Privacy Policy

Effective date: 2026-05-18 Last updated: 2026-05-18

This Privacy Policy explains how Alpha Rhythm Reader ("we", "us", "our") collects, uses, and shares information when you use the reader at reader.alpharhythm.org (the "Service"). It is designed to satisfy the disclosure requirements of the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act / California Privacy Rights Act (CCPA / CPRA).

Questions: austin@alpharhythm.org.

1. What we collect

We do not collect payment information, precise location, contacts, browsing history outside the Service, or device-sensor data.

2. Why we collect it (legal basis)

Purpose Legal basis under GDPR
Creating and authenticating your account Performance of a contract (Art. 6(1)(b))
Saving your tier decisions, notes, and library Performance of a contract (Art. 6(1)(b))
Security, abuse prevention, operational logging Legitimate interests (Art. 6(1)(f))
Communicating material changes to this policy Legitimate interests (Art. 6(1)(f))

3. Who we share it with

We share data only with the processors that make the Service work. Each is contractually bound to process data only on our instructions.

The Alpha Rhythm content-ingestion pipeline (the scraper that fills your queue from arXiv, PubMed, ClinicalTrials.gov, openFDA, and SEC EDGAR) runs on hardware we control and does not transmit your account data anywhere. Our Data Sourcing & Compliance Policy covers how source content is handled.

We do not sell or share your personal information for advertising or cross-context behavioral marketing, under either the CCPA's definitions or a common-sense reading.

4. How long we keep it

5. Your rights

Depending on where you live, you have some or all of the following rights: access, correction, deletion, portability, objection or restriction of processing, opt-out of "sale" or "share" (we do neither, but you may direct us not to start), and non-discrimination for exercising these rights.

To exercise any right, email austin@alpharhythm.org. We respond within 30 days (GDPR) or 45 days (CCPA), as applicable. EU/UK residents may also lodge a complaint with their local data-protection authority.

6. International transfers

Our processors operate primarily in the United States. If you access the Service from outside the US, your data is transferred to and processed in the US under our processors' published transfer mechanisms (Standard Contractual Clauses and, where applicable, certification under the EU-US Data Privacy Framework).

7. Cookies and local storage

The Service uses only strictly-necessary Clerk session cookies to keep you signed in. No analytics, advertising, fingerprinting, or third-party trackers.

8. Children

The Service is not directed to children under 13 (under 16 in the EEA / UK), and we do not knowingly collect data from them.

9. Changes to this policy

We may update this policy as the Service evolves. We will notify you by email of any material change before it takes effect and update the "Last updated" date above. Non-material changes are reflected by the date alone.

10. Contact