Privacy Policy
Last updated 10 October 2026
AxiOstra is a free, non-commercial science education site run by one person. This policy explains what the site keeps about you, where it is kept, who else handles it, and how you can remove it. There is no advertising on the site, no analytics and no tracking script.
1. Who runs the site
AxiOstra ("the site", "we") is run by an individual, referred to here as the operator. Where data protection law such as the EU or UK General Data Protection Regulation applies, the operator is the controller of the personal data described below.
For any question about this policy, or any request about your data, write to [email protected].
2. Using the site without an account
You can read the home page, the forum and the sample models in each field without an account, and we do not ask who you are. Your browser still has to send requests to our server, so the request records described in section 5 apply. To open the other models, or to post in the forum, you need an account.
3. Information you give us
- Account details: your email address, the nickname you choose, and your password. The password is never stored as you typed it. We keep only a salted hash (PBKDF2 with SHA-256), from which the password cannot be read back. Each account is also given a user number in the order of registration.
- Email verification: when you register, change your email address or delete your account, we send a 6-digit code. We store only a hash of the code. It is valid for 10 minutes and for at most 5 attempts. If you start registering but never finish, the email address and the hashed code are kept in a pending record, which is cleared automatically about a day after the code has expired.
- Optional profile details: an avatar image, age, gender, region, education and a short verification note. You can leave every one of them empty, and you can remove them later.
- Forum content: the posts and articles you publish, your comments, the images and files you upload, your likes, bookmarks and reposts, and any draft you save to the cloud while writing.
- Email you send us: if you write to [email protected], we keep your message so that we can answer it.
4. What other people can see
Posts and comments in the forum are public. Anyone can read them, including visitors who are not signed in. Next to each post and comment, other people see your nickname, your avatar, your user number, your verification note, and a badge if you have been verified or are an administrator. They also see how many likes, bookmarks and reposts a post has.
Your email address, age, gender, region and education are not shown to other users. They appear only on your own profile page. The operator can see them in the database, and uses them only to run the site.
5. Information collected automatically
The site runs no analytics, advertising or tracking scripts. The following records are a normal part of running a website.
- Request records: every request passes through Cloudflare and then reaches our server. Both record the IP address, the time, the page requested and the browser's User-Agent string. We use these records only to keep the site secure, stop abuse and find faults. They are not used to build a profile of you, and they are deleted by routine log rotation.
- Rate limits: to slow down password guessing and email abuse, we count sign-in attempts against a hash of the email address for 15 minutes, and we count how many codes have been sent to an address in the last hour.
- We do not record on the server which models you open or how long you stay on them.
6. Cookies and browser storage
The site keeps a few small items in your browser. You can review your choice at any time with "Cookie settings" at the bottom of every page.
- axiom_session (cookie, necessary): keeps you signed in for up to 7 days. It is HttpOnly, marked Secure so that it is sent only over HTTPS, and marked SameSite=Lax. Our server stores only a hash of it. Signing out deletes it.
- The language is part of the address: English pages have no prefix and Chinese pages start with /zh, so no cookie is needed to remember it. An old axiom_locale cookie, if your browser still has one, is deleted on your next visit.
- axiom-consent (local storage, necessary): remembers your answer to the cookie banner, so that we do not ask again on every page.
- axiom-chunk-reload (session storage, necessary): a short-lived marker that stops the page from reloading in a loop after the site has been updated. It disappears when you close the tab.
- Forum drafts (local storage, necessary for the editor): while you write a post or an article, the editor keeps a copy in your browser, so that a closed tab does not lose your work. The copy is removed when you publish.
- axiom-theme, axiom-keys and model progress (local storage, preferences): your light or dark theme, the keys you chose in Settings for moving around the 3D labs, and which models you have completed. These are written only if you allow preference storage. If you choose "Reject all", the site also removes the ones already saved.
7. Why we use your information
Where the GDPR applies, the legal basis for each use is given in brackets.
- To create your account, sign you in and keep your account secure (performance of our agreement with you).
- To send the verification and confirmation codes you ask for (performance of our agreement with you).
- To publish what you choose to publish in the forum, under your nickname (performance of our agreement with you).
