Privacy Policy
Last updated: 2026-05-19
This policy explains what data Ad Marginem collects, why, where it lives, and how to delete it. It applies to admarginem.ca and the Ad Marginem desktop, mobile, browser extension, and Word add-in clients.
Lawyer-reviewed copy pending. This is a developer-authored placeholder (F#70) accurate to the current MVP architecture but not vetted by counsel. Don't take it as legal advice — it's a description of the system.
1. Data we collect
- Account data: email address, OAuth provider identity (when you sign in with Google/GitHub/ORCID), per-device identifiers. Stored in our primary database (Neon, US-East per PIPEDA cross-border disclosure below).
- Library data: the bibliographic records, PDFs, notes, annotations, and whiteboards you create. Stored encrypted-at-rest in the same database; PDF attachments live in Cloudflare R2 (US).
- Usage telemetry (MVP): Cloudflare Workers Analytics aggregates only — no per-request user identifiers. Workers logs retain request URLs and timestamps for 7 days; PII fields are not logged.
- Waitlist signups: email + UTM source if you joined via the marketing
site. Stored in
waitlist_signups; used only to email you about launch.
2. What we don't collect
- No third-party analytics (no Google Analytics, no Mixpanel, no Segment).
- No marketing/ad pixels.
- No reading-behavior tracking — annotation events stay on your device unless you sync.
3. Where your data lives
Primary database: Neon Postgres in AWS us-east-2 (Ohio). Neon does not yet offer a Canadian region. Per PIPEDA §4.1.3, this constitutes a cross-border transfer of personal data subject to the policies and laws of the United States — including lawful-access requests from US authorities.
PDF attachments: Cloudflare R2 (replicated to AWS S3 Glacier for disaster recovery). Marketing + docs site: Cloudflare Pages. Updater binaries: Cloudflare R2.
4. Sub-processors
See the subprocessor list for the full set of vendors Ad Marginem relies on, plus their data-protection terms.
5. Your rights (GDPR, CCPA, PIPEDA)
- Access: request a copy of your data — Settings → Export Library.
- Deletion: Settings → Delete Account triggers a 30-day cool-off then permanent erasure (P8.4).
- Rectification: edit your data directly in the app.
- Portability: all exports use open standards (BibTeX, CSL-JSON, PDF, Markdown).
- Objection: email [email protected].
6. Retention
Deleted accounts: a 30-day cool-off window during which the deletion can be cancelled, then permanent hard-delete (rows + R2 objects). Audit logs: 90 days in the live table, then archived to R2 JSONL (P8.7). Waitlist signups: until launch, then transferred to a notify list with the same deletion semantics as account data.
7. Cookies
The web/extension/Word-add-in surfaces use a single first-party session cookie on
api.admarginem.ca for authentication. No third-party cookies. The marketing
site sets none.
8. Children
Ad Marginem is not directed at children under 13 (under 16 in the EU). We do not knowingly collect data from minors.
9. Changes to this policy
Material changes are emailed to all accounts with at least 30 days' notice. The last-updated timestamp at the top of this page always reflects the current revision.
10. Contact
[email protected] — privacy questions.
[email protected] — GDPR data protection officer
contact.