Privacy Policy

Effective date: 1 January 2026

This Privacy Policy explains how personal information is collected, used, stored and protected when you visit
xpeerd.online, create an account, subscribe to a plan or use the xPeerd API Server.

The xPeerd API Server provides metered programmatic access to the xPeer peer-review simulation engine. It may process manuscripts, scholarly documents, review instructions and related information submitted through the application programming interface.

This Privacy Policy should be read together with the applicable xPeerd API Server Terms of Use, subscription terms and any data-processing agreement entered into between KNOWDYN LTD and an institutional customer.

1. Who We Are

The xPeerd API Server is operated by KNOWDYN LTD, a private limited company registered in England and Wales.

Company number: 13812785
Registered office: 20 Wenlock Road, London, United Kingdom, N1 7GU
Service website: https://xpeerd.online/
Corporate website: https://knowdyn.com/

For personal information processed to administer the website, user accounts, subscriptions, invoices, security and customer relationships, KNOWDYN LTD is normally the data controller.

2. Scope and Data-Protection Roles

This Privacy Policy applies to the xPeerd API Server website, customer accounts, API access, subscriptions, billing records, support communications and technical operation of the service.

The data-protection role of KNOWDYN LTD depends on the information being processed.

When KNOWDYN LTD acts as controller

KNOWDYN LTD acts as a controller when it determines why and how personal information is processed for purposes including:

  • registering and administering customer accounts;
  • issuing and managing API credentials;
  • measuring API usage and applying plan limits;
  • producing invoices and administering subscriptions;
  • protecting the service against misuse, fraud and security threats;
  • providing support and service communications;
  • meeting legal, tax, accounting and regulatory obligations; and
  • operating and improving the reliability of the xPeerd API Server.

When KNOWDYN LTD acts as processor

When a customer submits a manuscript or other document containing personal information on behalf of an institution, journal, publisher, conference, research team or other organisation, that customer will normally determine the purpose of the processing.

In those circumstances, the customer is normally the controller and KNOWDYN LTD processes the submitted content on the customer’s documented instructions. The applicable customer agreement or data-processing agreement may provide additional terms.

3. Information We Collect

Account and contact information

We may collect:

  • your name;
  • email address;
  • username and account identifier;
  • organisation, institution or company name;
  • job title or professional role, where provided;
  • country or billing jurisdiction;
  • account preferences; and
  • password hashes and authentication records.

We do not need to know your account password in readable form. Passwords should be stored using an appropriate one-way password-hashing method.

API credentials and access information

We may process:

  • API key identifiers and authentication credentials;
  • credential creation, activation, rotation and revocation records;
  • the account or subscription associated with an API key;
  • authentication successes and failures; and
  • security information needed to identify compromised or misused credentials.

API keys should be treated as confidential credentials and must not be published, embedded in public client-side code or shared with unauthorised persons.

Subscription, billing and invoice information

We may collect or generate:

  • subscription plan and account status;
  • billing name, address and tax information;
  • subscription dates and renewal information;
  • API-call and spending-limit allocations;
  • credit, quota and usage balances;
  • invoice numbers, amounts, currencies and payment status;
  • transaction references supplied by a payment provider; and
  • records required for accounting, taxation, refunds or payment disputes.

Where payments are handled by an external payment provider, payment-card or bank information may be collected directly by that provider under its own privacy notice. The xPeerd API Server may receive limited transaction information needed to confirm and reconcile the payment.

API request and operational information

When the API is used, we may record:

  • request date and time;
  • account, API key or application identifier;
  • selected endpoint or stable review scenario;
  • request and job identifiers;
  • processing status, including queued, processing, completed or failed;
  • HTTP response status;
  • request and response sizes;
  • processing duration and system latency;
  • usage and cost-allocation records;
  • retry, recovery and error information;
  • IP address;
  • browser or client user-agent information;
  • server, security and audit-log events; and
  • diagnostic information concerning incomplete or truncated responses.

Manuscripts and customer content

Depending on how the API is used, we may process:

  • uploaded manuscripts and scholarly documents;
  • documents retrieved from a URL supplied by the customer;
  • titles, abstracts, keywords and manuscript metadata;
  • review instructions and selected stable review prompts;
  • author-supplied text and API request parameters;
  • page content needed to generate page-linked observations;
  • generated xPeer review reports;
  • editorial or reviewer-support outputs; and
  • technical records required to complete, retry or recover a review job.

Communications

When you contact us, we may process your name, email address, organisation, message, support history and any files or technical information you choose to provide.

Information we do not require

The xPeerd API Server does not require customers to submit patient-identifiable information, government identification numbers, financial account credentials, biometric information or other special-category personal information in order to perform an ordinary scholarly peer-review simulation.

