Back to Acadanex

Trust before scale

Privacy Policy

A draft privacy structure for Acadanex data, identity, learning, AI, and infrastructure practices.

DRAFT - REQUIRES PROFESSIONAL LEGAL REVIEWThis page is a technical and policy foundation, not legal advice or legal approval.

Scope and contact placeholders

This draft describes the intended privacy framework for Acadanex, a global learning and discovery platform. The operating legal entity, privacy contact, data protection contact, address, governing jurisdictions, and effective date must be supplied after professional review.

Information we may process

The final policy should explain collection by purpose and should apply data minimization to every category.

  • Account identity, email verification, password and session lifecycle metadata.
  • Educational progress, saved content, favorites, assessment attempts, and subscription state when an account feature is used.
  • AI usage metadata such as feature, provider, model, status, token counts, latency, and cost metadata. Raw prompts and responses are not stored by default.
  • Uploaded files or documents only when a later, explicitly enabled feature requires them.
  • Technical request, health, security, audit, and error data needed to operate and protect the service.
  • Theme preference in browser local storage and an HttpOnly authentication session cookie.
  • Support/contact information and payment records when those services are explicitly activated.

Public access and optional accounts

Public educational browsing remains usable without registration. An account is only required for account-specific persistence, subscriptions, cross-device progress, or other features that genuinely need identity.

Processors and international use

The final policy must identify categories of hosting, PostgreSQL, Redis, object storage, search, email, AI, payment, analytics, and support providers used in each deployment. Provider names and transfer mechanisms must not be invented before deployment decisions are made.

Children, students, and schools

Acadanex may be used by students, including minors. The final product and policy require jurisdiction-specific review of age thresholds, parental or guardian permissions, school contracts, student records, child-directed use, analytics minimization, and AI safeguards. Acadanex does not claim worldwide children or student privacy compliance in this draft.

Retention, deletion, and export

Retention periods must be purpose-based and configurable where legal requirements differ. The technical foundation supports owner-scoped account export, authenticated deletion requests, session revocation, personal-data cleanup for supported user-owned tables, and separate treatment of billing, audit, security, and legal records.

Rights and requests

The final policy should describe access, correction, export, deletion, objection, restriction, portability, and complaint rights where applicable. Requests should use the privacy contact placeholder and must be reviewed for identity, legal exceptions, retention duties, and third-party dependencies.

Security

Acadanex uses hashed passwords and opaque tokens, HttpOnly sessions, CSRF protection, row-level security, least-privilege database roles, redacted structured logs, rate limits, and security events. No security measure guarantees absolute security.