OSCR

How requests are decided

There is currently no human moderator on duty. What readers ask of OSCR — to remove something, to add a paper's code, to be recognized as a paper's author — is decided by the published rules below, applied by OSCR's own machine. The rules lean the safe way: hiding is automatic when in doubt, and publishing needs a verified identity or checks that pass. The operator, who runs OSCR, reviews what the rules cannot decide when available, and can reverse what they did; nothing waits more than 30 days — except a request about personal data, which the operator must answer within one month (the GDPR) and which is never closed unanswered.

When requests are decided

  • OSCR's machine reads the new requests about every 10 minutes and applies the rules at once. The decision, and its words, show on the request's page and on your account page. No email is sent.
  • What a decision removes or adds reaches the site at its next nightly publication, at 04:17 (the registry's local time).
  • Every automatic decision is recorded with the rule that made it, so that the operator can check it.

Removal requests

A removal request names what to remove: a paper's whole record, the copies of its authors' scripts (or their display from their source: the code policy), one repository's, one file's, or its tracing map.

From a verified author of the paper
Applied at once, whatever it names. You are a verified author when you signed in with the ORCID iD the paper lists among its authors (or your claim of authorship was verified).
From a maintainer of the code it names
Applied at once for the copies of the repositories you maintain as their owner or a public member of their organization (checked on GitHub), or as the operator made you. A contributor is recognized as a maintainer on GitHub, but one merged pull request makes one: a contributor's request follows the rules for anyone.
Copies of the authors' code, for copyright or personal data, from anyone
Hidden at once, pending the operator's review: the operator may restore what the request did not justify. To prevent abuse, at most 3 such requests from one account and 30 in all are hidden at once in a day; a justification sent with 3 requests or more in 7 days, or a request the operator already refused, waits for the operator instead.
Anything else
A whole record, a tracing map, or copies for another reason, from someone the registry cannot verify: nothing is hidden; the request waits for the operator, 30 days at most. Unreviewed after 30 days, it is closed without removal, with how to ask again. A record is built from the paper's own public metadata and links: removing it on anyone's word would let anyone erase anyone's work, so it takes a verified identity or the operator's decision.
The same, asked for personal data
Nothing is hidden either, and the request waits for the operator — but it is a request under the GDPR: the operator answers it within one month, and the rules never close it unanswered. It stays at the top of the operator's list, with its deadline.

Requests about your own data

Access to your data, the erasure of your contact details, an objection to their keeping, their rectification and the deletion of your account are asked on your data and your rights, signed in, and decided the same way, within about 10 minutes: the registry answers by itself what it can prove — access, erasure and objection for an account signed in with its ORCID iD (the iD is what ties an author's contact details to them), the deletion of an account. The rest — a rectification, or contact details asked for by an account without an ORCID iD, which a name, a GitHub login or a Google account cannot prove — waits for the operator, who answers within one month, and is never closed unanswered.

Submissions of a paper and its code

From an author of the paper
Published once you publish its draft (your ORCID iD among the paper's authors).
From anyone else
Published when each code link is proven the paper's by what the submitter cannot write: the paper itself cites it (its text, or the metadata its publisher deposited at Crossref; or it is the source an archive the paper cites names), or its owner is proven one of the paper's authors — an author's public ORCID record links to the owner's GitHub account, or a verified author of the paper owns the repository (its owner, or a public member of its organization, on GitHub). A README citing the paper, or a GitHub display name bearing an author's name, proves nothing: anyone can write them. Otherwise the submission waits for the operator, 30 days at most, and the submitter is told why; unreviewed, it is closed with how to ask again. A paper outside neuroscience is refused.
A draft not published
Closed after 30 days; it can be corrected and published again from your account page.

Claims

That you are a paper's author
Verified at once when the paper lists your ORCID iD among its authors, or when Crossref's automatic update put the paper in your ORCID record (its publisher deposited your iD with it) — checked again every day. A work you added to your ORCID record yourself, or through a search tool, proves nothing: anyone can add any paper. Otherwise, closed after 30 days with how to claim again.
That you maintain a repository
Verified at once when GitHub shows you as its owner, a public member of its organization or a contributor. Other forges cannot be checked automatically: such a claim waits for the operator, 30 days at most, then is closed with how to be checked again. Only an owner or an organization member (or a maintainer the operator made) can correct a paper's record as its maintainer or have a removal applied at once: a contributor cannot.

What only verified people can do

  • Correct a record's links: a verified author of the paper, or a maintainer of its code (its owner, or a public member of its organization) for their own repository. Every correction becomes a new version of the record, which says a verified person made it.
  • Validate a tracing map and have it deposited on Zenodo: a verified author, with their ORCID iD.

Free text

No text a reader types appears on a public page: the notes, statements, justifications and evidence links of requests are read by the operator only, and lose any email address. The only name of an account that can become public — the creator of a tracing map, when the paper does not list the validator's ORCID iD — is kept only when it looks like a name (no address, no link). So no automatic text filter is needed, and none is used.

Limits

  • Every request needs an account; per account and per day: 10 removal requests, 10 submissions, 20 corrections, 10 validations, 10 claims (and 20 claims waiting at once).
  • One removal request per account and record: complete it while it is open; once refused, it can be asked again only in a way the rules decide at once (as a verified author, as a maintainer, or for the copies only).

How to appeal

  • A request refused or closed by the rules: ask again in a way the rules decide — sign in with the ORCID iD the paper lists, verify your repository on GitHub from your account page, link your GitHub account from your ORCID record, or ask for the copies only. The operator can also override the rules and accept it.
  • Something the rules did wrongly (copies hidden without reason, a submission or a claim accepted by mistake): the operator reviews the automatic decisions, and can reverse any of them.
  • Anything else: the project's public issue tracker — public, so put no personal data there; for your own data, use your data and your rights, and for personal data in a record, the removal request page of the record, whose justification only the operator reads.