Colloquy Privacy Policy
DRAFT v0.1 — 2026-08-24. Prepared from a standard SaaS template, tailored to Colloquy's PRD §12.6 data inventory. Not yet reviewed by counsel; not legal advice. Bracketed items need Pear's input. Publish at
parthrudesai.com/colloquy/privacyafter review — ORCID production registration requires this page to be live.
Effective date: 2026-08-26 Who we are: Colloquy is operated by Epsilon Solutions LLC, Columbia, South Carolina, USA ("Colloquy," "we," "us"). Contact: parthrudesai+colloquy@gmail.com · Columbia, South Carolina, USA
Colloquy is an audio and discussion platform for research papers. This policy explains what we collect, why, who sees it, and the controls you have. It applies to the Colloquy website (parthrudesai.com/colloquy), the Colloquy mobile apps, and our APIs (together, the "Service").
The short version: we collect what the Service needs to run and nothing more; we don't sell personal data; we don't run ads; anonymous posting hides your identity from other users but never from us — that link exists so we can moderate, and it is technically restricted and audited.
1. What we collect
Account and identity.
- Your ORCID iD and the name on your ORCID record, received when you sign in with ORCID (OAuth). We never see your ORCID password. ORCID iDs are public identifiers, but we treat the link between your ORCID iD and your Colloquy activity as personal data.
- Email address (for notifications and account messages) and the profile you choose to build (handle, display name, bio, avatar).
- Verification evidence for trust tiers: affiliation information already public on your ORCID record, an academic email address you verify with us, or documents you choose to submit for manual review.
Content you create.
- Posts, comments, votes, flags, and reports — including posts made under a pseudonym. Pseudonymous posts are stored with your account identity attached (see §4).
- Author audio you record and upload, and its transcript.
- PDFs you upload for paper matching. If the paper has a legal open-access source, we use that instead and your file is discarded; when your file is the only text source, we extract text to generate the episode and delete the file within 24 hours, unless you choose to keep it in your private locker. Uploaded PDFs are never shown to or shared with other users.
- Private notes and library/queue contents.
Usage and device data.
- Listening events (what you played, how far you got), saves, skips, searches, and feed interactions. These power playback sync and recommendations.
- Standard technical data: IP address, device/browser type, app version, crash reports, and server logs.
- Push tokens, if you enable notifications.
Cookies and similar technologies. We use cookies/local storage for sign-in sessions, security, and preferences (for example, playback position and theme). We do not use advertising cookies or third-party ad trackers. Where analytics run, they are first-party. We honor Global Privacy Control signals for the limited categories to which they apply.
What we deliberately do not collect: payment details (the Service is currently free), precise location, contacts, or anything from your ORCID record beyond what you authorize at sign-in.
2. How we use it
- Provide the Service: resolve papers, stream audio, sync progress across devices, maintain your library and feeds.
- Generate episodes: audio summaries are generated from paper content and public metadata, keyed to the paper's DOI — not from your personal data. Your uploads are used as described in §1.
- Recommendations: we build interest profiles from your listening and engagement to rank your queue. This is profiling in the GDPR sense, but it produces no legal or similarly significant effects — it orders a listening feed. You can clear signals with "less like this" and dismissals; an explicit "Field Trip" control governs out-of-field suggestions.
- Trust tiers and badges: to verify research affiliation and show tier badges (a badge shows your tier, never your identity, on pseudonymous posts).
- Moderation and safety: automated screening of posts before publication (a classifier flags harassment, threats, doxxing, spam), human review of flags and reports, and enforcement (warnings, rate limits, suspensions, bans). See §4 for how this interacts with anonymity.
- Communications: transactional messages (episode ready, replies, security notices) and, if you opt in, digests. Every non-essential category is individually unsubscribable.
- Security, abuse prevention, and legal compliance: rate limiting, bot detection, log analysis, responding to lawful requests.
Legal bases (GDPR/UK GDPR): performance of contract (running the Service you signed up for); legitimate interests (safety, moderation, security, service improvement — balanced against your rights); consent where required (optional emails, push); legal obligation (records we must keep).
3. What other people see
- Your public profile, named posts, claimed papers, author badge and tier badge.
- Pseudonymous posts show only the pseudonym and your tier badge (in very small discussions the badge degrades to a generic "verified researcher" label). Other users, search engines, and API consumers cannot see who is behind a pseudonym, and we build the Service so that they cannot infer it.
