Privacy Policy

Last updated: 2026-08-31

Who we are

ScholaThomistica is a non-commercial digital library of scholastic theological texts, operated by Julio Alonzo Müller. Contact: contact@scholathomistica.com. Full operator details on the Imprint page.

We act as the data controller for the personal data described below, within the meaning of the EU General Data Protection Regulation (GDPR).

What we collect

We keep the smallest set of data the platform actually needs:

  • Account data. Username, email address, and a one-way hash of your password. You provide these at signup.
  • Contributions. The text of any correction, proposal, or translation you submit, along with a timestamp and your user ID. If approved, the contribution becomes part of the canonical corpus.
  • Server logs. Our hosting provider (Railway) records ordinary operational logs, including IP addresses, request paths, timestamps, and user agent information. These are not linked to account records by ScholaThomistica.
  • Anonymous reading analytics. If you consent, the reader reports only the work identity, whether reading started, and how many 30-second active-reading intervals occurred. Our application database stores daily work-level totals, with no account, device, or cross-site identifier and no raw event history.

We do not use third-party analytics, session replay, advertising pixels, or cross-site tracking scripts.

Anonymous reading analytics

Anonymous reading analytics are optional, first-party measurements from consenting readers. They help us understand which works are read and estimate engaged-reading time. They are directional, not a count of people: opt-outs, blockers, offline reading, bots, reloads, and failed client reports can all affect the totals.

The payload contains only the work identity and either a reader start or one of the 30-second active-reading intervals. It contains no account, device, or cross-site identifier. The application database keeps only daily, work-level aggregates indefinitely; it does not keep raw events or reader profiles. These figures are neither sold nor used for advertising.

Disabling analytics stops future reports across open tabs and tries to abort any delivery in progress. Because the stored totals do not identify you, we cannot identify or retract an aggregate that has already been committed.

Current choice: No choice saved

Legal basis

  • Your account and contributions are processed to perform the contract between you and the platform — GDPR Art. 6(1)(b).
  • Server logs are processed under our legitimate interest in keeping the service secure and operational — GDPR Art. 6(1)(f).
  • Anonymous reading analytics are processed only with your consent — GDPR Art. 6(1)(a). You can withdraw that consent below at any time.

How long we keep it

  • Account data is kept until you ask for deletion.
  • Contributions are kept indefinitely as part of the open corpus, under the license you granted when submitting them (see the Terms of Service). When you request account deletion, we sever the link between your identity and those contributions so that they remain in the library but are no longer attributed to you personally.
  • Account-backed unsubmitted work drafts are stored privately while your account is active so you can resume editing. You can delete them at any time from My contributions, and all remaining server drafts are erased when your account is deleted. While a save is pending or fails, a temporary recovery copy may remain in this browser’s local storage until the next successful save or submission.
  • Server logs are retained per our hosting provider’s default rotation (approximately 30 days).
  • Anonymous reading aggregates are retained indefinitely. They contain no reader identifier or raw event history.

Who we share it with

Personal data is processed by the following subprocessors:

  • Railway — hosting and managed Postgres database. Located in the United States; data-processing terms available from Railway.
  • Resend — transactional email delivery for account verification and essential account messages. Located in the United States; receives the recipient email address and the email content needed to deliver the message.
  • Sentry — error monitoring for production stability. Located in the United States; receives scrubbed technical errors such as stack traces, browser/runtime metadata, and limited request context. Session replay and analytics are disabled.

We do not sell personal data, and we do not share it with advertisers.

Cookies and storage

We do not set any cookies. The site uses your browser’s local storage for the account token (schola_admin_token), theme (theme), recent reading history (st:recent-reading), per-work reader position (st:reader-pos:{work-slug}), reader font scale (st:reader-font-scale), contents width (st:toc-width), per-work facsimile open state and width (st:facsimile-open:{work-slug} and st:facsimile-width:{work-slug}), and temporary unsaved contribution recovery (schola-work-submission-recovery:{recovery-identity}). These values stay in this browser and support site features; recovery drafts are not analytics.

If you make an analytics choice, we also store it under st:reading-analytics-consent. A value of granted is written only when you actively enable analytics; denied records your refusal so we do not ask again. Clearing the choice removes only this key. We do not set analytics, advertising, or preference cookies.

Data we use for OCR training

A core part of the project is improving OCR for scholastic Latin. Approved contributions — paired with the page scan they came from — are used to train and evaluate OCR models, as disclosed in the contributor license grant in the Terms of Service. Training uses the text and scan only; account metadata (username, email) is never part of the training data.

Your rights

Under GDPR you have the right to:

  • access the personal data we hold about you;
  • correct it if it’s inaccurate;
  • ask us to erase your account (see the Terms for what happens to your already-licensed contributions);
  • restrict or object to processing;
  • receive your account data in a portable format;
  • lodge a complaint with the data protection authority in your country.

To exercise any of these, write to contact@scholathomistica.com. We respond within 30 days.

Changes to this policy

If this policy changes in a way that affects how we handle data you’ve already given us, we’ll update the Last updated date and, where the change is material, notify registered users by email.