Privacy notice
This page describes what PlasticDB collects, where it goes and how long it is kept.
Who we are
PlasticDB is run by the PlasticDB team, which is responsible for the personal information described on this page. We handle it under New Zealand's Privacy Act 2020. For any privacy question or request, email contact.plasticdb@gmail.com.
Browsing without an account
You can search, browse and download everything without an account. We do not ask who you are. Some data about your visit is still processed:
- Rate limiting. To stop abuse, the server counts requests per IP address (or per account, when you send an API key or token). These counters live in memory and in a cache, and expire within the limit's time window (at most one day). They are not written to the database.
- Google Analytics. On the live site, every page loads Google Analytics
(measurement ID
G-M6ZQRS3NJ0). This includes the data-submission and AI-assistant pages. Google sets its own cookies (such as_ga). It receives the page address, the referring page, your browser and device type, and a location derived from your IP address. We use it only for aggregate traffic statistics. There is no consent banner yet. To opt out, blockgoogletagmanager.comandgoogle-analytics.comin your browser, or use Google's opt-out add-on. - Server logs. The public reverse proxy in front of PlasticDB does not keep an access log. The application's own logs can record requests to the server. They stay on the PlasticDB servers, are rotated with a size cap (so older entries are overwritten), and are not sent to any third party. The Slack notifications described further down are separate, and each one is listed where it happens.
Services your browser contacts
Some pages load files from other providers. Your browser then connects to them directly, and they see your IP address:
- Google Fonts (fonts.googleapis.com, fonts.gstatic.com), on every page.
- jsDelivr (cdn.jsdelivr.net), Plotly (cdn.plot.ly) and 3Dmol.js (3dmol.org). These serve chart, map and structure-viewer code on the pages that use it.
- Google reCAPTCHA, on the register, forgot-password and resend-confirmation forms, when it is enabled. Google receives a risk token, and our server checks that token with Google.
- Gravatar (gravatar.com). For signed-in users and on public contributor profiles, the avatar is loaded from Gravatar. The address includes an MD5 hash of the account's email address.
- Images and links from EBI/AlphaFold, RCSB PDB, UniProt and NCBI on record pages.
If you create an account
We store:
- your email address and the name you give;
- your password, as a one-way bcrypt hash (never the password itself);
- whether your email is verified, and your role (user, curator, administrator);
- a hash of your API key, if you create one;
- your ORCID iD and an ORCID access token, if you link ORCID (you can unlink it, which deletes both);
- when the account was created and last updated.
We email you to confirm your address and to reset your password. The emails are sent over SMTP through the operator's mail account. The application log records the recipient address of each email sent. We do not store your IP address against your account.
Cookies and browser storage when you sign in
plasticdb_session: a cookie holding your sign-in token. It is httpOnly (page scripts cannot read it), SameSite=Lax and Secure, and it expires after one day or when you log out. It is strictly necessary for signing in.plasticdb_tokenin your browser's localStorage: the same sign-in token, which the pages use to call the API. Logging out removes it.plasticdb_submit_draft:…in localStorage: an unsent data submission, kept only in your browser until you submit or discard it.plasticdb_chat_guestin localStorage: the id of a guest AI-assistant conversation. Curators also get two layout preferences for the review pages.
What other people can see
- Contributor pages are public. If you contribute or curate data, /contributors and your profile page show your name, your ORCID iD (if linked), your contribution counts and a timeline of your contributions. Your email address is not shown. The profile's Gravatar image address is derived from a hash of your email address, as described above.
- The forum is visible only to signed-in users with a verified email. Your name and email address are shown beside your posts and replies. You can delete your own posts and replies.
Data you submit
A data submission is stored with your account, the name and email you enter, and the records themselves. Curators and administrators see all of it while they review it. We also post a notification with your email address and the submission type to the maintainers' private Slack workspace.
Accepted records are published under CC BY 4.0 and credited to you on your contributor page. You agree to this licence when you submit, and the date you agreed is stored with the submission. We also keep a log of the changes each account makes to the data, with its user id, so every change to the database can be traced.
