Privacy Policy
Last updated: February 13, 2026 · Effective: February 13, 2026
Universe Solver ("we," "us," or "our") operates the website universesolver.com (the "Platform"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our Platform, create an account, or use any of our services. Please read this policy carefully. By accessing or using the Platform, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.
1. Information We Collect
1.1 Information You Provide Directly
- Account Information: Username, email address, password (hashed with bcrypt, 14 salt rounds — we never store plaintext passwords).
- Profile Information: Display name, biography, and avatar seed (used to generate a deterministic geometric avatar).
- Content: Publications, peer reviews, sealed predictions, and feedback you submit.
- Publications: Uploaded files, metadata (title, abstract, authors, keywords, funding information), DOI records.
- Consent Records: Your age confirmation, terms acceptance, privacy policy acceptance, and analytics consent choices.
1.2 Information Collected Automatically (Only With Your Consent)
We do not use any third-party tracking services. All analytics are collected by our custom-built, privacy-first analytics system, and only after you explicitly consent. If you decline analytics, we collect none of this data.
When consented, we may collect:
- Session Information: A randomly generated session identifier (stored in localStorage, not cookies), browser type and version, operating system, device type, screen resolution, viewport size, language preference, and timezone offset.
- Page Views: Pages visited, page titles, internal navigation path, performance metrics (load time, time to first byte, first contentful paint).
- Engagement: Scroll depth, time on page, click events (element type, position — no form field values or sensitive text), and JavaScript error reports.
- Mouse Movement Recordings: Compressed recordings of mouse coordinates, clicks, and scroll positions for session replay. These are used solely to improve the user experience and are automatically purged after 90 days.
- Referrer Information: The URL that referred you to the Platform, including UTM campaign parameters if present.
1.3 Information We Do NOT Collect
- We do not store raw IP addresses. All IP addresses are irreversibly hashed with SHA-256 before storage.
- We do not use cookies for tracking purposes.
- We do not share data with any third-party advertising networks, social media platforms, or data brokers.
- We do not sell your personal data. Ever.
- We do not use Google Analytics, Facebook Pixel, or any third-party analytics service.
- We do not perform cross-site tracking.
2. How We Use Your Information
We use collected information for the following purposes:
- Provide and maintain the Platform: Account authentication, content delivery, and notifications.
- Improve the user experience: Understanding how visitors navigate the site, identifying performance issues, and optimizing page load times (analytics data, with consent only).
- Scientific archive integrity: Maintaining DOI records, publication version history, and peer review integrity.
- Security: Detecting and preventing abuse, spam, brute-force attacks, and unauthorized access.
- Communication: Sending password reset emails, security alerts, and service notifications (never marketing emails without explicit opt-in).
- Legal compliance: Responding to lawful requests from public authorities.
3. Legal Bases for Processing (GDPR)
If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your data under the following legal bases:
- Consent (Art. 6(1)(a) GDPR): Analytics data collection, mouse movement recordings. You can withdraw consent at any time via the Settings page or by contacting us.
- Contract (Art. 6(1)(b) GDPR): Account creation, content hosting, publication archive services.
- Legitimate Interest (Art. 6(1)(f) GDPR): Security monitoring, fraud prevention, and service improvement (where not overridden by your rights).
- Legal Obligation (Art. 6(1)(c) GDPR): Compliance with applicable laws, tax obligations for publication records.
4. Your Rights
4.1 For All Users
- Access: You can view all data we hold about you by visiting your Settings page or by exporting your data (JSON format).
- Rectification: You can update your profile information at any time.
- Deletion: You can permanently delete your account and all associated data via Settings. This action is irreversible.
- Withdraw Consent: You can withdraw analytics consent at any time via the consent banner or Settings page. This does not affect the lawfulness of prior processing.
- Data Portability: You can export all your data in machine-readable JSON format via the Data Export endpoint.
4.2 Additional Rights — EEA / UK / Swiss Residents (GDPR)
- Right to object: You may object to processing based on legitimate interests.
