Privacy Policy

Effective 8 August 2026

This policy explains what amphi collects, why, who else sees it, how long we keep it, and what you can make us do about it. It describes the product as it actually works — where something is more exposed than you would expect, this document says so rather than glossing it.

amphi is operated by Amphitheatre ("Amphi", "we", "us"). For users in the European Economic Area and the United Kingdom, Amphi is the data controller for the processing described here.

Questions, or want to exercise a right: amphitheatreforum@gmail.com.

1. amphi is in beta

amphi is early software. Features change, schemas change, and data written during beta may be migrated or deleted as the product develops. We will not knowingly lose your data, but you should not treat amphi as the only home for anything you cannot stand to lose. This does not reduce any of your rights below; it is a statement about engineering reality, not a disclaimer of duty.

2. What we collect
2.1 Information you give us

Account. To sign in you provide an email address, and either a password or a Google account. Authentication runs on Supabase Auth. Passwords are stored by Supabase as salted hashes; we never receive or store your plaintext password. If you sign in with Google, Google tells us your email address, name, and profile picture URL — nothing else, and we never receive your Google password.

Profile. Your handle, display name, biography, self-selected tags, avatar, and banner. See §7 for what this means: profiles are public.

Content you create. Posts, comments, citations, votes, debate turns, challenge responses, essays, community and channel messages, direct messages, reflections on daily drops, saved items, and reports you file about other people's content.

Preferences. Onboarding choices such as the traditions you follow and your reminder time.

2.2 Information we infer

Philosophical and ethical leanings. amphi's games and quizzes — trolley problems, consistency checks, validity drills, belief-health scoring — produce a leanings profile summarising where you sit on philosophical and ethical questions. This is the feature that lets amphi say something meaningful about how you think. It is also, under EU and UK data protection law, special category data: information revealing philosophical beliefs. §5 explains how we treat it and how you decline it.

Academic tier and reputation. A rolling quality score derived from automated assessment of your published writing, and a percentile against other users, which together set your visible tier.

Feed affinity. Which circles, authors, and topics you engage with, used to rank your For You feed.

Reading progress. Which archive works and sections you have opened and how far through them you are.

Streaks. Consecutive days active, and your longest run.

2.3 Information collected automatically

Technical request data. Your IP address reaches our servers with every request, as it must for the internet to function. We use it in memory to rate limit expensive AI endpoints when you are not signed in. We do not write IP addresses to our database. Our hosting and database providers keep their own operational logs — see §9.

Local storage. Appearance settings, onboarding flags, reader preferences, and recent searches are stored in your browser, not on our servers. The Cookie and Local Storage Notice lists every key.

Browser notifications. Only if you enable the daily reminder, and only ever via your browser's own permission prompt, which you can revoke in browser settings.

2.4 What we do not collect

No advertising identifiers. No third-party analytics or tracking pixels. No cross-site tracking. No purchase or payment data — amphi does not charge for anything. No precise location. No biometrics. We do not buy personal data from data brokers.

3. Why we use it, and our legal basis

For users in the EEA and UK, GDPR requires us to name a lawful basis for each purpose.

PurposeData usedLegal basis
Create and authenticate your accountEmail, password hash, Google account identifiersPerformance of a contract
Show your profile and content to othersProfile fields, published contentPerformance of a contract
Deliver core features — feeds, debates, communities, archive, messagesContent, preferences, activityPerformance of a contract
Answer questions with AI featuresYour prompt, thread history, retrieved passagesPerformance of a contract
Infer and display your philosophical leaningsGame and quiz answersExplicit consent (Art. 9(2)(a))
Rank your For You feedEngagement history, leanings, preferencesLegitimate interests — a useful product
Score content and enforce our rulesPublished post and comment textLegitimate interests — a safe, good-faith forum
Compute academic tiersQuality scores over your writingLegitimate interests
Rate limit and prevent abuseIP address, access token, request countsLegitimate interests — protecting the service
Send transactional email — confirmation, password resetEmail addressPerformance of a contract
Comply with legal obligations, respond to lawful requestsWhatever is requiredLegal obligation

Where we rely on legitimate interests, we have weighed them against your rights and concluded they do not override your interests. You can object to any of it under §12, and we will stop unless we have compelling grounds to continue.

4. AI features and the model providers behind them

Read this section before typing anything sensitive into amphi.

Several features send your text to third-party AI providers for processing:

  • Grounded chat — your message, the earlier messages in that thread, and passages retrieved from the archive.
  • Steelman — the argument you submit for strengthening.
  • Argument linting and moderation scoring — the text of posts and comments you publish.
  • Search and recommendation embeddings — text converted into numeric vectors.
  • Challenge generation — prompts assembled from archive content.

