Privacy policy
Last updated October 6, 2026
Rostrum is software that organizations use to run a conference program: the call for abstracts, peer review, the schedule, speaker files, room signage, the attendee app and the on-site delivery of presentations. This policy says what personal data passes through it, why, who else touches it, how long it is kept, and how to reach us about it. It is written to be read, not skimmed; where a plain word will do, we use it.
1. Two kinds of data, two roles
Data you give us directly. When you create an organizer account, sign in, or write to us through the website, Rostrum decides what is collected and why. For that data we are the controller.
Data an organizer puts into their event. Most of what is in Rostrum — authors, abstracts, reviewers, speakers, attendees, files, on-site technicians — is entered by the organization running the event, for its own purposes. For that data the organization is the controller and Rostrum is its processor: we handle it on the organization’s instructions, under our terms of service, and we do not use it for anything else. If you are a participant in an event and have a question about your data, the organizer is the first place to ask; we will help them answer it.
2. What we collect
Organizer accounts
Name, email address, a password (stored only as a salted hash), the organization you belong to and the roles you hold. When you sign in we record the time, your IP address and a description of your browser, so you and your administrator can see where the account has been used.
Event data entered by organizers
- Authors and co-authors: names, email addresses, affiliations, and the abstracts, papers and posters they submit, with the committee’s reviews and decisions.
- Reviewers: names, email addresses, expertise, declared conflicts of interest, scores and comments.
- Speakers and co-presenters: names, email addresses, biographies, the files they upload and when they were uploaded.
- Attendees: names and email addresses when an organizer imports or invites them, the sign-in codes used to open the attendee app, and any feedback, questions or session ratings they choose to submit there.
- On-site crew: the names and mobile numbers of the audiovisual technicians an organizer adds to an event, their room assignments, and a PIN they choose (stored only as a hash). See the text message program.
- Sponsors and venue contacts, where an organizer records them.
Technical data
Our servers log the IP address, time and path of each request for security and troubleshooting. The portal keeps your sign-in tokens and language preference in your browser’s local storage; it sets no advertising or cross-site tracking cookies. The room computers that run the on-site software report their status (online, which file is loaded, which display is showing) so organizers can see that each room is ready; they do not report anything about the people in the room.
Every change made in Rostrum — who changed what, when, from which address — is written to an audit log. Organizers can read the log for their own events.
3. Why we use it
- To run the service: route an abstract to its reviewers, build the schedule, deliver a speaker’s file to the right room, show the right session on the right screen.
- To send the email the program needs: invitations, reminders, decisions, sign-in links. These go only to people an organizer has added to an event, about that event.
- To text an event’s technicians when a room needs them, as described on the text message program page.
- To keep the service secure: detect misuse, investigate incidents, keep the audit trail.
- To support you when you write to us.
- To meet legal obligations.
We do not sell personal data, we do not use it for advertising, and we do not combine it with data from other sources to build profiles.
4. AI features
Organizers can turn on assistants that triage abstracts, suggest a schedule, or draft text. These send the relevant event content — an abstract, a session list, a draft — to Anthropic, which returns a result and does not use the content to train its models. Every suggestion is shown to a person before anything happens, and the deterministic parts of the program (who reviews what, when a session runs) are decided by rules the organizer set, not by the model. Nothing attendee-facing is generated by AI, and no author’s identity is sent to a model during blind review.
