Global Research Nexus
Effective 27 August 2026

Privacy Policy

How the Global Research Nexus mobile app collects, uses, protects and deletes account, professional-network and community data.

Plain-language summary. We use personal data to operate research discovery, professional profiles and community updates. We do not sell personal data, we do not use it for behavioural advertising, and we do not use cookies or any other technology to track you.

On this page

  1. Scope
  2. Data we process
  3. Why we use it
  4. Service providers
  5. Cookies and tracking
  6. Your choices
  7. Retention
  8. Security
  9. Your rights
  10. Contact

1. Scope and controller

This policy applies to the Global Research Nexus mobile applications for iOS and Android, the Global Research Nexus website, and the connected Global Research Nexus service. Global Research Nexus is responsible for the processing described here. Questions and rights requests can be sent to privacy@researchnexus.in.

2. Data we process

CategoryExamplesHow it is provided
Account and identityEmail address, user ID, display name, full nameSubmitted during magic-link sign-in or profile setup
Professional profileRole, affiliation, research interests and verification statusProvided by you or recorded through an applicable verification workflow
Network and activityFollows, saved funding calls, event RSVPs, reminder choices and policy acceptanceCreated when you use app features
Community contentPost titles, post text, links, uploaded images, image type/dimensions and timestampsSubmitted by you when posting
Safety recordsReports, report reasons, blocks and moderation statusCreated when safety tools are used
Session and technical dataAuthentication tokens stored on your device, request timestamps and security logsGenerated to keep the service secure and signed in
Product analyticsAnonymous app-usage events (which screens are opened and which features are used), an app-generated account identifier, app version and device platformGenerated as you use the app. No advertising identifier is collected, and no message, post or search text is included
Notification deliveryExpo push token, device platform, notification preferences and delivery statusGenerated only after notification permission is granted

The app does not request precise location, contacts, call logs, SMS, microphone data, health records or payment-card data. Selecting a photo gives the app access only to the image you choose through the operating system picker. If you choose to add a research event to your device calendar, the app writes only that event: it never reads your calendar, and no calendar data is sent to us or stored on our servers.

3. Why we use data

Depending on where you live, processing is based on providing the service you request, your consent, our legitimate interests in operating a safe professional network, and legal obligations.

4. Service providers and sharing

We use Supabase to provide authentication, database, file storage and server-side functions. Expo and Firebase process device push tokens and delivery status solely to deliver optional notifications. PostHog processes anonymous product-analytics events for Global Research Nexus, in its European region; we do not enable session recording and we send it no advertising identifier. Supabase and PostHog process data for Global Research Nexus as service providers. We may also disclose limited data when required by law, to protect users and the service, or during a legitimate organisational transaction subject to appropriate safeguards.

We do not sell personal data. We do not share personal data with advertising networks and do not use behavioural advertising.

5. Cookies and tracking

We do not use cookies to track you, and we do not track you by any other means. We do not collect an advertising identifier, we show no advertising, we use no advertising, attribution or data-broker software, and we do not share personal data with anyone for tracking or advertising purposes. Nothing we collect is combined with data from other companies' apps or websites.

The mobile apps contain no embedded web browser. When you open a journal article, a funding call or another external link, it opens in your device's own browser, and any cookies that site sets are that site's and are governed by its own privacy policy, not ours.

Signing in with ORCID opens your device's secure sign-in window. That window is a private session: it is not shared with your browser and it is discarded when sign-in finishes. Cookies inside it exist only to make the sign-in work.

The website uses a small number of strictly necessary cookies, and no others: a session cookie that keeps you signed in, a short-lived security cookie that protects the ORCID sign-in from cross-site request forgery, and a cookie that records that you chose to open the read-only public demo. None of them identifies you to any third party, and none is used for analytics or advertising.

6. Visibility and your choices

Profile information and content you publish may be visible to signed-in users or followers according to the feature used. Reports and block relationships are private safety data. You can unfollow sources, remove saved activity, disable event or network notifications, deny notification permission in system settings, block users, report content, sign out and request account deletion. Do not publish confidential research, patient information or content you do not have permission to share.

7. Retention and deletion

Account and feature data is kept while your account is active and as needed to provide the service. When deletion is completed, account-linked profile, network, saved activity, posts, notifications and uploaded images are deleted or de-identified. Anonymised moderation and security records may be retained for up to 90 days to prevent abuse and document enforcement, then deleted. Backups may expire on their normal protected rotation and are not used to restore a deleted account.

See the Account and Data Deletion page for in-app and external request routes.

8. Security and international processing

We use encrypted network connections, row-level database access controls, authenticated server functions, private media storage and least-privilege administrative access. No internet service can guarantee absolute security. Supabase infrastructure may process data outside your country under its contractual and legal safeguards.

9. Your rights

Depending on your location, you may have rights to access, correct, export, restrict, object to or delete personal data, and to withdraw consent where consent is the basis. Email privacy@researchnexus.in from the address associated with your account. We may verify your identity before acting.

Age

Global Research Nexus is intended for adults aged 18 and over and is not designed for children.

Changes

Material changes will be identified by an updated effective date and, where appropriate, an in-app notice or renewed acceptance request.

10. Contact

Global Research Nexus privacy contact

Email: privacy@researchnexus.in
Suggested subject: Privacy Rights Request