even after you delete your account: the protection exists precisely for the moment when your account is no longer there and an old backup or another member's report might otherwise pull you back into measurement. Its legal basis is the same as the deletion ledger's: proof that the erasure/withdrawal obligation was fulfilled (a suppression list).
Legal basis of candidate-side records — an honest distinction: Measurement records of your own searches rest on your explicit consent (KVKK art. 5/1). Your appearing as a pseudonymous candidate in another member's report does not rest on your explicit consent: for members who have never been asked and for researchers who are not KONSİL members, those records rest on the legitimate interest (KVKK art. 5/2-f) of measuring the service's matching quality, under the per-search pseudonymous token. Members who have explicitly withdrawn measurement consent are never recorded on the candidate side either.
Even so, these records are not anonymous data in the sense of data-protection law: because the system holds the secret key and the search record, it can recompute a given researcher's token and locate their records. This is deliberate, and it works in your favour — it is precisely this recomputation that makes it possible to find and delete the records in which you appeared as a candidate in someone else's search when you withdraw consent or delete your account. The accurate description is that this is pseudonymised personal data, and every data-protection obligation applies to it in full.
Retention and withdrawal: these records are deleted automatically after 180 days. You may withdraw consent at any time from your account page; on withdrawal the measurement records accumulated so far (both in your own searches and where you appeared as a candidate in someone else's) are deleted and no new ones are written — even if you appear again as a candidate in another member's report, that exposure is not recorded. (Members who have never been asked for measurement consent, and researchers who are not KONSİL members, continue to be recorded under the per-search pseudonymous token described above.) No retroactive recording takes place: only what happens after you consent is measured. The legal basis for measuring your own searches is your explicit consent (KVKK art. 5/1); the basis for candidate-side records is set out separately below.
Your rights
You have the right to be informed, to rectification, to object and to erasure. Members can additionally delete their account permanently from the account page: the profile, the search archive and the technical event records are erased; chat messages are retained for the integrity of the other person's conversation but are unlinked from your account. KONSİL may send transactional email for account verification, passwords and invitations; it does not send collaboration outreach to a candidate researcher on your behalf. Novelty and feasibility outputs are an AI pre-assessment, not a systematic review. For membership terms see the Terms of Use ↗.
🚫 Remove me
If you do not want to appear in results, enter your ORCID iD, full name or OpenAlex identifier — you will no longer be shown in searches.