Privacy Policy
Last updated: 29 July 2026 · Effective date: 28 August 2026
This Privacy Policy explains how IAIC AI RESEARCH & TRADING - FZCO (“we”, “us”) collects, uses, and protects personal data when you use the ENIGMA.IST platform (the “Platform”). This policy is written to comply with the EU General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), and applicable global standards.
Data Controller: IAIC AI RESEARCH & TRADING - FZCO
IFZA Properties, DSO-IFZA, Dubai Silicon Oasis, Dubai, UAE
TRN: 105405840700001 · Reg# 79489
Privacy contact: legal@enigma.ist
1. What data we collect
1.1 Information you provide
- Account data: name, email address, password (hashed), language, timezone.
- Profile data (optional): affiliation, country, position, ORCID, biography, avatar image.
- Payment data: billing name and address, country, postal code (collected by our payment processor).
- Author data (if you submit work): manuscript text, co-author names and emails, supplementary files.
- Communications: messages you send through the Platform’s messenger, comments, support requests.
1.2 Information collected automatically
- Usage data: pages viewed, actions performed, last-seen timestamp, session metadata.
- Device data: IP address, browser, operating system, screen size.
- Service logs: for requests to our application programming interface (
api.enigma.ist) we record the time, the endpoint called, the response status, how long it took, and the originating IP address. These are operational records used to keep the service running, diagnose faults, and detect abuse. - AI usage records: when a feature calls an AI model on your behalf we record which model was used, how many tokens it consumed, what it cost, which of your allowances paid for it, and which feature made the call. The text of the request and the model’s answer are not part of this record.
- Cookies and similar technologies: session cookies for authentication; analytics cookies (Yandex.Metrica) if you consent.
1.3 Information from third parties
If you sign in via a social provider (Google, GitHub, Telegram, etc.) or via Single Sign-On (SSO) from a sister site, we receive the basic profile data those providers share (typically email, name, profile picture).
1.4 The ENIGMA Axiom mail add-on for Thunderbird
The add-on runs inside your own copy of Thunderbird and reads your mailbox there. What it does locally and what reaches us are different things, and the difference is the point of this section.
- Stays on your computer: your mailbox, your folders, the add-on’s own event log, its sending queue, and its per-mailbox counters. None of this is transmitted.
- Copies of the replies it sends, also on your computer: when the add-on sends an automatic reply it keeps that message — the text it wrote and the complete message Thunderbird built from it, with a checksum and the time the outgoing mail server accepted it — in the add-on’s own storage inside your Thunderbird profile. This exists so you can read back what was sent when your mail provider does not keep a copy, and so you can check ours against theirs. It is never transmitted to us. The complete messages are kept for the fifty most recent replies and the text for as long as the row lives; you can delete any of it, or all of it, from the add-on’s settings at any time.
- Two headers travel in the mail the add-on sends, and they reach the person you are writing to.
X-Auto-Response-Suppressasks their mail system not to answer a machine with another machine.X-ENIGMA-Axiomrecords which build of the add-on wrote the reply, the moment it was sent, and a random reference that links it to your own local copy. Neither is visible when the message is read, neither identifies you, and neither carries anything about your account. - Sent to us only to do the work you asked for: when you ask for a reply to be drafted, checked or sent automatically, the message being answered — sender, recipients, subject, date and body — and the draft itself are sent to
api.enigma.istfor that one operation. - The route, in full. The add-on never contacts an AI provider directly. It calls our service, and our service calls the model provider that runs the operation — the providers named in section 3. So the text of the message you are answering reaches that provider, by way of us. If you have stored a provider key of your own, the route is exactly the same: your key changes whose account the call is billed to, not where the text goes.
- How much of it. The body is sent as text, cut at 8,000 characters. Earlier letters from the same correspondence go with it so the reply makes sense in context: by default the last eight (at most twenty, and you set the number), of which only the four most recent carry their text — the rest are sent as subject and date alone — and the whole of that history is cut at 9,000 characters. Attachments are never sent.
- We do not keep your correspondence. Nothing from these operations is written into our database as a record of your mail. The message and the draft exist on our servers only for as long as the request takes; what remains afterwards is the accounting line every AI call produces — which model ran, how many tokens, what it cost, on which plan — and it contains no addresses, no subject and no text. The only mail-related thing we store for you is what you asked us to: your auto-reply policy and the address lists you put on it, and your routing rules — the next point but one.
- Your rules and settings: your auto-reply policy, the address lists you place on it, and your routing rules are stored under your account so they work across devices.
- Diagnostics (planned): we intend to have the add-on report a small technical digest — a random installation identifier, the add-on and Thunderbird versions, the operating system, the interface language, how many mailboxes it watches, and daily counts of drafts, sends and errors. It will carry no addresses, no subjects and no message content. Its purpose is to tell us what is deployed and whether it is working.
1.5 Your own AI provider keys
If you choose to store an API key of your own (a paid-plan feature), we hold it encrypted with a secret kept outside the database, and we never display it again. The interface can show you only the last four digits, when it was last used, and whether the provider refused it — no request returns more than that. You can delete it at any time, which removes it from our database. We record how many tokens were spent on your key so that both of us can see what it did; what your provider charged you is between you and them.
2. How we use your data
We process personal data on the following lawful bases:
- Performance of contract — to operate the Platform, run accounts, deliver paid services, and process payments.
- Legitimate interest — to keep the Platform secure, prevent fraud, improve features, communicate operational updates.
- Consent — for analytics cookies and optional marketing communications. You may withdraw consent at any time.
- Legal obligation — for tax records, accounting, and compliance with UAE / EU regulators where required.
