Personal information
Privacy Policy
1. Who controls your data
, , is the controller of personal data described here. Privacy questions and requests may be sent to .
Stripe acts as an independent controller or processor for payment data according to its own role and privacy notice. Cloudflare provides hosting, security, D1 database infrastructure, and private R2 object storage.
2. Information we collect
| Category | Examples | Source |
|---|---|---|
| Contact and identity | Email address, name to be pronounced, billing name, country | You; payment provider |
| Ritual submission | Optional intention, portrait when requested, pronunciation guidance, assigned ceremony, customer timezone, and delivery schedule | You; practitioner/coordinator; our systems |
| Member account and guidance | Billing email, salted password hash, session records, ritual-name settings, private portrait, written guidance, optional private replies, preparation status, and release time | You; our systems; authorized ritual coordinator |
| Subscription and transaction | Public reference, status, amount, currency, dates, Stripe customer/subscription/session identifiers, card brand and last four digits if supplied by Stripe | Stripe; our systems |
| Waitlist and communication | Email, requested offer, consent record, support correspondence, delivery status | You; communication provider |
| Technical and security | IP address, browser and device data, request time, security signals, rate-limit records, logs | Your device; Cloudflare |
| Privacy and legal requests | Request type, contact details, verification evidence where necessary, response and resolution records | You; authorized agent |
We do not intentionally collect complete payment-card numbers or security codes. Do not include medical diagnoses, government identifiers, financial account details, passwords, information about another person without permission, or other highly sensitive data in an intention. If a future ritual genuinely requires information that can reveal health, religion, or another specially protected category, we will provide a specific explanation and collect any legally required separate explicit consent before processing it.
Guidance history and review data: the application keeps the member-authored intention history, optional private replies, generated notes, the server-selected response mode and thematic ledger used to reduce repetition, the primary guidance request’s generate-or-human-review decision, and—when a cycle requires a person—the active human-coordination record. That active row contains the member email, ritual name, current and initial intention, retained message history subject to an operational safety limit, earlier notes and replies, generation plan, reason for human handling, verified ceremony context when available, the administrator response, and audit metadata. New human-coordination rows are deleted after successful batch publication; legacy semantic-review decisions may remain in the separate review archive until account erasure.
3. Why we use information and our legal bases
| Purpose | Data | EU/EEA legal basis |
|---|---|---|
| Create checkout, administer subscription, schedule and confirm the purchased ritual, support cancellation | Contact, submission, transaction, subscription | Performance of contract; steps requested before contract |
| Create and secure Member Access, display private ritual settings, portrait, release schedule, and post-ritual guidance | Member account, subscription status, ritual submission, private media, and written guidance | Performance of contract; legitimate interests in account security and reliable delivery |
| Operate waitlists and send the requested availability notice | Email, offer, consent record | Your request and consent where required |
| Prevent fraud, abuse, duplicate processing, and attacks | Technical, security, payment status | Legitimate interests in secure operations; legal obligations |
| Maintain accounting, tax, chargeback, and legal evidence | Transaction and limited contract records | Legal obligations; establishment or defense of claims |
| Respond to privacy, consumer, and support requests | Contact, verification, correspondence | Legal obligation; contract; legitimate interests |
| Measure how the site is read, so we can see where visitors turn back | A random identifier this browser generated for itself, the pages and sections reached, seconds spent, checkout steps, and the campaign labels in the link you arrived from | Legitimate interests in understanding our own site; consent where required, and never against a Do Not Track or Global Privacy Control signal |
Where we rely on legitimate interests, we balance those interests against your rights and use proportionate data. You can request more information about that assessment.
5. International transfers
We are established in France. Cloudflare and Stripe may process data in the European Economic Area, United States, and other locations described in their documentation. The participating practitioners and coordinator are located in the Buryat Republic and the Baikal region, outside the EEA. Where you supply an optional portrait, that image is transmitted to the practitioner and shown to him before the ceremony; the chosen name, pronunciation guidance, and intention are transmitted for the same purpose. That destination is not the subject of a European Commission adequacy decision.
For restricted transfers, we use an available lawful mechanism such as an adequacy decision, the EU Standard Contractual Clauses with supplementary measures, or a specific derogation when strictly applicable. Before sending ritual content to a non-EEA practitioner, we assess necessity, minimize the data, restrict reuse, and document the applicable transfer mechanism. You may request information about safeguards.
