Privacy notice.

JATS Verify

Privacy, as the gate operates today.

Effective 15 August 2026. This notice describes JATS Verify as it operates today.

What this covers

This notice covers the public JATS Verify website and XML packages submitted to the validation workspace. It describes the current service and may change if the service changes.

Package processing

JATS XML, optional assets ZIP files, baselines, and journal profiles are processed synchronously to produce the requested inspection report or release bundle. The service does not intentionally keep durable copies of submitted package content after the response is completed.

Current request files are held only in the server workspace needed to perform the request and are deleted when that request completes. Do not submit content you are not authorized to process.

No registry verification

Validation makes no external DOI, PMID, ORCID, or other registry calls. Identifier checks are limited to local syntax and checksum checks where applicable. The report marks registry checks as not run.

Operational metadata

Standard hosting, security, and request logs may contain limited operational metadata, such as time, network address, request status, and browser information. This notice does not promise that infrastructure providers retain no logs.

For free diagnostics, we store keyed, one-way hashes of the verified email address, email domain, and network address, plus request time, package hash, and finding count. These records enforce the stated free-use limits without storing the uploaded package or the email address in the usage database. The verification email is handled by Google Workspace.

Optional website analytics

With your permission, the public website uses Google Analytics to measure page views and product actions such as requesting a free link or opening checkout. Analytics parameters may include sanitized campaign source, medium, campaign, content, and term values. Submitted XML, filenames, email addresses, access keys, findings, and report contents are not analytics parameters. Analytics storage is denied unless you select Allow analytics, and you can change the choice by clearing this site's browser storage.

JATS Verify keeps a random campaign reference and sanitized campaign values in this site's browser storage for up to 30 days. A later direct visit preserves that campaign during the period, while a different attributed campaign replaces it.

Paid access

If paid access is purchased, payment handling involves Stripe. JATS Verify does not ask you to submit payment-card details in the validation workspace. Stripe's handling is subject to its own notices.

Checkout links may carry the sanitized campaign values and a random browser campaign reference into Stripe. To attribute fulfillment, JATS Verify stores the valid random reference and sanitized campaign source, medium, and campaign with the Stripe Checkout Session identifier, plan, package limit, and creation time. Campaign content and term are not stored in the fulfillment database.

To provision and recover paid access, JATS Verify also stores keyed, one-way hashes of the checkout email and API key, access timestamps, expiry, and keyed package hashes used to count unique packages. The plaintext API key is derived when needed and is sent only to the verified checkout email or returned through a time-limited Access Center link.

Access Center links expire after 30 minutes. Request records include keyed email and network-address hashes for rate limiting. Do not share an Access Center link or API key with anyone who should not use the paid access.

Questions

For privacy questions or a deletion request, contact [email protected]. We cannot promise a particular regulatory classification, retention outcome outside the current request flow, or suitability for a specific legal regime.