Axiomyx Privacy Notice
Document version: 1.2 Effective date: 2026-09-02 Last updated: 2026-09-02
1. Who this notice covers
This notice explains how AXIOMYX LIMITED, NZBN 9429052870873, New Zealand Companies Office company number 9345215, status Registered (Axiomyx) handles personal information connected with Axiomyx Personal, Business, and Enterprise.
Privacy Officer: Alex Veldman. Privacy contact: av@axiomyx.tech.
Private Edition is customer-hosted, but that does not mean Axiomyx receives no personal information. The data boundary depends on the activity.
2. Information categories
Customer-controlled operational data
Operational records, indexes, prompts, model inputs and outputs, provenance records, and similar Customer Data are stored in customer-controlled infrastructure during normal operation. The Customer chooses and controls the location of PostgreSQL and operational storage. Axiomyx does not host or take custody of that operational data in the standard Private Edition product.
Private Edition does not modify source systems by default. It writes derived canonical objects, signatures, indexes, and provenance into the customer-controlled Axiomyx data layer.
The Customer determines what operational data is processed, why it is processed, who can use it, and which infrastructure, model providers, and connectors receive it. The Customer is responsible for its own Privacy Act and other legal obligations for that data.
Commerce and account data
Apple or Microsoft can process Personal distribution and account information and, when Premium is purchased, billing, order, subscription, tax, refund, and fraud-prevention information under the relevant store terms. Lemon Squeezy and its payment providers can process corresponding information for Business orders. Axiomyx does not receive complete card details through those checkout flows.
Axiomyx can receive order, customer, product, subscription, licence, payment-status, and refund-status information needed to supply and administer the Software.
Activation and entitlement data
Activation or store-entitlement checks can process an opaque customer or order reference, Free or Premium plan status, subscription status, product and tier, installation UUID, deployment kind, release identifier, activation count, request time, response time, and limited security or error logs.
Personal calculates Active Evidence usage locally from supported source-file sizes. Normal local operation does not require the file names, file content or current evidence-usage total to be sent to Axiomyx for Free-plan enforcement.
The local installation UUID is intended to be randomly generated and is not a device fingerprint. The licence key is sent as an activation credential but is not intended to appear in the signed Entitlement or be stored by the customer runtime after activation. Axiomyx applies operational controls intended to keep raw licence keys out of logs and to limit service-side handling and retention.
The signed Entitlement should contain commercial and operational claims, not customer operational records or complete payment details.
Support, diagnostics, and communications
If a Customer contacts Axiomyx, Axiomyx can receive contact details, correspondence, installation and release information, configuration information, logs, diagnostics, and files the Customer chooses to provide. Support should normally use synthetic or minimised reproductions and customer-reviewed sanitised diagnostics. Customers should remove secrets and unnecessary personal or operational data before sending material.
3. Collection sources
Axiomyx may collect information:
- directly from the Customer through enquiries, support, Enterprise discussions, and activation requests;
- from Apple or Microsoft in connection with Personal distribution and Premium orders, subscriptions, entitlements, refunds, and disputes;
- from Lemon Squeezy in connection with Business checkout, orders, subscriptions, licence keys, refunds, and disputes;
- from Axiomyx activation, download, update, website, email, or security systems;
- from Authorised Users or administrators acting for a Business customer; and
- from service providers used to operate those functions.
Where personal information is collected indirectly, Axiomyx must comply with the Privacy Act 2020, including Information Privacy Principle 3A where applicable, or document a lawful exception.
Axiomyx reviews indirect collection from platform stores, Lemon Squeezy, customer administrators, and service providers against applicable notification requirements, including Information Privacy Principle 3A.
4. Purposes
Axiomyx may use relevant personal information to:
- answer sales and product enquiries;
- confirm Free or Premium plan status, orders, subscriptions, tier, payment status, refunds, and licence eligibility;
- activate installations and issue verifiable Entitlements;
- enforce agreed installation and Deployment limits;
- deliver downloads, updates, security notices, and support;
- diagnose defects and protect customers, systems, and credentials;
- maintain accounting, audit, dispute, and legal records;
- prevent fraud, abuse, and security incidents;
- comply with law; and
- improve the Software using appropriately limited information.
Axiomyx should not use submitted support content to train general-purpose models unless the Customer has been clearly informed and has provided any consent required by law and contract.
5. Service providers and overseas disclosure
Provider categories include:
- Apple and Microsoft: Personal store listing, distribution and account functions, plus Premium payment, tax, receipt, subscription, entitlement, refund, and dispute functions. This category does not imply that Customer operational data is sent to Apple or Microsoft by Axiomyx.
- Lemon Squeezy and its payment providers: Business checkout, merchant-of-record services, payment, tax, receipt, subscription, licence-key, refund, and dispute functions. This category does not imply that Customer operational data is sent to Lemon Squeezy.