We route these calls through OpenRouter, which forwards them to the model that handles the request. Today that means DeepSeek for conversational generation and Google (Gemini) for structured output and embeddings. Model routing changes as better models appear; the categories of data sent do not.

What this means practically:

  • Text you enter into these features leaves our infrastructure and is processed on third-party systems in third countries.
  • Each provider handles that text under its own terms and retention schedule, which we do not control and cannot shorten on your behalf.
  • We do not send your email address, account identifier, or profile to these providers. Requests carry the content to be processed, not your identity — but content you write can of course identify you if you put identifying details in it.
  • We do not authorise these providers to train models on your content, and we select settings that decline training where a provider offers the choice. We cannot audit their compliance.

Do not enter information into AI features that you would not be comfortable sending to an external company. Direct messages and private community channels are not sent to AI providers.

AI output can be wrong, and confidently so. Attributions and citations it produces can be fabricated. Treat every claim as a lead to verify against the archive text, not as an established fact.

5. Your philosophical leanings — special category data

Under GDPR Art. 9 and the UK equivalent, data revealing philosophical beliefs gets heightened protection. amphi's core feature infers exactly that. We are treating it as special category data whether or not you are in Europe, because the sensitivity is the same everywhere.

We process it only with your explicit consent. Consent is asked for separately from your acceptance of this policy, in plain terms, before any leanings are inferred.

Declining costs you nothing but the feature. Games and quizzes remain playable and scored for you; we simply do not build or store a leanings profile from them. Every other part of amphi works normally.

You can withdraw consent at any time by writing to amphitheatreforum@gmail.com. We will delete your stored leanings and stop inferring new ones. Withdrawal does not undo processing that already happened lawfully.

Where this sits today: leanings is stored on your profile row, and profile rows are readable by anyone — see §7. If you would rather your inferred beliefs not be publicly readable, decline the inference. We are working to make this a visibility setting rather than an all-or-nothing choice.

6. Automated moderation and automated decisions

Every post and comment published on amphi is automatically assessed by a language model on five axes: personal attacks, toxicity, spam, unsourced quotation, and academic quality.

Content scoring above our thresholds is redacted automatically, without a human looking at it first. Thresholds are stricter for personal attacks and toxicity than for the other axes. Repeated reports from distinct users can escalate content for assessment. Quality scores also feed the academic tier shown on your profile.

Under GDPR Art. 22 you have the right not to be subject to solely automated decisions with significant effects. Accordingly:

  • You can appeal any automated redaction, and appeals are read by a person.
  • You can ask for human review of an automated decision even without formal appeal, contest the outcome, and state your case.
  • Write to amphitheatreforum@gmail.com or use the in-product appeal.

We keep a moderation record of actions taken: what was actioned, on what, by which model and version, when, and the score that triggered it. This is what makes appeals reviewable rather than a matter of trust.

7. What is public, what is not

Public to anyone on the internet, including people without an account:

  • Your handle, display name, biography, tags, avatar, and banner.
  • Your inferred leanings, currently — see §5.
  • Your academic tier.
  • Posts, comments, votes, debate turns, challenge responses, and essays in public circles.
  • Reflections you explicitly mark as shared.

Two consequences worth being direct about. First, profile records are readable by anyone querying our public API, not only by people who visit your profile page in a browser — assume everything on your profile is fully public. Second, avatars and banners are stored in a public bucket: their URLs work without sign-in, and once a file exists at a URL it may remain reachable and may have been cached elsewhere even after you replace it.

Visible only to specific people:

  • Direct messages — you and the recipient.
  • Private community content — that community's members.
  • Reflections marked private — you.
  • Saves, reading progress, and streaks — you.

Direct messages are not end-to-end encrypted. They are encrypted in transit and at rest, and our access controls stop other users reading them, but they are stored in a form we can technically read and must produce if legally compelled. Do not use amphi DMs for anything requiring genuine confidentiality.

8. Who else gets your data

We do not sell personal information. We do not share it for cross-context behavioural advertising. We have never done either and have no plans to.

We share data with:

Service providers who process it on our instructions. Listed in §9.

Other users, as you direct — see §7.

Law enforcement and legal claimants, where we are legally required, or where disclosure is reasonably necessary to investigate rule violations, defend legal claims, or prevent imminent harm. Where we are permitted to notify you of a request, we will.

A successor entity, if amphi is acquired or merged. You will be notified before your data becomes subject to a materially different policy.