- Right to restrict processing: You may request we limit processing of your data while a complaint is investigated.
- Right to lodge a complaint: You have the right to file a complaint with your local Data Protection Authority (DPA).
4.3 Additional Rights — California Residents (CCPA / CPRA)
- Right to Know: You may request disclosure of the categories and specific pieces of personal information collected.
- Right to Delete: You may request deletion of personal information collected (subject to certain exceptions).
- Right to Opt-Out of Sale: We do not sell personal information. This right is satisfied by default.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
- Authorized Agents: You may designate an authorized agent to make requests on your behalf.
4.4 Additional Rights — Other Jurisdictions
- Brazil (LGPD): You have rights to access, correction, anonymization, blocking, deletion, data portability, information about sharing, and the ability to revoke consent.
- Canada (PIPEDA): You have the right to access your personal information, challenge its accuracy, and withdraw consent.
- Australia (Privacy Act 1988): You have rights to access and correct your personal information. We handle complaints in accordance with the Australian Privacy Principles.
5. Data Retention
- Account data: Retained until you delete your account. Upon deletion, all personal data is permanently removed within 30 days.
- Content (posts, discoveries, comments): Retained until you delete them or delete your account.
- Publications & DOI records: DOI records are permanent (as required by DOI standards). If you delete your account, publications are marked as "retracted" but metadata is preserved for citation integrity.
- Analytics data: Automatically purged after 90 days.
- Mouse recordings: Automatically purged after 90 days.
- Security logs: Retained for 1 year for security auditing, then deleted.
- Backup data: Encrypted backups are retained for 30 days, then permanently deleted.
6. Data Security
We implement the following technical and organizational measures to protect your data:
- Password hashing: bcrypt with 14 salt rounds — industry-leading protection against brute-force attacks.
- CSRF protection: All state-changing forms are protected with anti-CSRF tokens.
- Content Security Policy: Strict CSP headers to prevent XSS attacks.
- Rate limiting: All authentication and API endpoints are rate-limited to prevent abuse.
- Account lockout: Accounts are temporarily locked after 5 failed login attempts.
- Security headers: X-Content-Type-Options, X-Frame-Options, X-XSS-Protection, Referrer-Policy, Permissions-Policy.
- Input sanitization: All user-generated content is sanitized with Bleach to prevent XSS.
- File integrity: All uploaded publication files have SHA-256 checksums verified on upload.
- Encrypted backups: Database and file backups are encrypted at rest.
7. Children's Privacy (COPPA)
The Platform is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. During registration, users must confirm they are at least 13 years old. If we learn that a child under 13 has provided us with personal information, we will promptly delete that information. If you believe a child under 13 has registered, please contact us immediately.
8. Third-Party Services
We currently use the following third-party services:
- Google Fonts: For serving the Inter and JetBrains Mono typefaces. Google may log font requests. See Google's Privacy Policy.
We do not use any other third-party analytics, advertising, social media, or tracking services. All analytics are handled by our custom-built system running on our own servers.
9. International Data Transfers
Your data is stored on servers located in the United States. If you access the Platform from outside the United States, your data will be transferred to the United States. By using the Platform, you consent to this transfer. We take appropriate safeguards to ensure your data is treated securely and in accordance with this Privacy Policy, including implementing standard contractual clauses where required by applicable law.
10. Do Not Track (DNT)
We honor Do Not Track signals. If your browser sends a DNT header, our analytics system will not track your activity, regardless of your consent status.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by posting a prominent notice on the Platform and updating the "Last updated" date. For users with accounts, we will also send an in-app notification. If any change requires re-consent under GDPR, we will re-prompt for consent before applying the change.
12. Contact Us
If you have questions about this Privacy Policy, wish to exercise your data rights, or need to report a privacy concern, please contact us at:
Email: privacy@universesolver.com
Subject line: "Privacy Request — [Your Username]"
We will respond to all legitimate requests within 30 days (or within the timeframe required by applicable law).