Privacy Policy
Last updated: September 16, 2026
This Privacy Policy (the “Policy”) describes how Auxerta, Inc., a corporation organized under the laws of the State of Delaware, United States (“Auxerta,” “we,” “us,” or “our”), collects, uses, discloses, and otherwise processes personal information in connection with Argotu, a text-first social posting service (the “Service”). This Policy forms part of, and is incorporated by reference into, the Terms of Service governing your use of the Service. Capitalized terms not defined in this Policy have the meanings given to them in the Terms. By accessing or using the Service, you acknowledge that you have read and understood this Policy.
1Introduction & scope
Auxerta is an artificial-intelligence research company. The Service permits a registered user (a “User,” “you,” or “your”) to publish dated posts, apply a mood, tags, and a limited set of typographic effects, and engage in social features including following, bookmarks, comments, and mutual friendships, with each entry set to private, connections-only, or public visibility.
This Policy applies to personal information that we process about Users and visitors through the Service, including the Service website, and the embeddable text-effect widget. For the purposes of applicable data-protection laws, Auxerta acts as the controller (or business) with respect to the Personal Information described in this Policy. “Personal Information” means information that identifies, relates to, or could reasonably be linked with an identified or identifiable individual.
2Information we collect
We collect the following categories of information, including, without limitation:
(a) Account and profile information. Information that you provide when you register for and maintain an Account:
- your email address;
- a password, which is stored in hashed form and is not retained by us in plain text;
- a chosen handle and display name;
- your date of birth, used to apply age restrictions, administer safety requirements, and, where applicable, prepare the child-safety reports described in Section 6a. Your full date of birth and birth year are not displayed to other Users. You may separately elect to display the day and month on your profile and enable birthday notices to accepted friends. That election is off by default and may be withdrawn in Account settings. Restrictions on public display do not prevent lawful disclosure to authorized personnel or authorities under this Policy;
- an optional biography (“bio”);
- an optional name by which the Assistant (Terms, Section 5A) addresses you. This name need not be your display name or your handle. It is shown only to you, is not displayed to any other User, is not published, and is used for no purpose other than addressing you in messages from the Assistant. It may be changed or cleared in Account settings. Depending on the message, the Assistant may use an available profile name or omit a form of address; and
- preferences that you may set, comprising a self-declared language and your chosen display colours.
(a-2) Account status and subscription records. Information generated by the operation of your Account rather than provided by you:
- whether your email address has been confirmed, and the time of confirmation. Until it is confirmed, entries are stored privately and the features described in the Terms are unavailable;
- subscription and entitlement records, including billing source, the period of access, and identifiers used to reconcile payments. Direct subscriptions use a Stripe customer identifier. Apple subscriptions use verified transaction information, including transaction identifiers, product, signing dates, expiry and revocation information, and the associated Account identifier. Auxerta does not receive or store full payment-card numbers; the applicable billing provider processes payment details under its own policies (Section 6);
- counts of the entries, replies and connection requests you have made in the current day, of the reviews you have written in the current week, and of the pictures you have posted in the current month, together with the day, week, or month each count belongs to. These exist to enforce the limits stated in the Terms, are reset when the corresponding period turns, are not disclosed to any other User, and are not used to decide what you are shown; and
- where staff have taken action in respect of your Account, the records described in Section 3(b).
(a-1) Country. Where a User has consented to usage recording (Section 3), Auxerta records the country from which that User signs in, for the purpose of understanding where the Service is read. The value is limited to a two-letter country code. It is obtained from the country determination supplied by the content-delivery network that fronts the Service, which computes it at the network edge; Auxerta does not send the IP address to a separate geolocation service for this optional measurement. This measurement records country-level information rather than a city or precise coordinates. It is separate from location information a User may include in content, photographs, or a place-related review. Where a User has not consented, or where no country determination is available, no country is recorded. Withdrawing consent erases the country records already held for that User, in addition to preventing further recording; the authentication records described in Section 3 are retained on a separate basis and are unaffected.
(b) Your Content. The text and other material that you create, publish, or otherwise submit through the Service (“Your Content”), together with associated metadata such as the mood, tags, typographic effects, and visibility setting that you apply to an entry. An entry may also be a review of a work.
