Privacy Policy
In force from September 23, 2026
How inaporia handles personal data: what we collect when you read, answer and write in the margin, why we collect it, who else receives it, and what you can do about it.
1.Who we are
inaporia (https://inaporia.com) is operated by 4xxi Software Ltd. (“we”, “us”, “our”), registered in England and Wales. For the purposes of UK data protection law, and of the EU General Data Protection Regulation where it applies, we are the data controller of the personal data described in this policy.
Registered address: 23 Leyborne Park, Kew Gardens, TW9 3HB, Richmond, United Kingdom.
Contact for anything to do with your data: [email protected].
This policy covers the whole site: reading, answers at forks, the mirror, margin notes, the Agora, jurors and share cards. You can read a whole book without an account; you need one to answer at forks, write in the margin, react to other readers' answers and invite jurors.
2.What we collect
We collect the following personal data:
- Account data. If you register with an e-mail address and a password, we store your name, your e-mail address, a salted hash of your password (never the password itself) and whether your address has been verified. If you sign in with Google, Google sends us your name, e-mail address and profile picture and whether Google has verified the address, and we store your Google account identifier and the tokens Google issues for the sign-in. From your name we make your display name, which other readers see (“Name in the Agora” in Settings): by default its first word, and you can change it.
- Reading data. Where you are in each book, when you started and finished it, how many days in a row you have read and the last day you read, whether you have been through the introduction, and your settings: language, theme, text size and the switches in Settings, such as public answers and voice input.
- Answers at forks. The option you tapped, or the fact that you skipped the fork; your one-sentence answer and the language it is written in; your private note if you write one; the line of argument your answer was placed in; the mirror written for you; whether the answer is public and whether it has passed screening; whose answer changed your mind, if you say so; and when the answer was written or last edited.
- Margin notes. The words you selected and the paragraph they belong to, the kind of note (a “Lost me” question, “Oh, nice” or “Disagree”), your text and, for a question, the answer written to it.
- Reactions and jurors. The reactions you leave on other readers' answers and the answers you save; the readers you have agreed to read with (jurors); and the invitations you send or receive, including the e-mail address an invitation was sent to, which may belong to someone without an account.
- Share cards. The links to any cards you create to share a fork or your path through a book.
- Session and security data. When you sign in, we store a session record with a session token, the IP address and browser (user agent) it was created from, and its expiry time. We also keep one-time codes for verifying your address, signing in and resetting your password, and rate-limiting counters, kept per IP address, that protect sign-in from abuse.
- Technical records. Server and application logs that we use to find errors and keep the service secure, which record the IP address, the browser and the page of each request, and records of requests to language models (section 4). Logs are not meant to hold the text of your answers or notes, but they may include an e-mail address, for example the one an invitation was sent to.
- Analytics. We use Umami, a privacy-friendly analytics tool that 4xxi hosts on its own server (umami.fourxxi.com). Umami does not use cookies or other identifiers stored on your device and does not follow you across other websites. Like any web request, your browser's request to it carries your IP address and browser details; we see only aggregated statistics, such as pages viewed, countries, browsers and device types. Before a page view is sent, the page removes everything after “?” in the address and replaces the private part of share and invitation links with a placeholder, so the analytics never holds a link that opens anything.
- Correspondence. If you write to us, we keep your message and our reply in order to deal with your request.
A fork asks for your view of an argument in the text, and your answers and notes may reveal your views, including philosophical or religious beliefs. We use them only to provide the service as this policy describes, and other people see them only in the ways set out in section 5. We do not ask for special categories of personal data, and our Terms ask you not to include facts about your own or anyone else's health, religious or political affiliation, ethnic origin, sex life or sexual orientation in answers, notes, margin marks or your display name. If you do include such information in something you make public, you are making it public yourself.
3.How we use your data and why
We process personal data on the following lawful bases under the UK GDPR, and under the EU GDPR where it applies:
- Contract (Article 6(1)(b)): to run your account and sign you in; to keep your place in each book; to store your answers, notes and margin notes; to write the mirror and answer your margin questions (section 4); to show your public answers, your margin notes and your answers to your jurors as section 5 describes; to create the share cards you ask for; and to send the e-mails the service depends on, namely codes and the invitations you ask us to send.
- Legitimate interests (Article 6(1)(f)): to keep the service secure and prevent abuse (sessions, rate limits, logs); to screen public texts before other readers see them, when screening is switched on; to count anonymous totals of answers at each fork; to understand, in aggregate, how the site is used; to check the quality and cost of model responses; and to deliver invitations from other readers, including to people without an account whose address a reader has given us. You may object to processing on this basis (section 10).
- Consent (Article 6(1)(a)): if you write to us, we process your correspondence on the basis of your consent, which you can withdraw at any time.
- Legal obligation (Article 6(1)(c)): where the law requires us to keep or disclose information, for example in response to a lawful request from a public authority.
