Usage and privacy
pubcheck policy
pubcheck checks references and figure provenance evidence. The report is evidence for human review. It is not a publication decision.
Acceptable use
Use pubcheck to inspect citations, reference metadata, retraction signals, and figure provenance records.
Do not use pubcheck to:
- Reject a manuscript automatically.
- Claim fabrication or misconduct from a lookup failure.
- Infer that a cited paper supports a manuscript claim.
- Infer that an image is original because provenance evidence is absent.
Lookup requests
Online checks send the identifier, cited URL, or title required by the selected public resolver. Surrounding manuscript text is not sent. Title lookup can disclose part of a reference list. Use offline mode when that disclosure is not acceptable.
Offline mode prevents resolver calls. It also limits what pubcheck can verify unless the required record is available in a local snapshot.
Uploads and figures
Local browser jobs keep source text and uploaded PDF bytes in process memory while the job is available. Extracted figure bytes are inspected in process and are not stored in the report.
pubcheck does not submit an image to an external provider automatically. A reviewer must explicitly open a provider checker and submit the image under that provider's terms.
Stored reports
Durable reports contain redacted citation records, resolver evidence,
figure evidence, counts, warnings, limitations, and source_sha256.
Raw citation text, citation context, and extracted image bytes are omitted.
Reports carry a SHA-256 digest of the report body. Stored reports do not contain decisions, overrides, review queues, submission revisions, or author-response state.
Retention and deletion
Reports remain until deleted explicitly or selected by a configured retention sweep. Deletion removes the report envelope and stored PDF. A receipt remains with the report identifier, digest, counts, time, and service label.
Private deployments
The local server binds to loopback by default. A non-loopback deployment
requires PUBCHECK_ACCESS_KEY and TLS at the reverse proxy.
Operators must restrict access to the report database, backups, logs, and
repository credentials.
Contact
Report public issues at the pubcheck issue tracker. Use the private deployment's contact channel for confidential material.