✦ Limited-time launch promotion — sign in free with Google to unlock all premium features at no cost.

Aurora Oracle™ Privacy Notice

Version 7.4 — Effective July 9, 2026. Operator: Aurora Oracle Ltd., British Columbia, Canada. This Privacy Notice comprises §§14–14G of, and the Privacy Annexes to, the Aurora Oracle Terms of Use, reproduced here in full.

14. PRIVACY & DATA COLLECTION (GENERAL) — MINIMAL-COLLECTION VALIDATION LAUNCH; NO BIRTH-DATA STORAGE

This launch is designed to collect almost no personal data, and anonymous use is fully supported: the deterministic and static tools work without an Account and without server-side storage of your inputs. In particular, the Kua-number calculator uses only birth YEAR and gender, processed entirely in your browser and never transmitted to or stored by Provider. The birth-chart/natal, BaZi, and Vedic/Jyotish features DO collect your birth date, time, and place at launch to compute an ephemeris; this special-category birth data is processed only on your explicit, granular consent under §14.1 and is NEVER STORED — it is held transiently in memory solely to compute your chart, is discarded immediately after your reading is generated, and is not written to any server-side database, log, backup, or analytics system (§14.1). Provider does NOT accept photo uploads (that feature is dormant, see §14.1), does NOT collect precise/GPS geolocation, and does NOT collect or store any payment information (none exists). Accounts are OPTIONAL (email or Google SSO) and are needed to save reading history and streaks and to use the one free AI glimpse; anonymous use of tools that do not require birth data is supported. For Users who choose to interact, Provider may process: (a) birth date, time, and place you enter for a birth chart/BaZi/Vedic reading, and any optional free-text question you submit to receive the one AI glimpse, each under the explicit-consent terms of §14.1; (b) Account data (email and, for SSO, name and Identity Provider identifier) where you create an Account; (c) reading/streak history for signed-in Users (reading text only — never your birth date, time, or place), which you may hard-delete one-click; (d) an optional email address for the newsletter or a coming-soon interest registration (§6A.0.1); (e) device and log data and approximate (IP-derived) region for security, rate-limiting, and legal-compliance; and (f) privacy-friendly, aggregate analytics that do not use cross-site tracking, advertising pixels, or ad cookies. Provider practices data minimization and collects only what is necessary for the purposes described. A standalone Privacy Policy, available at https://auroraoracle.ai/privacy and presented at or before collection (notice-at-collection), identifies for each processing purpose the categories of personal data, sources, lawful basis, purposes, retention period, recipient/subprocessor categories, international-transfer mechanism, user rights and request/verification/appeal methods, GPC/opt-out handling, and regulator/supervisory-authority contacts, and must match this minimal collection. Where the Privacy Policy and these Annexes conflict, the more protective of the User controls.

