Privacy Policy
FORRT ORE — Open Research Extension · Last updated 6 September 2026
This policy explains how FORRT ORE — the Open Research Extension (“the Extension”) — handles data. The Extension is developed and maintained by FORRT — the Framework for Open and Reproducible Research Training — as part of the UKRI-funded project “Making Replications Count”.
The short version. No account, no analytics, no tracking, no advertising. What leaves your browser is paper identifiers (DOIs) and article titles, plus the contact email you enter in settings, which is passed to Crossref, OpenAlex, Unpaywall and NCBI because those services ask for one. On an article page, the address of that page goes to PubPeer with the comment lookup for the paper. Retraction checks happen entirely on your own device.
1. Data controller
For the purposes of the UK and EU General Data Protection Regulation, the data controller is FORRT — Framework for Open and Reproducible Research Training, contactable at info@forrt.org.
2. What the Extension does
The Extension reads the page you are viewing to find academic paper identifiers (DOIs) and, where no DOI is present, article titles. It then looks up what is known about those papers — replication and reproduction studies, retractions and expressions of concern, post-publication comments, and open-access copies — and displays the result inline on the page.
The Extension's content script runs on all websites, because papers are cited everywhere: journals, preprint servers, blogs, reading lists, library catalogues. It reads page content only to find identifiers and titles; it does not transmit page content itself. You can switch it off for any domain from the toolbar popup, and disabled domains are never scanned.
3. What data is processed
- DOIs found in page metadata, links, tables and visible text. Sent to the services listed in section 5 to retrieve information about those papers.
- Article titles (and, where available, author and year hints) for papers that carry no DOI on the page. Sent to Crossref and OpenAlex to resolve the correct identifier.
-
Your contact email address, if you enter one in
settings. It is used solely as the
mailto/emailparameter that Crossref, OpenAlex, Unpaywall and NCBI ask API users to supply as a contact address. It is stored in Chrome's sync storage, is sent to those four services only, and is never sent to FORRT's own servers. - The URL and hostname of the current page, used within your browser to scope scanning and to apply your per-domain settings. Article-page PubPeer lookups also send the page URL to PubPeer. If you choose to report an issue, the report may include page information; review it before sharing.
- Google Sheets content, when you have a Google Sheet open: the Extension requests that sheet's own export endpoint using your existing Google session in order to read paper identifiers from rows outside the visible area. That request goes to Google only — nobody else receives the sheet or its contents. Identifiers found in it are then looked up like any other.
The Extension does not collect:
- Names, accounts or sign-in details — there is no account to create
- Browsing history for tracking or analytics
- Automatic analytics, telemetry or crash reporting
- Cookies for tracking or advertising
4. Storage on your device
-
Settings (
chrome.storage.sync): your contact email, citation style, cache limit, disabled domains, muted PubPeer commenters and the “Offer Copy log after each pass” preference. Because this uses Chrome's sync storage, these settings are synchronised across browsers you are signed into — that synchronisation is performed by Chrome under your Google account, not by FORRT. -
Cache (
chrome.storage.local): results of the lookups described above, together with the retraction list, kept so that revisiting a paper does not repeat every request. Entries expire, and a shared soft limit covers all provider caches (50 MB by default; any limit you set is raised to at least 10 MB, and a limit of 0 means unlimited). Expired entries are removed first, then older entries; some provider caches are removed as a whole. Settings, diagnostic reports and the retraction list are outside this limit. The cache stays on your device and is never transmitted. Uninstalling the Extension, or clearing its storage from your browser, removes it.
Optional diagnostics: debug mode stores a bounded local log, which can contain paper identifiers, titles and page information. The issue-reporting tools let you review, copy, download or clear a report before you use it. Your configured contact email is excluded from reports. “Report an issue” opens GitHub's new-issue form with the report prefilled, so GitHub receives the report as the form opens; the issue becomes public only when you press GitHub's own submit button. The report goes nowhere else.
5. Services the Extension contacts
To do its job the Extension makes requests to the following services. Each receives only what is listed.