We do not sell, rent or share your personal data for marketing purposes. There is no advertising on inaporia, and nothing you write is used to show you advertising.
4.Language models
Most of inaporia works without a language model: the option you tap already decides what you see next. A model is used in four places only:
- The mirror, a short comment on your answer. The model receives your one-sentence answer, the fork's question, Socrates' move and the line of argument your answer was placed in. If you leave the sentence empty, nothing is sent.
- Classification, on forks where a tap alone does not decide the line of argument. The model receives your one-sentence answer, the fork's question and its lines of argument, and chooses the line your answer belongs to.
- Margin answers. When you ask a question in the margin, the model receives your question, the words you selected, the paragraph, and the book's title and author. Its answer is stored and shown to every reader of that paragraph.
- Screening. When we switch screening on, a model checks public answers, margin notes and margin answers before other readers see them.
Your private notes are never sent to a model. We do not send your name, e-mail address or account identifier with any of these requests.
Requests go through OpenRouter, a gateway based in the United States, which passes them to the company whose model we have chosen: at present OpenAI for the mirror, classification and margin answers, and Anthropic for screening, both also in the United States. Which model does each task is a setting we control. We may also send a task directly to OpenAI or to Microsoft's Azure OpenAI Service, and we will update this policy if the providers that receive your texts change.
We do not use your texts to train AI models of our own. The providers process them to return a response, under their terms for business customers of their APIs.
For each request we keep a technical record: the model, the number of tokens, the estimated cost, the duration and the purpose. The record may also hold the model's response (for example the mirror or a margin answer, which can restate what you wrote) and an internal identifier of the answer or note it concerns. We use these records to check the quality of responses, find errors and control costs; other readers cannot see them.
The mirror and the classification shape what you see next, and screening only decides whether a text is published; none of them is a decision about you. We do not make decisions that have legal or similarly significant effects on you by automated means.
Voice input is handled by your browser, not by us. If you dictate an answer, your speech is recognised by the browser and, depending on the browser, by its maker's speech service (for example Google in Chrome or Apple in Safari), under that company's terms. We receive only the text you then submit. You can switch voice input off in Settings.
5.What other readers can see
Some of what you write is meant to be read by others. Who sees what depends on what you write and on your settings:
- Public answers. Your answers are private unless you switch on “Public answers” in Settings or in the introduction. While it is on, each one-sentence answer you write is public (once screened, if screening is on) and is shown with your display name to signed-in readers who have answered the same fork: in the Agora, and after they give their own answer. In Settings you can take all your earlier answers out of public view, or publish them, at once. Treat a public answer as published: we display it only in the places described here, but we cannot control what others do with what they have read.
- Private notes are never shown to anyone but you: not in the Agora, not to jurors and not on share cards.
- Margin notes. Every margin note is public. Once it is complete (a question once it has been answered), it is shown with your display name beside its paragraph to everyone who reads it, including visitors without an account, and search engines may index the pages it appears on. You can delete a margin note at any time.
- Jurors. Readers you have agreed to read with see how far along the book you are and, at each fork they have answered themselves, your answer there (or that you skipped it), whether or not it is public. An invitation, whether sent by e-mail or as a link you share, shows whoever receives it your display name and the book; if the address you invite already belongs to an account, your list of invitations shows that account's display name. A reader who sees your public answer in the Agora can invite you to read with them: we send the invitation to the e-mail address on your account without showing that address to them.
- Reactions. Your reactions to other readers' answers, and the answers you save, are not shown to anyone else, including the answer's author.
- Totals. Every answer you give at a fork (your choice, not your words) counts towards the anonymous totals shown to other readers, such as the share who answered the same way, whether or not your answer is public.
- Share cards. Anyone with the link to a card you have made can see it. A card for a fork shows about 140 characters of your answer, Socrates' reply and the share of readers who answered the same way, even if the answer itself is private; a card for your path shows your progress, your run of days and a tally of how your answers compared with Socrates' moves. Neither shows your name, e-mail address or notes. The links are long and random, and search engines are asked not to index them.
Your display name is the first word of your name unless you change it in Settings. If none could be made from your name, the name on your account may be shown in its place at forks, in the margin and to your jurors; you can set a display name in Settings at any time.
6.Cookies and storage on your device
We use only cookies that the site needs in order to work or that remember choices you make. We do not use advertising, analytics or tracking cookies, and no one else sets cookies through inaporia, so we do not show a cookie banner. The cookies are:
- __Secure-aporia.session_token keeps you signed in. It lasts 30 days from when it was last renewed, which happens at most once a day while you use the site. Other short-lived __Secure-aporia.* cookies may be set during sign-in, for example with Google.
- aporia.locale, aporia.theme and aporia.text-size remember your language, theme and text size for one year.
- aporia.onboarded remembers for one year that you have seen the introduction on this device.
