Privacy Policy

Operated by Unify Labs, Ltd.. Effective July 31, 2026.

What we collect

Why we use it, and our legal basis

We use birth details, journal, chat, and settings to provide the charts, readings, and account features you request. We use contact submissions to answer you, billing data to process a purchase, and operational records to run and secure the service. Depending on the context and where you live, our legal bases include performing our agreement with you, your consent where we ask for it, our legitimate interests in operating and protecting the service, and compliance with legal obligations. You can withdraw consent where it applies without affecting processing that was already lawful.

Who processes it

We keep the list of service providers short and name them plainly. They process data as needed to provide the role described below.

Where your data lives

Your primary account and app data are stored with Supabase (Postgres) in a United States region and encrypted at rest by the platform. Row-level security means each account can reach only its own rows, and anonymous sessions get the same protection as email accounts. Other service providers, including AI and payment providers, may process the relevant data in regions where they operate. Processing may occur outside your country, subject to applicable data-protection requirements.

How long we keep it

DataKept for
Your charts, readings, journal, chat, and Oracle memoryUntil you delete them or delete your account
Contact form submissions and an optional reply addressUp to 180 days; account-linked submissions are removed sooner when you delete the account
Background job records (used to prepare your readings)7 days after they finish, then removed
Product analytics events (in-house, no third-party vendor)90 days, then removed
Safety and audit logs (abuse prevention, integrity)180 days, then removed; anonymized immediately if you delete your account
Short-lived rate-limit counters2 days, then removed; IP-based counters use a keyed, rotating digest rather than the raw address

Your rights and controls

Export returns the account data available through the export control, including Bonds birth data you added. Delete removes your account, its associated charts, readings, journal, chat, memory, Bonds, account-linked contact submissions, and the sign-in itself. Other contact submissions follow the retention schedule above; safety and audit records are anonymized when account deletion requires it. The account controls live in Settings → Data & privacy. You can also send a privacy request through our contact form.

Children

AwakenFate is for people 16 and older. We enforce this at onboarding from the birth date you enter, and we do not knowingly keep data from anyone younger.

What we never do

We do not sell your data, ever. We do not show ads. We do not infer sensitive attributes about you — the Oracle's memory keeps only facts you state yourself, and every remembered item is visible and deletable in the app. We do not use your content to train models that we operate or share it for anyone else's marketing. When an external AI route is used, the selected provider receives the request context described above; its handling is governed by its terms and our configuration.