Privacy Policy
Effective October 9, 2026
This Privacy Policy explains how Axiomancer Labs(“we”, “us”) collects, uses and shares personal data when you visit www.axiomcodex.io, buy an Axiom Codex subscription, or receive our emails. We are responsible for that personal data. Contact us at support@axiomcodex.io.
This policy does not cover personal information that may appear in the licensed datasets themselves. Requests about dataset records are handled under the corrections and takedowns section of the Commercial License.
1. What we collect
When you buy a subscription
Checkout runs on Stripe. Stripe collects your email address, your payment card details, the billing address details it needs to calculate tax, and an optional business tax ID. We never receive your full card number. Stripe creates a customer and subscription record that we can access, and we store your plan, billing interval, license key and the time your license email was sent with that subscription record.
Emails
We send your checkout email address, license key and plan to our email provider, Resend, to deliver your license email and, when your subscription ends, a confirmation email. If you write to us, we keep the correspondence so we can answer you and deliver your packages.
Usage analytics
We use product analytics services (PostHog, Mixpanel and Amplitude, each only when we have configured it) to understand how the site is used. Unless your browser sends Global Privacy Control or Do Not Track (see section 3), they may receive:
- page views and page leaves, with the page URL, path and referrer, and UTM or other campaign parameters in the URL;
- interactions such as clicks, form submissions and rage clicks (element type, text, classes and selector), and, where Amplitude is enabled, file downloads, dead clicks, web vitals and failed network requests (URL, method and status);
- named product events, such as clicks on dataset cards and calls to action, opening the license dialog, the steps of checkout, viewing a standards crosswalk, and a completed purchase, with the dataset and billing plan involved;
- browser, operating system, device type, screen size and language, and an approximate location that the provider derives from your IP address;
- an anonymous identifier stored in a cookie or in your browser’s local storage.
After a confirmed purchase, we identify the buyer to these services by the Stripe customer ID and also send a one-way SHA-256 hash of the checkout email address and the plan purchased. We never send them your email address in plain text, your name, address, payment details or license key. The Stripe Checkout Session ID is removed from every URL, referrer and property before any analytics or error-monitoring service receives it.
Session recording in these analytics services is turned off. We will not turn it on without first updating this policy.
Error and performance monitoring
We use Sentry to detect and fix errors in the browser and on our servers. Error reports include the error and stack trace, browser and operating system, the page URL, and a trail of recent events on the page (navigation, clicks recorded as page-element selectors, console messages and the URLs of network requests). About 10% of page loads are also sampled as performance traces. Sentry is configured not to attach your IP address, cookies or the contents of requests you send (such as form data) to these reports. When an error occurs, Sentry may keep a replay of the session around the error with all text and form inputs masked and all images and media blocked. Sentry never records replays of sessions without an error, never for visitors who send Global Privacy Control or Do Not Track, and never on the purchase confirmation page load.
Information our servers receive
Like any website, our hosting provider receives your IP address, browser user agent and the URLs you request, and keeps request logs. We use your IP address in memory to limit how many checkout sessions can be started per minute; our code does not store it.
Embedded services
- The home-page video streams from Mux. Mux Data records playback quality metrics (such as startup time, rebuffering and errors), the page URL, browser, operating system and device, and sets an anonymous viewer cookie. Mux Data tracking and its cookie are turned off for visitors who send Global Privacy Control or Do Not Track.
- The
/portalpage loads fonts from Google Fonts and fetches public sample rows from Hugging Face, without sending cookies. These providers receive your IP address and browser user agent. - If we offer live chat, it is provided by Intercom. Intercom receives the pages you view, your browser, operating system, language and approximate location, sets its own visitor cookie, and receives anything you type into a conversation. We do not pass your identity to Intercom.
We do not run user accounts or logins on the site, and we do not collect precise geolocation, or access your camera or microphone.
2. How we use personal data
- To take payment, calculate tax and run your subscription (performance of our contract with you, and our legal obligations for tax and accounting).
- To deliver license keys, packages and service emails, and to provide support (performance of our contract, and our legitimate interest in answering enquiries).
- To measure and improve the site and checkout (our legitimate interest in understanding how the site is used, subject to your opt-out signals described below).
- To keep the site secure, prevent abuse and fix errors (our legitimate interest in operating a secure, working service).
3. Global Privacy Control and Do Not Track
If your browser sends a Global Privacy Control or Do Not Track signal, we treat it as an opt-out. PostHog, Mixpanel and Amplitude are not loaded at all, no product analytics events are sent, Mux Data tracking and its cookie are turned off, and Sentry runs without session replay. Sentry error reports and, if enabled, the Intercom chat remain available, because we need them to operate the site and answer support requests. Neither is used for advertising.
4. Who receives personal data
We share personal data with service providers that process it for us:
- Stripe: payments, tax calculation, subscriptions and the customer portal;
- Resend: license and service email delivery;
- Vercel: website hosting and request logs;
- PostHog, Mixpanel and Amplitude: product analytics, when configured;
- Sentry: error and performance monitoring;
- Mux: home-page video delivery and playback analytics;
- Intercom: support chat, if offered;
- Google Fonts and Hugging Face: fonts and public sample data on
/portal.
Each provider handles personal data under its own terms and privacy policy. We may also disclose personal data if required by law, to protect our rights or the safety of others, or as part of a merger, acquisition or sale of the business.
We do not sell personal information or share it for cross-context behavioral advertising. The site loads no advertising pixels or advertising trackers.
5. Cookies and browser storage
Our own code stores the following in your browser:
axc_license_purchased:entries in local storage, on the purchase confirmation page, so a purchase is counted only once;axc_checkout_source_dataset_slugin session storage, to remember which dataset card started a checkout (cleared when the tab closes);axc-theme,axc.catalog.tray.v1andaxc-favoritesin local storage on/portal, for your theme, catalog selection and saved families.
The analytics, video and chat providers described above set their own cookies or local storage when they load. When your browser sends Global Privacy Control or Do Not Track, the analytics services do not load and Mux Data sets no cookie, as described in section 3; if we offer Intercom chat, it still loads and may set its visitor cookie. You can also clear or block cookies and storage in your browser settings.
6. Retention
We keep personal data only as long as we need it for the purposes described in this policy. Billing, tax and accounting records are kept for as long as the law requires. Our service providers retain data according to their own policies and the settings we use with them. Data in your browser’s storage stays until you clear it; session storage clears when you close the tab.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal data, to object to or restrict our processing, to withdraw consent, and to complain to a data protection authority. California residents have the right to know, delete and correct personal information, and to opt out of its sale or sharing, and we will not discriminate against you for using these rights.
To make a request, email support@axiomcodex.io, preferably from the address you used at checkout so we can verify the request. You can manage or cancel your subscription yourself in the Stripe customer portal.
8. International processing
We are based in the United States, and our service providers may process personal data in the United States and other countries where they operate.
9. Security
We protect the site with HTTPS and strict security headers, verify the signatures of payment notifications from Stripe, and limit what we send to third parties as described above. No method of transmission or storage is completely secure.
10. Age
The Service is for businesses and for individuals who are at least 18 years old. We do not knowingly collect personal data from anyone under 18.
11. Changes to this policy
We will post any update on this page with its effective date. For material changes, we will email paying customers at least 30 days before the change takes effect.
12. Contact
Privacy questions and requests: support@axiomcodex.io.