Data protection

Privacy policy

This notice explains what ACADEMIVA processes, why, for how long, and how you can exercise your rights.

Version
2026-08-27
Effective from
August 27, 2026

1. Controller and contact

The data controller is RobertIonutF (ACADEMIVA), established in România. For any personal-data question or request, email robertionutfundulea@gmail.com.

ACADEMIVA has not appointed a data protection officer because, as of this version, its activities do not fall within the mandatory appointment cases. Requests are handled directly at the address above.

2. Data we process

  • Account and authentication data: name, email, verification status, account and session identifiers; a profile image only when you use Google sign-in.
  • Academic data you enter: institution, programme, topic, requirements, outline, methodology, sources, citations, notes, thesis content, feedback, and AI-use preferences.
  • Files and results: uploaded documents, metadata, extracts, versions, checks, action logs, and DOCX/PDF exports.
  • Technical and security data: IP address and request metadata kept by infrastructure providers, authentication events, errors, rate limits, and signals needed to prevent abuse.
  • Payment, billing, and contribution data: customer, product, and transaction identifiers, subscription status, credits, optional contributions, refunds, or disputes. Full card details are collected by Stripe or PayPal for the chosen flow, not ACADEMIVA.
  • Support messages and rights requests you choose to send us.

3. Purposes and legal bases

PurposeMain dataLegal basis
Account and academic workspaceAccount, projects, content, files, exportsContract or pre-contractual steps
Authentication, security, fraud prevention, debuggingSession, IP, technical and audit eventsContract and legitimate interest in service security
AI, search, and checks requested by youInstructions, relevant excerpts, resultsContract; initiated only at your request and within the project policy
Payments, subscriptions, optional contributions, refunds, tax recordsBilling identifiers, transactions, credit ledgerContract for purchases; accounting/tax legal obligations and legitimate interest in recording optional contributions
Optional preference cookiesConsent choice and interface stateConsent, withdrawable at any time
Requests and legal claimsMessages, requests, relevant evidenceLegal obligation and legitimate interest in legal claims

4. Providers and recipients

We use providers only as needed for the feature you use. The configuration may include Vercel for app hosting, Convex for authentication, databases and files, Resend for email codes, Google for optional sign-in, Stripe for purchases, PayPal for optional contributions, OpenAI for AI features, and a similarity-check provider only when that integration is enabled.

We may disclose data to authorities or professional advisers where required by law or needed to establish, exercise, or defend legal claims. We do not sell personal data or use it for behavioural advertising.

5. International transfers

Some providers may process data outside the European Economic Area. We then use the mechanism applicable to the transfer, such as a European Commission adequacy decision or Standard Contractual Clauses and supplementary measures where appropriate. You may request information about the relevant safeguard.

6. Retention and deletion

  • Verification and reset codes expire after 15 minutes.
  • Authentication cookies are session cookies in the current configuration; server authentication records expire under the session lifecycle.
  • Active export files generally expire after 24 hours and can be deleted sooner. Audit snapshots needed for regeneration may be kept separately until the project is deleted/redacted or a request is resolved.
  • Projects and account content remain while the account is active or until you delete them or request deletion, except for records required by law or legal claims.
  • Billing data and transaction ledgers remain for the period required by accounting, tax, and fraud-prevention law.
  • Backups are overwritten on a limited cycle; data isolated for a legal obligation is not used for other purposes.

7. Your rights

You may request access, correction, deletion, restriction, portability, or object, and may withdraw consent without affecting earlier processing. Email robertionutfundulea@gmail.com; we may request reasonable identity verification and normally respond within one month.

You may complain to Romania's National Supervisory Authority for Personal Data Processing (ANSPDCP) or the competent authority where you live or work.

8. AI and automated decisions

ACADEMIVA uses automation for suggestions, checks, and organisation, but does not make solely automated decisions with legal or similarly significant effects on you. Results need human review, do not certify originality or university acceptance, and may contain errors.

9. Security and user responsibility

We apply access controls, per-user isolation, encrypted connections, server-side validation, audit logging, and short-lived files. No system can guarantee absolute security. Do not upload special-category or confidential participant data unless you have a lawful basis, proper notice, and institution-approved safeguards.

10. Changes

We update the date and version when this policy changes. For material changes, we show an in-app notice and request a new confirmation where needed. The Romanian and English versions are intended to carry the same meaning.