Bracket: terms of use
Version 0.3 (draft), 25 September 2026. Applies to the COP31 observation team. Draft for review, not yet in force; see `README.md` in this folder. Changes since 0.2: the summary at the top, who Bracket is for (§1), whose the notes are and the licence the study has (§3a), availability (§9), withdrawal of access (§10), which law applies (§14), the contact address (§13); all from `user-data-review-2026-09.md`.
In brief. Bracket is a private note-taking tool for the COP31 observation team. Your notes are research data: only you and the project owner can read them, they are kept while the research programme continues, and they leave the team only pseudonymised. Never record an individual delegate's name, never record audio or images, and never take notes out of the team. You keep the copyright in your notes and license their use to the study. Accepting these terms, the privacy notice and the acceptable-use rules is a condition of using the tool; taking part in the study as a subject is a separate, optional choice. Write to contact@bracketresearch.org with any question.
Who is responsible for this data. Matthew Winkler, as an independent researcher, is the data controller: he decides what Bracket holds and why, and he answers for it. No university or institute controls it, and none has been asked to. The lawful basis is legitimate interests (Article 6(1)(f)): running this study, on this method, with this team. privacy-notice.md §3 sets out the balancing that goes with that basis, and §1 says how to reach him. Whether the project later sits inside an association or a company, and what that would change, is open and recorded in open-questions.md; nothing here depends on the answer.
You accept these terms when you first sign in. One acceptance covers the terms, the privacy notice and the acceptable-use rules together: they are one set of conditions and splitting them into three identical chores would only make the third one unread. Research participation is separate and optional (research-participation.md), because a consent you cannot decline is not a consent. Accepting is recorded: who, which document, which version, when, and from which address. The project owner and administrators can read that record, because "has everybody accepted the terms" is a question about people and managing people is what administrators do. They still cannot read a word of your notes.
They are short on purpose. If something here does not match what you were told, say so before you start taking notes.
1. What Bracket is for
Bracket is a private note-taking tool for a research team observing UNFCCC meetings. You use it to record what happens in the room: who spoke, what they said, which text they were arguing about, and your own reading of it. Those notes are research data for Bracket, which studies how negotiations proceed.
Bracket is not a diary, not a messaging service and not a place for anything unrelated to the fieldwork.
It is for the members of the COP31 observation team, invited by the project owner and all of them adults. There is no public sign-up, and an account is not transferable.
2. Who can read your notes
- You can read, edit and delete your own notes at any time.
- The project owner (Matthew Winkler) can read everyone's notes. This is how the research gets done: the notes are the dataset, and they are read, coded and analysed.
- Nobody else can. Administrators manage people, meetings, the agenda and the text library. They cannot read your notes, and neither can track leads. That is enforced in the database by row-level security, not by a promise in an interface.
Track leads see aggregates only, and never raw notes. That is how it works today and it is not going to change during COP31: a lead sees how many notes a meeting produced, who covered which meeting and how much each delegation spoke, and never a word of what anybody wrote. Administrators see the same counts. If that ever changes it is a new version of these terms, announced, and not a quiet adjustment mid-conference.
The owner reads notes to analyse them, to check the quality of the coding, and to prepare publications. Where your notes are quoted or built on in a publication, see research-participation.md.
3. Your notes are kept, not erased
Deleting a note hides it from every view and from research exports. The record of it stays in the database, because the edit history is part of the audit trail and because two devices editing the same note offline need a single history to fold into. If you need something genuinely removed, ask the owner.
3a. Your notes are yours, and licensed to the study
The notes you write are your own work, and the copyright in them stays with you. So that the study can use them, you grant the project a licence that is non-exclusive, irrevocable and worldwide, for the purposes of the research programme: to read, analyse and code your notes; to quote them in publications, attributed as research-participation.md says (to a delegation, never to a named individual, and never with your identity attached to a delegation's conduct unless you are an author and agree); and to include them, pseudonymised, in the dataset that leaves the team and in any release of it, under the licence the project names for its annotation layer (CC BY 4.0, README.md in this folder). The licence is irrevocable because a published analysis cannot be unpublished; your right to object to the continued use of your notes, and the limits after publication, are in §10. You keep the right to use your own notes in your own work (research-participation.md, "Your own work").
4. The tool records who was in which meeting
When you open a meeting in Bracket, it records that you were there, in person or online, and when you left. This is deliberate. Coverage planning depends on it ("nobody is in the transparency contact group at 15:00"), and the analysis depends on knowing who observed what.