14.1 SENSITIVE & SPECIAL-CATEGORY DATA; EXPLICIT CONSENT (ACTIVE AT LAUNCH). At launch, Provider collects special-category birth data — birth date, birth time, and birthplace — for the birth-chart/natal, BaZi, and Vedic/Jyotish features, and Users may also submit optional free-text questions; such birth data and free text may constitute or reveal special-category or sensitive personal information under GDPR/UK GDPR Art. 9, the CCPA/CPRA ("sensitive personal information"), Quebec Law 25, and analogous laws, including data revealing religious or philosophical beliefs, health, or sex life. Where such laws apply, Provider processes this data solely on the basis of your explicit, separate, unambiguous, opt-in consent, captured by an unchecked control AT THE POINT OF BIRTH-DATA ENTRY (not buried in signup or these Terms) and immediately before the reading is generated, solely to compute and generate the requested reading, and — as a core design commitment — WITHOUT STORAGE: your birth date, time, and place are held transiently in memory only for the moment of computation, are discarded immediately after your reading is generated, and are never written to any server-side database, log, backup, or analytics system. For signed-in Users who opt in, reading history stores only the generated reading text — never your birth data. To obtain a further reading later, you simply re-enter your birth details; your own browser may optionally retain them locally on your device, under your sole control, and locally retained data is never transmitted to Provider for storage. Provider practices data minimization: birth data is never stored, is not required to browse or to use tools that do not need it, and you may withdraw consent at any time and one-click delete your readings and Account (effective prospectively); because birth data is not stored, there is no server-side birth data to delete. Before generating a birth-data reading, Provider will obtain separate unchecked consents for: (1) transient, non-stored processing of your birth date, time, and place to compute and generate the requested chart/reading; (2) processing any optional free-text prompt that may reveal sensitive data; and (3) storing your generated reading history (reading text only; never birth data). FREE-TEXT / AI-PROMPT CONSENT (ALL SURFACES): separately, before any optional free-text prompt or AI input on ANY surface that may include sensitive/special-category data — including the I Ching question, the free AI "glimpse," and any Oracle chat, whether or not tied to birth-data entry — Provider will either (a) block such fields and instruct Users not to enter sensitive data, or (b) present an unchecked, granular consent immediately adjacent to that specific prompt field and before submission, covering processing of that free text solely to generate the requested output, with any optional saved history consented to separately; this point-of-entry consent control fires before any AI prompt that accepts free text, not only birth-data readings. Provider does not sell or "share" sensitive or personal information, does not use it for advertising, profiling for advertising, or automated decisions producing legal or similarly significant effects, and honors CCPA/CPRA rights to limit the use of sensitive personal information, and will not use special-category data for product improvement unless it has been irreversibly anonymized to GDPR standards or another valid lawful basis applies. PHOTO-UPLOAD CONSENT — NON-OPERATIVE PREVIEW LANGUAGE: Provider does NOT accept photo uploads at launch; the consent mechanics for any future photographic feng-shui analysis (processing an uploaded image, which may include biometric or premises data) are non-operative preview language only and confer no authority to process any image. No photo processing may occur unless and until updated notice, Material Change re-acceptance where required under §23.2, and separate, unchecked, granular point-of-upload consent are live; today's assent does not pre-authorize any photo processing, and a future photo feature will capture fresh granular consent at that time. Enabling any photo feature is a Material Change under §23.2 and an independent re-verification gate in the pre-launch checklist.

14.1A UNIFIED BIRTH-DATA CONSENT (v7.4). One identical consent notice and unchecked consent control is presented at every point in the Application where birth information (birth date and, where requested, birth time, birthplace, birth year, or gender) is entered, immediately before the reading is generated. Checking that single control constitutes the explicit consent required by §14.1 for the one-time processing of the birth information entered on that screen, together with any text entered in the same flow, solely to compute and generate the requested reading. Birth information is not retained after the reading is generated, is never sold or shared with advertisers, and is never used to train AI models, per §14.1 and §14.2. Each consent is logged with a timestamp and version as a business record (Annex A). This §14.1A governs the presentation and grouping of the §14.1 consents; the no-storage, no-training, and no-sale commitments of §14.1 apply unchanged, and where this §14.1A and §14.1 differ on the number or grouping of consent controls, this §14.1A controls.

14.2 NO AI TRAINING; DPA. Provider does not use User Inputs, Readings, or personal data to train, fine-tune, or improve any AI model, and requires each AI-model supplier and sub-processor, by written data-processing agreement, to be similarly prohibited and to act only on Provider's documented instructions (Annex B).

14.3 DATA RIGHTS & PORTABILITY. You may exercise rights of access, rectification, erasure, portability (including export of your saved Reading history in a machine-readable format; birth data is not stored and therefore cannot be exported), restriction, objection, and withdrawal of consent as set out in Annex C.

14.4 DPIA ACKNOWLEDGMENT. Provider acknowledges that processing of special-category data at scale may require a Data Protection Impact Assessment under GDPR Art. 35 and maintains one where required; the transient, no-storage processing design of §14.1 is a primary mitigation recorded in that assessment.