(b-1) Photographs attached to an Entry. An Entry may contain up to two photographs. User-uploaded video is not supported as an ordinary post attachment. Advertising media is a separate feature.
Supported clients may resize or re-encode a photograph before upload. Auxerta stores the submitted media for display under the Entry’s access controls. Metadata remaining in a submitted file may include camera information, timestamps, or location information. The Service does not guarantee preservation of the original file or removal of every embedded identifier. Remove information you do not wish to submit before uploading a photograph.
Image files are addressed by a non-sequential identifier derived from the file’s contents and are served independently of the entry in which they appear. Access to an image file associated with an entry that is not public is restricted to Users entitled to view that entry. Where an entry is public, the associated image file may be retrieved without authentication while the Entry remains publicly accessible, including by a person to whom the address has been forwarded. Subsequent audience changes, archiving, moderation, and deletion may withdraw that access. Auxerta cannot retrieve an independent copy previously made by another person.
(c) Technical and usage information. Collected automatically when you use the Service:
- Internet Protocol (IP) address. Auxerta records the IP address from which an Account is registered, the IP address associated with the most recent authentication, and, for each authentication session, an IP address, a browser identification string, and associated timestamps. Auxerta processes this information on the basis of its legitimate interest in the security and integrity of the Service, including the detection of unauthorised account access, evasion of enforcement action, and coordinated abuse, and in order to satisfy the reporting obligations described in Section 6a. This information is not disclosed to other Users.
- Reading activity. Where a User who has consented to usage recording under Section 3(a) opens an entry authored by another User, Auxerta records that access; where consent has not been given, or has been withdrawn, no such record is made or retained. The author of an entry is shown the aggregate number of Users who have accessed it and how many of those Users are the author’s accepted friends; those figures accordingly count only consenting readers and understate total readership. The identity of an individual reader is not disclosed to the author or to any other User.
- Device-derived time information. Auxerta records the calendar date and Internet Assigned Numbers Authority time-zone identifier reported by a User’s device at the time of submission, so that an entry is filed under the date on which it was written.
- Visit measurement. For each page requested from the Service, including by a visitor who holds no Account, Auxerta records the page requested, the domain name (but not the full address) of any website that referred the request, any campaign parameters present in the address, and whether the request appeared to originate from automated software. Auxerta additionally derives a short identifier by combining the requesting IP address, the browser identification string, the current date, and a secret value; the IP address is used only for this derivation and is not stored. The identifier is pseudonymous. It groups the pages requested by one visitor within a single day, so that arrivals can be counted; because the current date forms part of the derivation, a new identifier is generated each day, and the identifier is specific to this Service. This measurement sets no cookie and writes nothing to your device. The absence of cookies does not establish anonymity or exclude applicable privacy rights. Records of visit measurement are retained for thirty (30) days and are then deleted automatically. Auxerta processes this information on the basis of its legitimate interest in understanding how the Service is found and used.
- Log data reflecting requests made to the Service, processed to operate, maintain, secure, and improve the Service.
(c-1) Review prior to publication. Certain entries are withheld from publication pending human review. Such review is applied where an entry designated other than private carries a User-submitted image, and in the further circumstances set out in Section 7 of the Terms of Service. While an entry is withheld, it is visible to its author alone. Authorised personnel of Auxerta review the entry, including any image it carries, for the purpose of releasing or refusing publication. Users should therefore be aware that a withheld entry may be read by personnel of Auxerta before it becomes visible to any other User.
(c-2) Private messages and calls. Private messaging and calling are available only to Users to whom Auxerta has granted access to those features; where you have not been granted access, no such information is created. Where you exchange private messages (“Ping”) with another User, Auxerta stores the text of those messages so that they may be delivered and shown to the two Users party to the conversation. Message content is not used for advertising, is never included in the de-identified corpus described in the Terms, and is not licensed to any third party. Auxerta does not read private messages in the ordinary course; a member of the two-person conversation may report a message, in which case Auxerta freezes and reviews a copy of the reported message and the surrounding messages for the purpose of enforcing the Terms. Message content is automatically and permanently deleted thirty (30) days after it is sent, and may be deleted sooner by a party to the conversation or upon erasure of an Account; a copy frozen for the review of a report (above) is retained under the bounded review and preservation rules in Section 8. Where you place or receive a voice call, Auxerta stores a record of the call — the Users party to it, the time it was placed, its duration, and how it ended — but does not record or store call audio. Audio is encrypted in transit between the participants; connection and relay infrastructure may process the data necessary to establish or maintain a call. Private messages you have written and your call records are included in the export described in Section 6 and are deleted when you erase your Account.
