Effective 10 September 2026
This Privacy Policy explains how ATHEX (“we”, “us”, or “the Service”), operated at athex.org, collects, uses, and discloses information in connection with your access to and use of the Service. By accessing or using the Service you acknowledge that you have read and understood this Policy. If you do not agree with it, do not access or use the Service.
This Policy applies to all access to and use of the Service and to any information processed through it, and it applies alongside our Terms of Service. Capitalised terms not defined here have the meaning given in the Terms of Service.
By using the Service you consent to the collection, use, storage, disclosure, and other processing of information as described in this Policy and as otherwise permitted by applicable law. Where consent is a legal basis for a particular processing activity, your continued use of the Service after this Policy is made available constitutes that consent to the fullest extent permitted by law. If you do not consent, your only remedy is to stop using the Service.
We may collect and process the following categories of information, now or in the future, to the extent applicable to the Service:
Information you provide: any and all content that you upload, submit, post, transmit, generate, or otherwise make available through the Service (collectively, “User Content”), in any form and of any media type, including without limitation records, handles, text, images, audio, video, documents, archives, and other files, together with any metadata embedded in or associated with that content, whether you store it in your vault, send it as a transfer, or submit it through any other feature of the Service.
Technical and usage information: including but not limited to Internet Protocol (IP) address, device and browser characteristics, operating system, language, referring and exit pages, timestamps, request and diagnostic logs, approximate location inferred from network information, rate-limiting and abuse signals, and other data automatically generated when software or a device interacts with the Service.
Information from cookies and similar technologies: including session identifiers and locally stored preferences necessary or convenient for operating the Service, as described in “Cookies and Local Storage” below.
Much of your User Content is encrypted in your browser under keys derived from your passcode, which we never receive. Such content, and the key material that protects it, are held by us only as ciphertext or as wrapped values we cannot open. Encryption conceals the contents of that User Content from us; it does not conceal its existence, and we process the associated metadata the Service needs in order to operate — including sizes, media types, record and transfer identifiers, timestamps, and the operator accounts involved. We may also process the technical and usage information described above, and we keep access and security logs.
Any other information you choose to provide, and any information we are permitted or required to collect under applicable law.
We may use information for any lawful purpose connected with operating and improving the Service, including to: provide, maintain, secure, and administer the Service; authenticate users and enforce access controls; prevent, detect, and respond to fraud, abuse, security incidents, and violations of our terms; monitor, analyse, and improve performance, reliability, and features; develop new products, services, and features; communicate with you about the Service; comply with legal obligations and enforce our agreements; and for any additional purpose disclosed to you at the time of collection or to which you consent.
We reserve the right to use information for purposes not presently anticipated. Where a new purpose is not compatible with the purpose for which the information was collected, we will provide notice or obtain consent to the extent required by applicable law. To the maximum extent permitted by law, your continued use of the Service after any update to this Policy constitutes acceptance of the then-current Policy.
Where applicable law (such as the EU or UK General Data Protection Regulation) requires a legal basis for processing personal data, we rely, as appropriate, on: your consent; the necessity of processing to perform a contract with you or to take steps at your request; compliance with a legal obligation; the protection of vital interests; and our legitimate interests in operating, securing, analysing, and improving the Service, except where overridden by your interests or fundamental rights. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out.
We do not sell your personal information for money. We may, however, disclose information: to service providers, vendors, and hosting, infrastructure, analytics, payment, and security partners who process it on our behalf and under obligations of confidentiality; to comply with applicable law, regulation, legal process, or an enforceable governmental or law enforcement request; to establish, exercise, or defend legal claims; to enforce our terms or protect the rights, property, or safety of us, our users, or others, including to prevent fraud or abuse; in connection with, or during negotiations of, any merger, financing, acquisition, reorganisation, bankruptcy, receivership, or sale of all or part of our assets, in which information may be transferred or disclosed as a business asset; with your direction or consent; and in aggregated or de-identified form that cannot reasonably be used to identify you.
Some data-protection laws define “sale” or “sharing” broadly. To the extent any disclosure described above is deemed a sale or sharing under such a law, we will honour applicable opt-out rights where required; see “Your Rights and Choices”.
