Skip to content
Legal

Privacy Policy

What a publication with no reader accounts records about the people who read it, who else handles it, and what you can do about it.

Last updated

What This Covers

This policy applies to stemreview.org and to the pages served from it. STEM Review is a publication about science and technology, and this page describes what happens to information about the people who read it. It does not govern the outside websites our articles cite. Several clauses below describe something the site does not do; those are descriptions of how it is built today.

You can read STEM Review without an account, because there are no accounts. The only information collected as a matter of course is what a web server necessarily records in order to send a page to a browser. What follows is the detail of that, the few places where you can choose to send us something, and the rights you have either way.

What the Server Records

Every page you open is delivered by a hosting platform, and delivering it produces a log entry. That entry can include your IP address, your browser's User-Agent string, the path you requested and any search parameters attached to it, the HTTP method and the response status, the referring page where your browser sends one, the time of the request, the edge location that served it, whether the response came from cache, and a generated request identifier. This is the only information the site gathers about readers without being asked.

Those records exist so that pages can be served, so that abusive traffic and automated attacks can be identified and slowed, so that errors can be diagnosed, and so that traffic volume can be understood in aggregate. Where the UK or EU General Data Protection Regulation applies, the lawful basis is legitimate interests under Article 6(1)(f). The interest is keeping a public website available, correct, and resistant to abuse, and the processing goes no further than the server needs. Nothing here asks for consent, because nothing here requires it.

The RSS feed at /feed/ is an ordinary web address, so a request from a feed reader is logged exactly like a request from a browser; some feed clients name themselves in the User-Agent string, and none of them is added to a subscriber list, because none is kept. Those logs are held by the providers that generate them, and how long they keep them is set by the hosting plan rather than by us; we do not extend it. No copy is moved into a database of ours, so nothing accumulates into a long-term record of who read what.

Cookies and measurement

The site uses Google Analytics 4 to count visits and see which articles are read. It is the only measurement on the site. GA4 sets cookies in your browser (names beginning "_ga") to tell one visit from another and to recognise a returning browser, and it sends Google your page address, referrer, approximate location, device and browser details, and your IP address. Google states that GA4 uses the IP address to derive that approximate location and does not retain it. Typefaces are compiled into the site and served from its own domain, so displaying a page sends no request to a font provider.

Nothing else measures you. There are no reader accounts, passwords, comments, or uploads. The site carries no advertising, no sponsored content, and no advertising identifiers. There is no session replay, no device fingerprinting, and no tracking pixel other than the analytics tag described above. STEM Review does not build profiles of readers, does not target content by behaviour, does not share reader information with data brokers, and does not sell personal information. No automated decision-making producing legal or similarly significant effects is applied to anyone who reads the site.

You can stop the analytics cookies at browser level by blocking third-party scripts or by installing Google's opt-out add-on, and the site works normally without them. STEM Review is written for a general and professional readership rather than for children, and it offers no registration, comment field, or upload. The only two fields anywhere on the site are the search box and the newsletter form, and the clause below says what happens to what is typed into each.

Search, Newsletter, and Email

A term typed into search travels in the address of the results page. It therefore appears in the hosting platform's request log along with the rest of the URL, and it is passed to the content system the site reads from, where that host keeps its own access log. Results pages are marked so that search engines do not index them. Because a query is written into a log line as a matter of course, do not type personal information into the search field.

Whether a mailing provider is connected is a matter of configuration rather than of code, so what follows describes the site as configured today and states a commitment for any change to that. As configured, the newsletter form is not connected to a mailing service: a submitted address is sent to an endpoint on this site, checked for the shape of an email address, and answered with a visible error saying signup is not connected yet. It is held only for the length of that request—not stored, not written to any log, and not passed to a mailing provider, because none is configured. No address will be passed to a mailing provider until this page names that provider and the way to unsubscribe. Naming it here is a precondition of connecting it, not a follow-up.

Email you send to the address at the end of this page arrives in an ordinary mailbox and stays there for as long as answering it requires. It holds whatever you chose to write and whatever your own mail provider attaches to it. This is the one part of the site where the amount of information involved is entirely your choice, and the only part where your information can be found again afterwards.

Who Else Handles Data

Four providers necessarily handle data in the course of this site working. The pages are built and served by Vercel, the hosting and content-delivery platform, which holds the request logs described above. The articles come from a WordPress installation that the site reads over its API, served by a commercial web host, which keeps its own server logs of those requests. Email sent to the address at the end of this page is delivered and stored by the mail provider behind unipub.org, a domain this publication does not control, and it holds the message and everything in it for as long as the mailbox does. Google receives the analytics data described above through Google Analytics 4 and processes it under its own terms, subject to the retention period configured on the property. Each of the four handles that data on the terms it publishes; those terms are not restated here, because they are the providers' to state and to change.

Nothing is passed to advertisers, analytics vendors, marketing platforms, or brokers, because none of them is involved in serving this site. The hosting platform serves the site from a global network of edge locations, so a request may be handled outside the country you are reading from, usually at whichever location is nearest to you. Where a request from the United Kingdom or the European Economic Area is handled outside those areas, the transfer relies on whatever safeguards that provider offers under its own terms. No specific transfer instrument is named here, because none has been confirmed against those terms as they currently stand.

Pages are served only over encrypted connections. Beyond that, the protection here is structural rather than technical: there is no reader database, so there is no store of reader identities to lose.

Your Rights

Readers in the United Kingdom and the European Economic Area have the rights the GDPR provides: to ask what is held about them, to have it corrected or erased, to have its use restricted, to object to processing carried out on the basis of legitimate interests, to receive it in a portable form where that applies, and to complain to the data protection authority in their own country. You do not have to explain why you are asking, and asking costs nothing.

What the site holds is technical log data with no name, account, or identifier attached, and we keep nothing that would connect a log line to a particular person. In most cases we therefore cannot locate your data in order to show it to you or delete it, and we will not gather further information about you in an attempt to. Article 11 of the GDPR anticipates this position. Correspondence you have sent us is the one category that can be located, and a deletion request can be acted on in the mailbox that holds it.

For readers in California: the categories of personal information collected are the request records described above, the search terms readers type into the site, and whatever a reader chooses to put in an email to us. They are handled by the four providers named above. No personal information is sold or shared, so there is no opt-out to offer and no such link on this site.

Changes and Contact

This page carries the date it was last updated. Any change that adds a way of collecting or handling reader information will be reflected here in the same change that introduces it, rather than afterwards. If a revision is material, the updated text will stand on this page in place of the old.

Questions about this policy, and requests under the rights described above, can be sent to info@unipub.org, the publication's general address. Where the GDPR gives you a right to an answer within a set period, that period applies to a request under those rights here as it does anywhere. How correspondence to this address is handled otherwise is described on Contact.

Last updated 13 August 2026. See also Editorial Policies, Terms of Service and Contact.