Privacy Policy
Controller/processor split, data collection, AI processing, retention, rights, and cookie policy.
Effective 8 August 2026 · Questions: legal@autoconference.ai
Privacy Policy
Document ID: LEG-03 · Version: 1.0 · Effective Date: 8 August 2026
Summary — the short version
We collect what we need to run peer review: who you are, what you submit, what you review, and how you use the site. Your submissions are processed by AI models, including models run by third-party providers under contracts that forbid those providers from training on your content. Reviews and submissions become public where the Venue's open-review policy says so. We also study this data to do research on peer review, and we publish that research — see the Consent to Research Use of Platform Data (LEG-01), which explains what is required, what is optional, and how to turn the optional parts off.
One thing to know before you pick a venue: some venues are Open Research Venues, where publishing the complete review record as a public, attributable corpus — your manuscript included, even if it is rejected — and training our own review models on it is a condition of taking part, and cannot be switched off once the corpus is released. You are shown exactly what that means on a dedicated screen before you join, you get a guaranteed window to pull out beforehand, and Standard Venues that do neither of those things are always available. We do not sell your data. You can access, correct, export, and delete your data, subject to the limits explained below.
This summary is for orientation. The full policy below is what governs.
1. Who we are
AutoConference.ai, AutoConference.ai (online; postal address available on request via legal@autoconference.ai), operates AutoConference.
- Privacy contact:
privacy@autoconference.ai - Data Protection Officer:
dpo@autoconference.ai - EU representative (GDPR Art. 27):
not yet appointed — contact dpo@autoconference.ai - UK representative:
not yet appointed — contact dpo@autoconference.ai
2. Controller or processor — which are we?
2.1 We are the controller — we decide the purposes and the means — for: account creation, identity verification, and profile management (including placeholder profiles built from public sources); platform security and fraud prevention; the design, operation, and improvement of the automated review pipeline, including which models are used, how prompts are constructed, how scores are calibrated, and which providers process your content; our own research and dataset programme (LEG-01); site analytics; and communications we send you.
2.2 We are a processor acting on a Venue's instructions for that Venue's editorial choices: its review criteria and score thresholds, its reviewer assignment rules and conflict policy, its visibility settings, its accept/reject decisions and the communication of them, and messages the Venue sends through the platform. For those activities the Venue is the controller and you should direct requests to it; we will help you identify and reach the right contact.
2.3 The line between the two runs like this: the Venue decides what counts as a good paper and who gets in; we decide how the machinery that assists that judgement is built and run. Where a single operation cannot be cleanly attributed to one of us, we and the Venue act as joint controllers under GDPR Art. 26, and the essence of that arrangement is published at https://autoconference.ai/legal/privacy-policy. You may exercise your rights against either of us.
2.4 Each Venue's identity and privacy contact are shown on its venue page before you submit.
3. What we collect
3.1 Information you give us
Name; email address; institutional affiliation and history; position and career stage; ORCID or other identifiers; homepage and profile links; areas of expertise; publication record; declared conflicts of interest; reviewer availability and preferences; and any optional demographic information you choose to provide.
3.2 Content you create
Manuscripts and supplementary materials; abstracts and metadata; reviews, scores, and confidence ratings; meta-reviews; rebuttals and discussion posts; public comments; appeals; and the full revision history of all of these.
3.3 Information generated by the Service
Prompts sent to and completions received from AI models in connection with your content; model and pipeline version identifiers; intermediate scores and confidence estimates; retrieval traces showing which related work was consulted; reviewer–submission matching scores; and integrity signals such as similarity scores and prompt-injection detections.
3.4 Technical and usage information
IP address; browser and device type; operating system; language settings; referring page; pages and API endpoints accessed; timestamps and session duration; interaction events; and error logs.
3.5 Information from other sources
Public bibliographic databases and preprint servers (to build and verify profiles and conflict-of-interest graphs); ORCID and institutional identity providers where you connect them; Venues that upload participant lists; and co-authors who list you on a submission.
Note on placeholder profiles. If we create a placeholder profile for you from public sources before you register, we will tell you when you first make contact with the Service, and you can claim, correct, or ask us to delete it.
Note on sensitive data. We do not intentionally collect special category data (GDPR Art. 9) or sensitive personal information (CPRA). Please do not put it in free-text fields.
4. Why we process it, and on what legal basis
Unless a row says otherwise, we act as controller for the processing described. Rows marked (processor) are processing we carry out on a Venue's instructions, where the Venue is the controller and supplies the legal basis.
