Privacy Policy

Last updated 17 August 2026

Stomics.io is a public repository for spatial transcriptomics data, operated by The Allman Institute for Personalized Medicine (“the Institute”, “we”, “us”). This policy covers the website at stomics.io, the API at api.stomics.io, and the Python and R SDKs that talk to it.

Most of what the repository holds is scientific data that submitters intend to publish. This policy is about the other part: the personal information attached to accounts and to the act of using the service.

Information you give us

Opening an account requires an email address, a name, and a password. You may add your institution and link an ORCID iD. Your name, institution and ORCID iD are shown alongside datasets you publish and comments you post, so treat those fields as public.

Signing in through ORCID sends us your ORCID iD together with the name and email address your ORCID record makes visible to trusted parties. Your ORCID password is never disclosed to us.

Passwords are stored as salted hashes and cannot be read back by anyone at the Institute. API keys are stored the same way; the full key is displayed once, when you create it, and never again.

If you contact support, we keep the correspondence and whatever you put in it.

Information the service generates

When you submit a dataset we store the metadata you enter and the files you upload, along with a record of who did what: who created the dataset, who edited it, who requested access to embargoed data, and what a curator decided. That history is part of the provenance of a scientific record and stays attached to it.

Our servers log requests. A log entry contains an IP address, a timestamp, the path requested, the response status, and the browser or client that made the request. We read logs to diagnose faults, plan capacity, and investigate abuse of the service. Logs are kept for 90 days.

Downloads and dataset views are counted in aggregate and reported back to submitters as usage figures for their own datasets. Those figures do not identify individual users.

Cookies, analytics and local storage

The site loads Google Analytics, which sets cookies in your browser and reports aggregate traffic patterns to us. We use it to see which parts of the repository get used. You can block it with browser settings or an extension without losing any function of the site. Google’s handling of that data is described in the Google Privacy Policy.

Signing in does not set a cookie. Your session tokens are held in your browser’s local storage and sent to the API as an authorization header. Clearing site data for stomics.io signs you out.

We run no advertising and no third-party tracking beyond the analytics described above.

Who else handles your information

  • Amazon Web Services hosts the application, the database and uploaded files in the US East (N. Virginia) region.
  • Amazon SES delivers our outbound email, including account verification, password resets and curation notices.
  • ORCID receives an authentication request if you choose to sign in or link your iD.
  • DOI registries and indexing services receive dataset metadata, including author names and affiliations, for any dataset issued a DOI. Once a DOI record is published it is redistributed widely and is outside our control.

We do not sell personal information and we do not disclose it for advertising. We will disclose information where the law requires it, and where it is needed to protect the service or its users from harm. If the repository is ever transferred to another operator, account records transfer with it, and we will give notice before that happens.

Legal basis for processing

For users in the United Kingdom and the European Economic Area, we process account information to perform our agreement with you, and we process logs and analytics under our legitimate interest in keeping a public research service running and secure. Optional email notifications rest on your consent, which you can withdraw at any time from your account settings.

Keeping and deleting information

Account information is kept while your account is open. Close it and we remove your profile, your saved searches and your API keys.

Released datasets are a separate matter. An accession such as STD0001 is meant to be citable indefinitely, and papers depend on it resolving to the same record with the same authorship. Datasets that have been released stay published under the names given at submission, whether or not the submitting account still exists. Drafts that were never released are deleted with the account.

If you need a released record corrected or withdrawn, write to us and we will work out the right route, which for a cited dataset usually means an annotated withdrawal rather than removal.

Your rights

You can see and change most of what we hold from your account page. For anything else, write to support@stomics.io and we will respond within 30 days.

Depending on where you live, you may have the right to obtain a copy of your personal information, correct it, have it deleted, restrict or object to how we use it, and receive it in a portable format. UK and EEA users may also complain to their national data protection authority. California residents may request the categories and specific pieces of personal information we hold, ask for deletion or correction, and will not be treated differently for doing so; we do not sell or share personal information as those terms are used in California law.

Where your information goes

The service runs in the United States. Using it from elsewhere means your information is transferred to and stored in the United States, under contractual protections with our hosting provider.

Security

Traffic to the site and the API is encrypted in transit. Passwords and API keys are hashed. Uploads go directly to storage over short-lived presigned URLs, and the credentials the application uses are scoped to the buckets it needs. No system is immune, and we do not claim otherwise.

To report a vulnerability, email it-serviceaccount@allmaninstitute.org rather than opening a public issue.

Children

The repository is built for researchers and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has created an account, tell us and we will remove it.

Changes

We update this policy as the service changes, and the date at the top shows when it last moved. If a change materially affects how we handle your information, we will say so by email or by a notice on the site before it takes effect.

Contact

The Allman Institute for Personalized Medicine
support@stomics.io

See also our Terms of Service.