clopen.solutions

Privacy policy

Last updated 26 September 2026

Who is responsible

Clemens Thalhammer, Switzerland, runs clopen.solutions and is responsible for the personal data described here. Write to privacy@clopen.solutions with any question or request.

What we collect

If you are named as a co-author

Your details came from the author who submitted the paper. We use them to credit you, and publish your name and ORCID iD with the paper. We never show your email address. Write to us to have your details corrected, or if you object to being listed.

Why we use it

We send no marketing email.

What becomes public

When you announce a submission, we publish its title, abstract, comments, PDF and sources, its Lean proof details, the authors' names and ORCID iDs, and the automated review's report once it is released. Author email addresses are never shown, but the PDF shows whatever the authors wrote into it.

An announced version is permanent, because others read and cite it. You can withdraw it but not delete it, and it stays up if you delete your account.

Automated review

When your sources build, we send your draft, with its abstract, comments and claims, to Anthropic in the USA, where an AI model reviews it. Anthropic keeps what we send for 30 days, or for up to two years if its safety systems flag it, and doesn't use it to train models. When you announce, the model also reads each Lean statement that has no formalisation in the registry.

The review decides one thing on its own. If it finds that the submission isn't a paper, is empty or malformed, is off-topic, or doesn't address the problem it claims, you can't announce it. We tell you why, and if you write to contact@clopen.solutions, a curator reviews the decision and can overrule it. Everything else the review says is advice, and it never changes a problem's status.

Who else receives it

These providers process data for us, only on our instructions, under a data processing agreement with each:

ProviderWhat forWhereSafeguard
RenderHosting and databaseUSASwiss-US Data Privacy Framework
CloudflareFile storageEastern EuropeSwiss-US Data Privacy Framework
ModalBuilding papers and checking proofsUSAStandard contractual clauses
ResendSending and receiving emailIreland and USAStandard contractual clauses
AnthropicAutomated reviewUSAStandard contractual clauses

The USA does not protect personal data to the standard Swiss law requires. Each transfer there therefore relies on the safeguard shown: the provider's certification under the Swiss-US Data Privacy Framework, or the EU standard contractual clauses as adapted for Switzerland. Ask us for a copy.

We disclose data to authorities only where the law obliges us to. We don't sell personal data or share it for advertising.

How long we keep it

Security

All traffic is encrypted. Files sit in a private bucket and are reached only through links that expire. Passwords are stored as hashes, and curators and admins must use a second factor.

Your rights

You can ask what data we hold about you and get a copy of it, have it corrected or deleted, receive it in a portable format, and object to how we use it. Write to privacy@clopen.solutions. We answer within 30 days, free of charge. You can edit your profile and delete your account yourself, from your profile page. Published papers stay, as described above.

If you think we have mishandled your data, you can complain to the Federal Data Protection and Information Commissioner in Switzerland, or to the data protection authority where you live in the EU.

Age

The site is not meant for anyone under 18. If we learn that someone under 18 has an account, we close it and delete their data.

Changes

When we change this policy, we update the date at the top, and we email account holders about any material change.