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Create and manage your account | 3.1 | Art. 6(1)(b) contract |
| Build and maintain profiles and conflict graphs from public bibliographic sources before you register | 3.5 | Art. 6(1)(f) legitimate interests; Art. 14 notice given |
| Operate the automated review pipeline; generate Automated Reviews and scores | 3.1–3.3 | Art. 6(1)(b) contract |
| Assign reviewers; apply the Venue's criteria; issue the Venue's decisions (processor) | 3.1–3.3 | Venue's basis, normally Art. 6(1)(b) or 6(1)(f) |
| Solely automated accept/reject decisions, where a Venue elects that configuration | 3.1–3.3 | Art. 22(2)(c) explicit consent, collected at submission |
| Publish content at the Venue's visibility level | 3.2 | Art. 6(1)(b) contract |
| Detect fraud, plagiarism, collusion, prompt injection; protect security | 3.1–3.4 | Art. 6(1)(f) legitimate interests |
| Measure and improve review quality, calibration, and fairness | 3.1–3.4 | Art. 6(1)(f) legitimate interests, with Art. 89(1) safeguards |
| Research and publication at aggregate/de-identified level (T0/T1) | 3.1–3.4 | Art. 6(1)(f) + Art. 89(1) |
| Attributable dataset release, model training, research contact at a Standard Venue (T2 and optional uses) | 3.1–3.3 | Art. 6(1)(a) consent — opt-in |
| Publishing the open attributable corpus and training review models at an Open Research Venue | 3.1–3.3 | Art. 6(1)(b) contract — the corpus is the venue's declared purpose and you agree to it on a dedicated screen before participating (LEG-01 §§5.4–5.8); Art. 6(1)(f) + Art. 89(1) in support |
| Service emails and notifications | 3.1 | Art. 6(1)(b) contract |
| Marketing or newsletter emails | 3.1 | Art. 6(1)(a) consent |
| Comply with law; establish or defend legal claims; research integrity investigations | as needed | Art. 6(1)(c), Art. 6(1)(f) |
4.1 Our legitimate-interests assessments are documented and available on request to privacy@autoconference.ai. You may object to processing based on legitimate interests at any time (§9).
5. Automated decision-making and AI processing
5.1 The Service uses AI models to generate reviews, scores, and recommendations. Depending on the Venue's configuration, these may contribute to an accept/reject decision about your work. Because such a decision can significantly affect you, we apply the safeguards in GDPR Art. 22 regardless of how the decision is technically classified: human review on request, an explanation of the main factors, the ability to state your case, and an appeal route. The full notice is at LEG-01 Part C.
5.2 Content sent to AI providers. To generate reviews we send your Submissions and related content to the model providers listed in §6.2. Our contracts with them require that your content is not used to train their models, that retention is zero or the minimum technically necessary, and that human access is limited to abuse investigation.
5.3 Labelling. AI-generated review text is labelled as machine-generated wherever displayed and carries machine-readable provenance metadata, consistent with Art. 50 of the EU AI Act.
6. Who we share it with
6.1 Publicly
Where the Venue operates open review, submissions, reviews, scores, meta-reviews, rebuttals, discussion, and decisions become publicly visible, along with author names and, where the Venue's policy provides, reviewer identities. Visibility settings are shown before you submit. Public content can be copied and indexed by anyone, and we cannot control what third parties do with it once it is public.
At an Open Research Venue, publication goes further: the complete record — manuscripts including rejected ones, all reviews and scores, discussion, decisions and their rationales, and the model interaction traces behind the automated reviews — is published as a single downloadable corpus under CC BY 4.0, attributable to authors and, where the venue so provides, to reviewers, and is used to train and evaluate our review models. There is no Data Use Agreement and no access control on it, because it is public. See LEG-01 §§4.5 and 5.4–5.8, and the §4 table row for the legal basis.
6.2 Service providers
Cloud hosting and storage; AI model providers; email delivery; error monitoring; analytics; similarity and integrity checking; identity verification; and customer support tooling. Each is bound by a data processing agreement and may use your data only on our instructions. Our current list, with the categories of data each receives and its location, is at https://autoconference.ai/legal/privacy-policy. We give notice before adding a new sub-processor that handles Submission content.
6.3 Venues
Venue organisers receive the participant data they need to run their process, including your name, email, affiliation, expertise, and conflicts. Their handling of that data is governed by their own privacy notice.
6.4 Researchers
De-identified (T1) and, with your opt-in, attributable (T2) datasets may be shared with named researchers under a Data Use Agreement that prohibits re-identification and re-distribution. Aggregate (T0) and de-identified (T1) datasets may also be released publicly under an open licence, in which case anyone can download them and the contractual controls described above do not apply. Separately, the Open Research Venue corpus is a public, attributable (T2) release with no Data Use Agreement and no opt-in, because its publication is a term of participating in that venue. See LEG-01 §§4.3–4.5 for all three routes and their limits.
6.5 Legal and integrity
We disclose data where required by law or valid legal process, to establish or defend legal claims, to protect the safety of any person, and to institutions or integrity bodies conducting a research misconduct investigation. Where lawful, we will notify you before disclosing in response to a legal request, and we publish a transparency report at https://autoconference.ai/legal.
6.6 Corporate transactions
If we are involved in a merger, acquisition, or asset sale, data may transfer, subject to this Policy and with notice to you. If the acquirer wants to use your data differently, that requires fresh consent.
6.7 We do not sell
We do not sell personal information, and we do not "share" it for cross-context behavioural advertising as those terms are defined under the CPRA.
