Skip to content

Privacy Policy

Effective date: 2026-09-29.

NEMAR (Neuroelectromagnetic Data Archive and Tools Resource) is a research data archive. This policy covers the personal information NEMAR holds about its registered users, and how the website measures its own use. The datasets NEMAR hosts are covered separately by the Data Contributor Terms and the GDPR Position Statement.

Contact for anything in this policy: privacy@nemar.org.

When you create a NEMAR account, we collect:

  • name and email address;
  • username and, where provided, ORCID (Open Researcher and Contributor ID) iD, GitHub username, affiliation, city, and country;
  • a password hash, but only for command-line accounts created before browser sign-in shipped (we never store plaintext passwords); a new account, on the web or the command line, has no password at all, since sign-in is through ORCID.

While you use the service, we also process:

  • credentials we issue to you (one or more named API keys, one per machine, storage credentials, and a GitHub access token), which exist so you can upload and manage datasets; each key is listed and revocable in Settings;
  • short-lived email verification and login codes, and, for command-line sign-in, a device code and a one-time confirmation code valid for ten minutes, stored hashed together with the name of the machine that requested it;
  • operational logs of requests to our services, used for reliability and abuse prevention;
  • your email notification preferences.

We do not sell personal information, use it for advertising, or share it with third parties except the service providers listed below.

  • To operate your account: authentication, dataset ownership, and collaborator access control.
  • To contact you about your account and datasets: verification, approval, publication review, and service notices. Non-essential notifications respect your email preferences.
  • To attribute published datasets: if you publish a dataset, your name and, where provided, ORCID iD appear in the public dataset metadata and Digital Object Identifier (DOI) record. This is standard scholarly attribution and is part of what you agree to when publishing.

NEMAR runs on infrastructure in the United States. Our service providers process data on our behalf: Cloudflare (application hosting and database), Amazon Web Services (dataset storage), GitHub (dataset version control), and an email delivery provider (transactional email). Each provides contractual data protection commitments, including Standard Contractual Clauses or certification under the EU-US Data Privacy Framework where European data is involved. See the GDPR Position Statement for details on international transfers.

The website sets two cookies:

  • a strictly necessary cookie that keeps you signed in;
  • a preference cookie that remembers your analytics choice for one year, on both nemar.org and app.nemar.org.

To learn how the website is used, NEMAR runs its own instance of Umami, a privacy-focused analytics tool, on NEMAR servers. It is on by default on the production website, on a fixed set of public pages and the upload pages. It records which of those pages was viewed and a fixed set of actions: opening a citation, opening or using the recording viewer, and starting or completing an upload. From each request it also derives the kind of browser, operating system, and device, and an approximate location from your IP address, which it does not store. It receives no account details, dataset identifiers, file names, or search text, and it sets no cookies of its own. We never sell this data.

To turn analytics off, choose Strict only in the cookie notice, or under Privacy settings in the website footer or your account Settings. The website then uses only the two cookies above. If your browser blocks the preference cookie, your choice is kept in browser storage for that site only.

Account records are kept while your account is active. Verification and login codes expire shortly after issue. Operational logs are retained for a limited period for security and debugging. If your account is deleted, we remove your account record and revoke all issued credentials; your name may remain in the public metadata of datasets you published, because published scholarly records are permanent.

You can ask us at any time to:

  • access or export the information we hold about your account;
  • correct it (much of it is self-service in your account settings);
  • delete your account, which revokes all issued credentials;
  • object to non-essential email, or adjust your notification preferences directly.

If you are in the European Union or another jurisdiction with statutory data subject rights, these requests are honored under those laws. Write to privacy@nemar.org and we will respond within 30 days. You also have the right to complain to your local data protection authority.