Skip to content

Privacy Policy

What we collect, why, and your rights under the GDPR. Effective 21 July 2026.

1. In short

  • We collect the minimum needed to run a wiki with accounts: an email address, a display name, and the content you write.
  • No advertising, no sale of data, no tracking cookies, no profiling.
  • The only cookie is the session cookie that keeps you logged in.
  • You can access, correct, export or delete your data; write to us at any time.

2. Who is responsible

Axiomatic Wiki is a personal, non-commercial project. The data controller for axiomatic.wiki is the site's operator, reachable at hello@axiomatic.wiki. This policy explains how personal data is handled under the EU General Data Protection Regulation (GDPR) and French law.

3. What we collect

Reading the wiki requires no account and no personal data beyond the technical minimum below. If you create an account, we store:

  • Account data: your email address, your display name, your role, and account timestamps. Login is passwordless: the login links and one-time codes we email you are short-lived, single-use, and stored only in hashed form.
  • Content you write: published articles and revisions (public, attributed to your display name), private drafts, collections, favorites, and Typst sources saved in the playground. Private material is visible only to you.
  • Notifications: in-app notices about your submissions and account.
  • API and connected apps: if you use them, personal access tokens and OAuth grants (token identifiers, scopes, timestamps), so you can see and revoke them.
  • Correspondence: emails you send to hello@axiomatic.wiki.

Like any website, our hosting infrastructure also processes technical data (IP address, browser user agent, requested pages) in short-lived server logs, used for security and debugging.

4. Why, and on what legal basis

  • Running the service (accounts, login emails, storing and publishing your contributions, notifications, API access): needed to provide the service you signed up for (GDPR art. 6(1)(b), performance of a contract).
  • Security and moderation (server logs, rate limiting, the review queue, keeping revision history and attribution intact): our legitimate interest in running a safe, trustworthy public wiki (art. 6(1)(f)).
  • Aggregate analytics (see section 6): our legitimate interest in understanding overall site usage (art. 6(1)(f)).
  • Legal obligations (responding to valid requests from authorities): art. 6(1)(c).

We do not use personal data for advertising, and we do not sell or rent it to anyone.

5. Cookies and local storage

We use a single first-party cookie: session, an httpOnly cookie that keeps you logged in. It is strictly necessary for the service, so no consent banner is required, and there are no advertising or third-party tracking cookies at all.

Your browser's local storage holds a few interface preferences (such as your light/dark theme choice). These never leave your device and are not used to identify you.

6. Analytics

We use Vercel Web Analytics to see aggregate usage: page views, countries, browsers. It works without cookies and without cross-site tracking; visitors are counted via a short-lived anonymized hash, and no advertising identifiers are involved.

7. Who processes data for us

We use a small number of service providers (processors) that store or transmit data on our behalf, under data-processing agreements:

  • Vercel (Vercel Inc., USA): hosting, server logs, and the cookieless analytics above.
  • Neon (Neon Inc., USA): the Postgres database where account data and content live.
  • Resend (Resend Inc., USA): sends our transactional emails (login links and codes, email-change confirmations).
  • ImprovMX (forwarding service): routes mail sent to hello@axiomatic.wiki to our inbox.

Published content is public by design and is served to anyone, including search engines. Beyond that, we disclose personal data only if the law requires it.

8. International transfers

Our providers are US companies, so data is transferred outside the EU. These transfers rely on the safeguards the GDPR provides for, such as the EU-US Data Privacy Framework and the European Commission's Standard Contractual Clauses, as applicable to each provider.

9. How long we keep data

  • Account data: for as long as your account exists, then deleted.
  • Login links and codes: minutes; they expire after a short validity window, are single-use, and are stored hashed.
  • Drafts, collections, saved artifacts: until you delete them or your account.
  • Published revisions: indefinitely. The wiki's revision history is a public record licensed under CC BY-SA 4.0, and attribution is part of that license (see section 10).
  • Server logs: short rotation periods set by the hosting provider.

10. Public content and attribution

Anything you publish (articles, revisions, public collections) is public, together with the display name attached to it, and remains so in the revision history. If you delete your account, private data is removed, but published revisions stay available under their license. You can change your display name at any time, including before requesting deletion; ask us if you want past attribution reviewed.

11. Your rights

Under the GDPR you can, at any time:

  • access the data we hold about you, and get a copy (portability);
  • correct it (email and display name are self-service in your account settings);
  • have it erased, including deleting your account;
  • restrict or object to processing based on legitimate interest;
  • complain to a supervisory authority: in France, the CNIL (cnil.fr), or the authority of the country where you live.

To exercise any of these rights, email hello@axiomatic.wiki from the address on your account. We answer within one month. Access tokens and connected apps can be revoked directly from your account page.

12. Security

All traffic is encrypted (HTTPS). Login tokens and codes are stored hashed, sessions use httpOnly cookies, agent credentials are restricted to drafts, and access to production data is limited to the operator. No system is perfectly secure, but the amount of personal data at stake is deliberately kept minimal.

13. Children

The site is a general-audience mathematics reference and is not directed at children. If you are under 15, please do not create an account without parental consent; we delete accounts we learn were created in breach of this rule.

14. Changes to this policy

If this policy changes materially, we will announce it on the site. The effective date at the top always reflects the current version.