6. How long we keep information
| Record | Default period |
|---|---|
| Uncompleted checkout | 30 days, then deletion or de-identification unless needed for fraud evidence |
| Active subscription administration | For the subscription. After cancellation, the operational record is de-identified at the end of the paid period unless immediate deletion is requested. |
| Member account and authentication records | Until cancellation or another verified deletion request. Account sessions are revoked as part of closure. |
| Current ritual intention, portrait, and other private account media | Until replaced, individually deleted, or cancellation, subject to short secure backup rotation and a documented deletion instruction for any operational recipient. |
| Post-ritual guidance, optional private replies, and preparation metadata | Until immediate deletion or automatic account closure at the end of a cancelled paid period, unless law requires restricted preservation. |
| Waitlist | Until the offer launches, you opt out, or 24 months after the latest confirmed interest, whichever comes first |
| Invoices and accounting records | The period required by French tax and accounting law, generally up to 10 years |
| Contract and dispute evidence | Applicable limitation period, with restricted access |
| Rate-limit/security records | Normally 24 hours to 90 days depending on risk, unless an incident requires longer preservation |
| Privacy requests | Normally 3 years after closure to demonstrate compliance |
Deletion may be delayed where law requires retention, a dispute is active, secure backup rotation is pending, or a verified external recipient is completing a deletion instruction. Data retained for one of these reasons is restricted from ordinary ritual, marketing, or account use. Cancellation confirmations and deletion-job records are minimized and kept only as compliance evidence.
Human coordination: an active row remains until it is answered and published by the scheduled batch, returned to automation, superseded by a newer intention, or deleted with the member’s data. Successfully published v1.9.2 coordination rows are deleted after the resulting guidance and thematic ledger are recorded. Legacy semantic-review decisions may be copied to the older review archive. Human rows, legacy review records, member-message history, any legacy triage cache, guidance state, thematic ledger, and guidance history are included in authenticated account erasure unless a documented legal exception requires restricted preservation.
7. Security
Measures include TLS in transit, Cloudflare security controls, Worker secret bindings rather than browser-exposed secret keys, prepared SQL statements, request-size and rate limits, origin checks, Stripe-controlled embedded payment entry, signed webhook verification using the raw request body, idempotent event processing, least-privilege access, redacted logs, private management and session tokens stored as one-way hashes, password-specific random salts with PBKDF2-HMAC-SHA-256, HttpOnly SameSite cookies, image decoding through the Cloudflare Images binding, conversion to a non-animated WebP capped at 1 MB, source-upload limits, cryptographic hashes, and non-public R2 storage. Stripe’s publishable key and short-lived Checkout Session client secret are intentionally supplied to the same-origin browser so Stripe Elements can operate; neither permits access to the Stripe secret key.
No system is perfectly secure. If a breach creates a legally reportable risk, we will notify the relevant authority and affected individuals as required. Never send a complete card number, password, or private management key by email.
8. Automated processing and written guidance
Security and payment providers may use automated signals to detect fraud. Those signals concern payment risk and do not write, select, or approve the content of a private ritual note.
Every private ritual note is written by an authorized human coordinator or translator. There is no automated drafting, scoring, profiling, or automated decision-making in the sense of Article 22 GDPR applied to your intention or your private thread, and no intention, member message, private note, or portrait is sent to an artificial-intelligence provider.
Server code schedules the work and prepares the coordinator's working context: it selects a response mode, narrative form, angle, practical orientation, and image policy from permanent thematic history, and assembles the current and initial intention, ceremony date, up to twelve recent member messages, up to eight previous notes and replies, and exact verified ceremony context when one exists. Obvious prompt-injection and specified urgent-safety wording are flagged locally so the coordinator sees them. A coordinator then writes the title and the member-facing note. While a case is waiting, the member sees a personal-review status.
If the member changes the intention, the prior active review is invalidated and archived as superseded. The batch checks the latest intention again before publishing an approved response. This processing does not make a decision producing legal or similarly significant effects. Contact us to question, correct, delete, or request human review of written guidance.
9. Your privacy rights
Depending on your location, you may have rights to access, correct, delete, restrict or object to processing, receive portable data, withdraw consent prospectively, opt out of certain sale/sharing or targeted advertising, and complain to a supervisory authority. French residents may also define directives concerning personal data after death where applicable.
Exercise rights through Your Privacy Choices, the cancellation control in Member Access, or email . Authenticated cancellation and active-data deletion are executed by the service at once, subject to retry if a storage or provider call temporarily fails. Other verified requests are handled without undue delay and normally within one month; a lawful extension will be explained. Authorized agents must provide evidence of authority. You will not be discriminated against for exercising a right.
You may complain to the Commission nationale de l’informatique et des libertés (CNIL) or the supervisory authority where you live or work.
10. Additional U.S. state disclosures
We do not sell personal information for money and this build does not share it for cross-context behavioral advertising. The visit measurement described above is first-party: no advertising network or data broker receives it. We do not knowingly sell or share the data of anyone under 16. A Global Privacy Control or Do Not Track signal switches the measurement off before anything is recorded, without you having to ask, and Cookie preferences on the homepage turns it off in one click. If future practices change, we will update this notice first and honor applicable opt-out signals.
In the preceding 12 months, the categories collected and disclosed for business purposes are those listed in Sections 2 and 4. Sensitive personal information is used only to provide a requested service, maintain security, comply with law, or for other purposes permitted without a right to limit. State-specific rights apply only when the relevant law covers us and the information.
11. Children
The Service is for adults 18 and older. We do not knowingly collect personal data from children. Contact us if you believe a child submitted information so we can investigate and delete it.
12. Changes to this Policy
We may update this Policy to reflect legal, operational, or provider changes. We post the new date and provide additional notice for material changes where required. An update does not retroactively authorize a materially different use without a valid legal basis.