- To keep the site running, stop abuse and find faults (our legitimate interest in a working, safe site, which we consider proportionate for a small non-commercial service).
- To keep your optional profile details and your preferences (your consent, which you can withdraw by removing the details or changing your cookie settings).
- To answer your email, and to meet legal obligations where they apply.
8. Who else handles your information
We do not sell, rent or trade personal data, and we do not share it for advertising. The following services process data for us, only to provide the parts of the site described here.
- Cloudflare, Inc.: DNS, the network every request passes through, and encryption in transit. Cloudflare also receives mail sent to [email protected] and forwards it.
- RackNerd LLC: the server in Dallas, Texas, United States, on which the site and its database run. Your account, your profile and everything you upload are stored there.
- Resend, Inc.: sends our emails, such as verification codes and the automatic reply to mail sent to the feedback address. Resend delivers mail through Amazon Web Services.
- Microsoft (Outlook.com): hosts the operator's mailbox, to which mail sent to the feedback address is forwarded.
- We may disclose information if the law requires it, or where it is necessary to protect the safety of users or the public.
- The share menu in the forum and the references on model pages link to other websites. The site does not load anything from those websites. Once you follow such a link, that website's own privacy policy applies.
9. Where your information is stored
The server and the database are in the United States. Cloudflare and Resend operate worldwide, so a request or an email may be handled in another country on its way. If you live outside the United States, this means your data is transferred there. These providers protect such transfers under their own published terms.
10. How long we keep it
- Your account and profile: until you delete your account. The user number is then kept on its own, with no details attached to it, so that it is never given to another account.
- Posts and articles: until you delete them or your account. Deleting a post also deletes the images in it, and the comments and reactions that other people left on it.
- Comments: at present, a single comment cannot be deleted on its own. A comment is removed when the post it belongs to is deleted, or when you delete your account. If you need one removed sooner, write to us.
- Files you attach, and images you uploaded but did not publish: until you delete your account.
- Cloud drafts: one for each kind of writing. Each save replaces the previous one, and it is deleted when you publish.
- Sign-in sessions: 7 days, or until you sign out.
- Verification codes: 10 minutes. Unfinished registrations: cleared about a day after the code has expired.
- Request records: until routine log rotation deletes them.
- Email you send us: as long as we need it to answer you and follow up.
- Database copies: before maintenance work, the operator sometimes makes a copy of the database. Such a copy is kept privately and deleted once the work no longer needs it. Until then, it can still contain an account that has since been deleted.
11. Deleting your account
You can delete your account from your profile page. To make sure the request really comes from you, we first send a code to your email address. Once you enter it, we permanently delete your account, your profile and avatar, your posts and articles (with the comments and reactions on them), your comments, your likes, bookmarks and reposts, your uploaded images and files, your drafts and your sessions. This cannot be undone. The account number (UID) is the one thing that stays: it remains on its own, with no name, email address, password or any other detail attached to it, so that the number is never given to another account.
Items kept in your browser, such as the theme or a local draft, stay on your device. You can remove them by clearing this site's data in your browser.
12. Security
Passwords, session tokens and verification codes are stored only as hashes. The site is served over HTTPS, which encrypts the traffic between your browser and the site. Only the operator can reach the server and the database. No system is perfectly secure, but we take reasonable care that suits the information we hold. If a breach affects you, we will tell you as the law requires.
13. Your rights
You can see and correct your account and profile details on your profile page, and change your email address or password there. Depending on where you live, you may also have the right to ask for a copy of your data, to have it deleted, to restrict or object to how it is used, to receive it in a portable form, and to withdraw consent. To use any of these rights, write to [email protected]. We will answer within the time the law where you live requires.
If you are in the European Economic Area or the United Kingdom, you may also complain to your local data protection authority.
14. Children
You need to be at least 14 years old to create an account. If the law where you live sets a higher age for agreeing to online services on your own (for example 16 in some European countries), you need permission from a parent or guardian until you reach that age. We do not knowingly keep accounts for children below these ages. If we learn of one, we will delete it.
15. Changes to this policy
When the site changes how it handles information, we update this policy and the date at the top. If a change matters to you, for example a new service that receives your data, we will also note it on the site before it takes effect.