What This Covers
This policy applies to stemreview.org and to the pages served from it. STEM Review is a publication about science and technology, and this page describes what happens to information about the people who read it. It does not govern the outside websites our articles cite. Several clauses below describe something the site does not do; those are descriptions of how it is built today.
You can read STEM Review without an account, because there are no accounts. The only information collected as a matter of course is what a web server necessarily records in order to send a page to a browser. What follows is the detail of that, the few places where you can choose to send us something, and the rights you have either way.
What the Server Records
Every page you open is delivered by a hosting platform, and delivering it produces a log entry. That entry can include your IP address, your browser's User-Agent string, the path you requested and any search parameters attached to it, the HTTP method and the response status, the referring page where your browser sends one, the time of the request, the edge location that served it, whether the response came from cache, and a generated request identifier. This is the only information the site gathers about readers without being asked.
Those records exist so that pages can be served, so that abusive traffic and automated attacks can be identified and slowed, so that errors can be diagnosed, and so that traffic volume can be understood in aggregate. Where the UK or EU General Data Protection Regulation applies, the lawful basis is legitimate interests under Article 6(1)(f). The interest is keeping a public website available, correct, and resistant to abuse, and the processing goes no further than the server needs. Nothing here asks for consent, because nothing here requires it.
The RSS feed at /feed/ is an ordinary web address, so a request from a feed reader is logged exactly like a request from a browser; some feed clients name themselves in the User-Agent string, and none of them is added to a subscriber list, because none is kept. Those logs are held by the providers that generate them, and how long they keep them is set by the hosting plan rather than by us; we do not extend it. No copy is moved into a database of ours, so nothing accumulates into a long-term record of who read what.
Who Else Handles Data
Four providers necessarily handle data in the course of this site working. The pages are built and served by Vercel, the hosting and content-delivery platform, which holds the request logs described above. The articles come from a WordPress installation that the site reads over its API, served by a commercial web host, which keeps its own server logs of those requests. Email sent to the address at the end of this page is delivered and stored by the mail provider behind unipub.org, a domain this publication does not control, and it holds the message and everything in it for as long as the mailbox does. Google receives the analytics data described above through Google Analytics 4 and processes it under its own terms, subject to the retention period configured on the property. Each of the four handles that data on the terms it publishes; those terms are not restated here, because they are the providers' to state and to change.
Nothing is passed to advertisers, analytics vendors, marketing platforms, or brokers, because none of them is involved in serving this site. The hosting platform serves the site from a global network of edge locations, so a request may be handled outside the country you are reading from, usually at whichever location is nearest to you. Where a request from the United Kingdom or the European Economic Area is handled outside those areas, the transfer relies on whatever safeguards that provider offers under its own terms. No specific transfer instrument is named here, because none has been confirmed against those terms as they currently stand.
Pages are served only over encrypted connections. Beyond that, the protection here is structural rather than technical: there is no reader database, so there is no store of reader identities to lose.
Media and Outside Links
The main image on an article is processed by the site and served from stemreview.org, and older upload addresses are routed through the site rather than fetched from the backend directly. Article bodies, however, are published as written. If a body contains an image, a video, or an embed pointing at another host, your browser retrieves it from that host, and that host will see your IP address and User-Agent exactly as any site you visit would.
Articles cite and link to outside sources as a matter of course; that is what makes them checkable. Following one of those links takes you to a website we do not run, cannot inspect, and cannot speak for, and from that point its handling of your information applies rather than ours. The same is true of the search engines, feed readers, and aggregators that may have brought you here.
Your Rights
Readers in the United Kingdom and the European Economic Area have the rights the GDPR provides: to ask what is held about them, to have it corrected or erased, to have its use restricted, to object to processing carried out on the basis of legitimate interests, to receive it in a portable form where that applies, and to complain to the data protection authority in their own country. You do not have to explain why you are asking, and asking costs nothing.
What the site holds is technical log data with no name, account, or identifier attached, and we keep nothing that would connect a log line to a particular person. In most cases we therefore cannot locate your data in order to show it to you or delete it, and we will not gather further information about you in an attempt to. Article 11 of the GDPR anticipates this position. Correspondence you have sent us is the one category that can be located, and a deletion request can be acted on in the mailbox that holds it.
For readers in California: the categories of personal information collected are the request records described above, the search terms readers type into the site, and whatever a reader chooses to put in an email to us. They are handled by the four providers named above. No personal information is sold or shared, so there is no opt-out to offer and no such link on this site.
Changes and Contact
This page carries the date it was last updated. Any change that adds a way of collecting or handling reader information will be reflected here in the same change that introduces it, rather than afterwards. If a revision is material, the updated text will stand on this page in place of the old.
Questions about this policy, and requests under the rights described above, can be sent to info@unipub.org, the publication's general address. Where the GDPR gives you a right to an answer within a set period, that period applies to a request under those rights here as it does anywhere. How correspondence to this address is handled otherwise is described on Contact.
Last updated 13 August 2026. See also Editorial Policies, Terms of Service and Contact.