← Terms and policies

Privacy notice for researchers using Bracket

Version 0.4 (draft), 25 September 2026. Draft for review, not yet in force. Changes since 0.3: the summary at the top, cookies (§2), the providers' log retention in place of the markers (§2, §6), what you must provide (§3), who else receives your data and the processors' agreements (§5), the contact address (§1, §7), and §10 citing the public statement; `user-data-review-2026-09.md`.

In brief. Matthew Winkler, an independent researcher, is the controller. Bracket holds your account, your profile, the meetings you were in, your notes with their history, chat, your acceptances of these documents and some logs, on servers in Ireland and Germany, to run the study. The basis is legitimate interests, with your consent only for the optional research profile. Your notes can be read by you and the project owner alone. Notes are kept while the programme continues and reviewed every ten years; chat is deleted twelve months after the conference. You can ask for a copy, a correction, erasure within the limits the law sets for research, or a restriction, you can object at any time, and you can complain to the CNIL or to your own authority. Write to contact@bracketresearch.org.

This notice is for the researchers who use Bracket. It tells you what the tool holds about you, why, and what you can do about it. It is written to meet Articles 13 and 14 of the UK and EU General Data Protection Regulation.

It is not about the delegates who appear in your notes, nor about the people named in the published documents Bracket holds. Both are covered separately in §10.

1. Who is responsible

Matthew Winkler, an independent researcher, is the data controller. He decides what Bracket holds and why, and he answers for it. No university or institute controls this data, none holds it, and none has been asked to: the study is run independently, which is what makes it possible to promise that only the author and the owner ever read a note.

ControllerMatthew Winkler, independent researcher
Contact for anything in this noticecontact@bracketresearch.org
Data protection officerNone. A controller of this size is not required to appoint one, and appointing a nominal one would be worse than saying so plainly. The contact above is the route for everything.
Supervisory authorityThe authority of the country you live or work in. For France that is the CNIL.

There is no joint controller arrangement, because there is no second controller. If the project later sits inside an association or a company, that becomes a change of controller, it is announced to the team, and this notice is reissued. What such a move would change, and what it might risk, is recorded in open-questions.md, which is marked for a critical review.

2. What Bracket holds about you

Your account. Your email address, a password (stored hashed by our authentication provider, never visible to us), the invitation that created the account, when you signed in, and your role (researcher, administrator, project owner).

Your profile, visible to the whole team. Display name, first and last name, pronouns, photograph if you upload one, organisation, department, position, a short biography, languages, a website, a contact email if you choose to publish one, your badge type and the organisation on your badge, the dates and days you are attending, and a messaging handle if you give one. Almost all of it is optional; the directory exists so that 40 people who have never met can find each other in a conference centre.

Your research profile, visible only to you and the project owner. Nationality, country of residence, birth year, gender, discipline, how many COPs you have attended, the year of your first, and an emergency contact. Every field is optional. These describe the observer for methodological purposes: who was watching affects what gets seen, and the analysis has to be able to say so.

Presence. Which meeting you are in, whether in person or online, when you joined, the last heartbeat from your browser, and when you left. §4 of terms-of-use.md explains why, and what the "share my presence" switch does and does not do.

Your notes. The text you write, its type (note, reflection or quotation), the delegations and tactic tags you attach, the text and paragraph you cite, the speaker turn you typed it under, its sensitivity, the time you wrote it, your device's timezone, and the time the server received it. Every change to a note is kept as a separate record, with your device's identifier, so that two devices used offline can be folded into one history. Deleted notes are hidden, not erased (§7). Also whether you have marked a meeting as read back.

Chat. Messages you send in a meeting's Panel or the event-wide channel, with your name and the time. Chat is coordination, not research data. It is never exported, and it is deleted twelve months after the conference closes (§6).

Your acceptance of these documents. Which document, which version, a checksum of the wording as it was shown to you, when you accepted it, the address the acceptance came from and which screen it was made on. The record cannot be changed or deleted afterwards, because a record of something that happened does not change; it is removed only when your account is. The project owner and administrators can read it, which is a deliberate departure from the rule for notes: "has everybody accepted the terms" is a question about people, and managing people is what administrators do. It tells them nothing about what you observed.

Training. Your attempts at the practice meetings, what you tagged, and the timing, so that calibration between observers can be measured.

Logs.

