AXIOMCodex editionDocs ↗
Legal

Privacy Policy

Effective October 9, 2026

This Privacy Policy explains how Axiomancer Labs(“we”, “us”) collects, uses and shares personal data when you visit www.axiomcodex.io, buy an Axiom Codex subscription, or receive our emails. We are responsible for that personal data. Contact us at support@axiomcodex.io.

This policy does not cover personal information that may appear in the licensed datasets themselves. Requests about dataset records are handled under the corrections and takedowns section of the Commercial License.

1. What we collect

When you buy a subscription

Checkout runs on Stripe. Stripe collects your email address, your payment card details, the billing address details it needs to calculate tax, and an optional business tax ID. We never receive your full card number. Stripe creates a customer and subscription record that we can access, and we store your plan, billing interval, license key and the time your license email was sent with that subscription record.

Emails

We send your checkout email address, license key and plan to our email provider, Resend, to deliver your license email and, when your subscription ends, a confirmation email. If you write to us, we keep the correspondence so we can answer you and deliver your packages.

Usage analytics

We use product analytics services (PostHog, Mixpanel and Amplitude, each only when we have configured it) to understand how the site is used. Unless your browser sends Global Privacy Control or Do Not Track (see section 3), they may receive:

After a confirmed purchase, we identify the buyer to these services by the Stripe customer ID and also send a one-way SHA-256 hash of the checkout email address and the plan purchased. We never send them your email address in plain text, your name, address, payment details or license key. The Stripe Checkout Session ID is removed from every URL, referrer and property before any analytics or error-monitoring service receives it.

Session recording in these analytics services is turned off. We will not turn it on without first updating this policy.

Error and performance monitoring

We use Sentry to detect and fix errors in the browser and on our servers. Error reports include the error and stack trace, browser and operating system, the page URL, and a trail of recent events on the page (navigation, clicks recorded as page-element selectors, console messages and the URLs of network requests). About 10% of page loads are also sampled as performance traces. Sentry is configured not to attach your IP address, cookies or the contents of requests you send (such as form data) to these reports. When an error occurs, Sentry may keep a replay of the session around the error with all text and form inputs masked and all images and media blocked. Sentry never records replays of sessions without an error, never for visitors who send Global Privacy Control or Do Not Track, and never on the purchase confirmation page load.

Information our servers receive

Like any website, our hosting provider receives your IP address, browser user agent and the URLs you request, and keeps request logs. We use your IP address in memory to limit how many checkout sessions can be started per minute; our code does not store it.

Embedded services

We do not run user accounts or logins on the site, and we do not collect precise geolocation, or access your camera or microphone.

2. How we use personal data

3. Global Privacy Control and Do Not Track

If your browser sends a Global Privacy Control or Do Not Track signal, we treat it as an opt-out. PostHog, Mixpanel and Amplitude are not loaded at all, no product analytics events are sent, Mux Data tracking and its cookie are turned off, and Sentry runs without session replay. Sentry error reports and, if enabled, the Intercom chat remain available, because we need them to operate the site and answer support requests. Neither is used for advertising.

4. Who receives personal data

We share personal data with service providers that process it for us:

Each provider handles personal data under its own terms and privacy policy. We may also disclose personal data if required by law, to protect our rights or the safety of others, or as part of a merger, acquisition or sale of the business.

We do not sell personal information or share it for cross-context behavioral advertising. The site loads no advertising pixels or advertising trackers.

5. Cookies and browser storage

Our own code stores the following in your browser:

The analytics, video and chat providers described above set their own cookies or local storage when they load. When your browser sends Global Privacy Control or Do Not Track, the analytics services do not load and Mux Data sets no cookie, as described in section 3; if we offer Intercom chat, it still loads and may set its visitor cookie. You can also clear or block cookies and storage in your browser settings.

6. Retention

We keep personal data only as long as we need it for the purposes described in this policy. Billing, tax and accounting records are kept for as long as the law requires. Our service providers retain data according to their own policies and the settings we use with them. Data in your browser’s storage stays until you clear it; session storage clears when you close the tab.

7. Your rights

Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal data, to object to or restrict our processing, to withdraw consent, and to complain to a data protection authority. California residents have the right to know, delete and correct personal information, and to opt out of its sale or sharing, and we will not discriminate against you for using these rights.

To make a request, email support@axiomcodex.io, preferably from the address you used at checkout so we can verify the request. You can manage or cancel your subscription yourself in the Stripe customer portal.

8. International processing

We are based in the United States, and our service providers may process personal data in the United States and other countries where they operate.

9. Security

We protect the site with HTTPS and strict security headers, verify the signatures of payment notifications from Stripe, and limit what we send to third parties as described above. No method of transmission or storage is completely secure.

10. Age

The Service is for businesses and for individuals who are at least 18 years old. We do not knowingly collect personal data from anyone under 18.

11. Changes to this policy

We will post any update on this page with its effective date. For material changes, we will email paying customers at least 30 days before the change takes effect.

12. Contact

Privacy questions and requests: support@axiomcodex.io.