Privacy Policy
Last Updated: January 8, 2026
1. Introduction
Urim and Thummim Labs ("UTLabs", "we", "us", or "our") respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use, and safeguard your information when you access our documentation download service.
2. Information We Collect
2.1 Account Information
- Email address (required for registration)
- Full name (required for registration)
- Password (encrypted and never stored in plain text)
2.2 Usage Data
- Documentation download history (filename, timestamp)
- IP address and browser information
- Login timestamps and session data
2.3 Cookies and Local Storage
- Authentication tokens (JWT) for maintaining login sessions
- GDPR consent preferences
- UI preferences (if applicable)
3. How We Use Your Information
We use your personal data for the following purposes:
- Account Management: To create and manage your user account
- Email Verification: To verify your email address during registration
- Access Control: To authenticate downloads and prevent unauthorized access
- Watermarking: To embed your email and user ID in downloaded PDFs for security purposes
- Audit Logging: To maintain download records for security and compliance
- Service Improvement: To analyze usage patterns and improve our services
- Marketing Communications: To send you promotional emails, product updates, newsletters, and other marketing materials about our services (only with your explicit consent)
4. Data Storage and Security
Your data is stored securely using industry-standard practices:
- Infrastructure: AWS (Amazon Web Services) EU region (eu-central-1, Frankfurt)
- Encryption: All data encrypted at rest (AES-256) and in transit (TLS/HTTPS)
- Authentication: AWS Cognito with secure password hashing (bcrypt)
- Access Control: Strict IAM policies limiting data access
5. Data Retention
- Account Data: Retained while your account is active
- Download Logs: Automatically deleted after 90 days
- Watermarked Files: Automatically deleted after 24 hours
6. Your Rights (GDPR)
Under the General Data Protection Regulation (GDPR), you have the following rights:
- Right to Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate data
- Right to Erasure: Request deletion of your account and data
- Right to Data Portability: Receive your data in a structured format
- Right to Object: Object to processing of your personal data
- Right to Withdraw Consent: Withdraw your consent for marketing communications at any time
- Right to Object to Direct Marketing: Opt-out of marketing emails at any time using the unsubscribe link in our emails
To exercise any of these rights, please contact us at: privacy@urimandthummimlabs.com
7. Watermarking and Document Tracking
All downloaded documentation is watermarked with your user information (email, user ID, timestamp) to prevent unauthorized distribution. This is necessary for protecting intellectual property and maintaining security.
8. Third-Party Services
We use the following third-party services:
- AWS Cognito: User authentication and management
- AWS S3: Secure file storage
- AWS Lambda: PDF watermarking processing
- CloudFront: Content delivery
These services are GDPR-compliant and have appropriate data processing agreements in place.
9. Marketing Communications
9.1 Consent
During registration, you will be asked to provide explicit consent to receive marketing communications from us. This consent is separate from accepting our Terms of Service and is required to register for our service.
9.2 Types of Marketing Communications
With your consent, we may send you:
- Product updates and new feature announcements
- Documentation releases and updates
- Educational content and tutorials
- Promotional offers and special discounts
- Company news and newsletters
9.3 Opt-Out and Unsubscribe
You can withdraw your consent and opt-out of marketing communications at any time by:
- Clicking the "Unsubscribe" link in any marketing email
- Contacting us at privacy@urimandthummimlabs.com
- Managing your preferences in your account settings (if available)
Note: Opting out of marketing emails will not affect essential service emails (e.g., email verification, password resets, security alerts).
10. Cookies Policy
We use essential cookies for:
- Maintaining login sessions
- Storing GDPR consent preferences
- Storing marketing consent preferences
We do NOT use tracking cookies, advertising cookies, or third-party analytics.
11. Changes to This Policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated "Last Updated" date.
12. Contact Us
For privacy-related questions or requests, contact us at:
Email: privacy@urimandthummimlabs.com
Website: https://urimandthummimlabs.com