Privacy Policy
Last updated: 10 July 2026
This Privacy Policy explains how Bition B.V. ("Gist.Science", "we", "us", "our") collects, uses, shares, and protects personal data in connection with the website gist.science and related services (the "Service").
Controller:
Bition B.V., Verdunplein 17, 5627 SZ Eindhoven, the Netherlands
KvK: 95743731 — VAT: NL867271966B01
Contact: mail@gist.science
We are the data controller for the personal data described below. We have not appointed a Data Protection Officer because we are not legally required to do so, but you can reach our privacy contact at the email address above.
1. Summary
- We try to collect as little personal data as possible.
- Anonymous visitors can browse the site without creating an account; we use privacy-friendly server-side analytics and Cloudflare for security and performance.
- Newsletter and Digest subscribers give us their email address; Digest subscribers also give us interest preferences. The Newsletter is free; Digest is a paid subscription, with legacy free-for-life access for grandfathered subscribers.
- Digest payments are handled by Stripe, our payment processor — we never see or store your card details.
- We do not sell personal data. We do share limited data with the providers we need to run the Service (hosting, email, payments, analytics, contextual advertising).
- You have rights under the GDPR (EU/UK) and the CCPA/CPRA (California) and we honour them.
The detailed sections below explain everything else.
2. Personal data we collect
We collect personal data in three ways: (a) you give it to us, (b) we collect it automatically as you use the Service, and (c) we receive it from third parties.
2.1 Data you give us
| When | Data |
|---|---|
| You subscribe to the free newsletter | Email address; the language of the page you signed up on |
| You create an account / start a Digest | Email address, preferences (categories, keywords, language, delivery frequency) |
| You subscribe to Digest | Payment details (card, billing address, VAT ID if provided) are collected directly by Stripe, our payment processor — we never receive or store card numbers. We receive your email address, subscription status and plan, and billing country/currency. |
| You contact us (mail@gist.science) | Your email address and the contents of your message |
| You correspond with us about a take-down or correction (e.g. you are an author of a summarised paper) | Identification information sufficient to confirm authorship and the substance of the request |
Email you send us may be processed by AI systems running on our own infrastructure (for example to draft a reply or to extract a correction or take-down request for handling). Your correspondence is not sent to third-party AI providers.
2.2 Data collected automatically
- Server logs. Each request is logged with IP address, user-agent, requested URL, response code, and timestamp. Logs are retained for up to 30 days for security and abuse prevention.
- Cookies and similar storage (see Section 6 for the full list).
- Analytics. We run a self-hosted analytics tool at
analytics.gist.sciencethat records aggregated, pseudonymous usage information (pages viewed, country, referrer, device type) without persistent cross-site identifiers. - Contextual advertising. We display developer-focused contextual advertising through Carbon Ads. Carbon Ads may load ad content from Carbon/BuySellAds domains and measure anonymized impressions and clicks. According to Carbon Ads, publisher placements are designed to avoid personal data collection, cookies, and fingerprinting. Carbon Ads may nevertheless receive standard technical request information such as IP address, user agent, page URL or referrer, timestamp, and impression/click event data.
- Cloudflare. As our CDN and security layer, Cloudflare processes connection metadata to protect against attacks and serve content; this includes IP addresses and request fingerprints.
- Anti-bot challenges. Forms such as newsletter signup and sign-in are protected by Cloudflare Turnstile, which evaluates browser signals to confirm you are a human. The Turnstile script is loaded on every page.
2.3 Data we receive from third parties
When you purchase Digest, we receive from Stripe the email address you used at checkout and the status of your subscription, so we can set up and maintain your account.
Authors of summarised papers. If you are an author of a paper we summarise, we obtain your name and, where published, your contact email address from the paper itself or from the repository that published it (arXiv, bioRxiv, medRxiv, Research Square, or similar). We use this to send you a one-time email letting you know a Gist of your paper exists, and to handle any correction or take-down request you send us. We rely on our legitimate interest in informing authors about summaries of their own work, and you can object at any time by replying or emailing mail@gist.science — if you do, we add your address to a suppression list so we do not contact you again.