4. How Information Is Collected

Information may be collected:

  • directly from you when you register, subscribe, contact us or configure an account;
  • through API requests submitted by you or by an application acting under your authority;
  • automatically through authentication, usage, server, security and audit logs;
  • from a payment or invoicing provider;
  • from your employer, institution or account administrator;
  • from a document URL or repository location that you instruct the service to access; or
  • from another authorised user managing an organisational account.

6. Manuscripts and Review Content

Manuscripts and related scholarly materials may contain unpublished research, confidential information, personal data, intellectual property or commercially sensitive content.

The xPeerd API Server processes this content only to perform the requested review simulation, deliver the resulting output, support short-lived technical recovery and meet applicable security or contractual requirements.

Source manuscripts are not intended to become a permanent document corpus. They are retained only for as long as reasonably necessary to:

  • retrieve and validate the document;
  • perform the requested simulation;
  • deliver the result;
  • detect processing failure or truncation;
  • complete authorised retry or recovery operations; and
  • investigate a specific support or security incident where necessary.

After those purposes have been completed, source manuscript files are deleted or rendered inaccessible in accordance with the operational deletion schedule.

Where a review output or job history is saved to a customer account, it may remain available until it is deleted by the customer, the applicable retention period expires or the account is closed. Where no stored history is provided, the output may be retained only for the limited operational period needed to complete and support the request.

Customers should not submit confidential journal manuscripts received as peer reviewers unless the journal or publisher has expressly authorised the use of the service.

7. AI Training and Model Development

Customer manuscripts, unpublished research documents and generated private review reports are not used as an unauthorised training corpus for xPeer.

The service does not claim ownership of customer manuscripts or use their scientific content to train or reinforce the peer-review engine merely because they were submitted for processing.

We may analyse limited technical and aggregated operational information to maintain security, measure reliability, identify errors, manage capacity and improve API performance. Where practical, this information is minimised, de-identified or aggregated.

Any separate programme involving licensed research data, voluntary research participation or model evaluation must be governed by distinct terms, permissions and notices.

8. Automated Decisions and Human Responsibility

xPeer generates simulated peer-review observations, recommendations and decision-support outputs. These outputs are advisory.

The xPeerd API Server does not independently make legally binding or similarly significant decisions about an individual.

Authors, reviewers, editors, publishers, institutions and other customers remain responsible for:

  • verifying generated observations;
  • assessing scientific correctness and severity;
  • determining whether a suggested revision is appropriate;
  • complying with confidentiality and disclosure requirements; and
  • making final editorial, academic, employment, funding or publication decisions.

Customers must not treat an xPeer recommendation as the sole basis for a consequential decision affecting a person without appropriate human review.

9. Cookies and Website Technologies

The xPeerd API Server website may use essential cookies or equivalent technologies to:

  • maintain secure login sessions;
  • remember account and interface preferences;
  • protect forms and authentication processes;
  • prevent fraud and cross-site request forgery;
  • balance server traffic; and
  • preserve the technical operation of the website.

Essential cookies are used because they are necessary to provide the requested service or protect it.

Where optional analytics, measurement or marketing technologies are used, they will be managed in accordance with applicable cookie and electronic-communications law. Where required, such technologies will not be activated before consent is obtained.

You can control cookies through your browser settings. Blocking essential cookies may prevent account login or other parts of the service from functioning correctly.

10. How Information Is Shared

KNOWDYN LTD does not sell customer personal information or manuscripts.

Information may be shared with carefully selected service providers where necessary, including providers of:

  • website and server hosting;
  • database, storage and backup infrastructure;
  • secure manuscript retrieval and processing;
  • peer-review simulation and upstream computational services;
  • email delivery and customer communications;
  • payment, subscription and invoice processing;
  • security, abuse prevention and system monitoring;
  • analytics used in accordance with applicable consent requirements;
  • professional legal, accounting, insurance or audit services; and
  • customer-support infrastructure.

These providers may process information only for defined purposes and are required to protect it through contractual, organisational and technical safeguards appropriate to their role.

Information may also be disclosed:

  • where required by a lawful court order or legal obligation;
  • to protect the rights, safety or property of KNOWDYN LTD, its customers or another person;
  • to investigate fraud, abuse, security incidents or violations of the Terms of Use;
  • in connection with a merger, restructuring, financing, acquisition or transfer of the service, subject to appropriate confidentiality safeguards; or
  • where you have instructed or authorised the disclosure.

Where legally permitted, only information reasonably necessary for the relevant purpose will be disclosed.

11. International Data Transfers

The xPeerd API Server may use infrastructure or service providers located in, or accessible from, countries outside the United Kingdom.

Where a transfer is restricted under UK data-protection law, we use an applicable transfer mechanism, which may include:

  • UK adequacy regulations;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to the European Commission Standard Contractual Clauses;
  • another legally approved safeguard; or
  • a permitted statutory exception where appropriate.

Additional technical or organisational protections may be used where necessary to maintain an appropriate level of protection.

12. Data Retention

We retain information only for as long as reasonably necessary for the purpose for which it was collected, subject to contractual, security, accounting and legal requirements.

