Privacy Statement

This statement explains what we do with the personal data of the people who read, write for and review for this journal. It is written to be read, not to be survived: if anything here is unclear, write to us and we will explain it and fix the wording.

What we collect, and why

Readers. You can read everything we publish without an account. If you create one to receive alerts, we keep your name, email and any interests you tell us about, and we use them for nothing except sending what you asked for. Our server records the usual technical data — address, browser, pages requested — which we use in aggregate to count how often articles are read and to keep the site working.

Authors. When you propose or submit, we collect the names, affiliations, emails and ORCID identifiers of everyone credited, plus the manuscript and correspondence about it. We need this to run the editorial process and to publish the article. If your article is published, the names, affiliations and ORCID identifiers of the authors become part of the permanent scholarly record.

Reviewers. We keep your name, email, affiliation and areas of expertise so we can invite you appropriately, and we keep your reports as part of the record of the decision. Your identity as a reviewer is not disclosed to authors unless you choose to sign your report.

What we do not do

We do not sell, rent or trade personal data. We do not run advertising, and we do not host third-party advertising trackers. We do not use your data to train machine-learning models, and we do not sell reviewer or author lists to anyone.

Who else sees it

Editors and reviewers involved in handling your manuscript see what they need to handle it. Beyond that, data reaches only the services that make the journal work: the hosting and content-delivery provider that serves this site, the system that registers DOIs, and the indexing services to which published metadata is deliberately sent (that is the point of publishing). Where we are legally compelled to disclose data, we will do so, and we will tell you unless the law forbids it.

How long we keep it

Editorial records — submissions, decisions, reviews, correspondence — are kept indefinitely, because the integrity of the scholarly record depends on being able to reconstruct how a decision was made. Accounts that are never used are deleted after five years of inactivity. Published articles are permanent by design: an article, once published, is part of the record and cannot be unpublished on request. Corrections and retractions are published openly and linked to the original.

Your rights

Under Brazil’s General Data Protection Law (LGPD, Law 13.709/2018) you may ask us to confirm what data we hold about you, correct it, delete it, or provide it in portable form; you may also withdraw consent for anything you consented to, such as alerts. We honour the equivalent rights of authors and reviewers based elsewhere, including under the GDPR, without asking where you live.

Two limits are honest to state up front: we cannot delete the authorship of a published article, and we cannot delete the record of an editorial decision. Everything else we can and will remove on request.

Security

The site runs over encrypted connections; passwords are stored hashed and are never visible to us. We keep the software patched. We will not pretend this is a guarantee: if a breach affects your data, we will tell you and the relevant authority, and we will say what happened rather than issue a statement about how seriously we take security.

Contact

For anything on this page — a request, a correction, a complaint — write to the editors. We answer data requests within 15 days, the period the LGPD sets.

This statement applies to this journal’s website. It does not cover sites we link to, which have their own policies.