Google Chrome extension

Privacy policy for Notandia

Last updated: October 1, 2026

Notandia, previously distributed as MDPI Filter, adds configurable publisher watchlists and optional formal post-publication checks. The new interface is implemented in current source but has not yet replaced the public Chrome store version. Most processing occurs locally in Chrome.

Notandia is independent and is not affiliated with, authorized by, or endorsed by MDPI AG, Frontiers Media SA, Crossref, Retraction Watch, NCBI, Google, or any publisher or data provider.

Publisher profiles and local processing

Content scripts inspect page structure, links, citation text, scholarly identifiers, and publisher evidence. Built-in MDPI and Frontiers settings and custom publisher names, domains, DOI prefixes, actions, colors, and confidence policies are stored through Chrome extension storage and processed locally.

These profiles are not sent to the developer, Crossref, NCBI, publishers, or an analytics provider. Custom profiles are validated declarative data and cannot contain scripts or executable selectors.

NCBI metadata lookups

When enabled, the extension sends only validated DOI, PMID, or PMCID values to the NCBI ID Converter over HTTPS. Requests identify the application as notandia, omit browser credentials and referrers, and are deduplicated, batched, and rate-bounded. Disabling NCBI lookups causes zero related requests but may reduce publisher detection from indirect identifiers.

NCBI also receives ordinary network metadata, including the IP address from which the request is made. Identifier lookup is optional and can be disabled in the extension settings.

Optional Crossref integrity lookups

This feature is off by default. When explicitly enabled, normalized DOI identifiers are sent to Crossref to retrieve formal update relationships. The extension may query both a DOI’s direct record and a reverse updates:<doi> relationship for separately registered notices.

Requests omit the page address, article text, citation text, publisher-profile settings, search query, browsing history, cookies, account identifiers, analytics identifiers, and referrers. A scan attempts no more than 50 DOI records and starts no more than four requests per second. Disabling the feature cancels active and queued requests.

Crossref also receives ordinary network metadata, including your IP address. It supplies publication-update metadata; an absent notice is not a guarantee that a paper has no issues.

Issue reports

Report article/context issue opens an editable public GitHub draft. It may prefill the selected category, page origin and path without query or fragment, extension and browser version, enabled publisher-profile IDs, and integrity-check state. It does not automatically include citation text or DOI lists.

Retention and control

Interpretation and commercial use

A publisher watchlist match is a user-selected display rule, not an objective quality score. No known integrity signal is not a guarantee of reliability.

The extension contains no advertising, product analytics, or remote executable code. The developer does not sell, rent, or share page content, browsing history, publication identifiers, or preferences for advertising, profiling, or data-broker purposes.

Security and contact

The extension uses Manifest V3, validated configuration and cross-context messages, bounded inputs and caches, a self-only content security policy, and no shipped runtime npm dependencies. Sensitive vulnerabilities should be reported privately through GitHub Security Advisories. For questions about this policy or the extension, visit the Notandia support page.