14A. GEOLOCATION DATA

Provider processes only approximate (IP-derived) region for security, rate-limiting, localization, and legal-compliance purposes. Provider does NOT collect precise or GPS geolocation at launch, and no feature requests it.

14B. MULTI-JURISDICTIONAL COMPLIANCE & INTERNATIONAL TRANSFERS

Where applicable law of your residence (including GDPR, UK GDPR, PIPEDA, Quebec Law 25, CCPA/CPRA, Virginia CDPA, Colorado CPA, and analogous statutes) grants rights or imposes requirements beyond these Terms, those laws control to the extent of the conflict. Where personal data is transferred internationally, Provider relies on lawful transfer mechanisms, including the EU/UK Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary measures where required. Region-specific disclosures (legal bases, transfer mechanisms, and supervisory-authority contacts) are set out in Annexes B–C.

14C. OPTIONAL ACCOUNTS, SSO AUTHENTICATION & ANALYTICS

Accounts are optional; the deterministic and static tools may be used anonymously, and Provider does not require sign-in to browse or to use them. Upon optional SSO sign-in via an Identity Provider, Provider receives your name, email, and Identity Provider identifier; Provider does not receive your password. For Account Holders, Provider logs only the functional data necessary to operate the Application and enforce fair-use limits under §12A (security, rate-limiting, feature-usage counts, the one-glimpse counter, and streak/history you choose to save). Product analytics are privacy-friendly and aggregate only: no cross-site tracking, no advertising pixels, and no third-party ad cookies; AI prompts are recorded only as anonymized counters, not as content, except for the signed-in User's own saved reading history. You may delete your Account and all associated data at any time via a one-click "Delete my data & account" control in settings (hard delete), subject only to retention required by law (Annex E).

14D. RECORDING & INTERCEPTION — PRIOR CONSENT

To the extent session-replay, chat-logging, or similar tools are used, they are disclosed here and activated only with prior consent where required, including under the California Invasion of Privacy Act. Reading transcripts are stored to provide your history and may be deleted by you at any time.

14E. AUTOMATED PROCESSING

Readings are, by their nature, automated generation of entertainment content. This processing does not produce legal or similarly significant effects within the meaning of GDPR Art. 22 or Quebec Law 25 s. 12.1; you may nonetheless object or request human review by contacting the privacy officer through the Contact & Legal Notices form in the Application. Provider will update this section, with prior notice and opt-out where required by law, if processing producing such effects is ever introduced.

14F. DATA BREACH NOTIFICATION

In the event of a security breach affecting your personal information, Provider will notify affected Users and applicable regulators in accordance with applicable law, including GDPR Art. 33 (72-hour regulator notification), Cal. Civ. Code §1798.82, NY SHIELD Act §899-aa, PIPEDA s. 10.1, and Quebec Law 25 s. 3.5.

14G. COMMERCIAL ELECTRONIC MESSAGES — CASL/CEM EXPRESS CONSENT

Because Provider is a British Columbia company, all optional marketing or promotional emails (including the newsletter/daily-wisdom digest under §14 and any "notify me if this feature launches" interest email under §6A.0.1) are Commercial Electronic Messages and are sent only with your express, opt-in consent under Canada's Anti-Spam Legislation (CASL) and analogous laws. (a) Express consent is captured by a separate, unchecked box or equivalent affirmative action; it is never bundled with, or a condition of, acceptance of these Terms or creation of an Account. (b) At the point of consent Provider identifies the sender (Aurora Oracle Ltd.), provides, within the message itself, the sender identification, mailing address, and working contact mechanism that CASL requires, and states the specific mailing purpose and scope. (c) Consent is scope-limited: registering interest in a coming-soon feature authorizes ONLY a one-time notification about that specific feature's launch, and does NOT sign you up for the newsletter or any other marketing unless you separately opt in to it; the newsletter and each feature-launch notice are separate, independently checked consents. (d) Where used, the newsletter uses double opt-in (a confirmation email verifying the request before any digest is sent). (e) Every CEM identifies Aurora Oracle Ltd. as sender, includes current contact information, and provides a working one-click unsubscribe honored promptly; you may withdraw consent at any time. (f) Transactional and service notices (e.g., Terms/Privacy changes, security, account, and billing communications) are not marketing, are governed by §15, and are kept separate from these commercial messages.