2.1 Statistics and internal reporting
We produce statistics to understand how the Platform is used and what it costs us to run. Two different things are involved, and we describe them separately because they carry different risks to you.
- Aggregate figures — totals and counts by day, by AI model, by feature and by plan. These contain no content, no addresses and no identifiers, and nothing in them can be traced back to a person. This is what we mean when we say our statistics are anonymous.
- Per-account operational views — our administrators can see, for an individual account, its plan, its usage and cost, its last activity, and the IP address of its most recent session. This is not anonymous, and we do not claim it is. It exists so that we can answer support questions, investigate abuse and bill correctly, it is restricted to administrators of our company, and it is subject to the retention limits in Section 5.
We do not build advertising or behavioural profiles, we do not sell any of it, and we do not use the content of your messages, goals or documents to train AI models.
3. Sharing with third parties
We share personal data only with the following categories of recipients, and only as necessary:
- Payment providers: for card payments taken through Paddle — Paddle.com Market Limited and affiliated entities, which act as Merchant of Record, for billing, tax compliance, fraud prevention and refund processing. For other payment methods — the authorised payment provider for the method you select. Which provider receives your payment data depends on the payment method and currency you choose; the seller and the provider are identified at checkout before you pay (see Terms, Section 3.3).
- AI model providers: features that draft, summarise, verify or answer send the text needed for that operation to the model provider that runs it — currently DeepSeek, Anthropic, OpenAI and Google. Only what the operation requires is sent, we do not permit it to be used to train their models, and where a feature can run on a model hosted on our own servers it does so and nothing leaves us. If you have stored a provider key of your own, the call is made with your key and the provider knows it as your account, not ours.
- Email infrastructure: our SMTP provider (Gmail SMTP relay) for transactional and notification emails.
- Hosting and analytics: our cloud hosting provider (Hetzner Online GmbH, Germany) and optional analytics provider (Yandex.Metrica) where you have consented.
- Co-authors and editors: when you submit a paper, your author details are visible to invited co-authors, editors, and assigned peer reviewers in line with editorial workflow.
- Legal authorities: when required by law, valid court order, or to protect the rights, safety, or property of users.
We do not sell or rent personal data to third parties for marketing purposes.
4. International transfers
The Platform is hosted in the European Union (Hetzner Online GmbH, Germany). When we transfer personal data outside the EU/UK (for example, to our headquarters in the UAE or to international service providers), we rely on Standard Contractual Clauses or equivalent legal mechanisms to ensure adequate protection.
5. Retention
We retain personal data only as long as necessary for the purposes described above:
- Account data: while your account is active, plus up to 12 months after closure;
- Published articles and authorship records: indefinitely (academic-record integrity);
- Payment and tax records: 7 years (UAE and EU tax-law minimum);
- Server and service logs, including the IP addresses in them: 90 days;
- Site activity records: 90 days;
- Verification records (the claims you submit for checking, stored encrypted): 30 days;
- AI usage records (model, tokens, cost — no content): 24 months, because they are also our accounting of what the service cost;
- Add-on diagnostics: 90 days;
- Your stored provider key: until you remove it, and in any case not beyond 12 months from when you last replaced it, or 90 days after it was last used;
- Aggregate statistics (no content, no identifiers): kept indefinitely, because they are no longer personal data;
- Marketing-consent records: until you withdraw consent.
Deletion is carried out by a scheduled process, not on request only: records past their window are removed automatically. Where a record must survive for a legal reason — a payment, a published article — it is named above.
6. Your rights (GDPR / UK / UAE PDPL)
Subject to applicable law, you have the right to:
- Access — request a copy of personal data we hold about you;
- Rectification — correct inaccurate or incomplete data;
- Erasure — request deletion (subject to legal-retention obligations such as published-article integrity);
- Restriction — ask us to limit processing in certain circumstances;
- Portability — receive your data in a machine-readable format;
- Object — object to processing based on legitimate interest or for direct marketing;
- Withdraw consent — for processing based on consent (e.g. analytics cookies, marketing emails);
- Lodge a complaint — with your local data-protection authority (in the EU: your national DPA; in the UK: ICO; in the UAE: UAE Data Office).
To exercise any right, email legal@enigma.ist. We will respond within 30 days.
7. Cookies
The Platform uses three categories of cookies:
- Strictly necessary: session cookie for authentication (no consent required by law).
- Functional: language and timezone preferences (set only when you change them).
- Analytics: Yandex.Metrica counter to understand usage patterns — only loaded after you accept analytics cookies in our cookie banner.
You can clear cookies in your browser at any time. Disabling strictly-necessary cookies will prevent you from logging in.
8. Security
We protect personal data with appropriate technical and organisational measures, including TLS/HTTPS encryption in transit, password hashing (bcrypt), encrypted database backups, principle-of-least-privilege access controls, and regular security audits. The content you entrust to us that is most sensitive — the claims you submit for verification, your goals and notes, and any AI provider key you store — is additionally encrypted at rest in the database (AES-256 via pgcrypto), and the secret that unwraps a stored provider key is held outside the database, so a copy of the database alone does not yield it. No system is perfectly secure; if a personal-data breach occurs, we will notify affected users and the relevant supervisory authority within 72 hours where required by law.
9. Children
The Platform is not directed to children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with data, please contact legal@enigma.ist and we will delete it promptly.
10. Changes to this policy
We may update this Privacy Policy. Material changes will be notified to registered users by email at least 30 days before they take effect. The “Last updated” date at the top reflects the most recent revision.
11. Contact
Questions or requests under this policy: legal@enigma.ist.
Postal: IAIC AI RESEARCH & TRADING - FZCO, IFZA Properties, DSO-IFZA, Dubai Silicon Oasis, Dubai, UAE.