(d) Communications. Information that you provide when you contact us, including support requests, accessibility feedback, and other correspondence.
3How we use information
We use the information described above for the following purposes, including, without limitation:
- to create, authenticate, and secure your Account;
- to send you service communications to the email address on your Account, comprising a message confirming that address at registration, a message containing a single-use link by which a forgotten password may be reset, and such notices as this Policy or the Terms require us to give. Each such message is sent because it is necessary to operate your Account or to perform our agreement with you; none is marketing, and Auxerta does not send marketing email. A link contained in a confirmation or reset message expires and may be used once;
- to provide, operate, maintain, and improve the Service and its features;
- to enforce visibility settings and to deliver Your Content consistent with your selections;
- to respond to your communications and provide support;
- to maintain the safety and integrity of the Service, including detecting, preventing, and addressing fraud, abuse, security incidents, and violations of the Terms;
- to conduct manual, human review of entries that appear substantially AI-generated and to apply, and where appropriate remove, an AI label;
- to administer the optional paid subscription described in the Terms; and
- to comply with our legal obligations and to establish, exercise, or defend legal claims.
Usage recording and safety records
Auxerta maintains two categories of record concerning a User’s use of the Service. Each rests on a separate lawful basis, and only the first is subject to the User’s election.
(a) Usage recording (optional). Where a User has given consent, Auxerta records that User’s use of the Service, including the entries that User opens. Consent is requested separately at registration, is not pre-selected, and is not a condition of registration or of access to any feature. A User may give or withdraw consent at any time in the Account settings, and withdrawal is effected by the same single action as consent. Withdrawal takes effect immediately and both prevents further recording and erases the usage records already held about that User, comprising invite-link attribution, the record of the entries that User has opened and the country records described in Section 2(a-1). Erasure is carried out at the time of withdrawal and without further request. Where consent has not been given, or has been withdrawn, Auxerta does not record the entries that User opens. This processing is carried out on the basis of consent (GDPR Art. 6(1)(a)).
When a member creates an invite link and a new member joins through it, we record who invited whom, the signup date, and each member’s consent date only if both allow usage recording. The admin panel also shows whether the new account has confirmed its email. Copying a link alone is not counted as a referral. Turning usage recording off removes referrals involving that member and deactivates their attributed invite link. Inviting and joining remain available without usage recording. We do not reconstruct past referrals.
(b) Safety records (not optional). Independently of paragraph (a), Auxerta retains the records necessary to maintain the security and integrity of the Service and to comply with its legal obligations, comprising authentication records (including IP address, browser identification string, and associated timestamps), reports made by or concerning a User, warnings issued to a User, and enforcement action taken. These records permit the detection and investigation of abuse, impersonation, evasion of enforcement action, and unlawful material, and the making of reports required by law, including those described in Section 6a. They are not subject to election, and the withdrawal of consent under paragraph (a) does not affect them. This processing rests on Auxerta’s legitimate interests in the security and integrity of the Service and on compliance with legal obligations (GDPR Art. 6(1)(f) and 6(1)(c)).
(c) Limitations applicable to both categories. No record described in this Section is used to determine the promotional material shown to a User, and no such record is disclosed to an advertiser. Section 9 of the Terms describes the selection and display of advertising; optional reading history is not used for advertising selection. Authorised personnel of Auxerta may access the records of an individual Account where necessary to review a report or to enforce the Terms, and each such access is recorded in an internal audit log.