- Google Cloud: private activation-service hosting, service authentication, limited activation logs, and Cloud KMS signing. Customer operational data is not required for those functions and is not intended to be sent to Google Cloud by the standard activation flow.
- Email, support, domain, and security providers: communications and operational protection used by Axiomyx.
- Customer-selected providers: identity, PostgreSQL hosting, infrastructure, external models, connectors, observability, and backups selected and controlled by the Customer.
Provider systems may process information outside New Zealand. Axiomyx must maintain an appropriate provider record and assess overseas disclosures it initiates under Information Privacy Principle 12 and related Privacy Act requirements. A Customer's own disclosure to a provider it selects remains the Customer's responsibility, but Axiomyx remains responsible for accurately describing disclosures its Software or services initiate.
Axiomyx maintains and revisits its Information Privacy Principle 12 assessment for overseas disclosures it initiates, including limited account, commerce, licence, activation, and support metadata that Axiomyx or its providers may process outside New Zealand.
6. Operational model and connector data
Private Edition does not require Axiomyx to receive operational Customer Data for its core local canonicalisation, signature, storage, retrieval, provenance, export, and deletion functions.
Data can leave customer-controlled infrastructure when the Customer configures an external model, connector, identity provider, database, backup destination, logging service, or other external system. Data can also leave when a Customer sends support material. The Customer must evaluate the recipient, region, privacy terms, security, retention, and legal authority.
Axiomyx must not claim that operational data can never leave customer infrastructure. The accurate statement is that Axiomyx does not require custody of that data for normal local operation, subject to Customer configuration and voluntary disclosures.
6A. Optional connection to ChatGPT and Codex
Axiomyx Personal can connect your indexed evidence to OpenAI services such as ChatGPT and Codex. You choose which sources to add to Axiomyx and approve the connection using the code shown during setup. The connection permits read-only searches, retrieval of evidence, source information, provenance checks and basic service-status checks. It does not provide tools to change or delete your files, run commands or place trades.
Your original files and local evidence index remain on your computer. However, when the connected OpenAI service calls an Axiomyx tool, the request and returned evidence pass through an Axiomyx-operated internet relay. The relay processes that information to deliver the result to the connected service. This optional hosted processing is an exception to descriptions of wholly local operation elsewhere in our notice.
The connection is not approval of each individual excerpt. After connection, the AI can request information from the sources available in your index to help answer your requests. Only add material you are authorised to make available in this way.
Information processed by the connector
Depending on which tool is used, the information can include:
- Search terms and tool parameters, including source or evidence identifiers.
- Retrieved text and search-result excerpts. These may contain personal or sensitive information present in your selected files, including information about other people.
- Source names, document names and relative paths, source/document/evidence identifiers, and locations within documents used to identify supporting evidence.
- Provenance details such as document type, size, content checksum, indexing date and chunk position; source summaries such as document/chunk counts and total indexed size.
- Basic operational information such as readiness, database availability, storage type, app version, distribution channel and limited licence/edition status. The status response is filtered; it is not a copy of your local configuration or credentials.
- Connection and authorisation information: the requesting client's identifier/name and callback address, temporary approval data, authentication tokens while being processed, a token-derived device identifier, connection/activity timestamps and application state.
The relay persistently stores a hash of each issued access token, a token-derived device-routing identifier, and authorisation/expiry timestamps. It does not persist the original access token or your document text in that authorisation file. Hashed identifiers still link a connection to a device and should not be treated as anonymous information.
Network and hosting systems also process connection information, such as IP addresses. The relay's routine HTTP audit records contain a timestamp, request method, URL path and response status. Paths can contain an opaque citation identifier. The routine audit does not record request/response bodies, authentication headers or URL query strings. Infrastructure or fault logs are separate from this routine audit.
Why we process it and who receives it
We use this processing to authenticate the connection, route your requested read operations to the correct computer, return supporting evidence, maintain availability and investigate technical or security problems.
The relay currently runs on Google Cloud infrastructure in the United States. Google Cloud provides the hosting and associated infrastructure services. Axiomyx's service processes the information in readable form while forwarding it: internet connections are encrypted in transit, but the route is not end-to-end encrypted against Axiomyx's relay.
OpenAI receives the tool requests/results used with its service. OpenAI's handling of that information, including storage, use and deletion, depends on the applicable service, account arrangements and your settings. Review the OpenAI privacy policy and any applicable business agreement. Removing data from Axiomyx does not remove a result already delivered to OpenAI.
The Axiomyx relay has no document-training, advertising or resale workflow. It does not create a hosted copy of your complete local index. Any support material you separately choose to send us remains subject to the support provisions of our main privacy notice.
Storage and retention
Local files and indexes remain subject to your local storage and backup choices. Removing a source from Axiomyx removes it from the active index, not the original files or every backup copy.