The AI assistant
When the assistant is switched on:
- Your questions go to DeepSeek. The assistant's language model is DeepSeek, a third-party hosted AI service, used through its standard API with DeepSeek's default settings. Each question is sent to DeepSeek together with up to 20 earlier messages from the same conversation, as context, and the results of the database queries the model asks PlasticDB to run (these come from PlasticDB's public data). Your name, email address and IP address are not sent.
- DeepSeek's terms apply. What DeepSeek does with the messages, including how long it keeps them, is governed by DeepSeek's Open Platform terms of service and privacy policy, not by PlasticDB. DeepSeek's privacy policy says it stores data in the People's Republic of China.
- PlasticDB itself keeps no separate log of what you type into the assistant. It keeps only the stored conversations described next.
- Signed in: your conversations are stored in our database until you delete them. You can delete a conversation at any time.
- Not signed in: the conversation is kept in a cache for 24 hours, then deleted. Guests are limited to a number of messages per day, counted by IP address; the counter also expires after 24 hours. If you sign in during a guest conversation, it can be moved into your account.
Please do not enter personal or confidential information in the assistant. If you do not want your questions to reach DeepSeek, do not use the assistant; everything else on the site works without it.
Analysis tools and uploaded files
- Uploading to a tool (Annotate Gene, Annotate Genome, Annotate Taxa Table, Compare Genomes, Pathway Analysis, HMM Screen) requires an account. Only you and the administrators can see your jobs and results.
- We delete the uploaded input files as soon as a job finishes. We delete result files 90 days after the job, in a weekly clean-up. We keep the job record (its settings and status) and the table of hits, so your job list keeps working. An administrator can delete a job.
- When a job is submitted or fails, a notification goes to the maintainers' private Slack workspace. It contains the job id, the job type and, when you submit, your email address.
Signal-peptide prediction runs on our servers
In Annotate Gene and Annotate Genome, the Organism Type option asks for signal-peptide prediction. It applies to protein (BLASTP) searches only. The prediction is made locally, by the DeepSig program running on PlasticDB's own servers, and your sequences are not sent to any third party for it.
If the local predictor is unavailable, the service may fall back to the Phobius
web service run by EMBL-EBI (www.ebi.ac.uk). It would then send up to 50 of your query
sequences (the highest-scoring ones with a database hit), and EBI's
terms of use and
privacy notice
would apply. The job's results page always names the tool that ran. If your sequences must never
leave our servers, leave Organism Type on No signal peptide.
Other lookups made on your behalf send only public identifiers, never uploaded files. The submission form's DOI and accession lookups send those identifiers to Crossref, NCBI and UniProt.
Error reports
When the server hits an unexpected error, it sends a report to the maintainers' Slack workspace. The report contains the request method, the page path (with anything that looks like a credential blanked out, and without the query string) and the error message. It does not contain your IP address, browser details or what you typed.
Your rights: access, correction and deletion
- Access and correction. Under the Privacy Act 2020 you have the right to ask for the personal information we hold about you, and to ask us to correct it. Email contact.plasticdb@gmail.com. We will respond as soon as practicable, and to an access request within 20 working days, as the Act requires.
- Doing it yourself. You can change your name on your profile. You can also delete your API key, your ORCID link, your AI-assistant conversations and your forum posts yourself.
- Deleting your account. There is no self-service button yet: email us from the account's address and we will delete it. Deletion removes your name, email address, password, API key and ORCID link from the account, and deletes your AI-assistant conversations and your analysis jobs with their files.
- What stays published. Records you contributed that have been published stay published under CC BY 4.0, because others may already rely on them. The credit is anonymised: you are removed from the contributors list, and your former profile page and your forum posts show Former contributor instead of your name.
- Inactive accounts are not deleted automatically. An account stays until you ask us to delete it.
See also the terms of use and the data licence. We will update this page when what the site does changes.