Privacy, in plain language
Restricted access is useful. It is not a promise of absolute confidentiality.
What members can see
Approved global members can see Global Commons posts, replies, and member profiles. Private room posts, replies, reactions, bookmarks and search results require membership in that room. A matching confirmed work domain allows automatic room joining; other requests need a private review. Shared university and research-network domains identify institution-wide rooms, not a specific lab or office. Room request notes are visible to authorized reviewers. Rooms open without an automatic first-joiner steward. A nominee must accept and another approved room member must confirm; existing appointments remain, and platform stewards handle appeals. Your chosen display name and unique @handle are visible to approved members. If you have not chosen a display name, your registration name is shown. Organization, role, and country/office are also visible to approved members. Even with a display name, these details can identify you in a small office; this is not anonymous posting. Choosing a new name does not remove names or clues you previously typed into posts and messages. Profiles never expose email addresses or verification details. Mentions and reply notifications follow the original conversation’s audience and never grant room or chat access. Conversations are restricted to their participants; moderators can inspect a specific reported message. Blocking hides each person’s content and stops access to their conversation.
Information you must not share
Sharing any organization’s secret, private or confidential information or documents is not allowed anywhere on RA Commons, including private rooms, messages and Global Commons. This includes internal files, restricted findings, financial or personnel records, credentials, and identifiable research participant data. Share general lessons and resources that are already public instead. Room-admin approval never overrides this rule.
Who else can access content
Authorized platform administrators and infrastructure operators may access posts, legacy messages, conversation membership, device records, timestamps, ciphertext and encrypted backups. Message and file decryption keys normally stay on participating devices. If you choose to email your recovery key, that key passes through RA Commons and our email provider to your verified sign-in inbox. Anyone with access to that email may be able to unlock your message history. We do not save the recovery key in the application database, but email systems may retain copies and backups. A member may choose to share readable message evidence with platform stewards when reporting it; that evidence is no longer end-to-end encrypted. Members can copy, forward, photograph or screenshot content. An unlocked, compromised or malicious device can expose messages. First conversations trust the contact’s initially observed encryption identity. Members can compare security codes for stronger assurance; a changed identity stops sending until it is verified. First-contact trust cannot by itself rule out an attacker impersonating a contact before that first exchange. Encryption does not guarantee anonymity or protect confidential information from recipients.
Sharing from a private room
A room post never becomes global automatically. Its author may prepare a separate draft for a room admin to approve; the submitted version is fixed for review. Another admin must review an admin's own draft. Approval publishes that exact draft as a separate Global Commons post credited to its author; the original post, replies, reactions, and review notes stay in the room. A published draft remains visible to global members even if the author later leaves the room or the source is hidden. Report the global copy separately if it needs moderation. Authors must remove private context and references to other people without their agreement. Approval never permits sharing organization secrets or private or confidential information or documents.
What we store
Our sign-in provider processes your login email, sign-in information, first and last name, organization, declared current research role, and country/office you enter during registration. Our community database stores your confirmed sign-in email, approximate last activity time, private registration name, optional public display name, role, organization, country/office, optional introduction and profile photo, current and previous handles, application and membership status, administrator dashboard layouts and administration-access records, along with room requests, admin and consent nominations, acceptance and confirmation records, discussions, messages, reply references, mentions, notifications and their read status, bookmarks, blocks, reports, sharing drafts and review decisions. Photos are cropped and resized; image metadata is removed before storage. Work-email verification keeps the approved domain, verification time, and a protected fingerprint of the email to limit reuse. It does not keep the full work email. One-time codes are stored in a protected form, expire after ten minutes, and are removed after successful verification.
Evidence and retention
Profile URLs and free-text application notes are cleared after automatic admission or a membership decision. Confirmed domain, institution mapping, email fingerprint, automatic admission and room-join events, reviewer decisions and timestamps remain to support membership integrity. Expired verification entries and unused invitations may remain until cleared. Posts, messages, mentions, notifications and moderation history remain until an operator handles a deletion request. Previous handles stay reserved to their owner while the account exists; earlier mentions retain their text and link to the same identity after a handle changes. Room request notes are cleared after a membership decision or automatic joining. Sharing drafts and admin nomination/decision records remain for review until an operator handles deletion. Replacing or removing a photo removes the previous active image; older backups may contain it. Write to [email protected] about access, correction, deletion, or backup retention. These requests are handled individually rather than through automatic account deletion.
Providers and browsing
Supabase provides managed authentication. Community content and profile photos stay in our PostgreSQL database; our email provider delivers verification codes and a membership welcome email to your confirmed sign-in inbox. The welcome includes your first name. We keep delivery timestamps and retry counts without tracking email opens. Private member content is not sent to analytics or AI providers. Platform administrators can view aggregate membership counts and Global Commons contribution totals, with small groups omitted. A separate private member directory lets platform administrators who complete a security check see registration and display names, sign-in emails, organizations, membership status, join dates and approximate last activity. Directory access is recorded. Last activity records an authenticated app request at most once every 15 minutes; it is not a live online indicator and does not record page history. Sign-in emails are updated when you use the app and are not shown on member profiles. These statistics use existing records; we do not add browsing trackers. Shared links show locally generated URL cards; no external preview or avatar service is used. Opening an external link exposes normal browser connection information to that website.
Cookies and preferences
Sign-in uses protected cookies that browser scripts cannot read. The hosted app must send them over an encrypted connection. Sign-in cookies persist across browser restarts for up to a year and renew during normal use. Steward email security checks can also be remembered in the same signed-in browser for up to a year, renewed when you return. Sign-out or clearing cookies removes browser access; account or provider security changes can require signing in again. Clearing browsing history alone may leave cookies intact. The theme preference may be saved in your browser. Encrypted messaging keeps device keys, encrypted drafts and encrypted history in member-scoped browser storage. Signing out clears this browser’s messaging storage; ordinary browser restarts keep it. Keep your recovery key or another trusted device. You can optionally email your recovery key to your sign-in inbox; this is less private because email delivery systems and anyone with inbox access can obtain it. An ordinary email or password reset cannot restore encrypted history without the recovery key or a trusted device. Login passwords and verification codes are not stored there. Your browser can still hold information in memory, and members can screenshot content.
Your profile and privacy
Your profile page and photo are available within the approved-member community, not as a public directory. Pending applicants can prepare their own profile while they wait for review. Email addresses and verification evidence are not shown on member profiles. You can change your introduction and remove your profile photo from your profile settings.
Encrypted messaging records
The private messaging service stores ciphertext, encrypted key backups, member and device identifiers, conversation membership, timestamps and file sizes. File names and decryption keys stay inside encrypted messages. Drafts and conversation preferences are encrypted. Link cards do not fetch third-party pages. Deleting a message removes access through the app and queues ciphertext cleanup; it cannot erase copies already downloaded. Abandoned uploads expire after 24 hours. Resolved report evidence is cleared after 90 days; backups can retain earlier versions. No analytics or third-party AI processes private message content.