Privacy Policy
Last updated: August 2026
1. Overview
Axiom (“we”) values your privacy. This policy explains what data we collect, why we collect it, and what we do with it. We comply with the EU General Data Protection Regulation (GDPR).
2. Data We Collect
- Account data: email address, display name (chosen during onboarding), timezone (from your browser).
- Learning data: lesson progress, question answers, XP, streak history, spaced-repetition review schedules.
- Authentication data: OAuth tokens (if you sign in with GitHub), magic-link tokens (if you sign in with email).
- Usage data: pages visited, features used, approximate device type. We do not use third-party tracking pixels.
- Billing data: if you subscribe to Pro, your payment is processed by Stripe. We store your subscription status and plan, but never your card number — Stripe holds that.
3. How We Use Your Data
- To provide the Service: track your progress, schedule reviews, sync across devices.
- To improve the Service: identify which lessons are hard, which questions are confusing.
- To communicate with you: service notices, billing receipts, major policy changes.
- To prevent abuse: rate-limiting, fraud detection.
We do not sell your data. We do not share your data with advertisers.
4. Legal Basis (GDPR)
We process your data under the following legal bases:
- Contract: to provide the Service you signed up for.
- Legitimate interest: to improve the Service and prevent abuse.
- Consent: for any optional analytics (you can opt out).
5. Data Retention
We keep your data for as long as your account is active. If you delete your account, we erase your personal data within 30 days, except where we are legally required to retain it (e.g., billing records for tax purposes).
6. Third-Party Services
- Stripe: payment processing. Card data never touches our servers. See Stripe's Privacy Policy.
- Resend: email delivery for magic-link sign-in. See Resend's Privacy Policy.
- GitHub: if you use GitHub sign-in, we receive your GitHub username and email. See GitHub's Privacy Policy.
- Neon / cloud database: your learning data is stored in a hosted PostgreSQL database.
7. Your Rights (GDPR)
You have the right to: (a) access your data, (b) correct inaccurate data, (c) delete your account and data (“right to erasure”), (d) export your data in a portable format, (e) object to processing, and (f) withdraw consent at any time.
To exercise any of these rights, email us at hello@hubaxiom.com.
8. Security
We use industry-standard measures to protect your data: encrypted connections (TLS), hashed authentication tokens, and a database with restricted access. No method of transmission or storage is 100% secure, but we work to protect your data appropriately.
9. Children's Privacy
The Service is not directed to children under 13. Users between 13 and 18 require parental consent. We do not knowingly collect data from children under 13. If you believe we have, please contact us to delete it.
10. Changes to This Policy
We may update this policy from time to time. We will notify users of material changes via email or in-app notice. Continued use after changes take effect constitutes acceptance.
11. Contact
Questions about your data? Email us at hello@hubaxiom.com.