7. International transfers
7.1 We are based in the United States and use providers in the United States and the European Union. Personal data of users in the EEA, UK, and Switzerland is transferred outside those areas.
7.2 For those transfers we rely on the European Commission's Standard Contractual Clauses (2021/914) with the UK International Data Transfer Addendum where applicable, adequacy decisions where they exist, and — where relevant — certification under the EU–US Data Privacy Framework. We carry out transfer impact assessments and apply supplementary measures including encryption in transit and at rest, access logging, and a policy of challenging overbroad government requests. Copies of the relevant safeguards are available from privacy@autoconference.ai.
7.3 Because open review is public, content published under §6.1 is accessible worldwide by design.
8. How long we keep it
| Data | Retention |
|---|---|
| Account and profile | Life of account + 24 months |
| Unclaimed placeholder profile | 36 months from creation, then deleted unless linked to a Submission |
| Public submissions, reviews, decisions | Indefinite, as part of the scholarly record |
| Non-public submissions and reviews | 10 years after the Venue closes |
| Model interaction logs | 90 days for prompts and completions, and 24 months for scores and version identifiers, except traces published in an Open Research Venue corpus, which are permanent |
| Open Research Venue corpus | Permanent once released |
| Security and access logs | 12 months |
| API traffic logs | 90 days |
| Analytics | 25 months |
| Integrity investigation records | 7 years |
| Consent records | 3 years after account closure |
| Research datasets | Life of the research programme, subject to LEG-01 §6 |
8.1 We delete or irreversibly anonymise data at the end of these periods, except where a legal hold applies.
9. Your rights
9.1 Subject to applicable law, you may: access your data and get a copy; correct inaccurate data; delete your data; restrict processing; object to processing based on legitimate interests, including profiling; port your data in a structured, machine-readable format; not be subject to solely automated decisions with significant effects without safeguards; and complain to a supervisory authority.
9.2 California residents additionally have the rights to know the categories and specific pieces of personal information collected, the sources, the business purpose, and the categories of third parties to whom it is disclosed; to delete; to correct; to limit use of sensitive personal information; to opt out of sale or sharing (we do neither); and to non-discrimination for exercising these rights. You may use an authorised agent. We do not use financial incentives.
9.3 How to exercise. Use Settings → Privacy, or write to privacy@autoconference.ai. We respond within 30 days (45 days for CCPA requests, extendable once with notice). We may need to verify your identity; we will ask only for what is necessary.
9.4 Honest limits on deletion. We cannot delete:
- content that is part of the public scholarly record and has been cited or relied upon — we can, however, dissociate your name where anonymisation is possible without destroying the record;
- reviews you wrote that a decision relied on, while that decision stands;
- records subject to a legal hold, an active integrity investigation, or a statutory retention duty;
- data already distributed in a released dataset, or copies held by third parties;
- your data from a model already trained on it, where removal is not technically feasible — we will exclude it from future training; and
- content published in an Open Research Venue corpus, once that corpus has been released — participation in that venue was conditioned on its publication, and the corpus is public and beyond our control from that point (LEG-01 §§5.4–5.8 and §6.2(f)). You had a guaranteed exclusion window before release under LEG-01 §5.8.
We will always tell you specifically what we did and did not delete, and why.
9.5 Supervisory authorities. EEA users may complain to their national data protection authority; UK users to the Information Commissioner's Office; Swiss users to the FDPIC. Our lead supervisory authority, if any, is not yet designated.
10. Security
10.1 We use encryption in transit (TLS 1.2+) and at rest, role-based access control with least privilege, multi-factor authentication for administrative access, logged and reviewed access to Submission content, network segmentation between the production and research data stores, regular backups, vulnerability scanning, and independent penetration testing at least annually.
10.2 No system is perfectly secure. We will notify affected users and the relevant supervisory authority of a personal data breach in accordance with GDPR Arts. 33–34 and applicable state breach-notification laws.
10.3 Report vulnerabilities to security@autoconference.ai under the policy at https://autoconference.ai/legal.
11. Cookies and similar technologies
11.1 We use strictly necessary cookies for authentication, session management, security, and load balancing. These do not require consent.
11.2 We use analytics and preference cookies only with your consent, collected through our cookie banner, which offers "reject all" as prominently as "accept all". You can change your choices at any time at https://autoconference.ai/legal/privacy-policy. We honour Global Privacy Control signals.
11.3 We do not use advertising cookies or third-party trackers for advertising purposes.
12. Children
The Service is not directed to children under 16. We do not knowingly collect their data. If you believe a child has provided us data, contact privacy@autoconference.ai and we will delete it.
13. Changes to this Policy
We will notify you by email and on-site at least 30 days before material changes take effect. We do not apply changes retroactively to widen the use of data already collected without asking you again. All prior versions are archived at https://autoconference.ai/legal.
14. Contact
AutoConference.ai · AutoConference.ai (online; postal address available on request via legal@autoconference.ai) · privacy@autoconference.ai · DPO: dpo@autoconference.ai · EU rep: not yet appointed — contact dpo@autoconference.ai · UK rep: not yet appointed — contact dpo@autoconference.ai