Governance & Compliance

Privacy Policy & Data Governance

Effective Date: August 27, 2026·GDPR & EU AI Act (Art. 50) Aligned·Version 2.5

Alcuin’s Archival Privacy Commitment

Alcuin is engineered as an open-access reading room and evidentiary synthesis engine. We do not sell personal data, we do not deploy third-party advertising trackers, and we never use your private research queries, challenge notes, or saved dossiers to train public AI foundation models.

1. Data Controller & Regulatory Scope

This Privacy Policy applies to all services provided via alcuin.site, its related API routes, and archival finding aids. Under the European General Data Protection Regulation (GDPR — Regulation EU 2016/679) and the UK Data Protection Act 2018, the Data Controller is the Alcuin Organization. For questions regarding personal data processing or data protection oversight, contact our Data Protection Office at privacy@alcuin.site.

2. Categories of Information Processed

A. Guest Explorers (Unauthenticated Visitors)

When exploring without an account, your inquiries are executed in-memory against open repository APIs (Wikipedia, OpenAlex, Internet Archive, Tavily). We process truncated, hashed IP addresses solely for rate-limiting, bot mitigation, and DDoS prevention. No behavioral tracking profiles are compiled.

B. Registered Scholars (Authenticated Accounts)

When authenticating via Google OAuth or Magic Link, we securely store your email, display name, avatar URL, subscription tier, and saved research dossiers in encrypted PostgreSQL storage. You retain total ownership and can export or delete your account at any time.

C. Evidentiary Challenges & Archival Contributions

When you submit a citation correction or historiographical challenge, your submitted source URL, explanation, and timestamp are recorded in the public finding aid to foster transparency and collective academic integrity.

EU AI Act (Art. 50) & CA Transparency Acts (AB 2013 / SB 942)

3. Generative AI Transparency & Synthetic Content Marking

Under the mandatory transparency obligations of the European Union Artificial Intelligence Act (Regulation EU 2024/1689, Article 50, in effect August 2026) and California AI transparency legislation:

  • AI Interaction & Synthesis Disclosure: All research articles, summaries, timelines, and claim verifications on Alcuin are generated via Large Language Models (LLMs) instructed to synthesize retrieved primary evidence passages.
  • Machine-Readable Content Marking: Generated research outputs include machine-readable Schema.org ScholarlyArticle metadata, passage provenance IDs, and digital timestamps identifying them as synthetic scholarly aids.
  • Zero Foundation Model Training: We maintain strict zero-data-retention enterprise agreements with AI inference providers (Google Vertex AI / Gemini). Your research inquiries, challenge notes, and private files are never used to train, retrain, or improve public AI models.

4. Legal Bases for Processing (GDPR Article 6)

We process personal data strictly under valid GDPR legal grounds:

  • Contractual Performance (Art. 6(1)(b)): To manage your subscription membership, enforce monthly research limits, and process payments via Stripe.
  • Legitimate Interests (Art. 6(1)(f)): To maintain infrastructure security, mitigate abuse, and protect against automated prompt injection and DDoS attacks.
  • Consent (Art. 6(1)(a)): Where you explicitly choose to authenticate with Google or submit public evidence challenges.

5. Third-Party Subprocessors & International Transfers

We engage only with certified enterprise subprocessors governed by GDPR Standard Contractual Clauses (SCCs) and EU-US Data Privacy Framework principles:

SubprocessorPurposeData Location
Supabase Inc.PostgreSQL Database, Auth & Profile StorageEU (Ireland / AWS eu-west-1)
Stripe Inc.PCI-DSS Level 1 Payment ProcessingGlobal / US (Safe Harbor)
Google Cloud / AI StudioZero-Data-Retention LLM Inference & SynthesisEU / US Enterprise
OpenAlex / Internet ArchiveOpen-Access Manuscript & Citation MetadataOpen Public Repositories

6. Your Rights Under GDPR (Articles 15–22)

Right to Access (Art. 15)

Request an export of all personal data and dossiers linked to your account.

Right to Erasure (Art. 17)

Request instant, permanent deletion of your profile, dossier, and session tokens.

Right to Portability (Art. 20)

Export your complete research library in standard machine-readable JSON / BibTeX.

Right to Object / Restrict (Art. 21)

Object to processing or lodge a complaint with your local EU Data Protection Authority.

To exercise your rights, email privacy@alcuin.site. Requests are completed free of charge within 30 days.

7. Cookies & Local Storage Policy

Alcuin operates on a minimal, zero-tracking storage model. We use only strictly necessary local storage items:

  • alcuin-theme: Stores your Dark / Light reading room preference.
  • alcuin-auth-session / Supabase JWT: Manages secure user authentication.
  • alcuin-dossier-bookmarks: Stores your locally saved research IDs.

Because we deploy zero third-party advertising cookies or cross-site tracking beacons, intrusive cookie consent banners are unnecessary under the ePrivacy Directive.

8. Policy Updates

Any material changes to our privacy practices or regulatory alignments will be posted on this page with an updated version timestamp. Continued use of Alcuin constitutes acknowledgment of the updated policy.