Privacy Policy
How Youssef Darahem handles personal data when you use VennPub.
Last updated: 8 August 2026
1. Who we are
VennPub is provided by Youssef Darahem, trading as VennPub, based in Türkiye. We are the controller for the personal data we collect about users of VennPub. Our registered address is:
Adnan Kahveci, Çankaya Cd. 2-634528 Beylikdüzü/İstanbulTürkiyeFor any privacy question, or to exercise the rights in section 8, contact privacy@vennpub.com.
2. What we collect, and why
Account data
Your email address, a securely hashed version of your password, and the dates your account was created and last updated. We use this to create and secure your account, to sign you in, and to contact you about the service. If you sign in with Google we also store the Google account identifier and the email address Google gives us, so we can recognise you on your next visit.
Legal basis: performance of our contract with you.
Your review content
The projects you create and everything in them: search strategies and queries, files you upload, the bibliographic records retrieved, your screening decisions, exclusion reasons, and any notes you write. This is normally research material rather than personal data, but it is yours, we store it to provide the service, and we treat it as confidential. We do not use it to train models, and we do not sell it or share it with anyone outside the providers listed in section 4.
Legal basis: performance of our contract with you.
Subscription data
If you subscribe to a paid plan, we store a copy of your subscription status as Paddle reports it: a Paddle customer identifier, a subscription identifier, which plan you are on, and the relevant dates. We use this to give you access to the features you paid for.
We never see or store your card details. Payment details are collected and held by Paddle, who act as the merchant of record and as an independent controller of that data.
Legal basis: performance of our contract with you.
Technical data
Our servers keep ordinary access logs, which include IP addresses, timestamps, the pages or endpoints requested, and browser user-agent strings. We use these to keep the service running, to investigate faults, and to detect and prevent abuse and fraud.
Legal basis: our legitimate interest in the security, reliability and improvement of the service.
3. What we do not do
We do not use third-party analytics, advertising or tracking services, and we do not profile you or make automated decisions that produce legal or similarly significant effects. We do not sell personal data.
4. Who we share data with
We share personal data only with the providers we need to run the service, and only for that purpose:
- Paddle — our merchant of record, for the sale of subscriptions, subscription management, payments, invoicing and tax compliance. Paddle is an independent controller for the payment data it collects; see Paddle’s privacy notice.
- Our hosting and storage providers — who host the application, the database and the files you upload, as processors acting on our instructions.
- Google — only if you choose to sign in with Google, and only to authenticate you.
- Professional advisers (legal, accounting) and authorities, where we are required by law or need to protect our rights or someone’s safety.
Separately, when you run a search, your search query is sent to the literature databases you selected — PubMed, Europe PMC and OpenAlex. Those requests carry your query, not your account details or identity.
5. Where your data is held, and international transfers
We are established in Türkiye, so we are subject to Turkish data protection law (KVKK, Law No. 6698). Because we also offer VennPub to people in the United Kingdom and the European Economic Area, the UK and EU GDPR apply to that processing as well, and the rights in section 8 are available to you wherever you are.
Your account data and review content are stored on servers in the European Union, and uploaded files in object storage in Frankfurt, Germany. Some of our providers operate elsewhere, including the United States. Where personal data leaves the UK or EEA, we rely on an adequacy decision where one applies, and otherwise on standard contractual clauses or the UK International Data Transfer Agreement, with appropriate additional safeguards.
6. How long we keep it
We keep your account and review content for as long as your account is open. If you close your account, we delete or anonymise your personal data within 90 days, except where we must keep something longer to meet a legal obligation — records relating to payments and tax are the usual example, and those are held by Paddle under its own retention rules. Server logs are kept for a short period, normally no more than 90 days.
7. Security
We apply appropriate technical and organisational measures to protect personal data. In practice that includes encryption in transit (HTTPS everywhere), passwords stored only as salted hashes and never in readable form, access controls restricting who can reach production systems, private object storage where uploaded files are reachable only through short-lived signed links, and regular patching of the software we run.
No service can promise perfect security. If a breach affects your personal data and presents a risk to you, we will notify you and the relevant regulator as the law requires.
8. Your rights
You have the right to:
- access the personal data we hold about you, and receive a copy;
- have inaccurate data corrected;
- have your data erased;
- restrict how we process it, or object to processing based on legitimate interests;
- receive your data in a portable, machine-readable format;
- withdraw consent at any time, where we rely on consent.
Email privacy@vennpub.com to exercise any of these. We will respond within one month, and will tell you if we need longer because the request is complex.
If you are unhappy with how we have handled your data, you can complain to the Personal Data Protection Authority (KVKK) in Türkiye, to the data protection authority where you live, or — in the United Kingdom — to the Information Commissioner’s Office. We would appreciate the chance to put it right first.
9. Cookies and local storage
We use only what the service needs to work. We set no advertising or analytics cookies.
- Session cookie — keeps you signed in after you log in. Essential.
- Sign-in security cookie — set briefly during Google sign-in to protect against cross-site request forgery. Essential.
- Browser local storage — remembers your light or dark theme choice, your exclusion keywords and your preferred screening view. This stays in your browser and is never sent to us.
When you go through checkout, Paddle may set its own cookies on its checkout frame. Those are covered by Paddle’s privacy notice, linked in section 4. You can clear or block cookies in your browser, but blocking the essential ones will stop you being able to sign in.
10. Changes
We will update this notice when our practices change. The date at the top shows when it last changed, and we will tell you about significant changes by email or in the app rather than relying on you to notice.