← Colloquy

Version 1.0 · Effective 2026-08-26 · Questions: parthrudesai+colloquy@gmail.com

Colloquy Privacy Policy

DRAFT v0.1 — 2026-08-24. Prepared from a standard SaaS template, tailored to Colloquy's PRD §12.6 data inventory. Not yet reviewed by counsel; not legal advice. Bracketed items need Pear's input. Publish at parthrudesai.com/colloquy/privacy after review — ORCID production registration requires this page to be live.

Effective date: 2026-08-26 Who we are: Colloquy is operated by Epsilon Solutions LLC, Columbia, South Carolina, USA ("Colloquy," "we," "us"). Contact: parthrudesai+colloquy@gmail.com · Columbia, South Carolina, USA

Colloquy is an audio and discussion platform for research papers. This policy explains what we collect, why, who sees it, and the controls you have. It applies to the Colloquy website (parthrudesai.com/colloquy), the Colloquy mobile apps, and our APIs (together, the "Service").

The short version: we collect what the Service needs to run and nothing more; we don't sell personal data; we don't run ads; anonymous posting hides your identity from other users but never from us — that link exists so we can moderate, and it is technically restricted and audited.


1. What we collect

Account and identity.

Content you create.

Usage and device data.

Cookies and similar technologies. We use cookies/local storage for sign-in sessions, security, and preferences (for example, playback position and theme). We do not use advertising cookies or third-party ad trackers. Where analytics run, they are first-party. We honor Global Privacy Control signals for the limited categories to which they apply.

What we deliberately do not collect: payment details (the Service is currently free), precise location, contacts, or anything from your ORCID record beyond what you authorize at sign-in.

2. How we use it

Legal bases (GDPR/UK GDPR): performance of contract (running the Service you signed up for); legitimate interests (safety, moderation, security, service improvement — balanced against your rights); consent where required (optional emails, push); legal obligation (records we must keep).

3. What other people see

4. Anonymity, the audit trail, and moderation

This is the clause to read if you use pseudonyms.

5. Who we share with (and who we don't)

We do not sell personal data. We do not share it for advertising. There are no ads on Colloquy.

We share personal data only with:

6. Retention

Data Kept
Account + profile While your account exists, + 30-day deletion grace period
Posts and comments While posted; on deletion, a tombstone (no content, no identity) preserves thread structure
Uploaded PDFs (non-OA generation source) ≤ 24 hours, unless saved to your private locker
Author audio Until you unpublish or delete it
Listening/engagement events 18 months in identifiable form, then aggregated or deleted
Server logs / IP ~90 days
Moderation records and identity-access audit log Up to 7 years (safety and legal defense)
Backups Rolling ~35 days, then expire

7. Your rights and controls

Everyone: export your data (Settings → Export, or the API), correct your profile, delete your account (Settings → Delete: content is tombstoned, your identity link is erased after the 30-day grace period; the tombstones and the legally-required audit records are what remain). Notification and digest toggles are per-category.

EEA/UK: access, rectification, erasure, restriction, portability, objection (including to legitimate-interest processing), and complaint to your supervisory authority. We are the data controller; contact us first and we'll try to fix it. California: rights to know, delete, correct, and to opt out of "sale or sharing" — we do not sell or share personal information as the CCPA defines those terms, and we do not use sensitive personal information beyond what the Service requires. We honor Global Privacy Control. We do not discriminate for exercising rights. Automated decisions: feed ranking and pre-publication screening are automated, but any enforcement beyond a temporary hold involves human review, and you can appeal any moderation action.

8. International transfers

We are a US service hosted in the United States. If you use Colloquy from outside the US, your data is processed in the US. For EEA/UK users we rely on Standard Contractual Clauses with our subprocessors where required.

9. Children

Colloquy is a service for the research community and is not directed to children. You must be 16 or older (or the age of digital consent where you live, if higher) to create an account. We delete accounts we discover to be underage.

10. Security

TLS everywhere; encryption at rest; the identity-linkage store is separately encrypted with its own keys and denied to application code; least-privilege access; audit logging; tested backups. No system is perfect — if a breach affects your personal data we will notify you and regulators as the law requires.

11. Changes

We'll post changes here with a new effective date; material changes get in-product notice (and email for significant ones) before they take effect. Continued use after the effective date is acceptance.

12. Contact

parthrudesai+colloquy@gmail.com · Epsilon Solutions LLC, Columbia, South Carolina, USA. EU/UK representative: not yet appointed.