Skip to content
Schovis

Privacy Policy

Effective . Applies to schovis.com and every Schovis page.

Schovis turns a public Google Scholar profile into a public page of research impact. This policy explains, as the EU General Data Protection Regulation (GDPR) requires, what personal data Schovis processes, why, and what rights you have. We process only what the service needs.

1Who is responsible

Schovis is run by Ekrem Çetinkaya and Ammar Rashed, who decide together how personal data is processed and are therefore joint controllers (Art. 26 GDPR). They have agreed that Ekrem Çetinkaya handles all data protection requests. You can still exercise your rights with either of them. Contact: privacy@schovis.com.

2What we process, why, and for how long

Table 1 lists every kind of personal data Schovis processes. You need a Google account and a public Google Scholar profile to create a page; without them we cannot provide the service. Visiting pages requires no account.

Table 1 | Purposes, legal bases and retention.
Name, email address and Google account ID, received from Google when you sign in
Purpose: Sign you in and run your account
Legal basis (GDPR): Contract, Art. 6(1)(b)
Kept: Until you delete your account
Your Google Scholar profile ID, username, and the bio and photo you add
Purpose: Publish your Schovis page
Legal basis (GDPR): Contract, Art. 6(1)(b)
Kept: Until you delete your account; a replaced photo is deleted at once
Public data from your Google Scholar profile and a daily record of your citation totals
Purpose: Build your page and keep it up to date
Legal basis (GDPR): Contract, Art. 6(1)(b)
Kept: Deleted within 30 days after you delete your account
Public Scholar data of a profile looked up during sign-up but not turned into a page
Purpose: Let you confirm that a profile is yours before a page is created
Legal basis (GDPR): Legitimate interests, Art. 6(1)(f)
Kept: Deleted within 30 days
A session record: a random token and its expiry date (no IP address, no device details)
Purpose: Keep you signed in
Legal basis (GDPR): Contract, Art. 6(1)(b)
Kept: Until you sign out or delete your account
Request data: IP address, browser, the page requested and the time
Purpose: Deliver the site, keep it secure and prevent abuse
Legal basis (GDPR): Legitimate interests, Art. 6(1)(f)
Kept: At most 7 days, in Cloudflare’s logs
Emails you send us
Purpose: Answer you and handle your requests
Legal basis (GDPR): Contract or legitimate interests, Art. 6(1)(b) or (f)
Kept: As long as needed to handle your request

From Google sign-in we receive your name, email address, Google account ID and profile picture. We keep the first three and discard the picture. We also discard Google’s access tokens: Schovis never accesses your Google account. When you sign in, your IP address is briefly held in memory to limit repeated sign-in attempts; it is never written to our database.

Our legitimate interests are running a secure, reliable service and letting researchers confirm their own profile before a public page is created. You can object to processing based on them (section 8).

3Where the data comes from

You give us your Google Scholar profile link. The data we show about your research comes from your public Google Scholar profile, which SerpApi retrieves for us once a day: your name, affiliation, verified email domain, research interests, homepage, citation statistics and publication list.

Publication lists include every author as Google Scholar shows them, so the names of your co-authors appear on your page too. We show them because an accurate publication record is what the page is for (legitimate interests, Art. 6(1)(f)). Co-authors and other people whose names appear can contact us to exercise their rights, including the right to object.

4Your page is public

A Schovis page is public by design. Anyone with the link can see it, and search engines may index it. It shows your public Google Scholar data together with the username, bio and photo you add. Your email address from Google sign-in is never shown. If you do not want a public page, do not create one, or delete your account (section 7).

5Cookies, and nothing else in your browser

Schovis sets only the cookies in Table 2. All of them are strictly necessary for sign-in, so they need no consent. There are no analytics, advertising or tracking cookies.

Table 2 | Cookies.
__Secure-better-auth.session_token
Purpose: Keeps you signed in
Lasts: 7 days after your last visit
__Secure-better-auth.session_data
Purpose: A signed copy of your session, so pages load without a database lookup
Lasts: 5 minutes
__Secure-better-auth.state
Purpose: Protects the Google sign-in against forged requests
Lasts: 5 minutes, during sign-in only

Pages, fonts and images are all served from schovis.com, including photos: Schovis never embeds your Google Scholar photo. Your browser contacts another company only when you follow a link, for example to Google Scholar, or when you choose to sign in with Google.

6Who receives data, and transfers outside the EU

Only the recipients in Table 3 receive personal data, and our processors use it only to provide their service to us, under data processing agreements (Art. 28 GDPR). We do not sell or rent personal data, show advertising, or send marketing email. We disclose data to authorities only when the law requires it.

Table 3 | Recipients, locations and transfer safeguards.
Cloudflare, Inc.
Role: Processor: hosting, databases, file storage, request logs, and forwarding emails sent to schovis.com addresses
Receives: Everything in Table 1
Location and safeguard: Databases and files are stored in Cloudflare’s Western Europe region. Requests and emails may be handled at Cloudflare locations worldwide under Cloudflare’s Data Processing Addendum, which includes the EU Standard Contractual Clauses.
SerpApi, LLC
Role: Processor: fetches public Google Scholar pages for us
Receives: Google Scholar profile IDs
Location and safeguard: United States, under the EU Standard Contractual Clauses in SerpApi’s data processing agreement. SerpApi deletes search data after 31 days.
Google LLC
Role: Independent controller for Google sign-in, and the provider of the mailbox that receives your emails to us
Receives: Your sign-in request; emails you send us
Location and safeguard: United States, under the EU–U.S. Data Privacy Framework. Google’s privacy policy applies to its sign-in service.

7How to delete your data

You can delete your account at any time in Settings. This immediately deletes your account, sessions, page, bio and uploaded photo, and stops the daily updates. The Google Scholar data mirrored for your page and its citation history are deleted within 30 days. Copies that Cloudflare keeps for database recovery expire after at most 30 days, request logs after at most 7 days, and SerpApi’s search records after 31 days.

8Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you (Art. 15);
  • rectification of inaccurate or incomplete data (Art. 16);
  • erasure of your data (Art. 17);
  • restriction of processing (Art. 18);
  • portability: to receive your data in a structured, machine-readable format (Art. 20);
  • objection to processing based on our legitimate interests (Art. 21).

Email privacy@schovis.com to use any of them. We reply within one month and may ask you to confirm your identity first. Data that comes from Google Scholar is best corrected at the source: change it on your Scholar profile and Schovis picks up the change within a day.

You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU country where you live or work, or where you think an infringement took place (Art. 77).

Schovis makes no decisions about you based solely on automated processing, and does no profiling in the sense of Art. 22 GDPR. The indices on your page are computed from your public publication data only to display them.

9Security

All traffic to Schovis is encrypted with HTTPS, and access to stored data is limited to the two people who run the service. If a personal data breach occurs, we will notify the supervisory authority and, where required, the people affected, as Articles 33 and 34 GDPR require.

10Children

You must be at least 16 to create an account (Art. 8 GDPR). Schovis is meant for researchers and is not directed at children.

11Changes to this policy

When we change this policy, we publish the new version here and update the effective date. We announce material changes on schovis.com before they take effect.

12Contact

Questions or requests about your data: privacy@schovis.com.