Effective 8 August 2026
This policy explains what amphi collects, why, who else sees it, how long we keep it, and what you can make us do about it. It describes the product as it actually works — where something is more exposed than you would expect, this document says so rather than glossing it.
amphi is operated by Amphitheatre ("Amphi", "we", "us"). For users in the European Economic Area and the United Kingdom, Amphi is the data controller for the processing described here.
Questions, or want to exercise a right: amphitheatreforum@gmail.com.
amphi is early software. Features change, schemas change, and data written during beta may be migrated or deleted as the product develops. We will not knowingly lose your data, but you should not treat amphi as the only home for anything you cannot stand to lose. This does not reduce any of your rights below; it is a statement about engineering reality, not a disclaimer of duty.
Account. To sign in you provide an email address, and either a password or a Google account. Authentication runs on Supabase Auth. Passwords are stored by Supabase as salted hashes; we never receive or store your plaintext password. If you sign in with Google, Google tells us your email address, name, and profile picture URL — nothing else, and we never receive your Google password.
Profile. Your handle, display name, biography, self-selected tags, avatar, and banner. See §7 for what this means: profiles are public.
Content you create. Posts, comments, citations, votes, debate turns, challenge responses, essays, community and channel messages, direct messages, reflections on daily drops, saved items, and reports you file about other people's content.
Preferences. Onboarding choices such as the traditions you follow and your reminder time.
Philosophical and ethical leanings. amphi's games and quizzes — trolley problems, consistency checks, validity drills, belief-health scoring — produce a leanings profile summarising where you sit on philosophical and ethical questions. This is the feature that lets amphi say something meaningful about how you think. It is also, under EU and UK data protection law, special category data: information revealing philosophical beliefs. §5 explains how we treat it and how you decline it.
Academic tier and reputation. A rolling quality score derived from automated assessment of your published writing, and a percentile against other users, which together set your visible tier.
Feed affinity. Which circles, authors, and topics you engage with, used to rank your For You feed.
Reading progress. Which archive works and sections you have opened and how far through them you are.
Streaks. Consecutive days active, and your longest run.
Technical request data. Your IP address reaches our servers with every request, as it must for the internet to function. We use it in memory to rate limit expensive AI endpoints when you are not signed in. We do not write IP addresses to our database. Our hosting and database providers keep their own operational logs — see §9.
Local storage. Appearance settings, onboarding flags, reader preferences, and recent searches are stored in your browser, not on our servers. The Cookie and Local Storage Notice lists every key.
Browser notifications. Only if you enable the daily reminder, and only ever via your browser's own permission prompt, which you can revoke in browser settings.
No advertising identifiers. No third-party analytics or tracking pixels. No cross-site tracking. No purchase or payment data — amphi does not charge for anything. No precise location. No biometrics. We do not buy personal data from data brokers.
For users in the EEA and UK, GDPR requires us to name a lawful basis for each purpose.
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and authenticate your account | Email, password hash, Google account identifiers | Performance of a contract |
| Show your profile and content to others | Profile fields, published content | Performance of a contract |
| Deliver core features — feeds, debates, communities, archive, messages | Content, preferences, activity | Performance of a contract |
| Answer questions with AI features | Your prompt, thread history, retrieved passages | Performance of a contract |
| Infer and display your philosophical leanings | Game and quiz answers | Explicit consent (Art. 9(2)(a)) |
| Rank your For You feed | Engagement history, leanings, preferences | Legitimate interests — a useful product |
| Score content and enforce our rules | Published post and comment text | Legitimate interests — a safe, good-faith forum |
| Compute academic tiers | Quality scores over your writing | Legitimate interests |
| Rate limit and prevent abuse | IP address, access token, request counts | Legitimate interests — protecting the service |
| Send transactional email — confirmation, password reset | Email address | Performance of a contract |
| Comply with legal obligations, respond to lawful requests | Whatever is required | Legal obligation |
Where we rely on legitimate interests, we have weighed them against your rights and concluded they do not override your interests. You can object to any of it under §12, and we will stop unless we have compelling grounds to continue.