Beyond that, we do not receive personal data about you from third parties. Our analytics and security providers process technical data on our behalf as described above, but do not supply us with additional personal information about you.
3. How we use personal data and our legal bases (GDPR)
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Operating the website and delivering the content you request | Performance of a contract; legitimate interests (running the Service) |
| Managing your account and your Digest preferences | Performance of a contract |
| Processing Digest payments, subscriptions, and invoices (via Stripe) | Performance of a contract; legal obligation (tax and bookkeeping) |
| Sending the free newsletter | Consent (you opted in by submitting your email) |
| Sending authors of summarised papers a one-time notification about their paper's Gist | Legitimate interests (informing authors about summaries of their own work) |
| Sending transactional emails (receipts, magic login links, service notices) | Performance of a contract; legitimate interests |
| Privacy-friendly analytics on usage trends | Legitimate interests in understanding and improving the Service |
| Displaying contextual advertising and measuring ad impressions/clicks (via Carbon Ads) | Legitimate interests in monetizing the website with privacy-friendly, contextual advertising |
| Detecting fraud, abuse, and security issues | Legitimate interests; legal obligation |
| Responding to legal requests, exercising or defending legal claims | Legal obligation; legitimate interests |
| Bookkeeping and tax compliance | Legal obligation (Dutch tax law) |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms; you may object to that processing as described in Section 9.
4. Sharing personal data
We share personal data only with the providers and parties we need to run the Service. We do not sell or rent personal data, and we do not share it for cross-context behavioural advertising.
| Recipient | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | CDN, DDoS protection, Turnstile anti-bot, web analytics beacon | Global (with Standard Contractual Clauses) |
| Amazon Web Services EMEA SARL (SES) | Sending and tracking delivery of newsletters, digests, and account emails (transactional and content email) | EU (Ireland) |
| Stripe Payments Europe, Ltd. (and Stripe, Inc.) | Payment processing, subscription billing, invoicing, VAT calculation, and fraud prevention for Digest | EU (Ireland), with transfers to the US under the EU–US Data Privacy Framework / Standard Contractual Clauses |
| Carbon Ads / BuySellAds | Contextual advertising, ad delivery, and anonymized impression/click measurement | US/global, with transfers under applicable transfer safeguards |
| GPU/hosting infrastructure | Generating Gists; hosting account data | EU |
| Professional advisers (accountants, lawyers) | Tax filings, legal advice when needed | EU |
| Government authorities | Where compelled by law (e.g. valid court order or tax inspection) | EU |
We also disclose personal data when reasonably necessary to comply with legal obligations, enforce our Terms, or protect the rights, property, or safety of our users or others.
5. International transfers
We are based in the Netherlands and prefer EU-based providers. Where personal data is transferred outside the European Economic Area (for example to certain US-based providers such as Cloudflare, Stripe, or Carbon Ads / BuySellAds), we rely on:
- the European Commission's adequacy decisions where applicable (e.g. the EU–US Data Privacy Framework for participating providers); or
- the Standard Contractual Clauses approved by the European Commission, supplemented where appropriate by additional safeguards.
You can request a copy of the relevant transfer mechanism by emailing mail@gist.science.
6. Cookies and similar technologies
We try to keep cookie usage minimal. The cookies and local storage entries we use fall into these categories:
6.1 Strictly necessary
gs_session— set after you log in; contains your signed session (including the email address you signed in with) and expires after 7 days. It is HttpOnly, so scripts on the page cannot read it. Without it, you cannot stay logged in.gs_auth— a companion cookie that only signals "signed in" so the page can adjust its navigation; it contains no personal data.gs_digest— a companion cookie that only signals "Digest subscriber" so cached pages can hide ads and show the subscriber version; it contains no personal data.- Cloudflare cookies (e.g.
__cf_bm,cf_clearance) — used to distinguish humans from bots and to keep the site secure.
6.2 Functionality (local storage)
theme— remembers your light/dark mode preference.preferred-tab— remembers whether you last viewed the "Gist" or "Technical" tab on a paper page.