Your profile has a switch for whether colleagues see which meeting you are in right now. The record itself is kept either way, and the owner can see it. Turning the switch off hides you from the team's live view, not from the dataset.
5. No audio, no photographs, no recordings
Do not record audio or video of any session, and do not photograph delegates. Bracket holds text only and will never gain a recording feature. This is not a technical limit we are working around: it is a condition of how the team works in the venue, and recording is in any case against UNFCCC rules in most rooms.
Photographing a projected text or a printed document you are allowed to have is a different thing and is fine. People are the line.
6. Bracket never records the name of an individual delegate
This is the rule the rest of this document is built on, and it has no exceptions.
Write about Parties, groups and roles, never about a named person. "The EU asked for the paragraph to be bracketed" carries the analysis. "[Name] asked for the paragraph to be bracketed" carries the analysis plus a named person's conduct in a role they hold on someone else's behalf, and Bracket is not the place for that.
Why the rule is absolute rather than a judgement made in the moment:
- A named delegate never met you, never agreed to anything and cannot correct your note. What you wrote would be their personal data, and what a delegate says in a negotiation can amount to their political opinions, which the law treats as a special category and which a field note cannot properly carry (see
privacy-notice.md). - Notes taken quickly in a noisy room are often wrong about who said what. A delegation is easy to get right; a person is not.
- Naming raises the stakes of any leak, and it can harm somebody's standing or career.
- A rule with exceptions is a rule argued about in a live meeting, which is exactly when there is no time to argue.
Presiding officers too. Where a chair or a co-facilitator is recorded, it is the role and the Party: "Co-facilitator, Norway". Who is in the chair is publicly announced, and the role plus the delegation carries every analysis this project makes of who ran a meeting. The meeting form has no field for a name, and will not get one.
What the tool does about it. Delegations, coalitions, bodies and roles are picked from a list; people are not, anywhere. As you write a note or correct one, Bracket quietly says when what you have typed looks like a personal name and offers the role or the Party instead. It never interrupts, never takes the cursor and never stops a note being saved: in a live meeting nothing gets in the way of capture. Your own downloads list the notes that tripped that check, so you can find them and reword them, and the research dataset export refuses to write a note that looks as though it names somebody unless the owner deliberately overrides it, which the export then says on its face.
The check is a prompt and not a guarantee. A surname on its own will not be caught by any rule of this kind, which is the real reason the rule is "do not write names" rather than "write them and we will find them".
If a name gets in anyway, reword the note. It is a correction like any other and nobody is in trouble for it.
Published documents that name people. Bracket's research library holds reporting on the negotiations by others, such as the Earth Negotiations Bulletin, which names negotiators and chairs. That is the publisher's record, and you may read it, search it and cite it by issue and page. You may not copy a negotiator's or a chair's name out of it into a note, a meeting title, chat, or a list or spreadsheet of your own: a record of named people made by the team is the team's record whatever tool it was made in. If a point needs the passage, cite the document; the Party carries the analysis, as it does everywhere else in Bracket. Citing a published author by name, as academic practice requires, is a different thing and is expected.
7. Closed and restricted sessions
Meetings in Bracket carry a sensitivity: open, observer-restricted, or closed.
- Open: plenaries and anything webcast. Note freely.
- Observer-restricted: you were admitted as an observer, but the room is not public. Note normally. Your badge entitled you to be there.
- Closed: informal informals, heads-of-delegation meetings, anything you were not admitted to. Do not take notes on a closed session from inside it, and do not write up what somebody told you afterwards as though you had observed it. If a colleague relays something, record it as hearsay, mark the note closed, and say where it came from.
Mark a note closed if it contains something from a closed room, whatever the meeting is set to. Closed notes are held back or stripped of their text at export by default.
If you are asked to leave a room, leave. If a session is placed under the Chatham House Rule, the substance may be noted; the speaker may not be identified, not even by delegation where that would identify them.
8. Chat is not research data
The Panel's chat is for coordination: who is going where, which room moved, who has the text. It is not part of the dataset, it is never exported, and it is not analysed. Do not put findings in it that belong in a note, because they will not reach the research.
Chat is readable by everyone in the event, including administrators. Treat it as a room with the whole team in it.
