Privacy Policy
Scope
This policy explains what personal data Bizarus AI collects when you use bizarus-ai.com, why we collect it, who else it reaches, and what rights you have over it. It covers both the public site and the authenticated research environment.
Bizarus AI (Mauritius) is the controller of the personal data described here. The contact page is how to reach the controller, including for any request about your data; a message sent there goes to the person responsible for this policy.
What we collect
If you only read the public site
Almost nothing. There is no analytics, no advertising and no tracking, and no cookie is set unless and until you sign in. Our web server keeps ordinary request logs, which include IP addresses, for security and diagnostic purposes.
If you contact us
The name, email address and message you submit through the contact form, so we can reply.
If you hold an account
At present, accounts are created by an administrator and there is no public sign-up; that is expected to change in future, and this policy will be updated before it does. We hold your name and email address, a one-way hash of your password (we never store the password itself), and, if you enable two-factor authentication, the secret your authenticator app uses and one-way hashes of your backup codes.
For security we record sign-in events: the account, the IP address, the browser's user-agent string and the time. This is what allows us to tell you when your account is used from a location it has not been used from before.
Your research content
Research sessions, questions, evidence records, argument structures, contradiction markers, search logs, checkpoints and the commands you send to the assistant, together with the responses returned.
Why we process it, and on what basis
To provide the service you have asked for, which is the performance of our agreement with you. To keep accounts and the platform secure, to prevent abuse and to keep audit records, which is our legitimate interest and in places a legal obligation. To reply to messages you send us, which is your request. To send service messages such as invitations, password resets and security alerts, which is necessary to operate an account.
We do not process your data for advertising, we do not profile you, and we do not sell or rent personal data to anyone.
Third parties that process your content
This section deserves your attention, because it is the one most people would not guess.
When you ask the assistant for help, the text of your request and the relevant research context are transmitted to a third-party AI provider to generate a response. Depending on availability, that provider is Google (Gemini), Groq, or OpenRouter. Each is an independent controller of the data it receives and applies its own terms and retention practices. If none is available, the system falls back to a deterministic local component and nothing leaves our server.
Because of this, you should not enter personal data about identifiable third parties, confidential material, or anything covered by a non-disclosure or ethics condition, into the assistant.
Other processors we use: Hetzner Online GmbH for hosting; Zoho for sending email; Google Drive as an off-server destination for encrypted database backups; and Google Fonts, which is requested by your browser when a page loads and therefore receives your IP address. When you search for literature, queries are sent to the public scholarly databases OpenAlex and Crossref.
The donation link on this site points to Ko-fi. Following it takes you to their site, which has its own policy; we receive no data from it beyond what any recipient of a donation would see.
Data about your research participants
A point that matters more here than on most sites, and that no standard privacy policy would cover.
If you enter personal data about identifiable people into the Service, for example interview transcripts or survey responses, you remain the controller of that data and we do not become one. We have no relationship with your participants, no basis on which to process their data, and no way to honour a request one of them might make. Our Terms of Service ask you not to enter such material for exactly this reason.
If it is entered anyway it is transmitted to a third-party AI provider whenever the assistant is used, which cannot be undone. Bring de-identified summaries here and keep identifiable data in your institution's approved environment.
Making a request about your data
Send it through the contact page and say what you want: a copy of your data, a correction, deletion, a portable export, or that we stop a particular use.
We will acknowledge within five working days and respond substantively within one month, or sooner where your local law requires it. If a request is unusually complex we will tell you why and when to expect an answer, rather than letting it lapse silently.
We may need to confirm you are who you say you are before acting, particularly for deletion or export. We will ask for the minimum needed to be satisfied, and will not use anything supplied for identity checking for any other purpose. There is no charge unless a request is manifestly excessive or repetitive, in which case we will say so before doing anything.
Two limits worth stating in advance. Deleted content persists in encrypted backups until they age out, as described above. And audit and sign-in records are the security history of an account: we retain them where we have a legitimate interest or a legal obligation to do so, and will tell you if that is why a deletion request is only partly met.
Tracking signals
There is nothing here to opt out of. We run no analytics, no advertising, and no cross-site tracking, so Do Not Track and Global Privacy Control signals have nothing to disable. We do not change what we collect based on those headers because we do not collect anything they are designed to stop.
International transfers
The providers above operate across several countries, so your data may be processed outside the country you are in. Where a transfer leaves a region with data-protection rules, it relies on that provider's published safeguards, such as standard contractual clauses or an adequacy decision.
How long we keep it
Account records and research content are kept while the account is open. If an account is archived it leaves the working list but its records are retained, so that audit history remains intact.
Backups are taken nightly, kept for fourteen days on the server and replicated off it. Content you delete will therefore persist in backups for up to that window before ageing out.
Contact messages are archived rather than deleted, so we keep a record of correspondence. Sign-in and audit records are kept as the security history of the account.
You can ask us to delete your data. See your rights below.
How it is protected
Passwords are hashed with bcrypt and never stored or logged in readable form. Two-factor secrets, backup codes, invitation tokens and password-reset tokens are stored only as hashes or are single-use, and none of them is ever written to a log. The site is served over HTTPS. Administrative sign-in is separated from ordinary sign-in, is rate limited, can require a second factor, and can be restricted to specific IP addresses.
No system is perfectly secure. If a breach affects your personal data and is likely to present a risk to you, we will tell you and any relevant regulator as the law requires.
Automated decision-making
The assistant generates suggestions, critiques and summaries. None of this produces a decision with legal or similarly significant effect about you. A human, you, decides what to accept. Promotion of any finding into your knowledge base is always a human action and is never automatic.
Your rights
Depending on where you live you may have the right to access the personal data we hold about you, to have inaccurate data corrected, to have data erased, to restrict or object to processing, to receive your data in a portable form, and to withdraw consent where processing relies on it.
To exercise any of these, write to us through the contact page. We will respond within the time your local law requires, and within one month where no shorter period applies.
Bizarus AI is established in the Republic of Mauritius, so processing is primarily governed by the Mauritius Data Protection Act 2017, which grants rights closely comparable to those above. If you are dissatisfied with how we have handled your data you may complain to the Data Protection Office of Mauritius, which is the independent supervisory authority under that Act.
If you are in the European Union or the United Kingdom, the GDPR or UK GDPR may also apply to your data, and you may instead complain to the supervisory authority in your own country. We do not treat the two regimes as alternatives: where they differ, we apply the standard more protective of you.
Children
This service is intended for researchers and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
Changes to this policy
We will update this policy as the service develops. The date at the top shows when it last changed. Where a change materially affects account holders we will notify them by email.
Contact
Questions about this policy, or requests relating to your data, can be sent through the contact page.
About this policy
This policy describes what the system actually does, rather than what a template assumes a website does. The list of third parties in it was compiled from the running service, which is why it names the specific AI providers your content reaches and the font service your browser contacts on every page load.
If the way the service works changes, this page changes with it and the date at the top moves.
Issued by Bizarus AI (Mauritius).