9. Service providers
ProviderWhat they doWhat they touch
SupabaseDatabase, authentication, file storage, realtimeAll stored account, profile, and content data
VercelWeb hosting and CDNRequest metadata, IP addresses in operational logs
GoogleGoogle sign-in; Gemini models via OpenRouterSign-in identifiers; text sent to AI features
OpenRouterRoutes AI requests to model providersText sent to AI features
DeepSeekConversational generation via OpenRouterText sent to chat and steelman

Each processes data under its own privacy terms. Public-domain text sources — Project Gutenberg, Wikisource, PhilArchive — supply archive content *to* us; we send them nothing about you.

10. International transfers

Our primary data store is hosted in AWS us-west-1 (N. California). Our providers operate globally, so your data may be processed in the United States and elsewhere, including countries whose data protection laws differ from those where you live.

Where we transfer personal data out of the EEA or UK, we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, as incorporated into our providers' data processing terms. Ask at amphitheatreforum@gmail.com for details of the safeguards for any specific transfer.

11. How long we keep things
DataRetention
Account and profileUntil you delete your account
Content you publishUntil you delete it, or delete your account
Direct messagesUntil either participant deletes their account
Inferred leaningsUntil you withdraw consent or delete your account
Reading progress, saves, streaksUntil you delete your account
Moderation records2 years after the action, then deleted
Appeals2 years after resolution
BackupsRolling 30 days, then overwritten
Provider operational logsPer each provider's schedule, typically 30 days

What deleting your account actually does. Unusually for a forum, deletion is real: your account, profile, and content are removed by database cascade — posts, comments, votes, debate turns, challenge responses, essays, community messages, direct messages, reflections, saves, quiz and game results, reading progress, and streaks. Content of yours that other people replied to disappears along with everything else. This is different from most platforms, which keep your posts and merely unlink your name. Deletion here is irreversible and we cannot restore it.

Two things survive: a moderation record retained under the schedule above, with your account identifier removed so it no longer points at you; and backup copies until the rolling window overwrites them.

Deletion completes within 30 days of a verified request.

12. Your rights

Wherever you live, you can ask us to:

  • Access the personal data we hold about you.
  • Correct anything inaccurate.
  • Delete your account and data.
  • Export your data in a portable, machine-readable format.
  • Object to or restrict processing based on legitimate interests.
  • Withdraw consent for leanings inference at any time.
  • Get human review of an automated moderation decision.

If you are in the EEA or UK these are GDPR rights (Arts. 15–22). If you are in California they are CCPA/CPRA rights, plus the right not to be discriminated against for exercising them — and note that we neither sell nor share personal information as those terms are defined, so there is nothing to opt out of. Several other US states grant comparable rights; we apply this section to everyone rather than sorting users by state.

How. Email amphitheatreforum@gmail.com from the address on your account. We respond within 30 days, and will tell you if we need longer and why. We do not charge for this. If we cannot verify that a request comes from you, we will ask for more information rather than act on it — protecting your account from someone else's deletion request is part of protecting your data.

Self-serve controls do not exist yet. amphi is in beta and settings offer appearance options only. Until deletion and export are buttons, they are emails, handled by hand within the same 30 days.

Complaints. Tell us first — amphitheatreforum@gmail.com — and we will try to fix it. You can also complain to your supervisory authority: in the EEA, the authority where you live or work; in the UK, the Information Commissioner's Office (ico.org.uk).

13. Security

Data is encrypted in transit (TLS) and at rest. Database access is governed by row-level security policies enforced at the database, so authorisation does not depend on the application layer getting every check right. Passwords are salted and hashed by Supabase Auth. Access to production systems is limited to people who need it.

No system is perfectly secure, and we will not claim otherwise. If we discover a breach affecting your personal data, we will notify you and the relevant authorities as required — for GDPR, within 72 hours of becoming aware.

Found a vulnerability? Report it to amphiforum@gmail.com. We will not pursue legal action over good-faith security research that respects the boundaries in the Acceptable Use Policy.

14. Children

amphi is for people 16 and older. We do not knowingly collect data from anyone under 16. If you believe a child under 16 has an account, write to amphitheatreforum@gmail.com and we will delete it.

The age floor is 16 rather than 13 deliberately: amphi infers and stores philosophical beliefs, and that is not data we want to hold about children.

15. Changes

We will update this policy as amphi changes. Material changes — new categories of data, new purposes, new recipients — get at least 30 days' notice by email and in-product before they take effect. Minor clarifications take effect on posting, with the date at the top updated. Superseded versions are kept, so we can always show which policy applied when.

16. Contact
  • Privacy and data rights: amphitheatreforum@gmail.com
  • Everything else: amphiforum@gmail.com
  • Post: Amphitheatre, 1055 Windermere Crossing, Cumming, GA 30041
A place to think
Built for depth, not dopamine. Come thinkwith us
join the betaDither Right Arrow
FIND US
amphi.
amphi Privacy Policy