Auxerta sells and selects advertising directly. Placements may contain text, images, or supported video and may differ by platform, placement, schedule, and device capability. Private content and optional reading history are not used to target advertising. Advertising media is served through Auxerta’s infrastructure; advertisers do not receive an identified viewer or clicker list. Following an advertising link connects the User to the destination operator, whose collection and use of information are governed by its own policies. Auxerta does not sell Account email addresses or contact lists to advertisers or disclose personal information for cross-context behavioral advertising. Optional content licensing is described separately in Section 5.
4Legal bases for processing
Where the General Data Protection Regulation (EU) 2016/679 or the United Kingdom GDPR (collectively, the “GDPR”) applies, we process Personal Information only where we have a lawful basis to do so. The legal bases on which we rely include, without limitation:
- Performance of a contract: to provide the Service to you in accordance with the Terms, including creating your Account and delivering Your Content according to your visibility settings;
- Legitimate interests: to operate, secure, and improve the Service, to prevent abuse and fraud, and to protect our rights and those of our Users, where such interests are not overridden by your interests or fundamental rights and freedoms;
- Consent: for optional usage recording under Section 3(a), AI Licensing under Section 5, and any additional processing for which consent is required; you may withdraw your consent at any time, prospectively, as described in Section 9; and
- Compliance with legal obligations: to comply with applicable law and lawful requests from public authorities.
5Optional AI Licensing and De-identification
AI Licensing requires an invitation and separate affirmative authorization under Section 5 of the Terms of Service. Accepting the general Terms, enabling the Assistant, subscribing, or allowing optional usage recording does not grant that authorization.
Authorized audience and timing. Version 3 of the Contributor consent covers public and Group Entries created while the relevant authorization is effective. Private Entries require a separate affirmative extension and must fall within its recorded scope and period. Earlier consent versions retain their narrower scope until the User separately accepts a replacement. Automatic thirty-day archiving does not itself remove an otherwise eligible Entry under version 3. Manually restricting an Entry to private excludes it unless a valid private-scope authorization covers it. Deleting content or withdrawing authorization prevents its subsequent inclusion and distribution.
Selection and exclusions. Only qualifying textual Entry fields and permitted associated metadata are considered. Photographs, private messages and calls, retained moderation evidence, support or crisis-related material, and content withheld by moderation or carrying an AI label are excluded. Eligibility does not guarantee selection. Auxerta provides an in-Service notice no later than the first recorded training use or distribution to a Licensee.
Processing and recipients. Auxerta may use authorized content for model development, training, evaluation, and improvement and may license it to third-party research partners and laboratories. Before distribution, direct identifiers are subject to redaction, account and entry identifiers are replaced with pseudonymous references, dates are coarsened, and free-text tags are excluded. These measures reduce identifiability but do not establish anonymity. Identifying context may remain, and information that can still identify a person remains subject to applicable privacy law. Licensee agreements restrict permitted uses, attempted re-identification, and further distribution.
Withdrawal and previously distributed data. Participation and the private-scope extension can be withdrawn through Account settings. Withdrawal stops future inclusion and distribution under the withdrawn authorization and does not affect the lawfulness of processing already performed. Auxerta shall assess and comply with any applicable erasure, restriction, recipient-notification, or other data-protection obligation concerning previously distributed personal information. Completed training or every recipient-held copy cannot necessarily be reversed or recalled; that practical limitation does not remove statutory rights. Account deletion withdraws participation.
Privacy-law classification. Auxerta does not sell Account email addresses or contact lists to advertisers or engage in cross-context behavioral advertising. A paid license of content that remains personal information may constitute a “sale” under an applicable privacy law, notwithstanding pseudonymisation. That activity requires the applicable separate authorization and remains subject to statutory rights, including withdrawal or opt-out where required. Contact contact@auxerta.com to exercise rights not available through the Account controls. These disclosures do not retroactively enlarge a prior consent.
6aChild safety and mandatory reporting
Auxerta is a provider of an electronic communication service or remote computing service within the meaning of 18 U.S.C. § 2258E and is required by 18 U.S.C. § 2258A to report apparent child sexual exploitation to the CyberTipline operated by the National Center for Missing & Exploited Children (“NCMEC”). This Section describes that process. It applies notwithstanding any other provision of this Policy.
