Privacy Policy

Last updated: June 21, 2026

This Privacy Policy explains how the Calyx website at calyxaimemory.com (the “Site”) handles information. Calyx is an education platform that teaches the Calyx association-native database and funnels to a community hosted on Skool. We practice data minimization: we collect as little as possible and store operating state rather than raw content wherever we can.

1. Information we collect

2. How we use information

3. Legal bases (EEA/UK)

Where the GDPR/UK GDPR applies, we rely on: your consent (email updates, optional storage); contract (providing membership you purchase); legitimate interests (site security, abuse prevention, basic analytics); and legal obligations where applicable.

4. Cookies and analytics

The Site aims to be cookie-light, and we do not use third-party advertising trackers. We group cookies and first-party measurement into three categories:

On your first visit a consent banner lets you Accept all, Reject all, or save a per-category choice; nothing beyond the necessary category runs until you choose. You can change or withdraw your choice at any time via the “Cookie preferences” link in the site footer.

5. Service providers we share with

We use a small set of processors, each only for its stated purpose:

6. Data retention

We retain personal data only as long as needed for the purpose collected or as required by law, then delete or anonymize it. We practice data minimization: we store learning state, hashes, and bounded signal summaries rather than raw transcripts, and we cap the growth of learner signals by keeping only your most recent batches within a retention window. The full retention schedule our systems enforce is below.

Data typeWhy we keep itRetentionDeletion
Account & email Provide and secure the account; send updates you opted into. Life of the account, then deleted on request. Account deletion (DELETE /api/auth/delete-account) removes the row.
Auth sessions & magic-link tokens Keep you signed in; one-time sign-in/verification links. Until expiry (transient) or sign-out; tokens are single-use. Expiry + cascade on account deletion.
Learning state Personalize teaching: mastery, spaced-repetition scheduling, course progress. Life of the account (needed to provide the tutor). Cascade on account deletion.
Learner behavioural telemetry First-party signals that improve the course experience (never ad tracking). Default: keep the 20 most-recent batches per learner; older batches are pruned after 90 days. Each learner can choose a stricter ("minimize history") or looser ("keep longer") window in Settings (#692). Scheduled prune (Worker cron, honoring the per-learner retention choice) + cascade on account deletion.
Learner constellations / vectors Edge mirror of a learner’s Calyx constellation for personalized recall. Keep last 20 per learner + 90-day window; ledger hashes kept. Well under the 10M-vectors/index ceiling. keep-last-K + window prune (planStaleLearnerVectorIds → deleteByIds); dormant until learner-constellation writes land.
Integrity ledgers (hash + lineage only) Tamper-evident provenance of answers/mastery. Raw query text is NEVER stored — only its SHA-256 hash. Retained for integrity (already minimized: hashes + lineage, no raw text/PII). Cascade on account deletion (learner ledgers).
Operational events Reliability, security, abuse prevention, and cost monitoring. Window-based operational data; carries no learner secrets and minimal PII. Operational rollup; not learner-identifying.

Raw learner text is stored only if you explicitly opt in; otherwise we keep a hash and lineage only. You can delete your account and all associated learner data at any time, and email subscriptions are kept until you unsubscribe or request deletion.

7. Children

The Site and its features are intended for users 13 years of age or older. We do not knowingly collect personal data from children under 13 (or the higher minimum age in your jurisdiction). If you believe a child has provided us data, contact us and we will delete it. Where parental-consent rules (COPPA, GDPR Art. 8) apply, we handle them accordingly.

8. Your rights

Depending on where you live (e.g. EEA/UK under GDPR, California under CCPA/CPRA), you may have the right to access, correct, delete, export, or restrict processing of your personal data, and to object to certain uses or withdraw consent. We do not sell your personal information. To exercise any right, contact us (Section 11); we will respond within the time required by applicable law.

9. International transfers

Our providers may process data in countries other than yours. Where required, transfers are protected by appropriate safeguards (such as Standard Contractual Clauses).

10. Security

We apply defense-in-depth: strict security headers and a Content-Security-Policy, secret scanning, dependency vulnerability scanning, and credential management through Infisical and Cloudflare Worker secrets. No method is perfectly secure, but we work to protect your data and to fail closed.

11. Contact

Questions or requests about this policy or your data — including data-subject access, correction, and deletion requests (DSAR) — can be sent through our contact form. We respond within the timeframe the applicable law requires. You can also delete your account and data directly from your account settings.

12. Changes

We may update this policy as the product evolves. Material changes will be reflected by the “Last updated” date above and, where appropriate, a notice on the Site.