Nobel
Sign in

Privacy policy

Version 1.3 — last updated 2026-10-07

This policy explains data processing for journal readers, issue buyers and the owner who manages research and publication.

1. Operator and contact

Nobel is operated by ai-nobel, which is the data controller for the personal data described in this policy and decides why and how it is processed. The contact channel is the Contact page.

2. What we collect from visitors today

  • Browsing public pages does not require an account. Readers can register to buy issues; visitors do not upload research files or create projects.
  • Contact messages only: name, email, request type and message text, plus a one-way hashed fingerprint of the IP address to limit excessive sending (the IP itself is not stored).
  • Browser local storage for the language choice only. No advertising cookies and no third-party analytics or tracking.
  • Technical server logs kept by the hosting provider.

3. Owner operating data (separate)

  • Research projects and their files are managed through the owner's account only. Buyer accounts do not grant access to these data.
  • Production data (projects, sources, evidence, drafts, Word files and the paper database) belongs to the owner and no other account can reach it, even through direct server requests.
  • Research text is sent to automated text-processing providers and scholarly source databases to run production, and the cost of each call is recorded.

4. Deletion and archive

  • When the owner deletes a project, all its data is deleted, including that project's archived Word versions in the paper database.
  • Downloads are not logged; there is no download log today.
  • Copies may remain in the hosting provider's backups for a period set by the provider that we have not verified, so we do not claim immediate deletion from backups.
  • Contact messages are kept until handled and can be deleted on request.

5. Buyers of journal issues

  • Account data: email address and sign-in credentials, used to create your account and deliver purchased issues (legal basis: performance of a contract).
  • Purchase records: which issue you bought and the order reference, used to grant downloads and for accounting (contract performance and legal obligation).
  • Security data such as IP-derived fingerprints, used to prevent fraud and abuse (legitimate interests).
  • Card and payment details are collected and processed by Paddle, not by us.

6. Service providers and what is sent to them

  • Paddle.com, our Merchant of Record, for the sale of journal issues, payment processing, tax compliance and invoicing. Your name, email and order details are shared with Paddle for this purpose.
  • Hosting, database and storage: Lovable Cloud (cloud infrastructure). Contact messages and the owner's operating data are stored there.
  • Automated text-processing and generation services through Lovable (e.g. Google Gemini, OpenAI): only the owner's project text and source excerpts are sent, to produce papers; no visitor data.
  • Open scholarly source databases: only search queries are sent.
  • Professional advisers (legal, accounting) where needed, and authorities where required by law.
  • The geographic processing locations of these providers have not been verified yet and may be outside your country.
  • Retention: account and purchase records are kept while your account exists and as long as required for tax and accounting law, then deleted or anonymised. We use appropriate technical and organisational measures (encryption in transit, access controls) to protect data.

7. Your rights

You may request access to, correction or deletion of your data, or object to its processing, as provided by applicable law, including the Saudi Personal Data Protection Law where it applies. Send requests via the Contact page and choose "Privacy / data request".

8. Changes to this policy

When this policy changes we bump the version number and last-updated date at the top of this page.