  • Downloads. Every download taken by an administrator or the owner is recorded: who, what, when and with which options. Your own downloads of your own notes are not logged.
  • Changes to shared records. Edits to meetings, the agenda and reference data are recorded with the before and after and who made them. Your notes are not in this log.
  • Technical logs. Our hosting providers keep ordinary server logs, which include IP addresses, browser type and the addresses requested. We use no third-party analytics and no error-tracking service that receives the contents of requests. Vercel keeps its runtime logs for one day and Supabase its logs for seven days, on the plans we use; Hetzner keeps web server logs for seven days by default and other log files for at most thirty days, with IP addresses anonymised.

On your own device. Bracket writes your notes to your browser's storage before sending them, so that a lost connection cannot lose a note. That copy is on your machine, under your control, and clearing your browser data removes it.

Cookies. Bracket sets the cookies it needs to keep you signed in and to remember your theme. None is used for tracking or advertising, and there are no third-party cookies.

3. Why, and on what lawful basis

The basis is legitimate interests, Article 6(1)(f), for almost everything. An independent researcher is not a public body, so the public-task basis in Article 6(1)(e) is not available, and this notice says so rather than claiming it. The interest is running this study: a method that only works if a team of observers records the same things in the same way, and a question about how negotiations proceed that the published record cannot answer.

WhatWhyLawful basis
Account, role, sign-inTo let you in and keep everyone else outArticle 6(1)(f)
Profile and directorySo a dispersed team can find and identify each otherArticle 6(1)(f), with everything beyond your name optional
Research profileMethodological: to describe the observersArticle 6(1)(f), and your consent (Article 6(1)(a)) for its use as research data, which is the tick box on that page. Where a field reveals something in a special category (Article 9), the basis is your explicit consent, Article 9(2)(a). You can withdraw it.
PresenceCoverage planning during the conference, and the analysis afterwardsArticle 6(1)(f)
Notes, tags, citationsThey are the research dataArticle 6(1)(f), with the safeguards for research processing in Article 89(1)
ChatCoordination during the conferenceArticle 6(1)(f)
Training and calibrationTo measure agreement between observers, which the method requiresArticle 6(1)(f)
Download and change logsSecurity, accountability and reproducibility: we can say what left the system and whenArticle 6(1)(f)
Acceptance recordsTo be able to say what each person agreed to, and whenArticle 6(1)(c) and (f)
Technical logsSecurity and keeping the service runningArticle 6(1)(f)
Published documents that name other people (the research library; not about you)Scholarship on the negotiations: the published record, held beside the team's ownArticle 6(1)(f), with the safeguards in Article 89(1). What the documents are, whose record they are and what Bracket will not do with them is §10.

The balancing test, in short. The interest is a research programme that cannot be run any other way. The data is about adults who chose to join a research team, it is minimised (no field asks for anything the analysis does not need), it is held in the EU, and access is enforced in the database rather than promised in an interface. Against that, your notes are your own work and can be personal in tone, which is why reflections are left out of a shared export by default and why you can object at any time. The conclusion is that the interest is not overridden, and if you disagree in your own case, §7 is the route and the answer comes in writing.

Why not consent for everything. We rely on consent only where it is genuinely free: the optional research profile. We do not use it as the basis for processing your notes, because your notes are the research and because consent you cannot realistically refuse while remaining on the team is not valid consent. Relying on legitimate interests instead gives you a right to object (§7), which is the appropriate protection here. Taking part in the fieldwork remains voluntary whatever the legal basis says.

What you must provide. An email address, to have an account, and a display name, so that the team can see who is in a meeting and who wrote in chat. Nothing else is required: every other field is optional, and nothing beyond accepting these documents is a condition of using Bracket.

Article 89 safeguards. Processing for research is subject to the safeguards in Article 89(1), which we meet by data minimisation (no field asks for anything the analysis does not need, and no field anywhere asks for an individual delegate's name), pseudonymisation of researchers at every export, access control enforced in the database, and a data management plan.

4. Who can see what

YouOther researchersTrack leadsAdministratorsProject owner
Your notesyesnononoyes
Counts derived from notesyesnoaggregatesaggregatesyes
Your profile (directory part)yesyesyesyesyes
Your research profile and emergency contactyesnononoyes
Your presence, liveyesif you share itif you share itif you share ityes
Your presence, recordedyesnonocoverage figuresyes
Chat you sendyesyes, in that channelyesyesyes
Your acceptance recordyesnonoyesyes
Download and change logsnononopartlyyes

This is enforced by row-level security in the database, tested on every change, not by what an interface chooses to show. Administrators manage people and meetings; they cannot read notes, and there is no screen that would let them. Track leads see aggregates only, never a word of a note, and that is not going to change during COP31 without a new version of the terms.

