RetractThat is designed around pseudonymity and data minimisation.

Access data

Eligibility is checked at sign-in, while stored rate-limit and session identifiers are pseudonymous. Raw email addresses and copied IP addresses are not retained in application storage or logs.

Authentication codes are short-lived, single-use credentials and must not be shared.

Analytics boundary

If research analytics are enabled, they are limited to an approved set of coarse product events and pseudonymous identifiers. Free text, clinical content, editorial drafts, provider details, and direct identifiers are excluded.

This page describes the application boundary; it does not claim that identifying analytics are live or collected.