Axorion

Privacy policy

Applies to the services of Axorion Oy, currently the Punakynä manuscript editor (punakyna.axorion.fi) and its Mac app, as well as the axorion.fi website. Updated: 10 October 2026.

Data controller

Axorion Oy, business ID 3013176-5, Suvikummunrinne 4 V 36, 02120 Espoo, Finland · contact: support@axorion.fi · About Axorion

What data we process

Account data: email address, display name and a technical identifier needed for signing in. You sign in with a one-time code sent to your email or with a passwordless passkey; passwords are not used.

Content: manuscripts, images, comments and suggested changes that authors upload or write, together with their complete change history.

Memberships: with whom a manuscript is shared and in which role (author or commenter), and pending invitations with their email addresses.

Access requests: the name, email address and optional message you give in the form on the Punakynä front page. The request is saved in the service and sent to the administrator by email. Once the request has been approved or rejected, the name and message are deleted; on approval, the author permission is stored against your email address.

Connected apps: if you connect an AI app (MCP) to the service, we store the app’s name, the permissions granted and the hashes needed to renew the sign-in.

Technical logs: server logs contain the IP address, the request path and the time. We use them for troubleshooting and abuse prevention.

Usage statistics, web service: only with your consent; see Statistics and cookies.

Usage statistics and error reports, Mac app: only with your consent; see Mac app.

Purpose and legal basis

We process data to provide the service to you (contract), to handle your access request (pre-contractual steps), and to ensure security and prevent abuse (legitimate interest). Usage statistics, error reports and AI analysis are based on your consent, which you can withdraw at any time.

Who can see a manuscript

A manuscript can be seen by its author(s) and the people the author has invited. The service administrator cannot see other people’s manuscripts in the service’s user interface. The administrator does, however, have technical access to the server and database, and content is not encrypted per author. Do not store anything in the service that you do not trust the administrator’s technical access with.

AI

Story analysis: when you start the AI analysis of a manuscript, the manuscript text is sent to a language-model service (Mistral AI, France, EU). The text is sent only if you separately consent to it for that manuscript. The AI does not change your text; it produces observations that only you can see. You can turn the analysis off at any time.

Your own AI apps (MCP): if you connect your account to an AI app, it gets access to the content of manuscripts according to the permissions you grant and processes the data under its own terms. You can disconnect it at any time in your account settings.

Service providers

Cloudflare (DNS, network traffic relay and static content; processes traffic), UpCloud (server and database, EU), Google (email: sign-in codes, invitations and notifications of access requests; Gmail) and Mistral AI (AI analysis, only with your consent). The sign-in service Hanko and the statistics service Umami run on our own server. We do not use third-party tracking or advertising services.

Statistics and cookies

We use only a strictly necessary session cookie to keep you signed in. We do not use tracking or advertising cookies.

If you allow usage statistics (cookie and statistics settings: Settings → Profile, or the choice shown on first use), we measure the use of the web service with the self-hosted Umami software. Only the page category (for example front page, sign-in, settings or editor) is recorded, not manuscript identifiers, search terms or content. The IP address is not passed to the statistics service. Without your consent no statistics are collected. Downloads of installation packages are also counted in the statistics.

Mac app

Usage statistics are collected only if you allow them in the app. The events are: app launch, daily activity, sign-in, synchronization (whether it succeeded, and its direction) and export (file format). In the statistics you are represented by a random installation identifier or, if you are signed in, a hash derived from your account from which your account cannot be inferred. Events are first stored on your device and sent in batches when a network connection is available. The content of manuscripts is not sent.

Crash and error reports are off by default. If you turn them on, the app sends a technical report when it crashes (app version, system information and the location of the error). A crash dump may incidentally contain manuscript text. Reports are anonymous and are deleted after 30 days.

You can change both settings at any time in the app’s settings.

Retention

Account data and content are kept for as long as the account exists. An author can ask for a manuscript to be deleted; after deletion the data disappears from backups within 7 days. Logs and error reports are kept for at most 30 days.

Your rights

You have the right to access your data, have it corrected, ask for its deletion, restrict or object to processing, transfer the data to another system, and withdraw consent. You can download your own data from your account settings (Download my data, .zip) or request it at support@axorion.fi. You can lodge a complaint with the Data Protection Ombudsman (tietosuoja.fi).