Privacy Policy
Operated by Unify Labs, Ltd.. Effective July 31, 2026.
What we collect
- Your birth details — date, time if you know it, place, the name you give us, your focus areas, and chart preferences such as polarity.
- Birth details of people you add in Bonds — third parties whose date, time, and place you enter to explore a connection.
- What you create in the app — journal entries, your chat with the Oracle, tarot draws, and the facts the Oracle remembers because you stated them.
- Your device timezone and settings — so readings land at the right local time and the app looks the way you chose.
- Messages you send through the contact form — the topic, message, and any optional reply address you choose to provide, so we can respond to your request.
- Operational records — request logs, in-house analytics events, and safety records, kept briefly to run the service and prevent abuse.
Why we use it, and our legal basis
We use birth details, journal, chat, and settings to provide the charts, readings, and account features you request. We use contact submissions to answer you, billing data to process a purchase, and operational records to run and secure the service. Depending on the context and where you live, our legal bases include performing our agreement with you, your consent where we ask for it, our legitimate interests in operating and protecting the service, and compliance with legal obligations. You can withdraw consent where it applies without affecting processing that was already lawful.
Who processes it
We keep the list of service providers short and name them plainly. They process data as needed to provide the role described below.
- SupabaseDatabase and authentication hosting (Postgres), United States region, encrypted at rest.
- VercelApplication hosting and serverless compute that runs AwakenFate.
- Stripewhen usedPayment processing when you purchase a paid plan. Stripe receives the billing and transaction details needed to process that purchase.
- Google Geminiwhen usedAI inference for Oracle replies and generated explanations, only when a Gemini route is selected. It receives the relevant prompt and chart or request context needed for that request.
- Anthropicwhen usedAI inference for Oracle replies and generated explanations, only when an Anthropic route is selected. It receives the relevant prompt and chart or request context needed for that request.
- DeepSeekwhen usedAI inference for Oracle replies and generated explanations, only when a DeepSeek route is selected. It receives the relevant prompt and chart or request context needed for that request.
- cron-job.orgTriggers our daily schedule on time. It holds no personal data — it only pings an AwakenFate endpoint.
Where your data lives
Your primary account and app data are stored with Supabase (Postgres) in a United States region and encrypted at rest by the platform. Row-level security means each account can reach only its own rows, and anonymous sessions get the same protection as email accounts. Other service providers, including AI and payment providers, may process the relevant data in regions where they operate. Processing may occur outside your country, subject to applicable data-protection requirements.
How long we keep it
| Data | Kept for |
|---|---|
| Your charts, readings, journal, chat, and Oracle memory | Until you delete them or delete your account |
| Contact form submissions and an optional reply address | Up to 180 days; account-linked submissions are removed sooner when you delete the account |
| Background job records (used to prepare your readings) | 7 days after they finish, then removed |
| Product analytics events (in-house, no third-party vendor) | 90 days, then removed |
| Safety and audit logs (abuse prevention, integrity) | 180 days, then removed; anonymized immediately if you delete your account |
| Short-lived rate-limit counters | 2 days, then removed; IP-based counters use a keyed, rotating digest rather than the raw address |
Your rights and controls
Export returns the account data available through the export control, including Bonds birth data you added. Delete removes your account, its associated charts, readings, journal, chat, memory, Bonds, account-linked contact submissions, and the sign-in itself. Other contact submissions follow the retention schedule above; safety and audit records are anonymized when account deletion requires it. The account controls live in Settings → Data & privacy. You can also send a privacy request through our contact form.
Children
AwakenFate is for people 16 and older. We enforce this at onboarding from the birth date you enter, and we do not knowingly keep data from anyone younger.
What we never do
We do not sell your data, ever. We do not show ads. We do not infer sensitive attributes about you — the Oracle's memory keeps only facts you state yourself, and every remembered item is visible and deletable in the app. We do not use your content to train models that we operate or share it for anyone else's marketing. When an external AI route is used, the selected provider receives the request context described above; its handling is governed by its terms and our configuration.