We use only the cookies needed to run the site and keep you signed in. No analytics, no advertising. Your answer covers anything optional we add later.

Cookie statement

Trust and security

Where your data sits, who touches it, and what we do not do with it. Written out rather than shown as a row of badges.

Last updated: 30 August 2026.

Where the data sits

The application runs in Frankfurt and the database runs in the same region, both inside the EU. They are pinned to each other on purpose: a query that has to cross a continent is slower and travels further than it needs to.

Who processes it

A short list, each one under a processor agreement. Vercel hosts the application. Neon runs the Postgres database. Mollie handles payments and holds the card details, which never reach us. Mailtrap sends transactional email: the verification link, the set-your-password link, and account notices. Cloudflare Turnstile checks that the signup form is being filled in by a person. That is the whole list. When it changes, this page changes with it.

What we do not do

No analytics, no advertising cookies, no tracking pixels, no third-party scripts following you between sites. We do not sell personal data and we do not share it for anyone else's marketing. There is no automated decision-making with legal effect: a signup is reviewed by a person.

Account security

Passwords are hashed with bcrypt and never stored in readable form, so a database leak does not hand anyone a password. Sessions use a signed cookie that expires after 30 days. Verification and password links are single-use, expire, and are stored as a hash, so the link in your inbox cannot be replayed from our side. Public forms are rate limited per address.

What we do not claim

IPMERC is not ISO 27001 certified and does not display badges it has not earned. What is written above is what is true today. If a certification arrives, it will be named here with its date and its scope.

Availability

We aim for high availability and do not promise uninterrupted service. The terms say the same thing in the language of a contract. Planned work that takes the platform offline is announced by email to account holders.

Your data, your call

Ask for a copy of your data, a correction, or deletion through the contact page, and you get an answer within one month. Deleting an account removes its personal data within a reasonable period, unless the law requires us to keep something longer, and the privacy policy says which rights you have and where to complain.

Research data

The research library is separate from your account data. Papers are built from public statistical sources, every one of them named on the sources page, and no customer data goes into a paper. The published figures are free to read, cite, and share.

Reporting a problem

Found a security issue? Report it through the contact page with enough detail to reproduce it. We confirm receipt within two business days, we will not pursue you for reporting in good faith, and we ask you to give us a reasonable window before publishing.

Something here unclear, or a security issue to report? Contact us.