We retain information for as long as necessary to fulfil the purposes described in this Policy, including for the duration of your use of the Service and thereafter as needed to comply with legal obligations, resolve disputes, enforce agreements, and maintain security and continuity. Retention periods vary by the type of information and the purpose for which it is processed. Some information is designed to be deleted automatically after a defined period; other information may persist in backups or logs for a commercially reasonable time before being overwritten or purged.
We take reasonable technical and organisational measures intended to protect information. However, no method of transmission over the Internet and no method of electronic storage is perfectly secure. We cannot and do not guarantee the absolute security of any information, and you provide it at your own risk. You are responsible for maintaining the confidentiality of any credentials, passphrases, keys, or recovery material associated with your use of the Service, and for all activity that occurs under them. Where the Service is designed so that we do not hold the material needed to decrypt your content, we may be permanently unable to recover that content if you lose that material.
If we become aware of a security incident affecting your personal information, we will notify you and any regulator to the extent and within the time required by applicable law, using the contact details we hold for you or, where that is not practicable, by a notice on the Service.
The Service may be operated from, and information may be processed and stored in, countries other than the one in which you reside, including the United States, whose data-protection laws may differ from those of your jurisdiction. Where required by applicable law, we take steps, such as relying on recognised transfer mechanisms, to provide an appropriate level of protection for such transfers. By using the Service you consent to this transfer, processing, and storage to the extent permitted by law.
The Service may reference, integrate with, or link to third-party websites, platforms, or services that we do not control, including platforms whose publicly available information may be displayed through the Service. We are not responsible for the privacy practices or content of any third party, and this Policy does not apply to them. We encourage you to review the privacy policies of any third party you interact with. Your dealings with any third party are solely between you and that third party.
The Service is not directed to children, and we do not knowingly collect personal information from anyone under the age of 13, or under the minimum age required to consent to the processing of personal data in your jurisdiction, whichever is higher. If you believe a child has provided us information, contact us at [email protected] and we will take reasonable steps to delete it.
Depending on your jurisdiction, you may have rights regarding your personal information, which may include the rights to access, correct, delete, port, or restrict certain processing, to object to processing, to withdraw consent, to opt out of the sale or sharing of personal information or of certain targeted advertising, and not to receive discriminatory treatment for exercising a right. Residents of the European Economic Area, the United Kingdom, and jurisdictions such as California may have additional rights under laws including the GDPR and the CCPA as amended by the CPRA.
To exercise any right, contact us at [email protected]. We will respond as required by applicable law, and we may need to verify your identity before acting on a request. You may also use an authorised agent where the law permits. If you are in the EEA or UK, you have the right to lodge a complaint with your local supervisory authority.
The Service may use cookies, local storage, session storage, and similar technologies to operate, to keep you signed in, to remember preferences, to secure the Service, and to understand usage. Some of these are strictly necessary for the Service to function. You may control these technologies through your browser or device settings; disabling them may impair or prevent parts of the Service. Because there is no common industry standard for “Do Not Track” signals, the Service may not respond to them.
We may send you administrative, transactional, security, and service-related communications, which are part of the Service and which you cannot opt out of while you continue to use it. Where we send promotional communications, we do so only as permitted by applicable law, and you may opt out at any time by following the unsubscribe instructions in the message or by contacting us at [email protected]. Opting out of promotional messages does not stop administrative or security communications.
We may use automated means, including rate limiting, abuse scoring, and automated classification or moderation, to secure and operate the Service. These may result in a request being slowed or refused, or in content or access being restricted. We do not use automated processing to make decisions producing legal effects concerning you, or similarly significantly affecting you, except as permitted by applicable law; where such a decision is made and the law so requires, you may request human review by contacting us at [email protected].
We may update this Policy at any time. When we do, we will revise the effective date above and, where appropriate, provide additional notice. Changes are effective when posted unless stated otherwise. Your continued use of the Service after changes take effect constitutes acceptance of the revised Policy to the fullest extent permitted by law. If you do not agree to a change, stop using the Service.
Questions, concerns, or requests regarding this Policy or your information may be sent to [email protected]. If a data controller or representative must be identified for your jurisdiction, the operator of the Service acts in that capacity and may be reached at the same address.
If any provision of this Policy is held invalid or unenforceable, it will be limited or severed to the minimum extent necessary and the remainder will stay in full force. Where applicable law grants you rights that this Policy does not, that law prevails to the extent of the conflict.