Version 3 Effective: 2 September 2026
FrançaisPrivacy Policy
Scienda is a subscription service that scans PubMed daily and emails you a concise digest of new articles in your specialty, filtered by the topics you choose and by journal quality. This policy explains what personal data we process, why, and the rights you have under the EU General Data Protection Regulation (GDPR).
1. Data controller
The controller responsible for your personal data is Édouard Bardou-Jacquet, sole trader, 59 lieu-dit La Haye, 35520 Melesse, France — publisher of Scienda.io. Full publisher details are in the legal notice. To exercise your rights or for any privacy question, contact us at [email protected]. The lead supervisory authority is the CNIL (France).
2. What data we process
- Account: your email address, and your password stored only as a one-way bcrypt hash (we do not store or have access to your password in plain text).
- Preferences: the categories you subscribe to, your time zone, your frequency, and your "empty digest" choice.
- Access requests: if you request access from the landing page, your email and, optionally, a short motivation.
- Subscription and billing: your subscription status and plan, and the start and end dates of any trial. Your billing address and card details are entered directly with our payment processor and never reach our servers — of the card, we only receive the last four digits, the brand, and the expiry date, for display on your invoices.
- Proof of consent: when you place an order, we record your email address, which checkboxes you ticked, the date and time, your IP address at that moment, and the version number of each document you accepted. We are legally required to be able to prove that you were properly informed.
- Service usage data: to deliver your digest without duplicates and to monitor delivery, we keep a record of the articles already included in your emails, the technical history of those sends (date, volume, success or failure), and, if you joined by invitation, the email address of that invitation. This data is deleted with your account on erasure.
- Trial registry: a record that a given email address has already used a free trial. We store a salted cryptographic fingerprint of the address, never the address itself, and this record is kept even if you later delete your account — see §6.
- Audience measurement: to know how many people visit the site, which pages they read and which link brought them, we keep daily aggregated counters (page views, referring source). So as not to count the same person twice within a day, we compute a salted cryptographic fingerprint of your IP address and browser; the day is part of that fingerprint, so visits on two different dates cannot be linked. The fingerprint is deleted after 30 days; only the totals, which identify no one, are kept. This measurement runs entirely on our own servers: no third-party script, no advertising or tracking cookie, no data sent to anyone else, and no tracking of your browsing across other sites.
- Technical data: your IP address is processed transiently (held in memory, not stored long-term) to rate-limit requests and protect the service against abuse, plus a single session cookie to keep you signed in. This cookie is strictly necessary to provide the service you requested and therefore does not require your consent (Art. 82 of the French Loi Informatique et Libertés).
Providing your email address is required to use Scienda — without it we cannot create an account or send you digests. The optional motivation field in the access-request form is not required; omitting it has no effect on whether your request is considered.
We do not use advertising, tracking cookies, or profiling; we do not sell or rent your data; and we do not carry out automated decision-making within the meaning of Art. 22 GDPR. Our audience measurement, described above, is in-house, aggregated and third-party free: it counts visits, it does not build a profile and it does not follow you across sites.
3. Why we process it, and our legal basis
- Account & digest delivery (email, preferences, session cookie) — necessary for the performance of the service you requested (GDPR Art. 6(1)(b)).
- Subscription, billing and invoicing — necessary for the performance of the contract you entered into (GDPR Art. 6(1)(b)), and, for the retention of invoices and accounting records, compliance with a legal obligation to which we are subject (GDPR Art. 6(1)(c)).
- Proof of consent (checkbox log, timestamp, IP, document version) — compliance with a legal obligation: French consumer law places the burden of proving pre-contractual information on the seller (Art. L221-7 of the French Consumer Code), and several US state auto-renewal laws require the seller to retain proof of consent (GDPR Art. 6(1)(c), and Art. 6(1)(f) for the establishment and defence of legal claims).
- Trial registry — our legitimate interest in preventing repeated use of free trials by the same person (GDPR Art. 6(1)(f)). You may object to this processing on grounds relating to your particular situation; we will then assess whether our interest overrides your objection.
- Audience measurement (aggregated counters, a deduplication fingerprint that lives for one day) — our legitimate interest in knowing whether the service finds its audience and through which channels, without which we could neither improve it nor make it known (GDPR Art. 6(1)(f)). This measurement stores nothing on your device, which places it outside Art. 82 of the French Loi Informatique et Libertés, and it falls within the consent exemption the CNIL recognises for audience measurement strictly necessary to operate and administer a site. You may object to it on grounds relating to your particular situation.
