Privacy Policy

Last updated: August 24, 2026

1. Overview

Universal Life Source ("ULS", "we", "us") operates the website universallifesource.com, a Catholic bioethical research platform. This Privacy Policy describes how we collect, use, and protect your information when you use our service.

We are committed to protecting your privacy and complying with applicable data protection laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Email address (used for login and account communication)
  • Display name (provided by you or your identity provider)
  • Account creation date

2.2 Research Data

When you use the platform, we store:

  • Search queries you submit
  • Journal entries you create (questions, AI-generated answers, citations, personal notes)
  • Research sessions and saved passages
  • Research agent chat history

This data is tied to your account and is not shared with other users unless you explicitly share a journal entry via a share link.

2.3 Technical Data

We automatically collect:

  • IP address (for security, rate limiting, and abuse prevention)
  • Browser type and user agent
  • Authentication timestamps and session tokens
  • Audit logs of actions performed (logins, searches, data changes)

2.4 BYOK API Keys

If you use the Bring Your Own Key (BYOK) feature, your AI provider API key (OpenAI or Anthropic) is encrypted using Fernet symmetric encryption (AES-128-CBC with HMAC authentication) before being stored in our database. The encryption key is stored in a secure environment variable, not in the database.

3. How We Use Your Information

  • Authentication: To verify your identity and manage your session
  • Service delivery: To process your searches, generate AI answers, and store your research
  • Security: To detect and prevent abuse, enforce rate limits, and maintain audit logs
  • Communication: To send account-related emails (verification, security notices)
  • Improvement: To understand usage patterns and improve the platform

4. Third-Party Processors

We use the following third-party services to operate the platform. Each processes data on our behalf as a data processor:

Service Purpose Data Shared
Logto Authentication (OIDC) Email, name, password (hashed by Logto)
Cloudflare CDN, TLS, DDoS protection IP address, request metadata
Railway Application hosting, database All application and database data
OpenAI AI answer generation Search query and retrieved passages (no personal data)
NVIDIA Query embeddings for semantic search Search query text (no personal data)
SendGrid Transactional email Email address, email content

Important: OpenAI and NVIDIA receive only the search query text and retrieved source passages — they do not receive your name, email, journal entries, or any personal data.

5. Data Retention

  • Account data: Retained while your account is active. Deleted within 30 days of account closure request.
  • Research data: Retained while your account is active. You can delete individual journal entries at any time.
  • Audit logs: Retained for 90 days, then automatically purged.
  • Session data: Expires after 8 hours of inactivity.

6. Your Rights (GDPR / CCPA)

You have the following rights regarding your personal data:

  • Access: Request a copy of your personal data
  • Rectification: Request correction of inaccurate data
  • Erasure: Request deletion of your account and associated data
  • Portability: Request export of your data in a machine-readable format
  • Objection: Object to processing of your data for specific purposes
  • Withdrawal of consent: Withdraw consent for data processing at any time

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

7. Data Security

We implement the following security measures to protect your data:

  • TLS 1.3 encryption for all data in transit (via Cloudflare)
  • Encrypted database connections (SSL/TLS)
  • Fernet symmetric encryption for BYOK API keys at rest
  • HttpOnly + Secure + SameSite session cookies
  • OIDC authentication via dedicated identity provider (Logto)
  • CSRF protection on all forms
  • Rate limiting to prevent brute-force attacks
  • Content Security Policy (CSP) and security headers on all responses
  • Audit logging of all security-relevant actions
  • Multi-factor authentication support (via Logto)

8. Data Location

Application and database data is hosted on Railway in the US East region. Authentication data is hosted on Logto Cloud (US). Email delivery is handled by SendGrid (US). AI processing is handled by OpenAI (US) and NVIDIA (US). All data is stored and processed within the United States.

9. Children's Privacy

This service is not directed to children under 13. We do not knowingly collect personal data from children under 13. If you believe we have collected data from a child under 13, please contact us and we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. We encourage you to review this policy periodically.

11. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at [email protected].