Security & Privacy Policy
Last Updated: November 14, 2025
Aevum Encyclopedia is committed to protecting your personal information and ensuring the highest standards of data security. This document outlines how we collect, use, safeguard, and share your data, as well as the rights you hold under applicable privacy laws.
1. Introduction
Welcome to the Aevum Encyclopedia Security & Privacy Policy. "Aevum," "we," "us," or "our" refers to Aevum Encyclopedia Inc. This policy applies to all users accessing our platform, mobile applications, APIs, and related services (collectively, the "Service").
We recognize that privacy and security are fundamental rights. Our infrastructure is built with a privacy-by-design and security-by-default approach, complying with GDPR, CCPA/CPRA, and other applicable data protection regulations worldwide.
2. Information We Collect
We collect only the data necessary to provide, maintain, and improve our Service. Categories include:
- Account Information: Name, email address, password hash, and optional profile details when you create an account.
- Usage Data: Pages viewed, search queries, time spent on articles, click patterns, and device/browser information.
- Contributor Data: For editors and reviewers: credentials, submission history, revision logs, and verification documents.
- Technical Data: IP address, cookies, local storage data, and performance metrics to ensure platform stability.
- Communications: Messages sent via support tickets, feedback forms, or community forums.
We do not collect sensitive personal data (e.g., racial origin, political opinions, health information, biometrics) unless explicitly provided for specific contributor verification processes.
3. How We Use Your Data
Your information is processed for the following legitimate purposes:
- Delivering and personalizing the encyclopedia experience
- Verifying contributor identities and academic credentials
- Improving AI search accuracy and knowledge graph mappings
- Preventing fraud, abuse, and ensuring platform security
- Complying with legal obligations and responding to lawful requests
- Sending service notifications, security alerts, and optional newsletters (with consent)
Note: We never sell your personal data. Revenue is generated through institutional partnerships, premium research tools, and optional voluntary donations.
4. Security Measures
Aevum Encyclopedia employs enterprise-grade security protocols to protect your data against unauthorized access, alteration, disclosure, or destruction:
- Encryption: AES-256 at rest and TLS 1.3 in transit for all data communications
- Authentication: Multi-factor authentication (MFA), hardware security key support, and adaptive session management
- Infrastructure: ISO 27001 certified cloud providers, isolated environments, and regular penetration testing
- Access Controls: Role-based access control (RBAC), principle of least privilege, and automated audit logging
- Incident Response: 24/7 security operations center (SOC) with documented breach notification procedures within 72 hours
5. AI & Algorithmic Transparency
Our AI systems enhance search, content recommendation, and fact-verification. We maintain full transparency regarding their operation:
- AI-generated insights are clearly labeled and can be toggled off in settings
- Training data is sourced from publicly available, verified academic and editorial materials
- We do not use personal data to train public-facing models without explicit opt-in consent
- Algorithmic decisions affecting user accounts (e.g., moderation, verification status) include human review options and appeal mechanisms
8. Your Rights & Controls
Depending on your jurisdiction, you may exercise the following rights:
- Access, correct, or export your personal data
- Request deletion or anonymization of your account and associated data
- Withdraw consent for optional processing (e.g., newsletters, analytics)
- Opt out of automated decision-making
- Lodge a complaint with a supervisory authority
All requests are processed within 30 days. You may manage these controls directly in your account Privacy Center or contact our Data Protection Officer.
9. Data Retention & Deletion
We retain personal data only as long as necessary to fulfill the purposes outlined in this policy:
- Active Accounts: Indefinitely while maintained, with periodic re-verification
- Deleted Accounts: Personal identifiers removed within 30 days; anonymized usage data may be retained for statistical purposes
- Contributor Revisions: Public editorial history remains for transparency, but attached personal metadata is stripped upon deletion request
- Legal Holds: Data may be preserved longer to comply with litigation or regulatory requirements
10. International Data Transfers
Aevum Encyclopedia operates globally. Your data may be processed in countries other than your residence, including the United States, European Union, and Switzerland. All cross-border transfers are governed by:
- Standard Contractual Clauses (SCCs)
- GDPR-compliant adequacy decisions
- Enhanced technical and organizational safeguards
We maintain transparent records of data flow and processing locations available upon request.
11. Policy Updates
We may revise this policy to reflect technological, legal, or operational changes. Material updates will be communicated via email and in-app notification at least 30 days before taking effect. Continued use of the Service after such notice constitutes acceptance of the revised policy.
12. Contact Us
If you have questions, concerns, or wish to exercise your privacy rights, please contact our privacy team:
- Email: privacy@aevumencyclopedia.com
- Data Protection Officer: dpo@aevumencyclopedia.com
- Postal Address: Aevum Encyclopedia Inc., Data Privacy Department, 100 Knowledge Blvd, Suite 400, San Francisco, CA 94105, USA
For urgent security matters or vulnerability disclosures, please use our Responsible Disclosure Portal.