Institutional trust
Security and confidentiality
Last updated: September 24, 2026
Scientific journals and academic publishers often work with JATS XML for articles that are not yet published, are under embargo, or remain in peer review. Before you upload a file to EditorialXML, it helps to know which flow you are using and what happens to that content.
This page describes, in operational language, how files are received, who can access them, how long they are kept, how they are stored, how they are deleted, whether they are used for product improvement or training, which third parties process data when applicable, and how an NDA or project agreement fits in.
It does not replace a Data Processing Addendum or a project-specific NDA. It also does not list infrastructure or certifications that are not described in the Privacy Notice or Terms of Service.
This page is informational. The binding documents are the current Terms of Service and Privacy Notice (and, when one exists, the Service Agreement or data-processing addendum for the project). If there is a conflict, those documents control.
Comparison by submission channel
EditorialXML does not treat every submission the same way. The channel you choose — quote form, free validator, paid report, professional export, or contracted service — determines retention, product improvement, and suitability for confidential manuscripts.
| Channel | What is sent | Where it is processed | Is raw XML stored? | Indicative retention | Improvement / training | Confidential manuscript |
|---|---|---|---|---|---|---|
| Quote form | Contact and project details; optional attachment (PDF, Word, XML, ZIP, or another accepted format). | EditorialXML site over HTTPS; attachments associated with Cloudflare R2 storage; fraud checks (Turnstile) when enabled. | If you attach a file, we receive it and associate it with the request. This is not the same flow as free-validator encrypted improvement samples. | Generally up to 12 months from our last communication about the request, unless deleted earlier or an active project continues (then longer as needed for the relationship). | Not retained as free-validator improvement samples. Used to assess scope and prepare a proposal. | Suitable for evaluation samples under the Terms’ confidentiality duties; a Service Agreement may add stricter terms. |
| Free JATS validator | JATS XML file or batch for well-formedness and schema validation. | Validation on EditorialXML servers. Limited product analytics (no titles, authors, DOI, or XML by default). | By default, content may be retained encrypted for product improvement when Data Controls policy is active and your preference allows it. You can turn this off for future submissions. | Improvement samples: generally up to 180 days from storage unless deleted earlier. Limited analytics: generally up to 180 days. | May be used to improve or train EditorialXML systems subject to Data Controls. Retention ≠ automatic training. | Not recommended for peer-review, embargoed, or otherwise confidential content under default retention. Disable Data Controls or use a private paid / professional flow. |
| Paid validation report (guest) | XML used to generate a paid professional report. | EditorialXML servers; payment processed by Stripe. XML is processed to produce the deliverable. | Not stored as raw XML after processing. Derived report artifacts (e.g. HTML/JSON) and order records are kept. | Report artifacts and order records as needed for delivery, support, accounting, fraud, and disputes. Download links: generally 7 days (link expiry alone does not delete artifacts). | Excluded: private, no training. Not retained as an improvement sample and not used to train under the free-validator policy. | Preferable to the free validator with default retention when XML must not enter product-improvement retention. |
| Professional export (authenticated account) | XML submitted from an authenticated account to generate and return the report. | EditorialXML servers; the report is generated and returned in the response. | Submitted XML is not retained after that processing. | No retention of input XML after the response. Report content is not used for product improvement or model training. | Excluded: private, no training. | Suitable when you need an authenticated private flow without free-validator improvement retention. |
| Contracted professional service | Manuscripts, metadata, images, or other editorial materials delivered for agreed production or validation work. | Under the Service Agreement. Lynsoft LLC may act as a processor or service provider for those materials. | As required by project scope and customer instructions. | For the contractual relationship plus any additional period needed for administration, accounting, or disputes, unless otherwise agreed. | Not governed by free-validator improvement-sample policy; processing follows the applicable Service Agreement / addendum. | Intended channel for institutional projects; may include stronger confidentiality, an NDA, or a DPA. |
Download links for paid reports and checklists generally expire after seven (7) days. Link expiry alone does not delete report artifacts, order records, or the lead record.