5. Where it is held, and who processes it

  • Database, authentication, real-time updates and file storage: Supabase, on Amazon Web Services in Ireland (eu-west-1). An earlier plan named Frankfurt; the project was created in Ireland and nothing depends on the difference. Both are in the EU.
  • The application itself: Vercel, with server functions pinned to Dublin (dub1) so that code runs next to the database.
  • Sign-in and password-reset email: Hetzner Online, from a mailbox in Germany. It sends the sign-in, password-reset and invitation emails, and holds the project's contact inbox.
  • Backups: Supabase's own daily backups of the database, kept for a few days, and a nightly copy of the database to Hetzner Object Storage in Falkenstein, Germany. The copy is encrypted on the project owner's computer before it leaves, and Hetzner holds only the encrypted file, which it cannot read. There is no point-in-time recovery.

All four are processors acting on our instructions under Article 28 contracts: Supabase's and Vercel's data processing addenda are incorporated in their terms of service, and Hetzner's is accepted in its customer portal. Supabase and Vercel are US-parented companies, so their contracts include the standard contractual clauses and, where applicable, reliance on the EU-US Data Privacy Framework; region pinning keeps the data in the EU. The assessment is recorded in the project's data protection impact assessment (docs/policy/dpia.md).

Who else receives your data. Beyond the processors: the team, for your directory profile, your shared presence and chat; the project owner, for everything; co-authors and named collaborators, for pseudonymised exports under the data management plan; and, if the dataset is archived, the repository, under the access conditions decided then (research-participation.md). Nobody else, and nothing is sold or shared for any other purpose.

There is no third-party analytics, no advertising technology, and no artificial-intelligence service that receives your notes.

6. How long it is kept

WhatKept for
Notes and the research datasetWhile the research programme continues. Reviewed every ten years, and at each review either kept for the next ten or deleted or anonymised, with the decision written down.
Account and profileWhile you are on the team; the account is closed when you leave and the profile is deleted a year after that.
Research profileWith the dataset, or deleted at once on withdrawal of consent
PresenceWith the dataset
ChatThe conference plus twelve months, then deleted. Never part of a research export.
Training attemptsWith the dataset
Acceptance recordsWhile the account exists, and deleted with it
Download and change logsWith the dataset: they are what lets anybody say later what left the system and when
Technical logsVercel, one day; Supabase, seven days; Hetzner, seven days for web server logs and at most thirty days for other log files

Backups. Something deleted from Bracket stays in the backup copies made before it was deleted (§5) until those copies age out, which takes up to a year.

Why the notes have no fixed number of years. This is a long programme built on a dataset whose value is that it can be re-analysed, by us and by others. A fixed period would be either a guess or a promise to delete something still in use. The ten-year review is the discipline instead: somebody has to look at it and decide again, in writing, rather than letting "for ever" happen by default. An archived dataset kept after such a review stays pseudonymised, which is normal for research data and is what makes findings checkable. research-participation.md says what that dataset contains about you.

7. Your rights

You can ask us to:

  • Give you a copy of what we hold about you (Article 15). You can already download your own notes at any time from Review.
  • Correct anything wrong (Article 16). Your profile is yours to edit.
  • Erase your data (Article 17). This one has a genuine limit: Article 17(3)(d) allows us to refuse erasure where it would seriously impair research that is in the public interest. Your account, profile and chat can be deleted. Notes already analysed and published on are a different matter, and we will explain in writing what we can and cannot remove, and why.
  • Restrict processing while a dispute about accuracy or objection is resolved (Article 18).
  • Object to our processing (Article 21). Because the basis is legitimate interests, you can object at any time and we must stop unless we can show compelling legitimate grounds that override your interests. This is the protection that comes with not using consent, and it is taken seriously: we answer in writing and say which way it went and why.
  • Withdraw consent for the optional research profile fields (Article 7(3)), at any time, without affecting anything that happened before. The fields are then deleted and left out of future exports.
  • Take your data elsewhere (Article 20), where it is processed on consent and by automated means.

Deleting a note removes it from every view and from every export. The record of the deletion remains, as §3 of terms-of-use.md explains.

How. Email contact@bracketresearch.org. We answer within one month; if a request is complex we may take up to two further months and will tell you why. There is no charge.

Research derogations. Some of these rights may be restricted where the data is processed for scientific research under Article 89(2) and the national law that implements it; in France that is the loi Informatique et Libertés. We will not use a derogation as a way of avoiding an inconvenient request, and any use of one will be explained to you. An independent controller has a narrower path here than a recognised research body would, which is one of the things open-questions.md weighs.

If you are not satisfied, you can complain to the supervisory authority: the CNIL in France (https://www.cnil.fr/fr/plaintes), or the authority in the country where you live or work. You do not have to come to us first.