Chat is kept for the conference and twelve months after it, and is then deleted. Twelve months so that a question about how the fieldwork was organised can still be answered while the papers are being written, and then deleted because coordination has no reason to outlive the coordinating. It is never part of a research export, so nothing in it reaches the dataset, a co-author or an archive. Deletion is permanent.
9. Devices and accounts
- Your account is yours. Do not share the password or hand your signed-in laptop to somebody else to take notes under your name.
- Notes are written to your device first and sync when there is a connection. A device with unsynced notes holds research data. Lock it, encrypt the disk (FileVault on macOS, BitLocker on Windows, LUKS on Linux: whole-disk encryption, not a folder), and do not leave it in a venue cloakroom.
- Sign out on any device you do not control, and on any device you are about to lend, sell or return.
- Tell the owner at once if a device is lost or stolen, or if you think somebody has used your account.
- Use a browser you keep up to date. Firefox and Chrome are both tested.
Bracket is a research tool run by one person on hosted services. It is provided as it is, without a guarantee that it is available at any moment, and without liability for a note lost to an outage or a fault beyond what the law does not allow to be excluded. The safeguards are the ones above: your notes are written to your device first and sync when the service returns, and your own downloads (§10) are always yours to take. If the service is down during a meeting, keep writing; the notes sync when it is back.
10. If you leave the team
Your notes stay in the dataset. They are research data about meetings that happened, and the analysis, the published figures and any paper already drafted depend on them; a note removed after the fact would make earlier results irreproducible.
What happens on departure:
- Your account is closed and you lose access to the tool.
- You can ask for a copy of everything you wrote, and you will get it as a readable file.
- Your name is replaced by a stable label in every export, as it is for everyone, whether you are still on the team or not (§10a).
- You keep the authorship and credit you earned (
research-participation.md). - You can object to the continued use of your notes; the owner must then weigh that objection against the research purpose and tell you the outcome in writing. This is a real right, not a formality, and
privacy-notice.mdsays how to use it.
If you want your notes withdrawn entirely, say so before the analysis is published. After publication the practical answer is usually no, and pretending otherwise would be dishonest.
Access can also be withdrawn, by the owner or an administrator, for a serious or repeated breach of these terms or of acceptable-use.md. What happens to your notes is then exactly as above.
10a. You are a stable label in every export
Researchers are pseudonymised whenever data leaves the tool. You are "Researcher 001", "Researcher 002" and so on, assigned by the order people first wrote a note at an event, and the same label every time so that a figure in one paper can be matched with a figure in another. Your name, organisation, account id and background details are left out.
The owner can also run an identified export, which adds those columns, for the project's own analysis. It is a deliberate choice, it is recorded permanently with who ran it and when, and the file says on its first page that it is personal data.
Be clear about what a label buys you: this is pseudonymisation, not anonymisation. The key exists, the owner holds it, and with a team of thirty to fifty a label plus a role plus the list of meetings somebody attended can identify a colleague to another colleague without any key at all. research-participation.md says the same thing at greater length.
11. How long things are kept
| What | Kept for |
|---|---|
| Notes and the research dataset | While the research programme continues. Reviewed every ten years, and at each review either kept for the next ten or deleted or anonymised. |
| Chat | The conference plus twelve months, then deleted. Never exported (§8). |
| Account and profile | While you are on the team, then closed; the profile is deleted a year after that. |
| Acceptance records | While the account exists, and they go with it. |
"While the research programme continues" is honest rather than evasive: this is a long study built on a dataset whose whole value is that it can be re-analysed. A fixed number of years would either be a guess or a promise to delete something still in use. What it is not is "for ever by default": every ten years somebody has to look at it and decide again, in writing.
12. Changes to these terms
Material changes are announced to the team and the version number at the top changes. A new version is asked for from the day it takes effect, and you have fourteen days to read and accept it before it stands in the way of anything. The very first version has no such period: you accept it before you start. Even after those fourteen days, the room and syncing are never blocked, because losing a fortnight of fieldwork over an unread update would be the worse outcome by far. Old versions stay in the project's repository so you can see exactly what you accepted and when.
13. Questions and complaints
Write to contact@bracketresearch.org. If you are unhappy with how your data is being handled, the independent route is in privacy-notice.md.
14. Which law applies
These terms are governed by French law, and any dispute about them goes to the courts of Paris. Nothing in this section takes away a right you have under the data protection law of the country where you live or work, including the right to complain to your own supervisory authority (privacy-notice.md §7).