SuttaWiki

Privacy Policy

Effective 14 July 2026

This policy explains what SuttaWiki collects, why it is used, and the choices available to account holders.

Information we collect

If you sign in with Google, we receive your Google account identifier, verified email address, and the display name made available by Google. We use these fields only to authenticate you, link or create your SuttaWiki account, and maintain account security.

Your SuttaWiki profile may also contain a display name, preferred language, affiliation, scholarly expertise, biography, website or ORCID, account roles, and account state. Security records include hashed session and CSRF tokens, hashed user-agent and network-prefix data, MFA assurance, recovery-code hashes, session times, and security or administrative audit events.

Questions submitted to Ask and messages sent in Exploratory Chat may be stored with answer text, evidence references, language and mode settings, review flags, model/backend metadata, and token counts when available. Editorial and administrative actions are recorded for accountability.

How we use information

We use this information to operate accounts, enforce permissions and MFA, prevent abuse, preserve an audit trail, support grounded question answering, and improve the reliability of the service. SuttaWiki does not sell Google user data, use it for advertising, or use Google identity data or account content to train machine-learning models.

Service providers and AI features

Google and Supabase process identity and account data as authentication and database providers. If you deliberately use an experimental AI feature, the text of your question or chat and a bounded evidence pack may be sent to the model service configured by the operator. Its own terms and privacy policy apply to that processing.

Retention and security

Account, session, audit, Q&A, and chat records are kept only as long as needed to operate and secure the current service, meet legitimate audit needs, or complete an approved deletion workflow. Retention periods may differ by record type. We use access controls, opaque sessions, hashing, MFA, and transport security, but no online system can guarantee absolute security.

Your choices

You can review and update your profile and revoke sessions from the Profile page. To request access to, correction of, or deletion of your account data, email admin@suttawiki.org. Deletion is handled through the administrative soft-delete and purge process so identity, session, and audit safeguards are applied consistently.

SuttaWiki also records privacy-limited operational analytics: normalized public routes, response status and latency, interface language, coarse device class, and approximate visible engagement time. A random first-party identifier is stored as an HMAC digest; no IP address, account identity, query string, search text, request body, referrer, or raw user agent is included. These records are retained until an administrator purges them and are available only to administrators. Do Not Track disables the identifier and engagement measurement.

Contact

Privacy and account questions: admin@suttawiki.org.