SURV : Ritual Access
CookiesYour choicesReturn to site
On this pageControllerData we collectPurposes and legal basesRecipientsInternational transfersRetentionSecurityYour rightsU.S. disclosuresContact

Personal information

Privacy Policy

Effective · Version

We collect the information needed to operate waitlists, checkout, subscriptions, ceremonies, and private post-ritual guidance. We do not sell personal information, and we do not share it for cross-context behavioral advertising. We do not use customer names, portraits, intentions, or guidance in advertising without separate permission.

1. Who controls your data

, , is the controller of personal data described here. Privacy questions and requests may be sent to .

Stripe acts as an independent controller or processor for payment data according to its own role and privacy notice. Cloudflare provides hosting, security, D1 database infrastructure, and private R2 object storage.

2. Information we collect

CategoryExamplesSource
Contact and identityEmail address, name to be pronounced, billing name, countryYou; payment provider
Ritual submissionOptional intention, portrait when requested, pronunciation guidance, assigned ceremony, customer timezone, and delivery scheduleYou; practitioner/coordinator; our systems
Member account and guidanceBilling email, salted password hash, session records, ritual-name settings, private portrait, written guidance, optional private replies, preparation status, and release timeYou; our systems; authorized ritual coordinator
Subscription and transactionPublic reference, status, amount, currency, dates, Stripe customer/subscription/session identifiers, card brand and last four digits if supplied by StripeStripe; our systems
Waitlist and communicationEmail, requested offer, consent record, support correspondence, delivery statusYou; communication provider
Technical and securityIP address, browser and device data, request time, security signals, rate-limit records, logsYour device; Cloudflare
Privacy and legal requestsRequest type, contact details, verification evidence where necessary, response and resolution recordsYou; authorized agent

We do not intentionally collect complete payment-card numbers or security codes. Do not include medical diagnoses, government identifiers, financial account details, passwords, information about another person without permission, or other highly sensitive data in an intention. If a future ritual genuinely requires information that can reveal health, religion, or another specially protected category, we will provide a specific explanation and collect any legally required separate explicit consent before processing it.

Guidance history and review data: the application keeps the member-authored intention history, optional private replies, generated notes, the server-selected response mode and thematic ledger used to reduce repetition, the primary guidance request’s generate-or-human-review decision, and—when a cycle requires a person—the active human-coordination record. That active row contains the member email, ritual name, current and initial intention, retained message history subject to an operational safety limit, earlier notes and replies, generation plan, reason for human handling, verified ceremony context when available, the administrator response, and audit metadata. New human-coordination rows are deleted after successful batch publication; legacy semantic-review decisions may remain in the separate review archive until account erasure.

3. Why we use information and our legal bases

PurposeDataEU/EEA legal basis
Create checkout, administer subscription, schedule and confirm the purchased ritual, support cancellationContact, submission, transaction, subscriptionPerformance of contract; steps requested before contract
Create and secure Member Access, display private ritual settings, portrait, release schedule, and post-ritual guidanceMember account, subscription status, ritual submission, private media, and written guidancePerformance of contract; legitimate interests in account security and reliable delivery
Operate waitlists and send the requested availability noticeEmail, offer, consent recordYour request and consent where required
Prevent fraud, abuse, duplicate processing, and attacksTechnical, security, payment statusLegitimate interests in secure operations; legal obligations
Maintain accounting, tax, chargeback, and legal evidenceTransaction and limited contract recordsLegal obligations; establishment or defense of claims
Respond to privacy, consumer, and support requestsContact, verification, correspondenceLegal obligation; contract; legitimate interests
Measure how the site is read, so we can see where visitors turn backA random identifier this browser generated for itself, the pages and sections reached, seconds spent, checkout steps, and the campaign labels in the link you arrived fromLegitimate interests in understanding our own site; consent where required, and never against a Do Not Track or Global Privacy Control signal

Where we rely on legitimate interests, we balance those interests against your rights and use proportionate data. You can request more information about that assessment.

