Security & Privacy Policy

Last Updated: November 14, 2025

Aevum Encyclopedia is committed to protecting your personal information and ensuring the highest standards of data security. This document outlines how we collect, use, safeguard, and share your data, as well as the rights you hold under applicable privacy laws.

1. Introduction

Welcome to the Aevum Encyclopedia Security & Privacy Policy. "Aevum," "we," "us," or "our" refers to Aevum Encyclopedia Inc. This policy applies to all users accessing our platform, mobile applications, APIs, and related services (collectively, the "Service").

We recognize that privacy and security are fundamental rights. Our infrastructure is built with a privacy-by-design and security-by-default approach, complying with GDPR, CCPA/CPRA, and other applicable data protection regulations worldwide.

2. Information We Collect

We collect only the data necessary to provide, maintain, and improve our Service. Categories include:

  • Account Information: Name, email address, password hash, and optional profile details when you create an account.
  • Usage Data: Pages viewed, search queries, time spent on articles, click patterns, and device/browser information.
  • Contributor Data: For editors and reviewers: credentials, submission history, revision logs, and verification documents.
  • Technical Data: IP address, cookies, local storage data, and performance metrics to ensure platform stability.
  • Communications: Messages sent via support tickets, feedback forms, or community forums.

We do not collect sensitive personal data (e.g., racial origin, political opinions, health information, biometrics) unless explicitly provided for specific contributor verification processes.

3. How We Use Your Data

Your information is processed for the following legitimate purposes:

  • Delivering and personalizing the encyclopedia experience
  • Verifying contributor identities and academic credentials
  • Improving AI search accuracy and knowledge graph mappings
  • Preventing fraud, abuse, and ensuring platform security
  • Complying with legal obligations and responding to lawful requests
  • Sending service notifications, security alerts, and optional newsletters (with consent)

Note: We never sell your personal data. Revenue is generated through institutional partnerships, premium research tools, and optional voluntary donations.

4. Security Measures

Aevum Encyclopedia employs enterprise-grade security protocols to protect your data against unauthorized access, alteration, disclosure, or destruction:

  • Encryption: AES-256 at rest and TLS 1.3 in transit for all data communications
  • Authentication: Multi-factor authentication (MFA), hardware security key support, and adaptive session management
  • Infrastructure: ISO 27001 certified cloud providers, isolated environments, and regular penetration testing
  • Access Controls: Role-based access control (RBAC), principle of least privilege, and automated audit logging
  • Incident Response: 24/7 security operations center (SOC) with documented breach notification procedures within 72 hours

5. AI & Algorithmic Transparency

Our AI systems enhance search, content recommendation, and fact-verification. We maintain full transparency regarding their operation:

  • AI-generated insights are clearly labeled and can be toggled off in settings
  • Training data is sourced from publicly available, verified academic and editorial materials
  • We do not use personal data to train public-facing models without explicit opt-in consent
  • Algorithmic decisions affecting user accounts (e.g., moderation, verification status) include human review options and appeal mechanisms

6. Cookies & Tracking Technologies

We use essential cookies to maintain session state and security. Non-essential cookies require explicit consent:

  • Essential: Authentication, CSRF protection, and security tokens
  • Analytics: Aggregated, anonymized usage patterns to improve navigation and content discoverability
  • Preference: Language, theme, and display settings

Third-party tracking pixels are strictly prohibited on our platform. You may manage or revoke cookie preferences at any time via the Privacy Dashboard or your browser settings.

7. Data Sharing & Third Parties

We share data only when necessary and under strict contractual safeguards:

  • Service Providers: Cloud hosting, CDN, email delivery, and security monitoring vendors (all DPA-compliant)
  • Legal Requirements: When compelled by court order, subpoena, or regulatory authority
  • Business Transfers: In the event of merger or acquisition, with continued privacy obligations

We do not share data with advertisers, data brokers, or unaffiliated analytics companies.

8. Your Rights & Controls

Depending on your jurisdiction, you may exercise the following rights:

  • Access, correct, or export your personal data
  • Request deletion or anonymization of your account and associated data
  • Withdraw consent for optional processing (e.g., newsletters, analytics)
  • Opt out of automated decision-making
  • Lodge a complaint with a supervisory authority

All requests are processed within 30 days. You may manage these controls directly in your account Privacy Center or contact our Data Protection Officer.

9. Data Retention & Deletion

We retain personal data only as long as necessary to fulfill the purposes outlined in this policy:

  • Active Accounts: Indefinitely while maintained, with periodic re-verification
  • Deleted Accounts: Personal identifiers removed within 30 days; anonymized usage data may be retained for statistical purposes
  • Contributor Revisions: Public editorial history remains for transparency, but attached personal metadata is stripped upon deletion request
  • Legal Holds: Data may be preserved longer to comply with litigation or regulatory requirements

10. International Data Transfers

Aevum Encyclopedia operates globally. Your data may be processed in countries other than your residence, including the United States, European Union, and Switzerland. All cross-border transfers are governed by:

  • Standard Contractual Clauses (SCCs)
  • GDPR-compliant adequacy decisions
  • Enhanced technical and organizational safeguards

We maintain transparent records of data flow and processing locations available upon request.

11. Policy Updates

We may revise this policy to reflect technological, legal, or operational changes. Material updates will be communicated via email and in-app notification at least 30 days before taking effect. Continued use of the Service after such notice constitutes acceptance of the revised policy.

12. Contact Us

If you have questions, concerns, or wish to exercise your privacy rights, please contact our privacy team:

For urgent security matters or vulnerability disclosures, please use our Responsible Disclosure Portal.