Privacy Policy
Last updated 1 September 2026
ThreatPaper is a research publication. Reading it requires no account and no personal information. An account is needed only to submit research or to vote on a paper, and this policy describes exactly what that involves.
This document describes the data the service actually holds. Where a section says something is not collected, that means there is no field for it in the database.
Reading the site
No account, cookie consent, or personal data is required to read any paper. We do not use advertising trackers, and we do not sell or share data with data brokers.
Aggregate traffic analytics are collected through Vercel Analytics, which records page views without cookies and without building a profile of individual visitors.
If you create an account
Signing up stores:
- Your email address, held by our authentication provider so you can sign in and be contacted about your submissions.
- A username and display name. If you sign in with Google we take your name and derive a username from your email; both are editable and both are public.
- Anything you add to your profile — a short bio, affiliation, and links. All optional, all public.
- Your role — reader, author, or editor.
Passwords are handled entirely by our authentication provider, Supabase. If you sign in with Google we never see a password at all. Where you set one, it is hashed by Supabase and is not stored in, or readable by, this application.
We do not collect your date of birth, address, phone number, employer, or payment details, because the service has no use for them.
If you submit research
Drafts are private to you and the editors. A draft is visible to nobody else until it is approved for publication.
We store the paper itself, plus:
- Its status through review, and the revision number.
- Every editorial decision on it, with the comment the editor wrote. This history is visible to you and to editors, and is kept as the record of why a paper was published or returned.
Published papers carry your byline and link to your public profile. Publication is the point of submitting, so this is not something you can opt out of while keeping the paper live — but you can ask for a paper to be withdrawn.
Votes
A vote records which paper, which account, and the direction. Vote totals are public; who voted which way is not shown anywhere on the site. Editors can see the underlying rows in the database, which is what makes vote manipulation detectable.
The newsletter
If you subscribe, we store your email address and the page you subscribed from. Nothing else. The list is not readable by other users or by the public, and it is never sold or shared. Every message includes a way to unsubscribe.
Who else handles this data
The service runs on third parties who process data on our behalf:
- Supabase — database and authentication. Your account and content live here. The database is hosted in Mumbai, India.
- Vercel — hosting and privacy-preserving analytics.
- Google — only if you choose Google sign-in, and only to confirm your identity. Google tells us your name, email address, and profile picture URL. We do not receive access to anything else in your Google account.
How long we keep it
Account data is kept while your account exists. Published papers are kept indefinitely — a research archive that silently loses papers is not an archive, and other work cites them.
If you delete your account, your profile, drafts, unpublished submissions, and votes are removed. Papers already published stay up. At your request we will replace the byline with an anonymous attribution rather than removing the paper.
Your rights
You can see and edit your profile at any time from your dashboard. On request we will provide a copy of everything associated with your account, correct anything inaccurate, or delete your account.
Depending on where you live you may have additional rights under the GDPR, the UK GDPR, or India’s Digital Personal Data Protection Act, including the right to complain to your data protection authority.
Security
Access control is enforced in the database itself through row-level security policies, not only in application code. Unpublished papers are invisible to everyone but their author and the editors because the database refuses to return them, rather than because a query remembered to filter.
No service can promise perfect security. If you believe you have found a vulnerability, please report it to us before disclosing it publicly.
Children
This service is not directed at children and accounts are not knowingly created for anyone under 16.
Changes
If this policy changes materially, the date at the top changes and account holders are notified by email before the change takes effect.
Contact
For any request under this policy — access, correction, deletion, or a complaint — contact the editors. The about page lists how to reach us.