Privacy Policy

Last Updated: February 17, 2026

Welcome to Hermetikon ("we," "our," or "us"). We are committed to protecting your privacy and ensuring you understand how your information is collected, used, and shared.

1. Data Controller

Hermetikon
Denmark
Email: privacy@hermetikon.com

2. Information We Collect

This Privacy Policy explains our data practices in connection with the Hermetikon website and service (the "Service"). By using the Service, you agree to the collection and use of information in accordance with this policy.

  • 2.1. Information You Provide to Us:
    • Account Information: When you sign up, we collect your email address and password (managed via our authentication provider).
    • Financial Information: If you subscribe to a paid plan, our payment processor (Lemon Squeezy) collects your name, billing address, and payment card details. We do not store full credit card numbers on our servers.
    • User Content: We collect the text, prompts, and inputs you submit to our algorithmic search interface, as well as any notes or highlights you create within the reader.
  • 2.2. Information We Collect Automatically:
    • Usage Data: We track your interactions with the Service, including reading history, search queries, citations clicked, and reading progress ("Scholar's Journey").
    • Device & Log Data: We may collect information about your device, browser type, IP address, and operating system for security and debugging purposes.
    • Cookies & Analytics: We use cookies and similar technologies (including Google Analytics) to understand how you interact with our Service and to improve your user experience.

3. How We Use Your Information & Lawful Basis

We process your data for the specific purposes below, based on the following legal grounds (GDPR Art. 6):

  1. Providing the Service: To manage your account, process payments, and provide access to the library and computational tools.
    Lawful Basis: Performance of Contract (Art. 6(1)(b)).
  2. Personalization: To track your reading progress and tailor the experience to your "Scholar's Journey."
    Lawful Basis: Legitimate Interest (Art. 6(1)(f)) in improving user engagement.
  3. Model Training & Improvement: As stated in our Terms and Conditions, we may use anonymized User Content to train and improve our computational models and algorithms.
    Lawful Basis: Legitimate Interest (Art. 6(1)(f)) in developing our products, or Contract where strictly necessary for service features.
  4. Communication: To send you administrative emails (e.g., password resets, billing updates).
    Lawful Basis: Performance of Contract (Art. 6(1)(b)) or Legal Obligation (Art. 6(1)(c)).
  5. Analytics: To analyze trends, usage, and activities in connection with the Service.
    Lawful Basis: Consent (Art. 6(1)(a)) for non-essential cookies.

4. Sharing Your Information

We do not sell your personal data. We share information only with:

  • Service Providers: Third-party vendors who help us operate the Service:
    • Supabase: For database hosting and authentication.
    • Lemon Squeezy: For payment processing.
    • OpenAI / Google: For generating computational responses.
    • Google Analytics: For traffic analysis.
  • Legal Requirements: If required by law, subpoena, or valid legal process, or to protect our rights and safety.

5. International Data Transfers

The Service is operated from Denmark. Information we collect may be transferred to, stored, and processed in the United States or other countries where our service providers (Lemon Squeezy, Supabase, Google) maintain facilities.

Safeguards for Transfers:
Where we transfer personal data outside the EEA to a country not ensuring an adequate level of data protection, we rely on specific safeguards such as the EU-US Data Privacy Framework (for certified providers like Google) or Standard Contractual Clauses (SCCs) approved by the European Commission to ensure your data rights are preserved.

6. Your Data Rights (GDPR)

If you are located in the European Economic Area (EEA), you have strictly defined rights regarding your personal data. You may exercise these rights by contacting us:

  • Right to Access: Receive a copy of your personal data.
  • Right to Rectification: Correct inaccurate or incomplete data.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your active personal data.
    Note: This right does not apply to User Content that has already been anonymized and utilized to train our computational models, as this data is no longer personal data and cannot be isolated or removed from the trained model weights.
  • Right to Restriction: Request we suspend processing of your data.
  • Right to Data Portability: Receive your personal data in a structured format.
    Note: This does not extend to our proprietary computational models or the weights derived from aggregated user interactions.
  • Right to Object: Object to processing based on "legitimate interest".
    Note: We may demonstrate compelling legitimate grounds for processing (e.g., maintaining the integrity of our computational models) that override this objection for previously anonymized data.
  • Withdraw Consent: Where we rely on consent (e.g., cookies), you may withdraw it at any time.
  • Complaint: You have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet) if you believe we have violated your rights.

7. Data Retention

We retain your personal information generally for as long as your account is active.

  • User Content: As per our Terms, upon account deletion, we may anonymize your User Content and retain it indefinitely for model training and analytical purposes.
  • Billing Data: We retain billing records for the period required by accounting and tax laws.

8. Security

We implement reasonable security measures to protect your information. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.

9. Children's Privacy

The Service contains historical texts regarding alchemy and occult practices and is not intended for individuals under the age of 18. We do not knowingly collect personal data from children.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date.

11. Contact Us

If you have any questions about this Privacy Policy, please contact us by email at privacy@hermetikon.com.