Privacy Policy
Last updated: July 13, 2026
This policy describes how the JZ Institute of Science ("JZIS", "we", "us") handles personal data for the JZIS Superconductivity Library ("SCLib") at jzis.org/sclib. JZIS is the data user responsible for the SCLib account service. Our address is Hong Kong, China, and our privacy contact is info@jzis.org.
1. Data we collect
Required account data
- Email address and name, used to identify and communicate with your account.
- For email sign-in, a one-way password hash. We never store your plaintext password.
- For Google sign-in, the Google account identifier, verified email, display name, and avatar returned by Google.
Optional research profile
Institution, country, research area, purpose of use, biography, ORCID, and any legacy age value are optional. They are not required to search, ask questions, or use the API. You can edit or clear them in your dashboard. The current registration form no longer asks for age.
Service activity and security data
- Ask questions, generated answers, cited sources, bookmarks, and API-key metadata.
- Request counts, timestamps, truncated key prefixes, and security events. API keys and reset tokens are stored only as non-reversible hashes.
- IP address and user-agent information used for rate limiting, fraud prevention, and feedback delivery. Authentication audit records store keyed hashes rather than the raw values.
- Optional analytics data and sampled browser-health measurements, but only after you enable Analytics in the cookie banner. Browser errors are counted without sending the error message, stack trace, page URL, account identifier, or raw IP address. See our Cookie Policy.
2. Why we use the data
We use personal data only to:
- create, verify, secure, and support your account;
- provide search, RAG question answering, saved items, and API access;
- enforce fair-use limits and investigate abuse or security incidents;
- respond to feedback and service requests;
- understand aggregate site usage when analytics consent is enabled; and
- meet legal obligations and establish or defend legal claims.
We do not sell personal data, use it for third-party advertising, or use optional research-profile data for direct marketing.
3. Service providers and international processing
SCLib uses service providers only where needed to operate the service:
- our PostgreSQL, Redis, API, and web infrastructure for account and service data;
- Google OAuth for optional Google sign-in;
- Google Cloud Vertex AI Vector Search and Gemini for retrieval and answer generation. Questions sent to Ask may be processed outside Hong Kong. Google Cloud states that customer data is not used to train or fine-tune its managed models without permission, although limited abuse-monitoring logging may apply. See Google Cloud's Vertex AI data-governance documentation;
- Resend for verification, reset, feedback, and account email delivery; and
- Google Analytics, only if you opt in to analytics cookies.
These providers may process data in other jurisdictions. We limit the data sent to each provider to what is needed for its function.
4. Retention
- Account and profile data, bookmarks, and API-key metadata are kept while your account exists and are removed when you delete it.
- Signed-in Ask history is kept in a rolling 90-day window. You can also delete individual history entries sooner.
- Redis quota counters expire automatically after their daily or short security windows; the weekly usage view covers seven days.
- Verification and reset grants stop working at their stated expiry. Their security metadata remains attached to the account until account deletion.
- Authentication audit events are retained as needed for security and legal claims. After account deletion, the direct user reference is removed and only pseudonymous security evidence remains.
- Analytics and aggregate browser-health retention are described in the Cookie Policy.
Deleted data may persist temporarily in protected backups until those backups complete their normal rotation. Feedback already delivered by email and records we must retain by law are not automatically removed by the account-delete button; contact us for a specific request.
5. Your choices and rights
- View and correct profile data from the dashboard.
- Download a machine-readable JSON copy from Dashboard → Data & privacy.
- Delete individual Ask-history entries or permanently delete your account.
- Revoke API keys and all browser/bearer sessions.
- Accept or reject optional analytics independently of account authentication.
- Request access to or correction of other personal data by emailing info@jzis.org. We may need to verify your identity before acting on a request.
These controls support the access and correction principles in Hong Kong's Personal Data (Privacy) Ordinance. Other rights may apply depending on where you live.
6. Security
We use HTTPS, HttpOnly session cookies, hashed credentials, restricted service networking, rate limiting, session revocation, and security auditing. No internet service is risk-free; please use a unique password and keep API keys confidential.
7. Children
SCLib is a research service and is not directed to children. Do not create an account if you are under 13 or cannot validly agree to the Terms in your jurisdiction.
8. Changes and contact
Material changes will be posted here with a revised date. Questions, access/correction requests, or deletion issues can be sent to info@jzis.org.