Who we are
Atheneum is the data controller for the information described here. Contact us about anything in this policy at privacy@atheneum.app.
✦ Legal · Last updated 6 August 2026
What we store, where it lives, who else touches it, and how to get it all deleted. Specific rather than exhaustive, because a policy you cannot read protects nobody.
✦ What we hold
| Data | Why | Retention |
|---|---|---|
| Email, display name, password hash | To create and secure your account | Until you delete your account |
| Google account id (if you use Google sign-in) | To recognise you on return visits | Until you delete your account |
| Notebooks, files, notes, tasks, calendar events, flashcards | They are the product — this is your work | Until you delete them or your account |
| AI chat conversations | So you can return to a conversation | Pinned: until you delete. Unpinned: 30 days after last use |
| Points, streaks, badges, module usage | To run the progress features | Until you delete your account |
| Billing plan, Paddle customer id | To apply the right plan limits | Until deletion; Paddle keeps transaction records for tax law |
| Error reports (message, stack trace, numeric user id) | To find and fix crashes | 90 days |
| Rate-limit counters keyed to IP or account | To stop abuse and runaway costs | Minutes to hours, then discarded |
We do not collect analytics about how you browse, we do not build advertising profiles, and there are no third-party trackers on the site. The only cookie we set is the one that keeps you signed in.
Atheneum is the data controller for the information described here. Contact us about anything in this policy at privacy@atheneum.app.
When you use Athena, summaries, quizzes, or flashcards, the relevant text is sent to Cloudflare Workers AI, which runs the model inside Cloudflare’s network. If those models are unavailable we may fall back to the Anthropic API.
Neither provider is permitted to train on data sent through these APIs, and we do not train models on your content either.
Chat conversations are encrypted with a key derived per user before they are written to our database, so the stored form is not readable without that key.
We keep this list short on purpose. Each of these is a processor acting on our instructions:
We do not sell or rent personal data, and we do not share it for anyone else’s marketing.
Atheneum runs on Cloudflare’s global network, so data may be processed outside your country, including in the United States. Transfers out of the UK/EEA rely on Standard Contractual Clauses with our processors.
If you are in the UK or EEA, the GDPR gives you the rights below. We extend the same rights to everyone, regardless of where you live.
We respond within 30 days and do not charge.
Passwords are hashed with PBKDF2 and never stored in a readable form. Chat history and Google Calendar tokens are encrypted before storage. Everything travels over HTTPS. Changing your password signs out every other device.
No system is perfectly secure. If a breach affects your data, we will tell you and the relevant authority within 72 hours of becoming aware of it.
Atheneum is not intended for under-16s. We do not knowingly collect their data — if you believe a child has created an account, email us and we will remove it.
We will post changes here and update the date at the top. For changes that materially affect how we handle your data, we will email you before they take effect.
This policy is written to be specific and honest rather than exhaustive, and it has not been reviewed by a lawyer. Have it professionally reviewed before Atheneum handles institutional accounts or significant revenue.
Email privacy@atheneum.app. Deletion you can do yourself, immediately, from Settings.