How files are received
Submissions to the EditorialXML site and APIs travel over HTTPS. The free JATS validator runs validation on our servers: the file is sent to produce the result; it is not limited to a browser-only check.
In addition to file content, each free validation may create limited product analytics designed to minimize personal data: pass/fail outcome, validation profile, approximate country when enabled, size and duration buckets, and normalized issue codes derived from validation. Those codes are not device fingerprints.
Browser or device signals used for abuse prevention and rate limits are hashed for those purposes; they are not stored in the clear in free-validator product analytics.
- Quote form: optional attachments associated with the request and, when applicable, Cloudflare R2 storage.
- Free validator: XML processed on the server; encrypted retention only when Data Controls policy and your preference allow it.
- Paid and professional-export flows: XML processed for the report; not retained as an improvement sample.
Who has access
Access to customer materials and operational data is limited to Lynsoft LLC personnel and contractors who need it to operate the Service, respond to requests, perform contracted work, provide support, or meet legal obligations, and who are bound by confidentiality duties at least as protective as those in the Terms.
Providers acting as processors (hosting, storage, email, security, payments) may process information on our behalf and under our instructions. Some may also process limited information for their own legal, regulatory, security, or fraud-prevention purposes, as described in their notices.
Authorized internal access to retained free-validator improvement samples is restricted to authorized accounts. That access is logged without storing XML content. Files retrieved through internal tools are not cached for reuse, and access is not possible after expiry, withdrawal, or deletion.
Retention and deletion
Timelines depend on the channel (see the table). For the free validator, turning off product-improvement retention in Data Controls affects future validations: files are still processed for the result, but are not kept to improve or train. Content already retained may continue to be used until it expires (generally within 180 days of storage) or is deleted earlier.
To request deletion of eligible retained XML linked to your account or browser, email [email protected]. There is no self-serve delete control for past samples on the Data Controls page. Deleting a retained sample does not undo training completed before the request.
Operationally, a scheduled cleanup process expires samples, wipes active ciphertext, and applies configured retention policies. Deletion immediately removes the active encrypted database record. Historical database backups may retain encrypted copies until the hosting provider’s backup-retention cycle completes; we do not promise immediate erasure from those historical backups.
- Quote requests and associated attachments: generally up to 12 months from last communication, unless an active project or legal duty requires longer.
- Technical website logs: generally up to 90 days, or longer for an active security or legal investigation.
- Legal acceptance records (version, locale, hash, timestamp): kept as proof of the agreement and are not deleted when an account or order is removed.
Storage and encryption
Operational Service data is stored in databases and supporting systems managed for EditorialXML (including PostgreSQL for application records). Quote-form attachments may be stored in Cloudflare R2.
Free-validator improvement samples are stored encrypted with AES-256-GCM. Key material is not written to PostgreSQL; it lives in server environment secrets. Each active sample stores ciphertext, IV, authentication tag, and policy metadata (fixed expiry at storage time, provenance, policy version).
This page does not assert a specific hosting geography beyond what the Privacy Notice describes. No transmission or storage system is completely secure; we apply reasonable measures and document honest limits (including backups).
Product improvement and training
Retaining encrypted XML does not mean it is automatically used in training. Retention and selection into a training dataset are separate steps. Including retained content in a training dataset requires an explicit, audited decision.
Content that has been deleted, expired, withdrawn, identified as sensitive or restricted, or otherwise ineligible cannot be newly selected for training. A later increase in the configured retention period does not extend samples already stored.
Paid guest validations and authenticated professional exports are treated as private and excluded from training: their content is not retained as an improvement sample and is not used to train EditorialXML systems under the free-validator policy.
Third-party processing
We use providers necessary to operate EditorialXML: hosting, file storage, email delivery, security, fraud prevention, payment processing, and technical support.