The relay forwards requests and evidence in memory rather than writing them to a hosted evidence repository or its routine HTTP audit log. In-memory request and connection state is released as requests and connections finish or time out. This is not a promise of immediate secure erasure of every memory buffer.
Temporary approval requests are valid for five minutes; authorisation codes are valid for two minutes and can be exchanged once. These validity limits are not guaranteed memory-deletion deadlines: expired temporary OAuth entries are cleaned when the OAuth handler runs again, or disappear on service restart. Registered client metadata is held in memory until the service restarts.
Access authorisations expire after 365 days unless revoked earlier. Successful relay-side revocation removes the associated active record from the authorisation file. We run hourly cleanup to delete expired records from the active store within 24 hours during normal service operation. Expired records and stale temporary copies are also cleaned before the relay becomes ready after startup. Expiry prevents further use even before the cleanup runs. A cleanup failure is reported in service health and retried; these controls are not a claim of instantaneous physical erasure from every underlying storage medium.
Routine application logs from the Personal relay and its shared HTTPS gateway are sent to Google Cloud Logging under a 30-day retention policy, measured from each log entry's original timestamp. Persistent local container-log caches are disabled. Separate Google Cloud administrative, system-event and access-transparency audit records are retained for 400 days in Google's locked required-audit bucket. These are configured retention policies, not a promise of instantaneous physical erasure from every underlying storage medium.
OpenAI-held information, support correspondence, store transactions and licensing records have separate retention arrangements. The connector's retention periods must not be presented as applying to all of those records.
Your controls
- Choose what to index. Use Remove from Axiomyx to disconnect and remove an indexed source; your original files are not deleted. This cannot recall evidence already sent to another service.
- Disconnect the app in the connected OpenAI service to stop using that connection there. Do not assume this also deletes Axiomyx's stored authorisation metadata: automatic relay-side revocation on that action has not been established.
- On the reviewed macOS app, use the application's Quit action to stop the running application/service. Merely closing its window can leave it available in the background. Restarting an approved connection may make the evidence available again.
- Disable start at login controls automatic startup at future logins. It does not revoke the OpenAI authorisation or delete evidence, and the current local session remains available until quit.
- Use OpenAI's own account/data controls for information already held there.
For access, correction or deletion requests concerning information held by Axiomyx, contact av@axiomyx.tech. We may need to verify your identity or authority and identify the relevant connection. Do not email passwords, authentication tokens or your complete evidence library. The access, correction, complaints and security provisions of our main notice continue to apply.
7. Retention
Axiomyx retains personal information only for a lawful purpose and no longer than reasonably required. Retention for commerce records, activation logs, security logs, support cases, communications, and backups is governed by operational, accounting, security, support, dispute, and legal requirements. Information is deleted or de-identified when it is no longer reasonably required, subject to lawful holds and backup cycles.
Customer operational data remains subject to Customer-configured storage and retention. Trial expiry, cancellation, non-renewal, or activation denial does not instruct the runtime to delete, encrypt, transfer, or seize retained Customer Data.
8. Security
Axiomyx will use safeguards reasonable for the information and service, including access control, least-privilege service identity, protected signing keys, public-key entitlement verification, secret-handling controls, logging discipline, and incident response appropriate to the final operation.
No internet-connected system is risk-free. Customers remain responsible for securing their infrastructure, databases, identity providers, networks, credentials, backups, endpoints, connectors, and Authorised Users.
9. Access and correction
Individuals may ask whether Axiomyx holds personal information about them and request access to or correction of that information, subject to the Privacy Act 2020. Requests should be sent to av@axiomyx.tech. Axiomyx may need to verify identity and authority before responding.
For operational Customer Data held only in customer-controlled infrastructure, the request should ordinarily be directed to the Customer organisation that controls that data.
10. Privacy complaints and breaches
Privacy questions or complaints should be sent to av@axiomyx.tech. The Privacy Officer will assess the matter and coordinate an appropriate response. Individuals may also have the right to complain to the New Zealand Office of the Privacy Commissioner.
Axiomyx will assess suspected privacy breaches and notify affected people and the Commissioner where required by the Privacy Act. Customer responsibilities for incidents in customer-controlled infrastructure should be addressed in deployment and Enterprise terms.
Changes to this Privacy Notice
AXIOMYX LIMITED may update this Privacy Notice from time to time. The current version and effective date will be published on the Axiomyx website. Where a change materially affects how personal information is collected, used, disclosed or retained, AXIOMYX LIMITED will provide reasonable notice before the change takes effect where practicable or legally required.
Contact
Privacy Officer: Alex Veldman Privacy contact: av@axiomyx.tech Legal notice contact: av@axiomyx.tech
Effective date: 2026-09-02
Questions about this document: av@axiomyx.tech