Policy documents
Privacy Policy
Last updated: 9 August 2026
This policy explains what PublishJourney collects about you, why, how long we keep it, and who else sees it.
Your research text is processed temporarily and is never stored.
1. Who we are
PublishJourney ("we", "us", "our") operates the PublishJourney website and service. We are based in Sydney, Australia.
For any privacy question or request, contact support@publishjourney.com.
2. Scope
This policy applies to the PublishJourney website and to the account you create on it.
It does not apply to third-party websites we link to, such as a journal's own site or a publisher's submission system. Those services operate under their own privacy policies.
3. Information we collect
Almost all of the information we hold is information you provide to us.
Account information. Your email address, your first and last name, and a secure cryptographic hash of your password. We do not store your password itself. If you sign in through a third-party identity provider, we receive the information that provider sends us, typically your name and, where available, an email address.
Profile information (all optional). Research interests, academic level, country, institution, ORCID iD, and your language and theme preferences.
Content you create in the service. The venues you track, the manuscripts and submissions you record, community reports and venue notes you write, and feedback you send us.
Communication preferences. Your notification and email settings.
Activity and security records. A log of significant actions taken in the account, the time they occurred, and a cryptographic hash of the originating IP address. We do not store raw IP addresses in this log.
We do not collect special category information, and we ask that you do not submit it to us.
4. Paper titles and abstracts
This section applies to the paper matching and discovery tools, and we ask you to read it.
We do not store the abstract you enter. We retain only a cryptographic hash of it, used solely as a cache key so that repeating the same search does not repeat the work.
Your abstract is not sent to the public scholarly database provider. To identify venues that publish work similar to yours, the information we send to the public scholarly database provider is your paper's title, together with keywords derived from that title on our own systems. Your abstract is transmitted to us over an encrypted connection, held in memory only while your results are calculated, and then discarded.
If you would prefer not to transmit an abstract at all, use title-only mode.
5. How we use your information
We use the information described above to:
- create and maintain your account, and authenticate you;
- provide the service, including venue matching, tracking, deadline reminders and the other research tools;
- send transactional email, such as address verification, password resets and the notifications you have enabled;
- respond to your feedback and support requests;
- protect the service against abuse, fraud and unauthorised access, and investigate incidents;
- understand aggregate usage so that we can improve the product; and
- comply with our legal obligations.
We do not sell your information, we do not share it for advertising purposes, and there are no advertising or analytics trackers on the site.
6. Who else sees your information
We use a small number of service providers to operate PublishJourney. Each receives only the information it requires to perform its function, and each is bound by contract to protect it and to use it only on our instructions:
- a cloud hosting provider, which serves the website and runs our scheduled jobs;
- a managed database provider, which stores your account and your content;
- a transactional email provider, which delivers verification, password reset and notification messages;
- identity providers, only where you choose to sign in through one of them; and
- the public scholarly database provider, the open scholarly database operated by OurResearch, which receives the search information described in section 4.
We may also disclose information where we are required to do so by law, where necessary to protect our rights or the safety of others, or in connection with a corporate transaction such as a merger or acquisition, in which case we will notify you before your information becomes subject to a different policy.
7. International transfers
Our service providers may store or process information in countries other than Australia. Where information is transferred outside Australia, we take reasonable steps to ensure it remains protected to a standard consistent with this policy.
8. Cookies
We use a small number of strictly necessary cookies and preference cookies, and no tracking cookies. Each one is listed by name in our Cookie Policy.
9. Security
We protect your information using measures appropriate to its sensitivity. Traffic to the service is encrypted in transit. Passwords are stored only as secure cryptographic hashes. Access to production systems is restricted, security headers and a content security policy are applied to every response, and a live session is invalidated server-side when an account is locked or closed.
No system can be guaranteed to be completely secure. We have not undertaken an independent security audit or penetration test of the service, and we state this rather than imply otherwise.
10. Retention and account closure
We keep your information for as long as your account is open, and afterwards only for as long as we need it for the purposes described in this policy or as required by law.
You can close your account at any time from the Danger zone in your profile settings. Please understand what this does today:
- your session ends and you are signed out shortly afterwards;
- you cannot sign in again; and
- the underlying account record, together with its audit history, is archived rather than immediately deleted.
Complete erasure is not currently available as a self-service action. If you want your information erased entirely, contact support@publishjourney.com and we will action the request manually.
11. Your rights
Subject to any legal limits that apply, you may:
- access the information we hold about you;
- correct information that is inaccurate or out of date, most of which you can edit directly from your profile;
- request deletion of your information, as described in section 10;
- object to or restrict certain uses of your information, including turning off email notifications;
- request a copy of information you have provided to us, in a commonly used format; and
- complain to us, or to your relevant privacy regulator, about how we have handled your information.
To exercise any of these rights, contact support@publishjourney.com. We will respond within a reasonable period. We may need to verify your identity before we act on a request. There is no charge for making a request, and we will not treat you differently for making one.
If you have closed your account and can no longer sign in, you can still contact us at the address above.
12. Children
PublishJourney is a tool for academic researchers and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has provided us with information, contact us and we will delete it.
13. Changes to this policy
We may update this policy from time to time. Where a change materially affects you, we will notify you within the product rather than amend this page silently. The date at the top of this policy shows when it was last revised.
14. Contact
PublishJourney
Sydney, Australia
support@publishjourney.com
15. Bibliography Health Check
When a reference includes a DOI, we send only that identifier to Crossref and DOI.org for verification. Records without a DOI stay on our systems and require manual confirmation. We do not send your manuscript, abstract, reference titles, or author names to these services.
The uploaded or pasted bibliography is processed temporarily to produce your report. We do not persist or log raw references, titles, authors, citation keys, DOIs, or proposed corrections; they are discarded after the request. Activity records contain aggregate counts and the detected file format only.