Privacy notice
Last updated 12 September 2026
The short version: we store your name and email so we can send you your shortlist. We never store the abstract you paste.
Who we are
Journal Hunt is operated from the United Kingdom and is the data controller for the personal data described here. For any question about your data, or to exercise any of the rights below, email privacy@journalhunt.org.
What we collect, and why
| What | Why | Lawful basis | Kept for |
|---|---|---|---|
| First name, last name, email | To unlock your full results and email you the shortlist | Legitimate interests — you asked us for this | Until you delete your account, or 24 months without use |
| Marketing consent, and when you gave it | To send occasional product updates, only if you ticked the box | Consent | While you remain subscribed, plus 2 years as a record |
| Your saved shortlist — journal names and your keywords | So the link we email you keeps working | Legitimate interests | 90 days |
| A one-way hash of your IP address | To stop one person creating thousands of signups | Legitimate interests | 24 hours |
| A daily-changing hash of your IP and browser | To count visitors without identifying anyone — see below | Legitimate interests | 35 days, then only the daily total survives |
Your abstract
The abstract you paste is unpublished research, and we treat it that way.
- It is used to run that one search, and nothing else.
- It is never written to our database — not even when you save a shortlist. What we keep is the list of journals we suggested and your keywords.
- It is never used to train an AI model.
How we measure what is read
We use Plausible to see which pages are opened and which sites people arrive from, so we know whether this is useful to anyone. It sets no cookies and stores nothing on your device.
Plausible recognises a visit the same way our own counter does: a hash of your IP and browser combined with a secret that is deleted every 24 hours. It does not store IP addresses, and the data stays in the European Union. It records the address of the page you opened and the site you came from — never what you typed, which is not in any page address here because searches are not sent through the address bar.
When something breaks
If a page fails, an automatic report goes to Sentry, our error-monitoring supplier, so that we find out without waiting for somebody to tell us. The report holds the programming error, the address of the page, and the name and version of your browser.
Before any report leaves our server we strip out everything you typed. That means the contents of the search — your abstract and your keywords included — as well as the web address you arrived from and your IP address. We do not record what you see on screen. This is enforced in the code and checked automatically every time the site is updated, rather than being a matter of configuration we might get wrong.
How we count visitors
The figures at the bottom of the home page are real, and they are collected without tracking anybody. We identify a visit by a hash of your IP address and browser combined with a secret that changes every day.
Within a single day that hash is stable enough to avoid counting you twice. The next day it is a completely different value, so nobody can follow you from one day to the next — including us. No cookie is set, which is why you have never been asked to accept one. The hashes are deleted after 35 days; all that remains is a number.
Who else handles your data
We use these suppliers, each acting as our processor under a data processing agreement:
| Supplier | What they handle | Where |
|---|---|---|
| Supabase | Our database — your name, email and shortlists | London, United Kingdom |
| Vercel | Hosting, and server logs including IP addresses | United States |
| Resend | Sending your shortlist email | United States |
| Voyage AI | Converting your abstract for searching, not stored | United States |
| Sentry | Telling us when a page breaks — see below | European Union |
| Plausible | Counting page views, without cookies — see below | European Union |
Where a supplier is outside the UK, the transfer is covered by the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. Your account data itself is held in the United Kingdom.
Your rights
Under UK GDPR you can ask us to:
- give you a copy of the personal data we hold about you
- correct anything that is wrong
- delete your data
- restrict or object to how we use it
- send your data to another service
- withdraw marketing consent, at any time, with no effect on your results
See or delete your data now
You do not have to email anyone or wait. Enter your address and we will send you a link that shows everything we hold, lets you download it, and lets you erase it permanently.
You can also email privacy@journalhunt.org and we will respond within one month. Either way, it costs nothing.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office, the UK regulator. We would rather you told us first so we can put it right.
Security
Data is encrypted in transit and at rest. Our database refuses all access to personal data except through our own server, and the browser is never given a key that can read it. Access to the live system requires two-factor authentication.
Children
Journal Hunt is for researchers and is not directed at children. We do not knowingly collect data from anyone under 16.
Changes
If we change how we use your data we will update this page and change the date at the top. If the change is significant and we hold your email, we will tell you directly.