8. Is anything automated?

No. There is no automated decision-making or profiling that has any legal or similarly significant effect on you. Tactic tags are suggested by people and confirmed by people; the tool computes counts, not judgements about you. The search over texts finds passages by their words; it builds no profile of anybody, you or a delegate.

9. Security, briefly

Invitation only, with public sign-up disabled. Every table in the database has row-level security and at least one policy, and a test fails if one does not. Server code queries the database as you, so the same rules apply to the server. The browser never queries data tables directly. Invitation tokens are stored hashed. Notes are never hard-deleted, so a mistake is recoverable. Responses carry a strict content security policy. Files you upload are readable only through the record they belong to. A security review and its three follow-up passes are recorded in the project's architecture decisions.

We will tell you, and the supervisory authority, if there is a breach that is likely to affect you.

10. The people in the room, and the people in the documents we hold

Two groups of people appear in Bracket without being asked: the delegates you observe, and the people named in published documents the project holds. The rule for the first is absolute. The second is a library, and this section says what that means and where the line is.

What the team records

Bracket never records the name of an individual delegate. It is a design rule rather than a habit. Notes are about Parties, negotiating groups and roles, which are picked from a list; a meeting's chair is a role and a Party ("Co-facilitator, Norway"); there is no field for a person's name anywhere in the tool, and there is not going to be one.

Why it matters so much here: what a delegate says in a negotiation can reveal their political opinions, which Article 9 treats as a special category. A field note naming an individual would be special-category data about somebody who never met us, never agreed to anything and cannot correct it, and an independent researcher has no research exception in French law to process it under. Rather than build safeguards around that, the project does not collect it.

Free text is the one way a name could get in, so it is checked. As a note is written or corrected, Bracket quietly says when the text looks like a personal name and offers the role or the Party instead; it never interrupts and never blocks, because a live meeting does not pause. A researcher's own downloads list the notes that tripped the check, and the research dataset export refuses to write one at all unless the owner deliberately overrides it, which the export then says on its face. The check is a prompt and not a guarantee, which is why the rule comes first.

What remains is therefore about Parties and groups, which are institutions rather than people. To the extent that anything about an identifiable individual survives in free text, the safeguards in Article 89(1) apply, and the notes are readable only by their author and the owner.

What others published, and we hold

The project keeps a research library of published reporting on the negotiations: the Earth Negotiations Bulletin, Third World Network's updates, the ECO newsletter and Carbon Brief's coverage, among other works. Those publishers name negotiators, chairs and ministers and report what they said. That is the publisher's record, not ours. We hold it the way any library holds a newspaper: unaltered, for reading, citation and search, under each publisher's own terms, and never republished.

Holding it is still processing personal data about the people named. The controller is Matthew Winkler; the lawful basis is legitimate interests (Article 6(1)(f)) in scholarship on the negotiations, for which this reporting is the standard record; and the safeguards in Article 89(1) apply. The people named are public officials acting in an official capacity in a process the world watches, the reporting was done by professional publishers, and Bracket adds nothing to what they published.

The line Bracket does not cross. Bracket may hold, show and search the publisher's record. It does not build a record of a person from it. There is no field, entity, index, filter, count, page or profile keyed on a person's name; a name in a document is never stored as a link to a Party, a group or a role; a name in a document is never joined to the team's notes, floor records or tags; and a search that asks for a person by name is declined, using the same check as the room. Where a document from the library is shown in Bracket or found by its search, it is shown as its publisher wrote it, to members of the team, and it never leaves the server for you or any team member: not in an export, a report or a copy on your device. The project owner, who holds the library under each publisher's terms, keeps his own copies outside Bracket.

What this means for you. You may read these documents, search them and cite them by issue and page. You may not copy a name out of them into a note, a meeting title, chat, or a list of your own: a record of named people made by the team is the team's record whatever tool it was made in. Write the Party; cite the document.

Both groups

We have not written to the several hundred delegates the team observes or to the people named across thirty years of published reporting. Article 14(5)(b) covers that: informing each of them individually would be a disproportionate effort for research processing under Article 89(1) safeguards, and the appropriate measure is to make the information public instead. That statement is published at https://bracketresearch.org/policies/public-statement; its wording is public-statement.md in this folder, and the page renders it.

Nothing in this section reduces anybody's rights. If a delegate or a person named in a document contacts us, we answer, and we can search the notes and the library for anything about them, because that is the only honest way to answer.

11. Changes

The version number at the top changes and the team is told. Previous versions stay in the project's repository.