Privacy Policy
Last updated: 2026-07-10
Who we are
Deep Oracle is an astrology analysis and chat product anchored to your birth data, operated by a UK-based sole trader under the brand name "Deep Oracle", and is the "data controller" for your personal data. This policy explains what we collect, how we use it, and the rights you have. Questions: support@deeporacle.ai.
Data we collect
• Account: your email address (sign-in and notifications), sign-in times, language preference.
• Birth data: the date, time, place and gender you enter to compute a chart.
• Usage: the charts and reports you generate, your chat messages, credit/pass balances, and usage counters.
• Payment data: the product and amount purchased, handled by our payment processor Stripe; we neither receive nor store your full card number.
• Technical data: minimal technical information such as IP address, processed for rate-limiting and abuse prevention.
How we use it
To provide the service (deterministically compute charts, generate reports, run chat), manage your account and purchases, keep the service secure and prevent abuse, and improve the product where lawful. We do not sell your personal information.
Legal bases (GDPR)
Performance of our contract with you (delivering the features you request), our legitimate interests (security and abuse prevention), and, where relevant, your consent.
How the AI model processes your data
The written interpretation in reports and chat is generated by an AI model. To write it, we send the engine-computed chart structure and the details needed to interpret it (such as gender, age and year), together with any questions you ask in chat, to our AI provider, OpenAI, for processing. The chart itself is computed by our deterministic engine on our servers, not by the AI. OpenAI is based in the US and processes API data under its own policies; under its current commercial terms, content submitted via the API is not used to train its models.
Third-party processors
• Supabase — authentication, database and storage hosting.
• Stripe — payment processing.
• OpenAI — turns the engine-computed chart into written interpretation (interpretation only; it does not compute the chart).
• Upstash (Redis) — rate-limiting and caching.
• Vercel — application hosting and content delivery (CDN).
• Resend — transactional email (e.g. password reset, account-deletion notices).
• Sentry — error monitoring and fault diagnosis.
International transfers
Some processors are outside the UK/EU (e.g. Stripe and OpenAI in the US). For those transfers we rely on appropriate safeguards (such as Standard Contractual Clauses / the UK International Data Transfer Agreement).
Retention & deletion
We keep your data for as long as your account exists. You can delete it from the Account page: deletion immediately locks login and starts a 30-day grace period, during which you can undo it by signing in; after the grace period your account and all associated data (charts, chats, reports, credits, etc.) are permanently deleted, and this cannot be reversed. Purchase and transaction records are retained separately for 7 years to meet tax and dispute-resolution requirements.
Cookies
We use only the essential session / authentication cookies required to keep you signed in. We do not use any third-party analytics or advertising trackers, so there are no tracking cookies that require consent.
Your rights
Under applicable law you can access, correct and delete your data, restrict or object to processing, and request portability. Deletion is self-serve on the Account page; for other requests email support@deeporacle.ai with "PRIVACY" in the subject and we'll respond within 30 days. You may also complain to your local data-protection authority.
Regional compliance
• UK / EU / EEA: the rights above are provided under the GDPR; you may complain to your local authority (e.g. the UK ICO).
• California: the rights above are provided under the CCPA; we do not sell personal information, and you have the right not to be discriminated against.
• Mainland China: the rights above are provided under the Personal Information Protection Law (PIPL); your data is processed outside mainland China by the processors above, and by creating an account or submitting birth data you consent to that cross-border transfer.
Security & breach notification
Communication between client and server is encrypted over HTTPS, and authentication is handled by Supabase. If a data breach affecting your personal data occurs, we will notify you within 72 hours of becoming aware, as required by Article 33 of the GDPR.
Children
The service is for users aged 18 and over and is not directed to minors.
Changes
We may update this policy; we'll notify you of material changes in-app or by email.
Contact
For privacy matters, contact support@deeporacle.ai.