6.3 Analytics
- A self-hosted analytics script on
analytics.gist.sciencethat does not use persistent cross-site identifiers and records pseudonymous, aggregated metrics. We treat this as legitimate-interests processing under GDPR; if you prefer not to be counted, you can use your browser's "Do Not Track" or block the script. dp_purchase_*— a session-storage entry set on the Digest checkout confirmation page so a page refresh is not counted as a second purchase in our analytics. It is deleted when you close the tab.
6.4 Contextual advertising
Carbon Ads may load ad content and measurement requests from Carbon/BuySellAds domains, including domains such as carbonads.net, cdn.carbonads.com, srv.carbonads.net, or syndicateads.net. According to Carbon Ads, publisher placements are cookieless and do not use fingerprinting. If Carbon Ads or its advertising partners introduce cookies or similar technologies that require consent, we will ask for consent before those technologies are used.
You can clear or block cookies via your browser settings; doing so may affect how the Service works.
7. Retention
| Data | Retention |
|---|---|
| Server access logs | Typically up to 30 days |
| Newsletter subscriber data | Until you unsubscribe or ask us to delete it; unconfirmed signups are periodically cleaned up |
| Account and Digest preferences | While your account exists; deleted (or anonymised) promptly after your deletion request (email mail@gist.science), normally within 30 days, except where we must keep limited data for legal reasons |
| Billing records (invoices) | 7 years (Dutch tax law) |
| Customer support correspondence | Generally no longer than 3 years after last contact; deleted earlier on request |
| Author opt-out / take-down suppression list | Kept for as long as needed to keep honouring your request |
| Backups | Rolling, typically up to 35 days |
We delete or anonymise personal data once we no longer need it for the purpose for which it was collected, unless a longer retention period is required by law.
8. Your rights
If the GDPR or UK GDPR applies to your data, you have the right to:
- access the personal data we hold about you;
- rectify inaccurate or incomplete data;
- erase your data ("right to be forgotten") in certain circumstances;
- restrict or object to processing, including direct marketing at any time;
- data portability — receive your data in a machine-readable format;
- withdraw consent at any time where processing is based on consent (this does not affect the lawfulness of processing carried out before withdrawal).
To exercise any of these rights, email mail@gist.science. We will respond within one month and free of charge in most cases.
You also have the right to lodge a complaint with a supervisory authority. In the Netherlands, that is the Autoriteit Persoonsgegevens — autoriteitpersoonsgegevens.nl.
9. California residents (CCPA / CPRA)
If you are a California resident, in addition to the rights above you have the right to:
- Know what categories of personal information we have collected, used, disclosed, and (if applicable) sold or shared in the past 12 months.
- Delete personal information we have collected from you, subject to limited exceptions.
- Correct inaccurate personal information.
- Opt out of "sale" or "sharing" of personal information as those terms are defined under the CCPA/CPRA. We do not sell or share personal information. If you wish to confirm or exercise this right, email mail@gist.science with the subject "Do Not Sell or Share My Personal Information".
- Limit use of sensitive personal information. We do not collect personal information that triggers this right.
- Non-discrimination — we will not deny service, charge a different price, or provide a lower quality of service because you exercised your rights.
You may exercise these rights yourself or through an authorised agent. We will verify requests by matching the email address used with our records or, where reasonable, requesting additional information.
Categories collected in the past 12 months
Identifiers (email, account ID, IP address); commercial information (subscription history); internet activity (page views, referrers); geolocation derived from IP at country level; inferences from your selected categories and keywords. We have not collected sensitive personal information.
10. Children
The Service is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, please contact mail@gist.science and we will delete it.
11. Security
We use industry-standard measures to protect personal data, including TLS for data in transit, passwordless magic-link authentication, principle of least privilege for staff access, and reputable hosting providers. No system is perfectly secure; if we become aware of a breach affecting your personal data we will notify you and the relevant authority where required by law.
12. Automated decision-making
Gist generation is automated, but it does not make decisions about you that produce legal or similarly significant effects. We do not use solely automated decision-making within the meaning of GDPR Art. 22.
13. Changes to this Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the current version. For material changes, we will notify subscribers by email or via a prominent notice on the Service before the change takes effect.
14. Contact
Privacy questions, requests, or complaints:
mail@gist.science
Bition B.V., Verdunplein 17, 5627 SZ Eindhoven, the Netherlands