PRIVACY ANNEXES

A. Acceptance Logging

Provider logs each acceptance event (timestamp, Terms version, hashed IP, user agent, Account ID and SSO provider if applicable, and each purchase, auto-renewal, and withdrawal-waiver consent) as a business record.

B. Processors

Personal data is processed by vetted sub-processors under data-processing agreements: cloud hosting, AI-model providers (which are contractually prohibited from using User Inputs, Readings, or personal data to train, fine-tune, or improve their models), payment processors, email-delivery, and security/anti-bot services. Each sub-processor acts only on Provider's documented instructions and is bound by GDPR Art. 28-compliant terms. A current sub-processor list is available on request.

C. Data Rights

Depending on your jurisdiction, you may have rights of access, rectification, erasure, portability, restriction, objection, withdrawal of consent, and the right to lodge a complaint with a supervisory authority. Requests: through the Contact & Legal Notices form in the Application (select "Privacy Rights"). Provider does not discriminate or retaliate against Users who exercise privacy rights. Provider does not sell or "share" personal information; "Do Not Sell or Share" and "Limit the Use of My Sensitive Personal Information" requests, and opt-out preference signals (including Global Privacy Control), are honored where applicable.

D. De-Identification Standard

Data used for service improvement is de-identified so that it cannot reasonably be used to infer information about, or otherwise be linked to, a particular individual; Provider maintains technical and organizational measures to prevent re-identification and does not attempt to re-identify. De-identified data is never used to train third-party AI models. For GDPR/UK GDPR special-category data, "de-identified" means irreversibly anonymized so the data is no longer personal data; pseudonymized or reasonably de-identified data is not used for product improvement without a separate valid lawful basis.

E. Retention (minimal-collection launch)

Anonymous tool use: no server-side storage of your inputs. Birth data (date, time, place): NEVER STORED — processed transiently in memory and discarded immediately after your reading is generated. Reading/streak history (signed-in Users only; reading text only, never birth data): until you delete it or your Account (one-click hard delete), and no longer than 24 months of inactivity. Account data: life of Account. Optional newsletter/interest email: until you unsubscribe or withdraw. Approximate region, device/log, and security data: short operational retention only. Aggregate analytics: retained in non-identifying form. Acceptance logs: 6 years. Billing records (DORMANT — none collected at launch): if paid features are enabled, as required by tax law (typically 7 years); unused credits per §6A.9.

F. Security

Encryption in transit and at rest, access controls, least-privilege staffing, logging, and periodic security review. No system is perfectly secure; see §14F for breach notification.

G. Children

The Application is strictly 18+. Provider does not knowingly collect data from anyone under 18; if Provider learns that a User is under 18, it will promptly disable the Account and delete the data except as legally required. (COPPA-style parental-consent flows are not offered because minors are not permitted at all.)

H. Changes

Privacy-annex changes follow §23.2.

I. Survival

Annexes A, D, E, F survive Account deletion to the extent of residual legal obligations.

J. Cookies

Provider uses strictly necessary cookies only and prefers to use no non-essential cookies; a consent banner is shown only if any non-essential cookie is introduced (ePrivacy/PECR). Analytics are privacy-friendly and do not use cross-site tracking. No third-party advertising cookies or ad pixels are used.

K. Conflict

Where an Annex conflicts with mandatory local law, local law controls.

L. Bot & Security Verification

Anti-abuse services (e.g., Cloudflare) process connection metadata to protect the Application and enforce fair-use limits under §12A; no Engagement Analytics is recorded by any such provider absent the §14C opt-in.

© 2026 Aurora Oracle Ltd. All rights reserved.