What we collect, why, and how to control it. Plain English, no tracking dark patterns.
When you use Corydon, we collect:
We don't sell your personal data. We share limited data with:
We use a small set of first-party cookies for sessions and preferences, plus self-hosted analytics (Plausible). No third-party tracking, no advertising cookies. You can opt out of analytics in your account settings.
Under GDPR, CCPA, and similar laws, you have the right to access, correct, export, or delete your data. Email info@corydon-publications.com and we'll respond within 30 days.
Data in transit is TLS 1.3 encrypted. At rest, sensitive fields are AES-256 encrypted with keys managed via cloud KMS. Independent security audits run annually.
Account data is retained while your account is active and for 24 months after deletion (in case you reactivate). Aggregated analytics are kept indefinitely in anonymized form.
Corydon is not intended for users under 16. We don't knowingly collect data from children. If you believe a child has shared data with us, contact us and we'll delete it.
Corydon operates from the United States, the United Kingdom, and the European Union. Data may be transferred between these regions under Standard Contractual Clauses or equivalent safeguards.
Questions, requests, or complaints: info@corydon-publications.com.