(a) Circumstances of reporting. Where Auxerta obtains actual knowledge of facts or circumstances from which there is an apparent violation of the offences enumerated in 18 U.S.C. § 2258A(a)(2), Auxerta submits a report to the CyberTipline as soon as reasonably possible. NCMEC may make such report available to federal, state, local, tribal, or foreign law-enforcement agencies. Auxerta becomes aware of such circumstances principally by means of reports submitted by Users.
(b) Contents of a report. A report submitted under this Section may include: the reported content, including any image; the reported Account’s email address, handle, display name, and date of birth; the date on which the Account was created and its status; the IP address from which the Account was registered; the IP addresses, browser identification strings, and timestamps associated with recent authentication sessions; and the identity of the User who submitted the report.
(c) Preservation. As required by 18 U.S.C. § 2258A(h), Auxerta preserves the contents of a report, and any images or data associated with it, for the period prescribed by that provision. Such preserved material is retained notwithstanding any subsequent deletion of the entry, the image, or the Account, and a request for erasure under Section 9 does not extend to it.
(d) Absence of notice. Auxerta does not notify a User that a report concerning that User’s Account has been submitted. Notification would frustrate the purpose of the report and may be prohibited by applicable law.
(e) Scope. This Section applies solely to apparent child sexual exploitation. It does not constitute a general channel for law-enforcement access, and requests of other kinds are addressed under “Legal and safety” in Section 6.
8Data retention
We keep Personal Information only for the purposes for which it is needed. When you delete your Account, ordinary Account records and your content are removed from the Service. Deletion is not a thirty-day account-recovery process. Specific evidence, limited restriction and audit records, and routine backups may remain under the conditions below, subject to applicable law.
Reported material and investigations. A report may preserve the reported post, comment, profile information, or message, with the relevant timestamps and identity information needed to understand it. A message snapshot includes only the reported message and limited surrounding context, not the entire inbox. Authorized staff may also preserve relevant public material for a specific moderation investigation. We do not copy an entire Account simply because it is deleted or reported. Evidence is held separately from the live Account, so deletion by the author or reporter does not destroy an active, necessary case record.
Time limits and review. Report snapshots have a thirty (30) day initial review window starting when the report is filed. A staff-initiated investigation has the same initial window from capture. Continued retention requires staff to select the evidence still needed, record why it remains necessary, and set a review-or-delete deadline within ninety (90) days of the decision. Legal-purpose holds also require a recorded legal basis or request or claim reference. An extension needs another documented review. Repeated reports and Account deletion do not restart an existing case clock. Staff must release evidence earlier if it is no longer necessary.
Access, purpose, and erasure. Evidence may be used only for the specific abuse or safety investigation, legal obligation, or legal claim that justifies retaining it, where applicable law permits that retention. It is not public, used for advertising, or included in AI training or licensing datasets. Access requires staff authentication and a recorded reason; evidence reads and retention decisions are audited. At expiry or release, access ends, the evidence and detailed case notes are deleted, and unused files enter a cleanup queue processed at approximately five-minute intervals, subject to backlog and retries after storage failures.
Limited records that may remain. A closed case may leave a record of its identifier, dates and outcome, without the retained content, account identifier, or detailed case notes, for up to one year after closure, or while an originating report remains in the moderation queue. Minimal staff audit records identify who accessed or changed a case and when; they do not contain the retained evidence or free-text case explanations. Detailed report notes are also cleared at closure; a minimal report reference and moderation outcome may remain for enforcement and appeals. Separately, an email or IP restriction and its decision record may remain while necessary to enforce that restriction or prevent repeat abuse. Deleting an Account does not automatically remove such a restriction. You may contact us to request review or exercise applicable rights.
Legal requirements and backups. Specific statutory preservation requirements, including the child-safety records described in Section 6a, are handled separately and may require longer retention. The ordinary moderation deadlines above do not override those requirements. Routine versioned backups may retain residual copies for up to ninety (90) additional days; they are not available as live content. These exceptions do not remove your rights under applicable privacy law.