Read this section before typing anything sensitive into amphi.
Several features send your text to third-party AI providers for processing:
We route these calls through OpenRouter, which forwards them to the model that handles the request. Today that means DeepSeek for conversational generation and Google (Gemini) for structured output and embeddings. Model routing changes as better models appear; the categories of data sent do not.
What this means practically:
Do not enter information into AI features that you would not be comfortable sending to an external company. Direct messages and private community channels are not sent to AI providers.
AI output can be wrong, and confidently so. Attributions and citations it produces can be fabricated. Treat every claim as a lead to verify against the archive text, not as an established fact.
Under GDPR Art. 9 and the UK equivalent, data revealing philosophical beliefs gets heightened protection. amphi's core feature infers exactly that. We are treating it as special category data whether or not you are in Europe, because the sensitivity is the same everywhere.
We process it only with your explicit consent. Consent is asked for separately from your acceptance of this policy, in plain terms, before any leanings are inferred.
Declining costs you nothing but the feature. Games and quizzes remain playable and scored for you; we simply do not build or store a leanings profile from them. Every other part of amphi works normally.
You can withdraw consent at any time by writing to amphitheatreforum@gmail.com. We will delete your stored leanings and stop inferring new ones. Withdrawal does not undo processing that already happened lawfully.
Where this sits today: leanings is stored on your profile row, and profile rows are readable by anyone — see §7. If you would rather your inferred beliefs not be publicly readable, decline the inference. We are working to make this a visibility setting rather than an all-or-nothing choice.
Every post and comment published on amphi is automatically assessed by a language model on five axes: personal attacks, toxicity, spam, unsourced quotation, and academic quality.
Content scoring above our thresholds is redacted automatically, without a human looking at it first. Thresholds are stricter for personal attacks and toxicity than for the other axes. Repeated reports from distinct users can escalate content for assessment. Quality scores also feed the academic tier shown on your profile.
Under GDPR Art. 22 you have the right not to be subject to solely automated decisions with significant effects. Accordingly:
We keep a moderation record of actions taken: what was actioned, on what, by which model and version, when, and the score that triggered it. This is what makes appeals reviewable rather than a matter of trust.
Public to anyone on the internet, including people without an account:
Two consequences worth being direct about. First, profile records are readable by anyone querying our public API, not only by people who visit your profile page in a browser — assume everything on your profile is fully public. Second, avatars and banners are stored in a public bucket: their URLs work without sign-in, and once a file exists at a URL it may remain reachable and may have been cached elsewhere even after you replace it.
Visible only to specific people:
Direct messages are not end-to-end encrypted. They are encrypted in transit and at rest, and our access controls stop other users reading them, but they are stored in a form we can technically read and must produce if legally compelled. Do not use amphi DMs for anything requiring genuine confidentiality.
We do not sell personal information. We do not share it for cross-context behavioural advertising. We have never done either and have no plans to.
We share data with:
Service providers who process it on our instructions. Listed in §9.
Other users, as you direct — see §7.
Law enforcement and legal claimants, where we are legally required, or where disclosure is reasonably necessary to investigate rule violations, defend legal claims, or prevent imminent harm. Where we are permitted to notify you of a request, we will.
A successor entity, if amphi is acquired or merged. You will be notified before your data becomes subject to a materially different policy.
| Provider | What they do | What they touch |
|---|---|---|
| Supabase | Database, authentication, file storage, realtime | All stored account, profile, and content data |
| Vercel | Web hosting and CDN | Request metadata, IP addresses in operational logs |
| Google sign-in; Gemini models via OpenRouter | Sign-in identifiers; text sent to AI features | |
| OpenRouter | Routes AI requests to model providers | Text sent to AI features |
| DeepSeek | Conversational generation via OpenRouter | Text sent to chat and steelman |
Each processes data under its own privacy terms. Public-domain text sources — Project Gutenberg, Wikisource, PhilArchive — supply archive content *to* us; we send them nothing about you.
