Privacy Policy
DRAFT — pending legal review
Items marked like [THIS] must be completed before publication.
1. Who we are
[COMPANY LEGAL NAME], business ID [BUSINESS ID], registered at [ADDRESS], Finland ("we", "us"), is the data controller for the Academica service at app.academica.com. Contact for privacy matters: [PRIVACY CONTACT EMAIL].
2. What we collect
- Account data: your email address and authentication data, managed in AWS Cognito. Passwords are never stored or visible to us in plain text.
- Conversation content: the questions you submit and the answers generated, including any patient-context details you type, stored so your history works across sessions and devices.
- Feedback: ratings and comments you leave on answers.
- Technical data: standard server logs (IP address, timestamps, requests) kept for security and operations.
- Local preferences: theme, text size and similar settings are stored only in your browser (localStorage) and never sent to us. We use no advertising or third-party tracking cookies.
3. A note on patient data
Academica is a clinical reference tool. Do not enter information that identifies a patient (names, personal identity codes, contact details). Describe cases in general clinical terms (age, sex, weight, conditions, medications). You are responsible for ensuring anything you type complies with your own professional and legal obligations.
4. Why we process your data (legal bases, GDPR art. 6)
- Providing the service (contract): account, conversation history, answers.
- Improving answer quality and safety (legitimate interest): reviewing feedback and conversations flagged by clinicians.
- Security and abuse prevention (legitimate interest): technical logs.
- Transactional email (contract): sign-up verification and password-reset codes, sent from no-reply@academica.com.
5. Where your data lives and who processes it
All service data is stored in Amazon Web Services (AWS), region eu-north-1 (Stockholm, EU): Cognito (authentication), Aurora PostgreSQL (conversations, feedback), SES (email delivery). Question text is processed by the AI model providers configured for the service [LIST CURRENT MODEL/INFERENCE PROVIDERS AND THEIR REGIONS, e.g. Scaleway (EU)] solely to generate answers. We do not sell personal data and do not use it for advertising.
6. Retention
- Account and conversation data: kept until you delete a conversation or your account.
- Deleting your account (Account → Delete account) permanently removes your login and the conversations tied to it.
- Technical logs: kept up to [LOG RETENTION, e.g. 90 days].
- Backups roll off automatically within [BACKUP WINDOW].
7. Your rights
Under the GDPR you may access, rectify, export or erase your data, restrict or object to processing, and withdraw consent where processing rests on it. Built into the app: conversation export (Markdown/JSON/PDF), conversation deletion, and full account deletion. For anything else, contact [PRIVACY CONTACT EMAIL]. You also have the right to lodge a complaint with the Finnish Data Protection Ombudsman (Tietosuojavaltuutetun toimisto, tietosuoja.fi).
8. Changes
We will post any changes to this policy here and update the date above. Material changes will be communicated in the app or by email.