Privacy Policy
Last updated 18 September 2026
This policy explains what AxiOstra collects, why, and what you can do about it. It describes the site as it actually works: there is no advertising, no analytics and no third-party tracking.
1. Who we are
AxiOstra ("the site") is an independent, non-commercial science education project operated by an individual. For the purposes of the EU General Data Protection Regulation, that individual is the data controller for the personal data described below.
Questions about this policy, or any request relating to your data, can be sent to [email protected].
2. Information you give us
We collect only what the service needs to function.
- Account details — your email address, a display name you choose, and a password. The password is stored only as a salted cryptographic hash; we cannot read it.
- Optional profile details — age, gender, region, education and an avatar image. These are optional, and are shown on your public profile if you provide them.
- Forum content — the posts, comments, images and reactions you publish, together with their timestamps.
- Correspondence — if you write to us, we keep your message so we can reply.
3. Information collected automatically
We do not run analytics, advertising or tracking scripts of any kind. The following is collected as an unavoidable part of serving a website.
- Server request logs — the requesting IP address, the page requested, the time, and the browser User-Agent string. These are used for security, abuse prevention and troubleshooting.
- A session cookie — set when you sign in so that you remain signed in. It is marked HttpOnly and SameSite=Lax, and is removed when you sign out or when it expires.
4. Cookies and local storage
The site stores very little on your device. A consent banner lists the categories and lets you change your choice at any time through "Cookie settings" in the footer.
- Strictly necessary — the session cookie (axiom_session) that keeps you signed in, and a short-lived marker used to recover from a failed page reload. The site cannot function without these.
- Preferences — your theme choice and your completed-lesson progress, held in your browser local storage. If you decline preference storage these are not written, and the site returns to its defaults on each visit.
5. How we use your information
- To create and secure your account, and to sign you in.
- To send verification codes and other transactional email you have asked for.
- To publish the content you choose to publish, and to display your public profile.
- To keep the site working, prevent abuse, and diagnose failures.
- To comply with legal obligations where they apply.
6. Legal bases
Where the GDPR applies, we rely on the following legal bases.
- Performance of a contract — providing the account and forum you signed up for.
- Legitimate interests — protecting the site against abuse and keeping it operational. We have weighed these against your rights and consider them proportionate for a small, non-commercial service.
- Consent — optional profile fields and preference storage. You may withdraw consent at any time; withdrawal does not affect processing that has already taken place.
7. Sharing and third parties
We do not sell, rent or trade personal data, and we do not share it for advertising. A small number of infrastructure providers process data on our behalf.
- Cloudflare, Inc. — DNS, content delivery and security. Requests pass through Cloudflare, which processes IP addresses and request metadata.
- Resend, Inc. and Amazon Web Services (SES) — delivery of transactional email such as verification codes.
- RackNerd LLC — the virtual server on which the site and its database are hosted.
- Cloudflare Email Routing — forwards mail sent to our feedback address to the operator personal mailbox.
- We may also disclose information where we are legally required to, or where it is necessary to protect the rights and safety of users or the public.
8. International transfers
The providers listed above operate globally, so your data may be processed outside your country of residence, including in the United States. Those providers maintain their own safeguards for international transfers under their published terms.
9. How long we keep it
- Account and profile data — for as long as your account exists.
- Content you have published — until you delete it, or until your account is deleted.
- Deleted accounts — removed from the active database promptly, and from routine backups within 30 days.
- Server logs — retained for a limited period for security and troubleshooting, then discarded.
- Email verification codes — short-lived, and invalidated once used or expired.
10. Security
Passwords are stored as salted hashes. Traffic to the site is encrypted in transit. Access to the production database is restricted to the operator. No system is perfectly secure and we cannot guarantee absolute security, but we take reasonable measures appropriate to the sensitivity of the data we hold.
11. Your rights
Depending on where you live, you may have the right to access your personal data, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw consent. You can delete your account from your profile page at any time. For anything else, write to us and we will respond within the period required by applicable law.
If you are in the European Economic Area or the United Kingdom, you also have the right to complain to your national data protection authority.
12. Children
The site is not directed at children. You must be at least 16 years old to create an account, or younger if your country sets a lower digital age of consent and you have permission from a parent or guardian. If we learn that an account belongs to a child who does not meet this requirement, we will close it and delete the associated data.
13. Changes to this policy
If this policy changes in a way that materially affects you, we will note the change on this page and update the date above. Continued use of the site after a change means you accept the revised policy.