Information Retention approach
Source manuscripts and retrieved documents Retained only for processing, delivery and any short-lived retry, recovery, support or security requirement, after which they are deleted or rendered inaccessible under the operational deletion schedule.
Generated review outputs and job histories Retained where needed to provide account history, deliver results, support retries or resolve disputes. They may be deleted by the customer where that function is available or removed after account closure and expiry of the applicable operational period.
Account and authentication records Retained while the account remains active and for a limited period afterwards where necessary for closure, security, dispute resolution or legal claims.
API usage and metering records Retained for the period needed to calculate usage, apply quotas, allocate spending, reconcile invoices, investigate errors and maintain an auditable service record.
Security and audit logs Retained for the shortest period reasonably necessary to detect abuse, investigate incidents, protect credentials and maintain service integrity. Logs may then be deleted, anonymised or aggregated.
Billing, accounting and invoice records Normally retained for at least six years from the end of the relevant financial year, or longer where required by tax, accounting, dispute or regulatory obligations.
Support communications Retained until the enquiry is resolved and for a reasonable period afterwards to maintain service history, resolve disputes and improve support consistency.
Marketing preferences Retained until consent is withdrawn or the communication is no longer relevant. A minimal suppression record may be retained to ensure that an opt-out continues to be respected.

Backups may retain information temporarily after deletion from the active system. Backup copies are protected, are not used for ordinary business purposes and are overwritten or deleted according to the applicable backup cycle.

13. Data Security

We use technical and organisational measures designed to protect information against unauthorised access, alteration, disclosure, loss or destruction.

Measures may include:

  • encrypted HTTPS connections and transport-layer security;
  • access controls and account authentication;
  • credential rotation and revocation procedures;
  • restricted administrative access;
  • server, database and application security controls;
  • security and audit logging;
  • request validation and rate limiting;
  • backup and recovery controls;
  • monitoring for abnormal or unauthorised activity;
  • separation of customer accounts and API credentials; and
  • procedures for investigating and responding to incidents.

No internet service can guarantee absolute security. Customers must protect their login details and API keys and must notify us promptly if they believe a credential has been disclosed or misused.

Where a personal-data breach creates a legal notification obligation, KNOWDYN LTD will notify the relevant supervisory authority and affected individuals in accordance with applicable law.

14. Customer Responsibilities

Customers submitting personal information through the API are responsible for ensuring that they have a lawful basis and the necessary authority to do so.

Customers must:

  • submit only information necessary for the review purpose;
  • remove unnecessary personal identifiers from manuscripts where practical;
  • avoid submitting patient-identifiable or special-category information unless its processing is lawful, necessary and contractually authorised;
  • obtain any required author, participant, institution, journal or publisher permissions;
  • comply with confidentiality obligations relating to unpublished manuscripts;
  • protect API credentials against disclosure;
  • inform authorised end users about relevant data-processing activities; and
  • review generated outputs before using them in consequential decisions.

15. Your Data-Protection Rights

Subject to applicable conditions and exemptions, you may have the right to:

  • be informed about how your personal information is used;
  • request access to personal information held about you;
  • request correction of inaccurate or incomplete information;
  • request erasure of information where there is no lawful reason to retain it;
  • request restriction of processing in certain circumstances;
  • object to processing based on legitimate interests;
  • object to direct marketing at any time;
  • request data portability where the legal requirements apply;
  • withdraw consent where processing is based on consent; and
  • raise concerns about automated decision-making where applicable.

Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.

Where KNOWDYN LTD processes information solely on behalf of an institutional customer, we may refer your request to that customer because the customer is responsible for determining how the request should be handled.

We may need to verify your identity before responding to a rights request. We will not request more information than reasonably necessary for verification.

16. Children

The xPeerd API Server is a professional and institutional scholarly service. It is not directed to children.

Persons who are not legally able to enter into the applicable service agreement should not create an account or use the API without appropriate institutional or parental authority.

17. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in the service, technology, legal requirements or data-processing practices.

The effective date at the beginning of the policy will be revised when a material update is published. Where appropriate, registered customers may also be informed through the website, account interface or email.

Earlier versions may be retained where necessary to document which privacy terms applied during a particular period.

18. Contact and Complaints

Questions, data-protection requests and privacy complaints may be submitted through the support or contact facility displayed on
xpeerd.online.

Written correspondence may also be addressed to:

Data Protection Contact
KNOWDYN LTD
20 Wenlock Road
London
United Kingdom
N1 7GU

Please include sufficient information to identify your account and explain the nature of your request. Do not include your password, complete API key or unnecessary manuscript content in a privacy request.

You also have the right to complain to the United Kingdom Information Commissioner’s Office if you believe your personal information has been processed unlawfully.

Information Commissioner’s Office:

https://ico.org.uk/make-a-complaint/

You may also contact the data-protection authority in the country where you live or work where applicable.