Skip to content

Privacy and permanence

ARIADNE is built so that the scientific record cannot be rewritten: nothing is deleted, and every action is a public, signed record. That is good for science and needs care from you. This page sums up what is public, what you can still change, and what stays private. The sources are the About page (“What runs outside the blockchain” and “Known limits”) and the code of the web app and the indexer.

Examples
Public and permanent everything recorded on the blockchain: publications and every version, reviews, comments, votes, flags, follows, public lists, ORCID and DOI declarations
Can be withdrawn or marked, but stays in the history retraction, unfollowing, unlinking an ORCID iD, withdrawing a DOI, editing or deleting a public list
Copies you cannot recall article files on IPFS, ARIADNE’s second copy, copies others keep, Zenodo records
Only in your browser private lists, your pinning key, the Zenodo permission, read marks, preferences
Seen by ARIADNE’s server your searches, the names it looks up for you, browser notification subscriptions, Zenodo drafts while you make them

The blockchain is a shared record that thousands of computers keep identical; once an action is written there, nobody can change or remove it, including the people who run ARIADNE (see What is on the blockchain, and what is not). On ARIADNE this covers:

  • publications: every version of every article, its fields, type, co-authors and status;
  • reviews and comments, with their recommendation, and the addresses they mention;
  • votes, which can never be changed or withdrawn, and flags;
  • reputation claims and co-authorship confirmations;
  • follows: anyone can see who follows whom;
  • public lists: every name, description, addition, removal and deletion;
  • ORCID declarations: anyone can see which iD an address declared, and when;
  • DOI declarations.

The texts themselves are on IPFS, and the blockchain keeps their fingerprint. Everything in a publication’s folder is public and permanent, including comments in the source (<!-- ... -->) and every file in assets/. Check them before you publish.

Your address is not your name, but anything that links the two (an ORCID iD, an NFD name, a signature in your text) links all of the address’s activity to you, publicly and for good. See Identity: addresses, names and ORCID.

Notifications are derived from this public data, so the indexer serves the notifications of any address to anyone.

You can What changes What stays
Retract an article (see New versions, amendments and retraction) the article is marked retracted, everywhere every version stays readable; a retraction is a visible status, not an erasure
Unfollow someone they leave your inbox; the follow is marked inactive the follow and the unfollow, on the blockchain
Unlink your ORCID iD the iD, its name and the details read from ORCID disappear from your profile the declaration, in the blockchain history
Hide a detail of your ORCID record change its visibility on ORCID; your profile follows at the next check (weekly) nothing on chain: these details are never written there
Withdraw a DOI it disappears from the article the declaration, on the blockchain; the Zenodo record, on Zenodo
Rename, empty or delete a public list your profile shows the change every earlier change, on the blockchain
Delete a private list it is gone nothing: it never left your browser
Turn off browser notifications ARIADNE’s server forgets that subscription nothing

What you cannot change: a vote, the list of co-authors declared when publishing, a published version, a review or a comment.

A published article lives on IPFS, the storage network where a file is found by its fingerprint (see Storage: IPFS, pins and copies).

  • Your pinning service (Filebase, Pinata or your own node) holds the copy you uploaded.
  • ARIADNE’s indexer keeps a second copy of every article it validates, and of every review and comment, and serves it through its gateway, https://ipfs.ariadne.press. After a retraction the content stays addressable.
  • Anyone, a reader or an institution, can pin a copy; the article page even shows the command.
  • A Zenodo record cannot be deleted once published, even if the article is later retracted on ARIADNE; its description can still be edited (see Get a DOI with Zenodo).

So treat publishing as final: assume that every published file will stay available somewhere.

These are kept in your browser’s storage on this site, never on ARIADNE’s servers, and other devices do not have them. Clearing the site’s data removes them.

  • Private lists (see Lists and bibliographies).
  • Your pinning key for Filebase or Pinata; “Forget it” removes it.
  • The Zenodo permission, in a sealed cookie that lasts at most an hour; “Disconnect Zenodo” removes it sooner.
  • Which notifications you have read, and what you have already seen from the people you follow.
  • Preferences: theme, citation format, bibliography order, comment order, the network you used last, and the wallet you connected.
  • Your last 8 searches; “Forget recent searches” clears them.

Reading needs no wallet and no account: you can read and search everything without connecting anything.

  • Your searches. The search runs on ARIADNE’s indexer, so the server receives what you search for.
  • Names and pictures. ARIADNE’s server asks NFD for the .algo names and avatars of the addresses on a page and passes them to your browser, so your browser never contacts NFD. Names are kept in the server’s memory for up to 30 minutes.
  • Browser notifications. When you turn them on, the server keeps the push address your browser gave (at Google, Mozilla, Microsoft or Apple), its two keys, the network, the address you receive for and the kinds you chose. The messages travel encrypted end to end through that push service. Turning notifications off removes the subscription.
  • Zenodo drafts. While you prepare a draft, the server uses the permission from your sealed cookie to create it in your Zenodo account; it does not keep the permission.
  • ORCID and OpenAlex. For a declared ORCID iD, the indexer reads the public part of the ORCID record (names, websites, e-mails, countries) and, once the iD is verified, its current employments and OpenAlex’s counts of the person’s works and citations. It reads only what the record shows to everyone, and shows it only while the iD is verified.

ARIADNE never sees your wallet’s private key, and it has no advertising. Images from other websites are not embedded in articles but shown as links, because an external image can change, disappear or be used to follow readers.

  • Publishing: is every file and every source comment something you want public for ever?
  • Linking an ORCID iD: are you happy for this address’s whole history to carry your name?
  • Following, voting, making a list public: are you happy for anyone to see it?
  • Publishing on Zenodo: the record will outlive any retraction.

Try things on TestNet first: it works exactly like MainNet, with free ALGO, though what you do there is public and permanent on TestNet too (see TestNet and MainNet).