Legal
Privacy Policy
Last updated:
1. Who we are
Homeopathic Library (homeopathy.one) is a digital archive of primary historical homeopathic literature. The site is operated as a research resource and is not affiliated with any commercial organisation or medical body.
For privacy enquiries, please contact us at [email protected].
2. What information we collect
We collect only the minimum information necessary to operate the service:
- Account data — if you register for an account, we store your name, email address, and a hashed password. We do not store your password in plain text.
- Session data — a short-lived session token stored in a secure HTTP-only cookie to keep you logged in.
- Search queries — search terms you enter may be logged temporarily for performance monitoring and abuse prevention. We do not link search queries to individual users.
- Server logs — standard web server logs (IP address, browser type, pages visited, timestamps) retained for up to 30 days for security and diagnostic purposes.
We do not use advertising trackers, third-party analytics scripts, or sell any data to third parties.
3. How we use your information
We use the information we collect solely to:
- Provide and maintain the library service
- Authenticate registered users and protect admin functions
- Diagnose technical problems and prevent abuse
- Respond to enquiries you send us directly
4. Cookies
We use a single essential session cookie to keep you logged in. This cookie is strictly necessary for the service to function and does not track you across other websites. No marketing or analytics cookies are set.
5. Data retention
Account data is retained for as long as your account is active. You may request deletion of your account and associated data at any time by contacting us at [email protected]. Server logs are deleted after 30 days.
6. Your rights
Depending on your location, you may have rights under applicable data protection law (including the UK GDPR and EU GDPR) to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request erasure of your data
- Object to or restrict processing
- Data portability
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
7. Third-party services
The library uses OpenAI's API solely to generate semantic search embeddings from passage text. No personal data or user queries are sent to OpenAI. Passage text is historical public-domain material.
8. Security
We take reasonable technical and organisational measures to protect your data, including encrypted connections (HTTPS), hashed passwords, and HTTP-only session cookies. No method of transmission over the internet is 100% secure.
9. Changes to this policy
We may update this policy from time to time. The "last updated" date at the top of this page will reflect any changes. Continued use of the service after changes constitutes acceptance of the revised policy.