| Service | Receives | Why |
|---|---|---|
FORRT replication API (rep-api.forrt.org) |
DOIs, in batches; DOI lists for long Atlas links, encrypted before they are stored | Replication and reproduction records; storing DOI sets referenced by a shorter Atlas link |
| Crossref | Titles, DOIs, your contact email | Resolving titles to DOIs; formatted citations |
| OpenAlex | Titles, OpenAlex work ids, your contact email | Resolving titles to DOIs; resolving OpenAlex search results to DOIs |
| Semantic Scholar | Semantic Scholar paper ids | Resolving Semantic Scholar search results to DOIs |
| Unpaywall | DOIs, your contact email | Whether a free full text exists |
| PubPeer | DOIs and, for article-page lookups, the current page URL | Post-publication comment counts and threads |
doi.org and data.crosscite.org |
DOIs | Confirming identifiers and rendering citations |
| PubMed Central ID converter (NCBI) | DOIs, PMC identifiers or PubMed ids, your contact email if set | Locating PMC-hosted full text; resolving PubMed and Europe PMC search results to DOIs |
| Scopus and EBSCOhost (the site you are searching on) | The record ids of the results on screen | Resolving those results to DOIs, through the same requests the site's own page makes; nothing is sent to a third party |
GitHub (raw.githubusercontent.com) |
Nothing about you — a plain file download | The weekly refresh of the retraction list, which is derived from Retraction Watch data released with Crossref |
GitHub new-issue form (github.com) |
The diagnostic report you chose to send — the captured log, your settings and the page or domain you were on, without your contact email. The link carries as much of the report as fits within its length limit, newest log entries first, or a placeholder when too little of it fits. The Extension fills the complete report into the form once the page has loaded. | Reporting a problem with the Extension |
| Google Sheets export endpoint | The identifier of the sheet you already have open | Reading paper identifiers from the whole sheet |
Title matching alternates which of Crossref or OpenAlex is queried first. The other service is contacted when the first fails or returns no single DOI. Both may therefore receive the same title.
For a long Atlas link, ORE sends the DOI list to FORRT to create a stored set and uses its identifier in the link. This happens while preparing the link, before you click it. The separate Meta Report share link encodes its report in the URL fragment instead.
Retraction status is determined locally. The Extension downloads the retraction list about once a week and checks papers against it on your own device, so no DOI is ever sent anywhere in order to ask whether a paper has been retracted.
No data is sold, rented or shared with data brokers, advertisers or analytics companies, and none of it is used for advertising.
6. Legal basis (GDPR)
Where GDPR applies, the legal basis for this processing is legitimate interest (Art. 6(1)(f)): providing the inline functionality you installed the Extension to perform. The data involved is, in the ordinary case, publicly available scholarly identifiers rather than personal data about you. The one exception is the contact email you choose to enter; you supply it voluntarily, it is used only as described in section 3, and you can remove it at any time in settings — the Extension then stops making the requests that require it.
Local storage is used strictly for the Extension's own function and not for tracking or advertising.
7. Retention
- FORRT API requests retrieve evidence for the submitted DOIs. DOI sets created for long Atlas links are stored by FORRT so those links can retrieve the list later; they are separate from the lookup cache on your device. Each set is encrypted before it is stored, under a key generated for that set alone and kept only inside the Atlas link — FORRT does not hold the key and cannot read the DOI list back from its own database. Anyone you give the link to can, so treat it as you would the list itself. Sets are deleted automatically 30 days after they are created; clearing extension storage does not delete one early.
- Third-party services (Crossref, OpenAlex, Unpaywall, PubPeer, NCBI, Google) apply their own retention policies to requests they receive.
- GitHub issue form holds a prefilled report only in the open form until you submit it; closing the form discards it. An issue you do submit is public and kept by GitHub under its own terms.
- Local cache and settings remain on your device until they expire, are evicted, or you clear the Extension's storage or uninstall it.
8. International transfers
The FORRT replication API is hosted on Amazon Web Services in the eu-central-1 (Frankfurt, Germany) region. The third-party services in section 5 are operated in other jurisdictions, including the United States; they are named there so that you can see exactly which services are involved, and the per-domain switch lets you stop the Extension running on any site.
9. Your rights
Under GDPR you have the right to access, correct, delete, restrict or object to processing of your personal data, to data portability where applicable, and to complain to your data protection supervisory authority.
In practice, FORRT holds nothing that identifies you: there is no account, the Extension's data lives in your own browser, and the only personal datum involved — your contact email — is stored on your device and sent onward only to Crossref, OpenAlex, Unpaywall and NCBI. You can exercise the practical equivalent of these rights yourself at any time by editing or clearing your email in settings, clearing the Extension's storage, or uninstalling it. If you would like FORRT to look into anything on your behalf, write to info@forrt.org and we will respond.
Under California's CCPA/CPRA and similar US state laws: the categories of data processed and the third parties involved are disclosed in sections 3 and 5; you may delete the Extension's data at any time as described above; and no data is sold or shared as those laws define the terms.
10. Children's privacy
The Extension is intended for researchers, students and other academic users, generally aged 16 and over. It is not directed at children and does not knowingly collect data from them.
11. Security
All requests are made over HTTPS. Data stored locally is subject to your browser's own security model. The Extension requests only the browser permissions it needs — storage, extended storage for its cache, and access to the tab you are actively viewing, plus alarms for scheduled maintenance — and its full source code is public.
12. Contact
Questions about this policy: info@forrt.org.
13. Changes to this policy
This policy will be updated as the Extension changes. The “last updated” date above reflects the most recent revision, and significant changes will be noted on this page.
This policy covers FORRT ORE only. Other FORRT services, such as the FLoRA Replication Atlas, may have their own policies.