4. Who receives information

We disclose only what is reasonably needed to the following recipients:

  • participating practitioner and local coordinator: only the operational information lawfully required for the assigned ritual, such as the chosen name, pronunciation, optional portrait when applicable, intention, assignment, and necessary coordination messages;
  • authorized service administrators: the member email, ritual name, current and initial intention, retained member-message history, earlier private notes and replies, permanent thematic ledger, server generation plan, routing reason, and relevant ceremony context when a response requires human coordination;
  • Stripe: checkout, billing, subscription, fraud-prevention, and payment information;
  • Cloudflare: website delivery, security, scheduled Worker execution, technical logs, D1 database hosting, and private R2 portrait storage;
  • configured review-notification provider: a review identifier, member email, ritual date, reason code, priority, and administrator-page link when an administrator webhook is enabled;
  • professional advisers and authorities: where reasonably necessary for legal compliance, claims, audit, safety, or fraud prevention; and
  • business successor: under confidentiality and lawful notice in a merger, financing, reorganization, or sale.

Private ritual notes are written by an authorized human coordinator. No intention, member message, private note, or portrait is sent to an artificial-intelligence provider. Information stored by this application in D1, R2, administrator review records, audit events, and member history follows the retention and deletion rules below.

Practitioners and collaborators must be contractually restricted from promotional reuse. Private R2 objects are not placed in a public bucket and are delivered only through an authenticated account request. We do not publish a customer submission by default.

5. International transfers

We are established in France. Cloudflare and Stripe may process data in the European Economic Area, United States, and other locations described in their documentation. The participating practitioners and coordinator are located in the Buryat Republic and the Baikal region, outside the EEA. Where you supply an optional portrait, that image is transmitted to the practitioner and shown to him before the ceremony; the chosen name, pronunciation guidance, and intention are transmitted for the same purpose. That destination is not the subject of a European Commission adequacy decision.

For restricted transfers, we use an available lawful mechanism such as an adequacy decision, the EU Standard Contractual Clauses with supplementary measures, or a specific derogation when strictly applicable. Before sending ritual content to a non-EEA practitioner, we assess necessity, minimize the data, restrict reuse, and document the applicable transfer mechanism. You may request information about safeguards.

6. How long we keep information

RecordDefault period
Uncompleted checkout30 days, then deletion or de-identification unless needed for fraud evidence
Active subscription administrationFor the subscription. After cancellation, the operational record is de-identified at the end of the paid period unless immediate deletion is requested.
Member account and authentication recordsUntil cancellation or another verified deletion request. Account sessions are revoked as part of closure.
Current ritual intention, portrait, and other private account mediaUntil replaced, individually deleted, or cancellation, subject to short secure backup rotation and a documented deletion instruction for any operational recipient.
Post-ritual guidance, optional private replies, and preparation metadataUntil immediate deletion or automatic account closure at the end of a cancelled paid period, unless law requires restricted preservation.
WaitlistUntil the offer launches, you opt out, or 24 months after the latest confirmed interest, whichever comes first
Invoices and accounting recordsThe period required by French tax and accounting law, generally up to 10 years
Contract and dispute evidenceApplicable limitation period, with restricted access
Rate-limit/security recordsNormally 24 hours to 90 days depending on risk, unless an incident requires longer preservation
Privacy requestsNormally 3 years after closure to demonstrate compliance

Deletion may be delayed where law requires retention, a dispute is active, secure backup rotation is pending, or a verified external recipient is completing a deletion instruction. Data retained for one of these reasons is restricted from ordinary ritual, marketing, or account use. Cancellation confirmations and deletion-job records are minimized and kept only as compliance evidence.

Human coordination: an active row remains until it is answered and published by the scheduled batch, returned to automation, superseded by a newer intention, or deleted with the member’s data. Successfully published v1.9.2 coordination rows are deleted after the resulting guidance and thematic ledger are recorded. Legacy semantic-review decisions may be copied to the older review archive. Human rows, legacy review records, member-message history, any legacy triage cache, guidance state, thematic ledger, and guidance history are included in authenticated account erasure unless a documented legal exception requires restricted preservation.

