Privacy Policy
Written to be read, not skimmed past.
Draft — pending legal review. This describes how Auspice handles data in the current preview. It will be finalized with counsel before public launch.
What we collect
- Your birth details — date, time if you know it, place, the name you give us, your focus areas, and chart preferences such as polarity.
- Birth details of people you add in Bonds — third parties whose date, time, and place you enter to explore a connection.
- What you create in the app — journal entries, your chat with the Oracle, tarot draws, and the facts the Oracle remembers because you stated them.
- Your device timezone and settings — so readings land at the right local time and the app looks the way you chose.
- Operational records — request logs, in-house analytics events, and safety records, kept briefly to run the service and prevent abuse.
Why we use it, and our legal basis
Birth details, journal, and chat are personal, and we use them for one purpose: to compute and deliver your readings. Timezone tunes delivery timing; operational records keep the service running, secure, and free of abuse. Our legal basis is your consent, which we ask for explicitly at onboarding (“birth details, journal and chat are personal; stored to compute your readings”) and record with a timestamp. You can withdraw it any time by deleting your data.
Who processes it
We keep the list of processors short and name them plainly. Each acts on our instructions only.
- SupabaseDatabase and authentication hosting (Postgres), United States region, encrypted at rest.
- VercelApplication hosting and serverless compute that runs Auspice.
- Stripeonly when livePayment processing for Premium — only once billing is switched on, and only your billing details.
- Anthropiconly when liveGenerates the Oracle's deeper replies — only when a live AI provider is enabled. Grounded on your chart context; no training on your data.
- cron-job.orgTriggers our daily schedule on time. It holds no personal data — it only pings an Auspice endpoint.
Where your data lives
Your data is stored with Supabase (Postgres) in a United States region, encrypted at rest by the platform. Row-level security means each account can reach only its own rows, and anonymous sessions get the same protection as email accounts. We do not move your data to other regions for our own convenience.
How long we keep it
| Data | Kept for |
|---|---|
| Your charts, readings, journal, chat, and Oracle memory | Until you delete them or delete your account |
| Background job records (used to prepare your readings) | 7 days after they finish, then removed |
| Product analytics events (in-house, no third-party vendor) | 90 days, then removed |
| Safety and audit logs (abuse prevention, integrity) | 180 days, then removed; anonymized immediately if you delete your account |
Your rights and controls
Export returns everything we hold about you, including any Bonds birth data you added. Delete erases it all — charts, readings, journal, chat, memory, and Bonds — and removes the sign-in itself; safety and audit records are anonymized rather than kept. Both controls live in Settings → Data & privacy, with no email required. You can also reach us with any request at brian@bmdigital.io.
Children
Auspice is for people 16 and older. We enforce this at onboarding from the birth date you enter, and we do not knowingly keep data from anyone younger.
What we never do
We do not sell your data, ever. We do not show ads. We do not infer sensitive attributes about you — the Oracle's memory keeps only facts you state yourself, and every remembered item is visible and deletable in the app. Your birth details, journal, and chat are never used to train models or shared for anyone else's marketing.