Privacy Policy
Last updated: September 2026
1. Who we are
Anatium is operated by Nikolas Patso, c/o IP-Management #11193, Ludwig-Erhard-Str. 18, 20459 Hamburg, Germany. We are the controller for the personal data described here. For anything to do with your data, write to support@anatium.com or use the contact form on anatium.com.
2. What we store
Account: your email address, your display name, your password in the hashed form our authentication provider keeps it, whether two factor authentication is on, and your role on the platform. Access request: when you ask for access we store the name, occupation, reason and referral source you give us, and the country you select. Learning: your progress through modules and lessons, quiz scores and attempts, flashcard progress, clinical case and diagnostic exercise progress, article highlights and which articles you have marked read, your unit and language preferences, and a count of how often each clinical calculator is used. Security: email verification records, which include your full IP address and a device identifier; device registrations, which include an IP address; and sign in history, which includes a shortened IP address, your browser's user agent string, a device identifier and a two letter country code. The distinction matters, so it is stated plainly: verification records hold your IP in full, while the sign in history holds only a shortened form of it. Messages: contact form messages, including the name, email address and text you send, and your full IP address for thirty days; support chat conversations; and feedback you submit. Galen AI: your conversation messages, a running count of tokens used, and a per request record used to work out what the service costs us. Social: friend requests, and, if you turn it on, your appearance on the leaderboard. Contributors: if you apply to contribute, the biography, areas and country you provide. Administration: a log of actions taken by administrators in the content management tools.
3. Why we process it, and on what legal basis
Running your account and recording your progress: necessary to provide the service you signed up for, Article 6(1)(b) GDPR. Sending service emails such as verification codes and account notices: also necessary to provide the service, Article 6(1)(b) GDPR. Preventing abuse, including bulk automated signups, repeated failed logins and contact form spam: our legitimate interest in keeping the platform and its users secure, Article 6(1)(f) GDPR. Knowing which countries our users are in, at country level only: our legitimate interest in understanding who we serve, Article 6(1)(f) GDPR. Answering your messages: our legitimate interest in replying to people who contact us, Article 6(1)(f) GDPR, or the performance of our agreement with you where the message concerns your account. Showing your name on the leaderboard: only if you switch it on, on the basis of your consent, Article 6(1)(a) GDPR. You can withdraw that consent at any time in Profile and Settings, and withdrawing it does not affect anything done beforehand. Handling access requests and contributor applications, and providing Galen AI when you use it: necessary to take steps at your request before and under our agreement with you, Article 6(1)(b) GDPR. Providing an email address is necessary to create an account. Without one we cannot give you access.
4. Where your data is stored
Our database and authentication run on Supabase in the London region of the United Kingdom. Your account, your progress and everything else listed above is held there. The United Kingdom is covered by an adequacy decision of the European Commission under Article 45 GDPR, which means personal data may flow there from the European Economic Area without further safeguards. The Commission renewed its 2021 decisions for the United Kingdom in December 2025. Should that decision lapse or be withdrawn, the Standard Contractual Clauses in our agreement with Supabase apply instead, and they also cover any access to the data from outside the United Kingdom. We are on Supabase's free plan, which does not include project backups. This has a consequence worth stating: when data is deleted it is gone, and we cannot restore it from a backup, neither for you nor for us.
5. Who else handles your data
We do not sell your personal data. These providers process it on our instructions, under data processing agreements: Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, United States. anatium.com is proxied through Cloudflare, which means every request reaches Cloudflare before it reaches our host, including your IP address and the address of the page you asked for. Their data processing agreement relies on the European Commission's Standard Contractual Clauses and states that Cloudflare complies with the EU-U.S. Data Privacy Framework. Their published self-serve terms do not name a separate contracting entity for the European Economic Area, so we name the entity their data processing agreement names. Supabase Pte. Ltd, 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513, privacy@supabase.io. Database and authentication, stored and processed in the London region. Their data processing agreement forms part of their terms of service, and accepting those terms constitutes signing the European Commission's Standard Contractual Clauses, Module Two, controller to processor. Render Services, Inc., 525 Brannan St, San Francisco, CA 94131, United States, privacy@render.com. Website hosting. Processing is primarily in the United States, covered by the EU-U.S. Data Privacy Framework, with the Standard Contractual Clauses as a fallback. Their data processing agreement is incorporated into their terms. Plus Five Five, Inc., trading as Resend, 2261 Market Street #5039, San Francisco, CA 94114, United States, privacy@resend.com. Delivery of our transactional email, such as verification codes and contact form notifications. Certified under the EU-U.S. Data Privacy Framework including the UK Extension, with the Standard Contractual Clauses, Commission Decision 2021/914, incorporated as a fallback. Their data processing agreement is incorporated into their terms. Anthropic Ireland, Limited, 6th Floor South Bank House, Barrow Street, Dublin 4, Ireland, company registration number 760497. Anthropic provides the Galen AI assistant, and this is the contracting party for customers in the European Economic Area, Switzerland and the United Kingdom. The messages you send to Galen are transmitted to Anthropic to generate a reply. Their data processing agreement is incorporated automatically into their commercial terms, and the safeguard for data leaving the European Economic Area is the Standard Contractual Clauses set out in that agreement. flagcdn.com serves small country flag images inside the administration dashboard only. It is never loaded on any page a learner sees, so an ordinary visit to Anatium sends nothing to it.
