Your data and your rights
See what OSCR holds about you, and use your rights under the EU's General Data Protection Regulation (GDPR): access, erasure, objection, rectification, the deletion of your account. You ask signed in, and the answer comes to this page: OSCR has no email address, and asks for none. The privacy page lists everything the registry holds, why, and for how long.
Sign in to ask
A request is made signed in: it is how the registry knows that the data is yours, and where its answer comes back. No email address is asked for or sent.
- Sign in with ORCID: if you are an author, your ORCID iD is what ties your contact details to you, and the answer is automatic
- Sign in with GitHub
- Sign in with Google
Signed in with GitHub or Google only, the registry cannot tell by itself which authors' contact details are yours: such a request waits for the operator, who answers it within one month. Link your ORCID iD for an automatic answer.
Request received
Your requests
None yet.
What the site's database holds about your account
— a JSON file of what this page shows, the answers to your requests included, made in your browser
What OSCR may hold about you
- Your account, if you signed in
- The name your provider gave, your ORCID iD and GitHub login once linked, the identifiers of your linked identities, your sessions (a short description of the browser, never an IP address), your roles. Shown on this page once you are signed in.
- Your requests
- What you submitted, claimed, corrected, validated or asked to remove, with the decisions; and, on the operator's computer, the moderator's log of those decisions (12 months).
- Your contact details, if you are an author of a paper the registry read
- What the paper publishes about how to reach you: email address, given and family names, ORCID iD, organisation, postal address and affiliation — kept privately, to cite the authors of the code and to reach you about your own work; never shown, never published, never used for mass email. The registry recognizes them as yours by your ORCID iD only: a name, a GitHub login or a Google account proves nothing.
- Your name in the published records
- Your name, ORCID iD and affiliations as a paper and its public metadata publish them: that is the public record of the paper, which this page does not change. To have part of a record removed, use its removal request.
How a request is answered
- OSCR's machine reads the requests every 10 minutes or so. It answers by itself what it can prove: access (your account's data; and, signed in with your ORCID iD at orcid.org, each contact detail kept under that iD, your email address masked), erasure and objection (signed in with your ORCID iD), the deletion of your account.
- What it cannot prove — a rectification, or contact details asked for by an account without an ORCID iD — waits for the operator, who answers on this page within one month, as the GDPR requires (article 12(3)). There is no human moderator on duty at the moment, but a request about your data is never closed unanswered: it stays open until the operator answers it.
- An erasure reaches the private copy of the contact details on Hugging Face at the next nightly publication (04:17, the registry's local time), which rewrites that copy's history, so that no earlier version keeps you.
- A refusal says why. You may also complain to the data protection authority of the country where you live or work.
What is kept of a request
- The right you asked for, your words (without any email address: a text that holds one is refused), the ORCID iD of your account and which ORCID proved it, the answer, the dates, and the legal deadline — with your account, like your other requests.
- After an erasure or an objection: your ORCID iD and a fingerprint (SHA-256) of each address found with it, never the address, on the list of people whose contact details the registry never collects again.
- 5 requests a day at most, one open request per right. A deleted account takes its requests with it.