Providers named in the Privacy Notice include Stripe (report payments and related purchases) and Cloudflare services used on the quote form (including Turnstile, R2 storage, and email sending). These providers process information as described in that Notice and in their own privacy notices.
We do not invent additional subprocessors here. If your institution needs a more detailed contractual list for a project, request it under a Service Agreement or data-processing addendum.
NDAs and confidential information
The Terms of Service include a mutual confidentiality clause. “Confidential Information” means non-public information disclosed in connection with the Service that is identified as confidential or that a reasonable person would understand to be confidential, including unpublished manuscripts, pricing, methodologies, and technical and business information.
Confidentiality obligations for unpublished manuscripts continue until the manuscript is lawfully published, released from confidentiality in writing, or otherwise enters the public domain without breach. For other Confidential Information, duties apply while the relationship continues and for three (3) years afterwards, and for as long as the information qualifies as a trade secret under applicable law. On written request, each party will return or delete the other party’s Confidential Information, subject to legal retention duties and routine backups overwritten on their normal cycle.
That clause does not authorize submitting confidential, embargoed, or peer-review content through the free JATS validator, and it does not override the licenses and limits in that section of the Terms. A Service Agreement may add stricter confidentiality terms, an NDA, or a Data Processing Addendum for a specific project. We do not publish a downloadable NDA template; institutional requirements are negotiated in writing. Contact [email protected].
What to do in practice
If the XML is embargoed, is peer-review material, or its submission, retention, or use for product improvement would violate confidentiality, copyright, licensing, or other restrictions: do not use the free validator with default retention.
Options: turn off product-improvement retention in Data Controls before validating; use a paid report or professional export (private flows without improvement samples); or commission the work under a Service Agreement with stronger confidentiality.
Submit content only if you have the necessary rights or authorization. The free validator is not intended for directly identifiable patient data or other sensitive personal information. If we identify such information in retained content, we may delete the sample and exclude it from improvement or training datasets.
- Data Controls: editorialxml.com/validator/data-controls (localized paths on the site).
- Privacy Notice and Terms: binding documents with the full detail.
- Contact for IT or committee review: [email protected].
Frequently asked questions
Can I validate an accepted but unpublished article in the free validator?
You can submit it technically, but the free validator is not intended for confidential peer-review material or content whose retention or improvement use would violate an embargo or other restrictions. If the XML is confidential, disable Data Controls or use a paid / professional / contracted flow.
Does turning off Data Controls delete what I already uploaded?
No. Turning it off affects future free validations. Content already retained may continue to be used to improve or train until it expires (generally within 180 days) or is deleted earlier. To request earlier deletion of eligible retained XML, email [email protected].
Are paid reports or professional exports used for training?
Not under the free-validator policy. Those flows are treated as private and excluded from training: content is not retained as an improvement sample and is not used to train EditorialXML systems under that policy.
Who can download internal validator samples?
Only authorized staff. Access is audited without recording XML. It is not possible after expiry, withdrawal, or deletion, and internal tools do not cache retrieved XML for reuse.
What about hosting backups?
Deleting a sample immediately removes the active encrypted record. Historical backups may retain ciphertext until the provider’s backup-retention cycle completes. We do not promise immediate erasure from those historical backups.
Can you sign an NDA before a large project?
The Terms already include mutual confidentiality, including for unpublished manuscripts. A Service Agreement may add stricter terms or a project NDA/DPA. There is no public downloadable template; email [email protected] with your institution’s requirements.
Do you store my card details?
Payments are processed by Stripe. We do not receive or store full payment-card data; Stripe processes payment data under its own terms and privacy policy.
What records remain if I delete an account or order?
Legal acceptance records (Terms and Privacy version and locale, content hashes, timestamp, and related action) are kept as proof of the agreement. Deleting an account or order does not delete those records; the account or order reference is removed from the record instead.
Related documents and controls
Contact for institutional review
If your ethics committee, legal office, or IT team needs additional detail for a review, email us. We will respond with reference to the current documents and, where relevant, the scope of a Service Agreement.
[email protected]