Retired Studio creations. The Studio feature is no longer offered. Creations made with it are no longer accessible, including to their creators, and are deleted on their original schedule: thirty (30) days after they were first posted, or three hundred sixty-five (365) days where Subscriber Access was active at that time. Expired entries and their editing snapshots are deleted, and unreferenced Studio files are queued for erasure; storage cleanup normally runs at five-minute intervals and may be delayed by workload or storage failures. Routine versioned backups may remain for up to ninety (90) additional days. Moderation and other holds described above may preserve records privately.
Manual deletion. Deleting a post or its Account also queues the post’s unused uploaded files for erasure. A file still used by another entry or by a specific active preservation requirement is kept until that need ends. The same access restrictions and cleanup rules apply to ordinary photos.
Verification and password-reset credentials expire according to the authentication provider and applicable security configuration and may be invalidated upon use, replacement, or relevant Account changes. Session credentials may expire or be revoked independently of the retention of a security record concerning the session. The Service and its authentication providers retain the records necessary to operate those controls and investigate security incidents, subject to this Policy.
9Your rights and choices
Depending on your jurisdiction, you may have certain rights with respect to your Personal Information. Subject to applicable law, these may include the right to access, correct, delete, and export your Personal Information, the right to object to or restrict certain processing, and the right to withdraw consent. Where Account access permits, the available controls allow you to:
- edit or delete Your Content and delete your Account; Auxerta supports Account deletion and data export;
- withdraw your consent to AI Licensing on a prospective basis, as described in Section 5;
- publish or withdraw the day and month of your date of birth, at any time and with immediate effect, in the Account settings, as described in Section 2(a); and
- contact us at contact@auxerta.com to exercise any of your rights.
If an Account or access restriction prevents use of those controls, submit the request to contact@auxerta.com. Auxerta may require information reasonably necessary to verify identity and will assess the request under applicable law. An access restriction does not itself extinguish a statutory privacy right.
European Economic Area and United Kingdom (GDPR). Where the GDPR applies, you have the rights of access, rectification, erasure, restriction, data portability, and objection, and the right to lodge a complaint with your competent supervisory authority. Where processing is based on consent, you may withdraw that consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
California (CCPA/CPRA). Where the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies, you have the rights to know, access, correct, and delete your Personal Information, and the right to opt out of the “sale” or “sharing” of Personal Information. Auxerta does not disclose personal information for cross-context behavioral advertising. Optional licensing under Section 5 may constitute a sale where the licensed content remains personal information and the applicable statute applies. You may withdraw participation in Account settings and contact us to exercise other applicable rights.
We will not discriminate against you for exercising any of these rights. We may take reasonable steps to verify your identity before responding to a request.
10Security
We employ administrative, technical, and organizational measures designed to protect Personal Information, including encryption in transit and at rest, hashing of passwords, and access controls that limit who may access data. Notwithstanding these measures, no method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. We will notify you of security incidents affecting your Personal Information to the extent required by applicable law.
11Children’s privacy
The Service is intended for Users who are at least sixteen (16) years of age. The Service is not directed to, and may not be used by, children under the age of thirteen (13), consistent with the Children’s Online Privacy Protection Act (“COPPA”). We do not knowingly collect Personal Information from children under sixteen (16). If you believe that a child has provided us with Personal Information in violation of this Policy, please contact us at contact@auxerta.com and we will take appropriate steps to delete such information.
12International transfers
Auxerta is based in the United States, and we process Personal Information in the United States and in other jurisdictions in which we or our service providers operate. If you access the Service from outside the United States, you understand that your Personal Information may be transferred to, stored, and processed in a country whose data-protection laws may differ from those of your jurisdiction. Where we transfer Personal Information subject to the GDPR outside the European Economic Area or the United Kingdom, we implement appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, where required by applicable law.
13Changes to This Policy
Auxerta may revise this Policy to reflect changes in processing, law, or the Service. Material changes will be communicated through reasonably prominent in-Service notice or email before the affected processing begins, except where immediate action is required by law or an urgent security need. Auxerta will obtain renewed consent where required. Continued use or an updated revision date does not by itself authorize a new optional processing purpose, expand a previously accepted AI Licensing scope, or revive withdrawn consent.
14Contact
For questions regarding this Policy, to exercise your privacy rights, or for matters concerning the Terms generally, please contact us at contact@auxerta.com.