Privacy Policy
Draft: this policy has not yet been reviewed by a lawyer and may change before AcadMatch launches publicly. It describes what AcadMatch does today.
Last updated:
Who we are
AcadMatch is a platform for finding academic research positions in Israel. For any privacy question or request, contact orirot13@gmail.com.
What we collect, and why
Browsing positions does not require an account or any personal details.
When you ask for a sign-in link, we store the email address and the time of the request, to deliver the link and to limit abuse, whether or not you then sign in.
If you sign in, we also keep:
- your email address, to send you sign-in links and to check which institution it belongs to, which decides the labs you may join;
- your roles (for example permission to publish for a lab) and the labs you belong to, to decide what you may publish;
- your session: a single cookie that keeps you signed in. It is strictly necessary for signing in, cannot be read by scripts on the page, and is not used for tracking;
- the positions you publish. They are public and shown under the lab's name; we record internally that you published them, so that only you can edit or close them.
Like most websites, our servers keep technical logs of requests (IP address, time, the page requested and browser details) to run the service and keep it secure.
We do not use analytics, advertising, or third-party tracking, and we do not sell personal data.
Who else processes data
Our hosting provider, Google Cloud, runs the site and stores its data. The database, technical logs and backups are kept on servers in Israel (Google Cloud's Tel Aviv region, me-west1). Secure (HTTPS) connections to the site are received by Google's global network at a point near you, which may be outside Israel, and passed on to our servers in Israel; nothing is stored at that point. Cloudflare provides our domain's DNS only: it answers lookups of the site's address and does not handle your connection to the site. When sign-in emails are sent, an email delivery service processes your email address for that purpose only.
How long we keep it
- Sign-in requests: deleted within one day.
- Sessions: you stay signed in until you sign out, for at most 30 days.
- Technical logs: up to 30 days.
- Backups: the database is backed up daily and each backup is kept for 7 days, so data that was deleted can remain in a backup for up to 7 days.
- Your account: until you delete it. Afterwards we keep only an anonymous record (an internal identifier and the dates the account was created and deleted), linked to the positions you published; it contains no email address or other details about you.
- Published positions: they stay public after you delete your account, attributed to the lab only, including any text you typed into them (such as contact details). Closing a position keeps it public. Before deleting your account, edit out any contact details you do not want to remain public, or ask us to remove the position.
Your rights
You can see your account details on the account page and delete your account there at any time; deletion removes your email address, roles, lab memberships and sessions. You may also ask us to access, correct or delete your personal data by writing to orirot13@gmail.com. You have rights under the Israeli Protection of Privacy Law, and if you are in the EU, under the GDPR, including the right to complain to the relevant data-protection authority.
Changes
We will update this policy when how we handle data changes; the date above shows the latest version.