5. Who else handles the data
We run on a small number of service providers, each under a contract that limits what they may do with the data. They are:
| Provider | What for | Where |
|---|---|---|
| Railway | Application hosting, PostgreSQL database and Redis queue | United States |
| Vercel | Web hosting and content delivery for the portal and these pages | United States (global edge network) |
| Cloudflare R2 | Storage of uploaded files (presentations, posters, papers, imports) and encrypted database backups | United States |
| Twilio SendGrid | Transactional email (invitations, reminders, sign-in links, decisions) | United States |
| Twilio | Text messages to on-site event technicians (see the SMS program page) | United States |
| Anthropic | AI features for organizers (abstract triage, scheduling suggestions, drafting help). Inputs are not used to train models. | United States |
| Sentry | Error monitoring. Error reports are scrubbed of personal data before they leave the service. | United States |
| Google Fonts | Typefaces for the public pages (the browser requests the font files directly) | United States |
| Microsoft Office Online viewer | Preview of Office documents inside the portal, when an organizer opens one | United States |
Beyond these, personal data leaves Rostrum only when the organizer exports it, when the law requires us to disclose it, or, in a sale or merger of the business, to a successor bound by this policy. We will tell affected organizers before any such transfer.
6. Where it is stored
The service is hosted in the United States. If you use Rostrum from elsewhere, your data is transferred to and processed there. For organizers in the European Economic Area, the United Kingdom or Switzerland, we offer a data processing agreement incorporating the standard contractual clauses; write to support@gorostrum.com.
7. How long we keep it
Personal data is kept no longer than its purpose needs. The schedule is enforced by a nightly job and recorded in the audit log:
| Data | Kept for |
|---|---|
| Organizer accounts and profiles | Life of the account; removed or anonymized on request |
| Program content (abstracts, presentations, posters, papers, reviews, feedback) | Life of the organizer’s event program; attribution anonymized on an erasure request |
| Uploaded files | Life of the content; deleted with their records |
| Import spreadsheets and import logs | 90 days |
| Email bodies | 30 days; email delivery records 1 year |
| Sign-in sessions and tokens | 30 days after they expire or are revoked |
| On-site crew mobile numbers and PINs | 7 days after the event’s last day, then cleared automatically |
| Audit logs (who changed what, with IP address) | 2 years |
| Erasure records (a hash of the email, who requested it, when) | Kept as evidence that the request was honored |
| Database backups | Nightly, encrypted, rotated; a deleted record leaves the backups as they rotate |
8. How we protect it
Data is encrypted in transit and at rest. Passwords are hashed; PINs are hashed; sign-in tokens are short-lived and tied to a session you can revoke. Access inside Rostrum is governed by roles with the least permission needed for each job, and a reviewer under blind review never sees an author’s identity. File uploads are scanned for type and size before they are accepted. Backups are encrypted and restores are rehearsed. We log and review administrative access. No system is perfectly secure; if we learn of a breach affecting your data we will tell the affected organizers without undue delay and work with them on notifying the people concerned.
9. Your rights
Depending on where you live you may have the right to see the personal data we hold about you, correct it, have it deleted, receive a copy, object to or restrict how it is used, and complain to a supervisory authority. We honor these requests for everyone, wherever they are.
If you have an organizer account, write to support@gorostrum.com from the address on the account. Postal requests go to 1946 Brights View Ln., Morristown, TN 37814, USA.
If you are a participant in an event (author, reviewer, speaker, attendee, technician), ask the organization that runs the event; it controls that data and Rostrum gives it the tools to correct, export and erase it. If you cannot reach the organizer, write to us and we will help.
Erasure removes your identity from the record and anonymizes your contributions; a short record that the request was made and honored is kept as evidence. We respond within thirty days.
10. Cookies and local storage
The portal stores your sign-in tokens and your chosen language in your browser’s local storage so you stay signed in and the pages come up in your language. The public pages set nothing. We do not use advertising cookies, analytics trackers or social media pixels. Our error monitoring (Sentry) receives a report when something breaks, with personal data scrubbed before it is sent.
11. Children
Rostrum is a tool for organizations and the professionals who take part in their events. It is not directed at children, and we do not knowingly collect data from anyone under sixteen. If you believe we have, write to us and we will delete it.
12. Changes to this policy
When this policy changes, the date at the top changes with it, and organizers with an account are told by email before a material change takes effect. Earlier versions are available on request.
13. Contact
Rostrum LLC — support@gorostrum.com — 1946 Brights View Ln., Morristown, TN 37814, USA.