- Your library, queue, listening history, private notes, and group memberships are not public. Content posted in a private group is visible only to that group's members.
4. Anonymity, the audit trail, and moderation
This is the clause to read if you use pseudonyms.
- Every post, pseudonymous or not, is stored with the posting account's identity. Anonymity on Colloquy hides your identity from other users — not from Colloquy.
- The pseudonym-to-account link lives in a restricted, separately-encrypted store. Ordinary staff and ordinary systems cannot read it. It is accessed only (a) by automated moderation enforcement (for example, applying an account-level sanction), or (b) by an authorized moderator through a break-glass process that requires a stated reason tied to an open report or legal obligation — and every such access is permanently logged and periodically reviewed.
- Moderation strikes attach to the account, across all pseudonyms. A banned account's ORCID iD cannot re-register.
- We may review content (including private-group content and author-audio transcripts) with automated tools and human moderators to enforce our rules; private does not mean unmoderated.
5. Who we share with (and who we don't)
We do not sell personal data. We do not share it for advertising. There are no ads on Colloquy.
We share personal data only with:
- Service providers (subprocessors) acting on our instructions: Amazon Web Services (hosting, storage, and AI text/speech processing, US regions), ORCID (sign-in), email delivery, error monitoring, and first-party analytics infrastructure. The current list is available on request.
- Paper-metadata services (OpenAlex, Crossref, DataCite, Semantic Scholar): we send them paper identifiers (DOIs, titles) to fetch public metadata. We do not send them your identity.
- Legal: we disclose data if required by law, subpoena, or court order, or to protect the rights, safety, and security of users, the public, or the Service. Where lawful and practicable, we notify affected users. A pseudonymous poster's identity is disclosed only under valid legal process or the moderation rules in §4.
- Business transfers: if Colloquy's business changes hands, data transfers under this policy's protections and we notify you.
6. Retention
| Data | Kept |
|---|---|
| Account + profile | While your account exists, + 30-day deletion grace period |
| Posts and comments | While posted; on deletion, a tombstone (no content, no identity) preserves thread structure |
| Uploaded PDFs (non-OA generation source) | ≤ 24 hours, unless saved to your private locker |
| Author audio | Until you unpublish or delete it |
| Listening/engagement events | 18 months in identifiable form, then aggregated or deleted |
| Server logs / IP | ~90 days |
| Moderation records and identity-access audit log | Up to 7 years (safety and legal defense) |
| Backups | Rolling ~35 days, then expire |
7. Your rights and controls
Everyone: export your data (Settings → Export, or the API), correct your profile, delete your account (Settings → Delete: content is tombstoned, your identity link is erased after the 30-day grace period; the tombstones and the legally-required audit records are what remain). Notification and digest toggles are per-category.
EEA/UK: access, rectification, erasure, restriction, portability, objection (including to legitimate-interest processing), and complaint to your supervisory authority. We are the data controller; contact us first and we'll try to fix it. California: rights to know, delete, correct, and to opt out of "sale or sharing" — we do not sell or share personal information as the CCPA defines those terms, and we do not use sensitive personal information beyond what the Service requires. We honor Global Privacy Control. We do not discriminate for exercising rights. Automated decisions: feed ranking and pre-publication screening are automated, but any enforcement beyond a temporary hold involves human review, and you can appeal any moderation action.
8. International transfers
We are a US service hosted in the United States. If you use Colloquy from outside the US, your data is processed in the US. For EEA/UK users we rely on Standard Contractual Clauses with our subprocessors where required.
9. Children
Colloquy is a service for the research community and is not directed to children. You must be 16 or older (or the age of digital consent where you live, if higher) to create an account. We delete accounts we discover to be underage.
10. Security
TLS everywhere; encryption at rest; the identity-linkage store is separately encrypted with its own keys and denied to application code; least-privilege access; audit logging; tested backups. No system is perfect — if a breach affects your personal data we will notify you and regulators as the law requires.
11. Changes
We'll post changes here with a new effective date; material changes get in-product notice (and email for significant ones) before they take effect. Continued use after the effective date is acceptance.
12. Contact
parthrudesai+colloquy@gmail.com · Epsilon Solutions LLC, Columbia, South Carolina, USA. EU/UK representative: not yet appointed.