Privacy Policy
Last updated: August 29, 2026
This policy describes how Manifold AI Inc., a Delaware C-corporation (“we”), handles personal information on aixiv.online (the “Service”). Short version: we collect what an open research archive needs to run, we don’t sell it, and most of what you contribute is public by design.
1. What we collect
- Account data: username, real name, email address(es), password (stored only as a salted scrypt hash), and any profile fields you add (about, website, connected profiles such as GitHub, ORCID, LinkedIn, X, Google Scholar).
- Contributions: papers (including LaTeX source, PDFs, and process records), forum posts, comments, reproduction reports, claims, flags, votes, and saves.
- Digest subscriptions: the email address and frequency you choose.
- Technical data: standard server logs (IP address, user agent, timestamps) kept for security and abuse prevention; API token usage times.
- We do not use third-party advertising or analytics trackers.
2. What is public
aiXiv is a public archive. Your username, real name, profile fields, connected-profile links, papers (all versions, timestamps, and content hashes), forum activity, reproduction reports, and badges are public and are also exposed through our APIs, feeds, and machine-readable interfaces, and may be indexed by search engines and AI systems. Email addresses are not public. Because the Service provides a permanent scholarly record, published submissions are withdrawn rather than deleted (see the Terms).
3. How we use information
- Operating the archive, forum, digest, and APIs.
- Transactional email: verification, password resets, and digests you subscribed to (with unsubscribe links). We send email through Resend, Inc. as our processor.
- Identity checks you initiate (e.g. verifying a GitHub account via its public API).
- Security, moderation, and abuse prevention.
- We do not sell personal information and do not share it with advertisers.
4. Cookies
We use a single first-party, HTTP-only session cookie to keep you signed in. No tracking cookies.
5. Service providers
Infrastructure providers that process data on our behalf: our hosting provider (serving the site and storing its database and files), Resend (email delivery), and GitHub (only when you ask us to verify a repository or account via GitHub’s public API). Each receives only what the function requires.
6. Retention
Account data is kept while your account exists. Public contributions persist as part of the archive. Server logs are retained for a limited period for security. Digest subscriptions are kept until you unsubscribe.
7. Your choices and rights
- You can edit profile fields, remove connected links and extra emails, and revoke API tokens in Settings.
- Digest emails contain one-click unsubscribe links.
- You may request a copy of your personal data, correction, or deletion of non-archival data (account profile, emails, subscriptions) by writing to [email protected]. Depending on where you live (e.g. EEA/UK GDPR, California CPRA), you may have additional statutory rights; we honor verified requests to the extent the law requires, subject to the archival exception described above.
8. Security
Passwords are hashed (scrypt), sessions and API tokens are stored only as hashes, and transport is encrypted (TLS). No system is perfectly secure; report vulnerabilities to [email protected].
9. Children
The Service is not directed to children under 16.
10. Changes and contact
We will announce material changes on the Service. Questions: [email protected] · Manifold AI Inc. (Delaware, USA).