- Security & abuse prevention (transient IP processing, rate-limiting, short-term technical logs) — our legitimate interest in protecting the service and its users from abuse, fraud and denial-of-service (GDPR Art. 6(1)(f)).
- Optional access-request field (motivation) — your consent (GDPR Art. 6(1)(a)). You may omit it, and you can withdraw this consent at any time by emailing [email protected]; withdrawal does not affect the lawfulness of processing carried out beforehand.
4. Who can access your data (processors)
We rely on a small number of service providers acting on our behalf under a data processing agreement:
- Hetzner Online GmbH — server hosting, in Germany (EU).
- Mailgun (Sinch) — email delivery, EU region.
- Cloudflare, Inc. — DNS, CDN and security/edge protection; it processes connection data (including IP addresses) to route and protect traffic. Cloudflare also hosts the backup of our database, on its R2 storage service. That backup is encrypted on our server before it is ever sent: Cloudflare does not hold the key and only ever holds an unreadable blob.
- Stripe — payment processing, subscription management and invoicing. Stripe acts as an independent controller for parts of this processing (fraud prevention, regulatory obligations applying to payment institutions) and as our processor for the rest.
We query PubMed (US National Library of Medicine) to retrieve articles; no personal data about you is sent to PubMed.
5. International transfers
Your account data is hosted in the EU (Germany) and email is sent via an EU region. Cloudflare, Inc. (United States) processes connection data (including IP addresses) at the network edge; this transfer is covered by a signed Data Processing Addendum incorporating the EU Standard Contractual Clauses (controller-to-processor, Module 2).
The encrypted backup of our database is stored on Cloudflare's R2 storage service, in a Western Europe region (European Union); that storage is therefore not a transfer outside the European Union. It is covered by the Cloudflare Data Processing Addendum. Encryption is applied before the upload: the provider cannot read any of the stored data.
Stripe processes payment data in the United States. This transfer is covered by Stripe's Data Processing Agreement, which incorporates the EU Standard Contractual Clauses, and by Stripe's certification under the EU-US Data Privacy Framework.
6. How long we keep it
- Account and preferences: for as long as your account is active; deleted when you close your account or ask us to erase it — except for the records listed below, which we are either required to keep or keep for the specific purpose stated.
- Access requests: deleted a short time after a decision (approximately 90 days for handled requests).
- Technical and security logs: retained for up to 30 days, then deleted. They carry
technical identifiers (account id, subscription id, IP address) and, where no identifier
exists yet — a sign-in attempt, an invitation being sent — a masked email address of the form
e***@example.com. No email address appears in them in the clear. - Invoices and accounting records: retained for 10 years, as required by French commercial law (Art. L123-22 of the French Commercial Code). This obligation overrides a deletion request.
- Proof of consent (email address, checkbox log, timestamp, IP, document version): retained for 3 years from the end of the contract. This proof stays identifiable (it carries your email address): without it, it would no longer prove who consented.
- Proof of contractual notices (cancellation or withdrawal acknowledgement: the content of your declaration, its date and time, your email address): retained to show that we met our information obligations, including after account deletion, then deleted.
- Audience measurement: the deduplication fingerprint is deleted after 30 days, like the technical logs. The aggregated counters (visits per day, per page and per source) are kept with no time limit: they relate to no identifiable person and cannot be used to reconstruct any individual visit.
- Trial registry: the fingerprint of an email address that has used a free trial is retained after account deletion, so that the trial cannot be taken again. We keep the minimum necessary for that single purpose and nothing else — no preferences, no history, no digest content.
7. Your rights
Under the GDPR you can ask to:
- access your data and receive a copy, and — where applicable — receive it in a portable format (Art. 20);
- rectify inaccurate data;
- erase your data ("right to be forgotten");
- restrict certain processing;
- withdraw your consent at any time (for the optional field above).
Where we process your data on the basis of our legitimate interest (Art. 6(1)(f) — security, abuse prevention, and the trial registry), you also have the right to object at any time, on grounds relating to your particular situation.
Some of these rights have limits. We cannot delete invoices and accounting records before the legal retention period expires, and we keep a minimal trial record after account deletion (§6). Where that is the case, we tell you which records we kept and why.
To exercise any of these, email [email protected]. You also have the right to lodge a complaint with your data protection authority — in France, the CNIL.
8. Security
We protect your data with HTTPS/TLS in transit, password hashing (bcrypt), access controls, EU hosting, and periodic encrypted backups. Those backups are encrypted on our server before they are ever sent; where they are stored is described in Section 5 and may differ from where the service is hosted.
9. Changes to this policy
We may update this policy; the version and effective date above reflect the latest version. Material changes will be notified to active subscribers by email before they take effect.