Skip to main content

Legal · Last updated 6 August 2026

Privacy
Policy.

What we store, where it lives, who else touches it, and how to get it all deleted. Specific rather than exhaustive, because a policy you cannot read protects nobody.

The short version

  • We store your account details and whatever you put into Atheneum. Nothing more.
  • We do not sell your data, and we do not use your content to train AI models.
  • There are no advertising or analytics trackers on the site.
  • Your AI chat history is encrypted before it is written to our database.
  • You can delete your account — and everything in it — yourself, immediately, from Settings.

What we hold

Every category, and how long.

DataWhyRetention
Email, display name, password hashTo create and secure your accountUntil you delete your account
Google account id (if you use Google sign-in)To recognise you on return visitsUntil you delete your account
Notebooks, files, notes, tasks, calendar events, flashcardsThey are the product — this is your workUntil you delete them or your account
AI chat conversationsSo you can return to a conversationPinned: until you delete. Unpinned: 30 days after last use
Points, streaks, badges, module usageTo run the progress featuresUntil you delete your account
Billing plan, Paddle customer idTo apply the right plan limitsUntil deletion; Paddle keeps transaction records for tax law
Error reports (message, stack trace, numeric user id)To find and fix crashes90 days
Rate-limit counters keyed to IP or accountTo stop abuse and runaway costsMinutes to hours, then discarded

We do not collect analytics about how you browse, we do not build advertising profiles, and there are no third-party trackers on the site. The only cookie we set is the one that keeps you signed in.

Who we are

Atheneum is the data controller for the information described here. Contact us about anything in this policy at privacy@atheneum.app.

How AI features handle your content

When you use Athena, summaries, quizzes, or flashcards, the relevant text is sent to Cloudflare Workers AI, which runs the model inside Cloudflare’s network. If those models are unavailable we may fall back to the Anthropic API.

Neither provider is permitted to train on data sent through these APIs, and we do not train models on your content either.

Chat conversations are encrypted with a key derived per user before they are written to our database, so the stored form is not readable without that key.

Who else touches your data

We keep this list short on purpose. Each of these is a processor acting on our instructions:

  • Cloudflare — hosting, database, file storage, and AI inference. Effectively all your data lives here.
  • Paddle — payments, as merchant of record. They receive your billing details directly; we never see your card number.
  • Google — only if you choose Google sign-in or connect Google Calendar. Calendar tokens are encrypted before storage and you can disconnect at any time.
  • Semantic Scholar — receives your search terms when you search for papers. It does not receive your identity.
  • Our email provider — receives your address to send verification and password-reset messages. We do not send marketing email.

We do not sell or rent personal data, and we do not share it for anyone else’s marketing.

Where your data is

Atheneum runs on Cloudflare’s global network, so data may be processed outside your country, including in the United States. Transfers out of the UK/EEA rely on Standard Contractual Clauses with our processors.

Your rights

If you are in the UK or EEA, the GDPR gives you the rights below. We extend the same rights to everyone, regardless of where you live.

  • Access and portability — notebooks export to PDF and flashcards to Anki format inside the app; email us for anything else.
  • Erasure — delete your account from Settings. Immediate, not reversible, and you do not need to ask us.
  • Correction — edit your profile in Settings, or email us.
  • Objection and restriction — email us and we will stop the processing you object to, where the service can still run without it.
  • Complaint — you can complain to your data protection authority. In the UK that is the Information Commissioner’s Office.

We respond within 30 days and do not charge.

Security

Passwords are hashed with PBKDF2 and never stored in a readable form. Chat history and Google Calendar tokens are encrypted before storage. Everything travels over HTTPS. Changing your password signs out every other device.

No system is perfectly secure. If a breach affects your data, we will tell you and the relevant authority within 72 hours of becoming aware of it.

Children

Atheneum is not intended for under-16s. We do not knowingly collect their data — if you believe a child has created an account, email us and we will remove it.

Changes to this policy

We will post changes here and update the date at the top. For changes that materially affect how we handle your data, we will email you before they take effect.

One caveat, stated plainly

This policy is written to be specific and honest rather than exhaustive, and it has not been reviewed by a lawyer. Have it professionally reviewed before Atheneum handles institutional accounts or significant revenue.

Questions about your data?

Email privacy@atheneum.app. Deletion you can do yourself, immediately, from Settings.