6. Transfers outside the European Economic Area
Several parts of the service involve a processor outside the European Economic Area, and each relies on a named safeguard. Every request to anatium.com passes through Cloudflare before reaching our host. Cloudflare relies on the Standard Contractual Clauses, and states that it complies with the EU-U.S. Data Privacy Framework. The database is in the United Kingdom, which is covered by the European Commission's adequacy decision described above. Hosting is in the United States with Render, under the EU-U.S. Data Privacy Framework, with the Standard Contractual Clauses as a fallback. Email delivery is in the United States with Resend, under the EU-U.S. Data Privacy Framework including the UK Extension, with the Standard Contractual Clauses as a fallback. Messages to Galen AI go to Anthropic Ireland, Limited, which is established in Ireland. Anthropic processes that data outside the European Economic Area, including in the United States, and the Standard Contractual Clauses in their data processing agreement cover that processing. You can ask us for a copy of the safeguards that apply. If you would rather no message of yours reaches Anthropic, simply do not use Galen AI. Every other part of Anatium works without it.
7. How long we keep data
Account and learning data: for as long as your account exists, and deleted when you ask us to delete it. Email verification records, including the full IP address they carry: thirty days, then deleted automatically. Device registrations and sign in history: twelve months, then deleted automatically. Contact form messages: the message is kept until it has been dealt with. The IP address attached to it is erased after thirty days, because it exists only to limit how often the form can be used from one connection. Galen AI conversations: your most recent fifty messages. Older ones are deleted automatically. Daily usage counters are kept for thirty days. Records of what each request cost us are kept as accounting history and hold no conversation text. Administration logs: kept as a record of who changed what in the content tools. Our providers keep their own technical logs, and most of them publish no figure for how long. Supabase does not state a retention period for its audit and traffic logs. Render does not state one. Cloudflare's data processing agreement states no fixed period either, tying retention to the life of the agreement instead. Anthropic deletes inputs and outputs from its systems within thirty days of receipt or generation, with exceptions for custom retention arrangements, enforcement of its usage policy and legal compliance. Resend does not publish a retention period for delivery records that we have been able to verify. Where a provider publishes nothing we say so, rather than quote a number we cannot stand behind.
8. Cookies and browser storage
Anatium sets no advertising cookies, uses no analytics, and loads no third party tracking of any kind. There is nothing here to consent to, which is why you are not asked. What we do store on your device, all of it strictly necessary to run the service you asked for, or a preference you set yourself: Your sign in session, kept by our authentication provider so you are not logged out on every page. Your language choice, so the site opens in the language you picked. A marker that your second factor has been verified on this device. Two short lived markers that remember, for the current tab only, that your access request is pending and that the Galen introduction has been shown. Under Section 25(2) TDDDG this storage does not require consent. Until September 2026 this site also loaded Google Analytics. That has been removed, along with every request to Google, and no replacement has been added.
9. Your rights
Under the GDPR you have the right to access your data, to have it corrected or deleted, to receive it in a portable format, to restrict how we use it, and to object to processing carried out on the basis of our legitimate interests. Where we rely on your consent, you can withdraw it at any time. You can request account deletion at any time by contacting us, and you can control privacy settings including leaderboard visibility in Profile and Settings. Remember that we hold no backups, so a deletion is final. You also have the right to complain to a data protection supervisory authority. Ours is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2-4, 40213 Düsseldorf. You may also complain to the supervisory authority in the country where you live.
10. Automated checks
When you request access, sign in, verify your email or use the contact form, automated checks help us block bulk automated signups, repeated failed logins and spam. These checks can temporarily limit how many attempts or messages are accepted from one address or one network. They do not decide whether you may use Anatium: access requests are reviewed and approved by a person. If you think a check has got it wrong, contact us. Attempts that these checks reject are not stored. A message rejected as spam leaves no record of itself, including no record of the address or network it came from.
11. Your country, and why we do not track your location
We do not track your location. When you request access, sign in or verify your email, we determine the country a request came from so that we can spot unusual access and know where our users are. Only the two letter country code is kept. This lookup happens on our own server, using a table stored there. No question about your connection is ever sent to an outside location service. If you tell us your country on the access request form, we use your answer instead.
12. Galen AI
Conversations with Galen AI are stored so your chat history follows you between sessions and devices. Your most recent fifty messages are kept and older ones are deleted automatically. Anatium staff do not read individual conversations except where the law requires it or to investigate reported abuse. You can clear your history at any time, and you can switch history off entirely in Profile and Settings.
13. Changes to this policy
We update this policy when what we do changes. This version reflects the removal of Google Analytics and of all Google requests, the addition of contact form storage and rate limiting, and the enforcement of the retention periods stated in section 7.
14. Contact
For anything about your data, use the Support chat in the app, the contact form on anatium.com, or email support@anatium.com.