- aporia.reading remembers for one year the reading switches chosen in the introduction, such as public answers, so that they apply before you have an account and can be carried over to it when you sign in.
The site also uses your browser's local storage, which stays on your device: an unfinished answer, including a private note, is kept as a draft until you submit it (a draft older than 30 days is ignored); an invitation link you opened is remembered for an hour so that you can accept it after signing in; and a record is kept of which celebrations you have already seen.
You can delete cookies and local storage in your browser settings. Without the session cookie you cannot stay signed in.
7.Who else processes your data
We share personal data only with the following, and only as far as each of them needs it:
- DigitalOcean, LLC, our hosting provider, which runs the servers and the database behind the service, as our processor.
- Resend, Inc., our e-mail delivery provider, which receives your e-mail address and the content of the e-mails we send you (codes and invitations) in order to deliver them, including the address of someone a reader invites.
- Google, only if you choose to sign in with Google. Google authenticates you and returns your name, e-mail address and profile picture, and acts under its own privacy policy.
- OpenRouter and the model providers it passes requests to (at present OpenAI and Anthropic) and, if we choose them, OpenAI or Microsoft's Azure OpenAI Service directly. They receive the texts described in section 4.
- Services that 4xxi runs itself: our log service (Logoverse) and Umami analytics. They are operated by 4xxi, not provided by another company, and our logs go nowhere else.
- Professional advisers, such as lawyers, auditors and insurers, where necessary, and public authorities where the law requires it.
Other readers see what section 5 describes. We do not sell personal data to anyone.
8.International transfers
Your data may be processed outside the United Kingdom and the European Economic Area. In particular, DigitalOcean, Resend, OpenRouter, OpenAI, Anthropic and Google are based in, or have group entities in, the United States. Transfers to them are made under Standard Contractual Clauses or equivalent safeguards approved under the UK GDPR. Where a provider is certified under the UK Extension to the EU-US Data Privacy Framework, that certification may also apply.
9.How long we keep data
We keep personal data only for as long as we need it:
- Your account and everything linked to it (reading progress, answers, private notes, margin notes, reactions, jurors, the invitations you have sent and your share links) for as long as the account exists. If you ask us to delete your account, we delete all of this within one month of your request.
- Sign-in: a one-time code stops working after 15 minutes, and a session ends 30 days after it was last renewed. Session records are deleted with your account.
- Invitations: an invitation stops working after 14 days. The record of an invitation, including the address it was sent to, is kept while the account that sent it exists; the person invited can ask us to delete that address at any time.
- Server and application logs and records of model requests: up to one year, whether or not the account they concern still exists.
- Analytics: page views are kept without cookies and without your name, e-mail address or account, and we use them only as aggregated statistics.
- Drafts in your browser: until you submit the answer or clear your browser's storage.
The totals at each fork are anonymous and are recalculated from the answers that remain.
10.Your rights
Under the UK GDPR, and the EU GDPR where it applies, you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased;
- restrict how we process it;
- receive your data in a structured, machine-readable form (portability);
- object to processing based on legitimate interests;
- withdraw your consent at any time where we rely on it.
Much of this you can do yourself. In Settings you can download your data as a JSON file (“Export my data”), change your display name, make all your answers public or private at once, and switch off voice input. You can change an answer by answering the fork again, delete your margin notes and undo your reactions.
Some things cannot yet be done in the interface: deleting your account or a single answer, ending a juror pairing, disabling a share link, or changing your e-mail address or the name on your account. For these, and for any other request, write to [email protected] from the address on your account, or tell us how we can check that the request is yours. We will respond within one month.
11.Children
inaporia is not intended for anyone under 18, and we do not knowingly collect personal data from anyone under 18. If you are under 18, please do not create an account. If you believe that a child has given us personal data, write to [email protected] and we will delete it.
12.Security
We protect personal data against accidental loss and against unauthorised access, use, alteration and disclosure. Connections to the site are encrypted (HTTPS); passwords are stored only as salted hashes, from which the password cannot be read; the access and refresh tokens received from Google, and the keys for model providers that we keep in the database, are stored encrypted; and access rules in the database keep each reader's private data from other readers: a private note, for example, can be read only by its author.
No system is completely secure. If a breach of security puts your rights at risk, we will tell you and the regulator as the law requires.
13.Changes to this policy
We may update this policy from time to time. Any changes will be posted on this page with a new effective date. Your continued use of inaporia after a change constitutes acceptance of the updated policy.
14.Complaints
If you are unhappy with how we handle your data, please write to us first at [email protected] and we will try to put it right. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at https://ico.org.uk or, if you live in the European Union or the European Economic Area, with the data protection authority of your country.
15.Contact
For any question about this policy or your data, write to [email protected].
By post: 4xxi Software Ltd., 23 Leyborne Park, Kew Gardens, TW9 3HB, Richmond, United Kingdom.