Privacy Policy
This policy explains what personal data Econ Cortex processes, why, and what rights you have. It is written for the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU GDPR.
1. Controller
Dennis Grobe, Switzerland, TODO.
2. What we process and why
| Data | Purpose | Kept |
|---|---|---|
| Account: username, email address, password (hashed), time of registration and last login, whether the email was confirmed | Providing your account, password reset, confirming you can be reached | Until you delete your account |
| Content you create: entries, collections, comments, uploaded files and images (including PDFs attached to publications on your CV), revision history | The service itself. Private content is visible only to you; unlisted content to anyone with the link; public content to everyone | Until you delete it. Deleted entries stay in a trash for 30 days so they can be restored, then they are erased |
| Connections you set up: Zotero API key, GitHub access token and repository, collection settings. If you connect GitHub or sign in with it: your GitHub user id, login and verified email address, which of your repositories you let the app read, and the access tokens GitHub issues for them | Importing citations and notebooks on your request. Keys and tokens are stored encrypted | Until you disconnect them or delete your account |
| Flashcards you create, your review history (which card you rated how, and when it is due again), the scheduler's per-card estimates and your target retention | Spaced-repetition scheduling. Your review history is visible only to you | Until you delete your account |
| Mock exam results you chose to save (collection, score, time used) | Showing your own progress; visible only to you | Until you delete your account |
| Exam dates you enter in the exam planner (collection, date, optional name) | Pacing your new cards and showing how ready you are; visible only to you | Until you remove the exam or delete your account |
| Classes you teach (course, name, optional exam date) and classes you join (when, and whether you show your name and progress to the instructor) | Showing an instructor totals over their class, only once they cannot be traced back to fewer than five people, and the name and progress (lessons read, cards learned, when you last studied, best mock exam) only of members who allow it | Until you leave the class, the instructor deletes it, or you delete your account |
| Your reading list: which cited works you marked as read and the notes you wrote about them (the literature matrix: question, data, method, identification, findings, limitations and topics, plus a free note) | Your own literature overview; visible only to you | Until you remove them or delete your account |
| Weekly digest setting and the date the last digest was sent | Sending the weekly email only if you switched it on; the date prevents duplicate mails | Until you switch it off or delete your account |
| Your privacy settings: who may see your profile page and your activity, who may follow you, who may comment on your entries, whether the member directory and search engines may list your profile, whether others see your name or your @username, and the visibility new entries start with | Deciding what we show to whom. They are applied on the server, not only in the interface | Until you change them or delete your account |
| A message you send through a member's contact form: your name, email address and the message; for rate limiting, a one-way fingerprint of your IP address and email address | Passing the message on to the member by email, with your address as the reply address, and keeping the form free of spam. The member's own address is not shown to you | The message is not stored here, only sent. The fingerprints are counters that expire after one hour (sender) or one day (per recipient) |
Visits to an application link a member sent you: how often it was opened and when last (no IP address, no name). A cookie (ec_pl_β¦, half an hour) keeps a reload from counting twice | Telling the member whether their application was looked at | Until the member deletes the link |
| Follows and comments | Community features; shown to other members | Until you remove them or delete your account |
| Server access logs with a shortened IP address (last part removed) and the page requested | Security and error analysis | 90 days |
| Daily counters per shared entry (number of views, copies, downloads, AI reads) and the domain of the referring website, if any. No IP address, account, cookie or browser identifier is stored with them | Showing authors how often their entries are read ("Reach") | 400 days |
| Two-factor sign-in, if you switch it on: the authenticator secret (stored encrypted) and your recovery codes (stored hashed) | Asking for a second code when you sign in | Until you switch it off or delete your account |
| Signed-in browsers: browser and operating system name, IP address, time of sign-in and last activity | Showing you where your account is signed in and letting you end those sessions | Until you sign out; sessions expire after two weeks without activity and the rows are removed |
| Sign-in records: the name typed into the sign-in form, IP address, browser and time of each sign-in and failed attempt | Protecting accounts against password guessing: five failed attempts lock the name for an hour | 90 days |
| Session cookie and CSRF cookie | Keeping you signed in for up to two weeks and protecting forms. There are no tracking or advertising cookies, and no analytics service | Session: two weeks |
Language cookie (django_language), only once you pick a language in the menu or the footer | Showing the navigation in the language you chose; without it the site is in English | One year, or until you pick again |
3. Who else sees data
- Railway Corp. (USA) hosts the application and the database in the TODO region.
- Resend, Inc. (USA) delivers confirmation and password-reset emails and therefore receives your email address.
- Modal Labs, Inc. (USA) converts PDFs you upload into text on a graphics processor. It receives the file and returns the text; neither is used for anything else, and results are deleted there after a few days at most.
- Zotero, GitHub, Crossref, arXiv, Mathpix receive data only when you use the corresponding feature (for example, the repository you connect or the DOI you look up).
- jsDelivr (a public content delivery network, cdn.jsdelivr.net) delivers the Python runtime only when you open a notebook in JupyterLite; it then sees your IP address. Every other page loads its scripts, styles and fonts, including the formula renderer, from this site only.
- Other members see what you publish, your username, and the comments you write.
- Search engines are offered your public entries and collections, and your profile page unless you switch that off under Settings β Privacy.
How much of your profile other people see is up to you. Under Settings β Privacy you decide, separately, who may open your profile page, who may see your activity and follower counts, who may follow you and who may comment on your entries. The choices are: everyone, signed-in members, people you follow back, or nobody but you. Entries and collections you published stay public whatever you choose here β their own visibility setting decides that.
Signed-in members can find each other in the member directory. It shows you only to people allowed to see your profile page, and you can leave it under Settings β Privacy. Under Settings β Account you choose whether others see your name or your @username, on the site, in feeds, link previews, exports and the API.
Where providers are outside Switzerland or the EU, transfers rely on the providers' standard contractual clauses. We do not sell data and do not use it for advertising.
4. Your rights
You can at any time:
- Export everything we hold about you as a zip file from Settings β Data.
- Delete your account and all your content from the same page. Deletion is immediate and cannot be undone.
- Correct your display name or email address under Settings β Account, and change your password there too.
- Restrict what is shown about you under Settings β Privacy, and stop the weekly email under Settings β Notifications.
- Ask questions or object to processing by writing to TODO.
If you are in the EU you may also complain to your national data protection authority; in Switzerland to the Federal Data Protection and Information Commissioner (FDPIC).
5. Security
Connections are encrypted (HTTPS). Passwords are stored only as salted hashes. Third-party keys are encrypted at rest. Access is logged for security purposes as described above.
6. Changes
We update this policy when the service changes. The date below shows the current version.
Last updated: 2026-09-26