WikiBiomeThe human microbiome encyclopedia
Governance · effective September 5, 2026

Privacy

WikiBiome is designed for public reading with minimal data collection. This page describes the information used by the features currently implemented on the site.

Public browsing

You can read articles, sources, indexes, and research tools without creating an account. Standard technical request information may be processed by the hosting and security infrastructure to deliver pages, prevent abuse, and maintain service reliability.

Signed-in contributions

WikiBiome uses ORCID for the unified researcher proposal workflow. Legacy ChatGPT contribution identities and submissions are preserved and linked to the local researcher account when the same signed-in contributor connects ORCID. A proposal stores its account, target, scientific anchor, proposed text, mechanism, causal limits, supporting identifiers, conflicts, timestamps, status, and moderator events.

This information is used to attribute submissions, communicate about review, prevent anonymous medical rewriting, and preserve a recoverable editorial history. Contributions are not published automatically.

Researcher identity and profiles

Researcher privileges require authentication through ORCID. WikiBiome stores the authenticated ORCID iD, public name, profile biography, affiliations, expertise, claimed works, submissions, discussions, and moderation history. Public profiles clearly distinguish self-declared expertise from expertise inferred from verified works.

WikiBiome asks researchers to provide a separate magic-link-verified contact email. That address is stored privately and is never displayed on a public profile, source claim, discussion, or institution page. ORCID is not used as an email-harvesting source.

ORCID work discovery

After sign-in, WikiBiome may read the public works on your ORCID record and cache only minimal public metadata: work key, title, DOI, year, journal, ORCID put-code, source-update time, and sync status. Exact DOI and possible title/year connections are private suggestions until you confirm them. Private or missing ORCID works are not inferred or exposed.

Email choices and citation notices

Research activity notifications, community digests, researcher-event updates, and early-invitation consideration are separate, optional choices. Historical fundraising consent is retained as historical data and is not interpreted as event or invitation consent. Platform access is not conditional on any marketing or event consent. Every address is checked against a global suppression list, and bounces, complaints, and unsubscribe requests disable further delivery as applicable.

A limited author-outreach pilot may send one factual notice to a documented corresponding-author address explaining where a work is cited. The contact ledger records the address source, purpose, applicable jurisdiction rule, delivery history, and suppression state. Cold citation notices contain no fundraising request.

Research uploads and discussions

Paper intake uses private storage and, when configured and with the submitter’s permission, OpenAI-assisted extraction after malware scanning. Extracted passages, page numbers, document fingerprints, metadata, proposed changes and review history are retained for editorial provenance. Private packets are accessible to the submitter, their actively appointed and assigned reviewer, and editors. Approved publication metadata and editorial reasons may accompany the resulting public source record; the uploaded PDF remains private.

Submitted bibliographic metadata and review records are retained for editorial provenance. Optional PDF manuscripts are accepted only with a rights attestation, stored privately in a quarantine bucket, and are not made available to readers. Files that are oversized, encrypted, or contain active or embedded content are rejected; quarantined files remain unavailable until a clean scan is recorded.

Public discussion posts, revisions, source links, conflict disclosures, and attributed researcher identities are retained as part of the scientific record. Reports, moderator notes, blocks, rate-limit events, and audit events are kept to support safety and accountable moderation. Do not post personal health information.

Proposals, follows, and notifications

Scientific proposals store their framework anchor, draft content, sources, rationale, mechanistic connection, causal limitations, conflict disclosure, status, events, and editorial linkage. Only accepted proposals are public. Follows and in-app notifications are private account records used to route replies, mentions, decisions, and activity on followed or claimed work.

Researcher messaging

Private messaging requires an accepted contact request. Messages are visible to participants and are not end-to-end encrypted. WikiBiome moderators may inspect a reported message and the surrounding conversation needed to evaluate the report. Message metadata, blocks, reports, rate-limit records, and moderation outcomes are retained for safety and auditability. Attachments are not accepted.

Research events and recognition

The researcher-event registry stores selected event types, roles, tracks, format preference, location, availability, a proposed question, separate early-invitation consent, and separate event-update consent. Interest and consent can be withdrawn. Joining does not register you for an event or guarantee an invitation.

Public contribution stars are recorded in an immutable recognition ledger with the level, qualifying source, reason, reviewer where applicable, status, and date. Pending, rejected, duplicated, removed, or payment-related activity does not count.

Support payments

Support payments open a Stripe-hosted checkout page. Stripe processes payment credentials for Microbiome Signatures LLC. WikiBiome does not request or store card numbers in its application code. Stripe’s own privacy terms apply to the checkout service.

Cookies and local storage

The site uses essential, signed-in session cookies for contribution and researcher workflows. Researcher cookies are HTTP-only and SameSite-protected; OAuth attempts use expiring, single-use state records. Device-native features such as copying or sharing a link run in your browser. WikiBiome does not include an advertising network or sell browsing information for marketing.

Search and performance measurement

WikiBiome uses a first-party, privacy-limited measurement endpoint to count landings by search-engine family and to sample Core Web Vitals. The application records the normalized page path, metric name, value, rating, and navigation type. It does not record a search query, full referrer, cookie, account or session identifier, IP field, or user-agent field in the analytics event. These events are written to the site’s existing operational logs; no third-party analytics script or advertising tracker is loaded.

Retention and requests

Contribution records are retained to support attribution, editorial review, abuse prevention, and revision history. To request access, correction, or deletion of personal information where applicable, email privacy@wikibiome.com. Some records may need to be retained when required for security, legal obligations, or the integrity of an attributed public revision.

Related pages

Read the Terms of Use, contact WikiBiome, or inspect the public go-live and corpus register.