7. Security

Measures include TLS in transit, Cloudflare security controls, Worker secret bindings rather than browser-exposed secret keys, prepared SQL statements, request-size and rate limits, origin checks, Stripe-controlled embedded payment entry, signed webhook verification using the raw request body, idempotent event processing, least-privilege access, redacted logs, private management and session tokens stored as one-way hashes, password-specific random salts with PBKDF2-HMAC-SHA-256, HttpOnly SameSite cookies, image decoding through the Cloudflare Images binding, conversion to a non-animated WebP capped at 1 MB, source-upload limits, cryptographic hashes, and non-public R2 storage. Stripe’s publishable key and short-lived Checkout Session client secret are intentionally supplied to the same-origin browser so Stripe Elements can operate; neither permits access to the Stripe secret key.

No system is perfectly secure. If a breach creates a legally reportable risk, we will notify the relevant authority and affected individuals as required. Never send a complete card number, password, or private management key by email.

8. Automated processing and written guidance

Security and payment providers may use automated signals to detect fraud. Those signals concern payment risk and do not write, select, or approve the content of a private ritual note.

Every private ritual note is written by an authorized human coordinator or translator. There is no automated drafting, scoring, profiling, or automated decision-making in the sense of Article 22 GDPR applied to your intention or your private thread, and no intention, member message, private note, or portrait is sent to an artificial-intelligence provider.

Server code schedules the work and prepares the coordinator's working context: it selects a response mode, narrative form, angle, practical orientation, and image policy from permanent thematic history, and assembles the current and initial intention, ceremony date, up to twelve recent member messages, up to eight previous notes and replies, and exact verified ceremony context when one exists. Obvious prompt-injection and specified urgent-safety wording are flagged locally so the coordinator sees them. A coordinator then writes the title and the member-facing note. While a case is waiting, the member sees a personal-review status.

If the member changes the intention, the prior active review is invalidated and archived as superseded. The batch checks the latest intention again before publishing an approved response. This processing does not make a decision producing legal or similarly significant effects. Contact us to question, correct, delete, or request human review of written guidance.

9. Your privacy rights

Depending on your location, you may have rights to access, correct, delete, restrict or object to processing, receive portable data, withdraw consent prospectively, opt out of certain sale/sharing or targeted advertising, and complain to a supervisory authority. French residents may also define directives concerning personal data after death where applicable.

Exercise rights through Your Privacy Choices, the cancellation control in Member Access, or email . Authenticated cancellation and active-data deletion are executed by the service at once, subject to retry if a storage or provider call temporarily fails. Other verified requests are handled without undue delay and normally within one month; a lawful extension will be explained. Authorized agents must provide evidence of authority. You will not be discriminated against for exercising a right.

You may complain to the Commission nationale de l’informatique et des libertés (CNIL) or the supervisory authority where you live or work.

10. Additional U.S. state disclosures

We do not sell personal information for money and this build does not share it for cross-context behavioral advertising. The visit measurement described above is first-party: no advertising network or data broker receives it. We do not knowingly sell or share the data of anyone under 16. A Global Privacy Control or Do Not Track signal switches the measurement off before anything is recorded, without you having to ask, and Cookie preferences on the homepage turns it off in one click. If future practices change, we will update this notice first and honor applicable opt-out signals.

In the preceding 12 months, the categories collected and disclosed for business purposes are those listed in Sections 2 and 4. Sensitive personal information is used only to provide a requested service, maintain security, comply with law, or for other purposes permitted without a right to limit. State-specific rights apply only when the relevant law covers us and the information.

11. Children

The Service is for adults 18 and older. We do not knowingly collect personal data from children. Contact us if you believe a child submitted information so we can investigate and delete it.

12. Changes to this Policy

We may update this Policy to reflect legal, operational, or provider changes. We post the new date and provide additional notice for material changes where required. An update does not retroactively authorize a materially different use without a valid legal basis.

13. Contact

Privacy contact:
Postal address:
Controller:

©