Privacy Policy
Effective . Applies to schovis.com and every Schovis page.
Schovis turns a public Google Scholar profile into a public page of research impact. This policy explains, as the EU General Data Protection Regulation (GDPR) requires, what personal data Schovis processes, why, and what rights you have. We process only what the service needs.
1Who is responsible
Schovis is run by Ekrem Çetinkaya and Ammar Rashed, who decide together how personal data is processed and are therefore joint controllers (Art. 26 GDPR). They have agreed that Ekrem Çetinkaya handles all data protection requests. You can still exercise your rights with either of them. Contact: privacy@schovis.com.
2What we process, why, and for how long
Table 1 lists every kind of personal data Schovis processes. You need a Google account and a public Google Scholar profile to create a page; without them we cannot provide the service. Visiting pages requires no account.
- Name, email address and Google account ID, received from Google when you sign in
- Purpose: Sign you in and run your account
- Legal basis (GDPR): Contract, Art. 6(1)(b)
- Kept: Until you delete your account
- Your Google Scholar profile ID, username, and the bio and photo you add
- Purpose: Publish your Schovis page
- Legal basis (GDPR): Contract, Art. 6(1)(b)
- Kept: Until you delete your account; a replaced photo is deleted at once
- Public data from your Google Scholar profile and a daily record of your citation totals
- Purpose: Build your page and keep it up to date
- Legal basis (GDPR): Contract, Art. 6(1)(b)
- Kept: Deleted within 30 days after you delete your account
- Public Scholar data of a profile looked up during sign-up but not turned into a page
- Purpose: Let you confirm that a profile is yours before a page is created
- Legal basis (GDPR): Legitimate interests, Art. 6(1)(f)
- Kept: Deleted within 30 days
- A session record: a random token and its expiry date (no IP address, no device details)
- Purpose: Keep you signed in
- Legal basis (GDPR): Contract, Art. 6(1)(b)
- Kept: Until you sign out or delete your account
- Request data: IP address, browser, the page requested and the time
- Purpose: Deliver the site, keep it secure and prevent abuse
- Legal basis (GDPR): Legitimate interests, Art. 6(1)(f)
- Kept: At most 7 days, in Cloudflare’s logs
- Emails you send us
- Purpose: Answer you and handle your requests
- Legal basis (GDPR): Contract or legitimate interests, Art. 6(1)(b) or (f)
- Kept: As long as needed to handle your request
From Google sign-in we receive your name, email address, Google account ID and profile picture. We keep the first three and discard the picture. We also discard Google’s access tokens: Schovis never accesses your Google account. When you sign in, your IP address is briefly held in memory to limit repeated sign-in attempts; it is never written to our database.
Our legitimate interests are running a secure, reliable service and letting researchers confirm their own profile before a public page is created. You can object to processing based on them (section 8).
3Where the data comes from
You give us your Google Scholar profile link. The data we show about your research comes from your public Google Scholar profile, which SerpApi retrieves for us once a day: your name, affiliation, verified email domain, research interests, homepage, citation statistics and publication list.
Publication lists include every author as Google Scholar shows them, so the names of your co-authors appear on your page too. We show them because an accurate publication record is what the page is for (legitimate interests, Art. 6(1)(f)). Co-authors and other people whose names appear can contact us to exercise their rights, including the right to object.
4Your page is public
A Schovis page is public by design. Anyone with the link can see it, and search engines may index it. It shows your public Google Scholar data together with the username, bio and photo you add. Your email address from Google sign-in is never shown. If you do not want a public page, do not create one, or delete your account (section 7).
5Cookies, and nothing else in your browser
Schovis sets only the cookies in Table 2. All of them are strictly necessary for sign-in, so they need no consent. There are no analytics, advertising or tracking cookies.
__Secure-better-auth.session_token- Purpose: Keeps you signed in
- Lasts: 7 days after your last visit
__Secure-better-auth.session_data- Purpose: A signed copy of your session, so pages load without a database lookup
- Lasts: 5 minutes
__Secure-better-auth.state- Purpose: Protects the Google sign-in against forged requests
- Lasts: 5 minutes, during sign-in only
Pages, fonts and images are all served from schovis.com, including photos: Schovis never embeds your Google Scholar photo. Your browser contacts another company only when you follow a link, for example to Google Scholar, or when you choose to sign in with Google.
6Who receives data, and transfers outside the EU
Only the recipients in Table 3 receive personal data, and our processors use it only to provide their service to us, under data processing agreements (Art. 28 GDPR). We do not sell or rent personal data, show advertising, or send marketing email. We disclose data to authorities only when the law requires it.
- Cloudflare, Inc.
- Role: Processor: hosting, databases, file storage, request logs, and forwarding emails sent to schovis.com addresses
- Receives: Everything in Table 1
- Location and safeguard: Databases and files are stored in Cloudflare’s Western Europe region. Requests and emails may be handled at Cloudflare locations worldwide under Cloudflare’s Data Processing Addendum, which includes the EU Standard Contractual Clauses.
- SerpApi, LLC
- Role: Processor: fetches public Google Scholar pages for us
- Receives: Google Scholar profile IDs
- Location and safeguard: United States, under the EU Standard Contractual Clauses in SerpApi’s data processing agreement. SerpApi deletes search data after 31 days.
- Google LLC
- Role: Independent controller for Google sign-in, and the provider of the mailbox that receives your emails to us
- Receives: Your sign-in request; emails you send us
- Location and safeguard: United States, under the EU–U.S. Data Privacy Framework. Google’s privacy policy applies to its sign-in service.
7How to delete your data
You can delete your account at any time in Settings. This immediately deletes your account, sessions, page, bio and uploaded photo, and stops the daily updates. The Google Scholar data mirrored for your page and its citation history are deleted within 30 days. Copies that Cloudflare keeps for database recovery expire after at most 30 days, request logs after at most 7 days, and SerpApi’s search records after 31 days.
8Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15);
- rectification of inaccurate or incomplete data (Art. 16);
- erasure of your data (Art. 17);
- restriction of processing (Art. 18);
- portability: to receive your data in a structured, machine-readable format (Art. 20);
- objection to processing based on our legitimate interests (Art. 21).
Email privacy@schovis.com to use any of them. We reply within one month and may ask you to confirm your identity first. Data that comes from Google Scholar is best corrected at the source: change it on your Scholar profile and Schovis picks up the change within a day.
You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU country where you live or work, or where you think an infringement took place (Art. 77).
Schovis makes no decisions about you based solely on automated processing, and does no profiling in the sense of Art. 22 GDPR. The indices on your page are computed from your public publication data only to display them.
9Security
All traffic to Schovis is encrypted with HTTPS, and access to stored data is limited to the two people who run the service. If a personal data breach occurs, we will notify the supervisory authority and, where required, the people affected, as Articles 33 and 34 GDPR require.
10Children
You must be at least 16 to create an account (Art. 8 GDPR). Schovis is meant for researchers and is not directed at children.
11Changes to this policy
When we change this policy, we publish the new version here and update the effective date. We announce material changes on schovis.com before they take effect.
12Contact
Questions or requests about your data: privacy@schovis.com.