Our primary data store is hosted in AWS us-west-1 (N. California). Our providers operate globally, so your data may be processed in the United States and elsewhere, including countries whose data protection laws differ from those where you live.
Where we transfer personal data out of the EEA or UK, we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, as incorporated into our providers' data processing terms. Ask at amphitheatreforum@gmail.com for details of the safeguards for any specific transfer.
| Data | Retention |
|---|---|
| Account and profile | Until you delete your account |
| Content you publish | Until you delete it, or delete your account |
| Direct messages | Until either participant deletes their account |
| Inferred leanings | Until you withdraw consent or delete your account |
| Reading progress, saves, streaks | Until you delete your account |
| Moderation records | 2 years after the action, then deleted |
| Appeals | 2 years after resolution |
| Backups | Rolling 30 days, then overwritten |
| Provider operational logs | Per each provider's schedule, typically 30 days |
What deleting your account actually does. Unusually for a forum, deletion is real: your account, profile, and content are removed by database cascade — posts, comments, votes, debate turns, challenge responses, essays, community messages, direct messages, reflections, saves, quiz and game results, reading progress, and streaks. Content of yours that other people replied to disappears along with everything else. This is different from most platforms, which keep your posts and merely unlink your name. Deletion here is irreversible and we cannot restore it.
Two things survive: a moderation record retained under the schedule above, with your account identifier removed so it no longer points at you; and backup copies until the rolling window overwrites them.
Deletion completes within 30 days of a verified request.
Wherever you live, you can ask us to:
If you are in the EEA or UK these are GDPR rights (Arts. 15–22). If you are in California they are CCPA/CPRA rights, plus the right not to be discriminated against for exercising them — and note that we neither sell nor share personal information as those terms are defined, so there is nothing to opt out of. Several other US states grant comparable rights; we apply this section to everyone rather than sorting users by state.
How. Email amphitheatreforum@gmail.com from the address on your account. We respond within 30 days, and will tell you if we need longer and why. We do not charge for this. If we cannot verify that a request comes from you, we will ask for more information rather than act on it — protecting your account from someone else's deletion request is part of protecting your data.
Self-serve controls do not exist yet. amphi is in beta and settings offer appearance options only. Until deletion and export are buttons, they are emails, handled by hand within the same 30 days.
Complaints. Tell us first — amphitheatreforum@gmail.com — and we will try to fix it. You can also complain to your supervisory authority: in the EEA, the authority where you live or work; in the UK, the Information Commissioner's Office (ico.org.uk).
Data is encrypted in transit (TLS) and at rest. Database access is governed by row-level security policies enforced at the database, so authorisation does not depend on the application layer getting every check right. Passwords are salted and hashed by Supabase Auth. Access to production systems is limited to people who need it.
No system is perfectly secure, and we will not claim otherwise. If we discover a breach affecting your personal data, we will notify you and the relevant authorities as required — for GDPR, within 72 hours of becoming aware.
Found a vulnerability? Report it to amphiforum@gmail.com. We will not pursue legal action over good-faith security research that respects the boundaries in the Acceptable Use Policy.
amphi is for people 16 and older. We do not knowingly collect data from anyone under 16. If you believe a child under 16 has an account, write to amphitheatreforum@gmail.com and we will delete it.
The age floor is 16 rather than 13 deliberately: amphi infers and stores philosophical beliefs, and that is not data we want to hold about children.
We will update this policy as amphi changes. Material changes — new categories of data, new purposes, new recipients — get at least 30 days' notice by email and in-product before they take effect. Minor clarifications take effect on posting, with the date at the top updated. Superseded versions are kept, so we can always show which policy applied when.