Privacy Policy
How we collect, use, and protect your information.
Last updated: September 5, 2026
- Who we are
- What information we collect
- How we use it
- AI processing and automated decision-making
- Legal basis for processing
- Who we share it with
- How long we keep it
- Your rights and how to exercise them
- California residents (CCPA / CPRA)
- EEA / UK residents (GDPR)
- Children
- Security
- Cookies and local storage
- Changes to this policy
- Contact
1. Who we are
"Arcana Origin," "we," "us," and "our" refer to Alex Costa, an individual based in the United States, doing business as Arcana Origin. Our primary website is arcanaorigin.com (the "Service"). The Service is operated as a sole proprietorship.
For all privacy inquiries, contact us at hello@arcanaorigin.com.
2. What information we collect
Information you give us
| Data | Where it comes from | Required? |
|---|---|---|
| Full name | Profile form in the engine | Yes — used in numerology and name-based calculations |
| Date of birth | Profile form | Yes — the foundation of every reading |
| Time of birth | Profile form | Optional — improves astrological accuracy |
| Place of birth (city, country) | Profile form | Optional — used for chart-based traditions |
| Email address | Free-tier signup, paid purchase via Stripe, or support contact | Yes for purchases and free tier |
| Payment information | Submitted directly to Stripe — we never see card numbers | Yes for paid tiers |
| Persona fields (gender, relationship status) | iOS app onboarding only | Optional — used to tailor the app's love and relationship readings; never required |
Information collected automatically
- IP address (truncated to /24) — used solely to rate-limit free-tier abuse (max one free reading per network per 30 days). Full IP addresses are not stored.
- Browser User-Agent (first 80 characters) — used to detect automated abuse.
- Device identifier — a random value the browser generates and stores for itself, sent with API requests as
X-AO-Deviceto rate-limit free-key abuse. Not a hardware or advertising identifier; clearing site data replaces it. - Country code — derived from your network connection, used for analytics aggregates and abuse prevention.
- Local storage values — stored in your own browser, not on our servers. See Cookies and local storage below.
What we do NOT collect
- Health information, sexual orientation, religious or political affiliation (beyond what users voluntarily put in their name field)
- Precise geolocation (we only see country)
- Advertising IDs, cross-site trackers or browser fingerprinting. Both the website and the iOS app do generate a random, resettable identifier for the browser or app installation itself, used only to stop one free key being claimed over and over — see Cookies and local storage and 2a
- Information from third-party data brokers
- Information about your activity on other websites
2a. The iOS app and accounts
The Arcana Origin iOS app has its own App Privacy Policy at arcanaorigin.app, which describes exactly what the app collects on your device (birth data, optional persona fields, a random Keychain identifier, photographs for Oracle rites, a one-time location read, local notifications) and how App Store purchases and optional accounts work. This document covers the website. Where you use both, the App Privacy Policy governs data collected in the app and this policy governs data collected on the website; your reading keys and any account you create are shared between the two under the terms of both. If you have an account, its data (email, birth data, readings, journal) is stored in our user database hosted by Cloudflare and can be exported as JSON or deleted from the app, from the account page on the website, or by emailing hello@arcanaorigin.com. Deletion is immediate and irreversible; your key balance is kept on the token and is not affected.
3. How we use it
- To generate your reading. Your name and birth data are passed through deterministic calculation engines (numerology, ephemeris, calendrical) and to our AI provider for synthesis (see Who we share it with).
- To deliver and watermark your PDF. Your name appears on the cover and in a tracking watermark.
- To process payments. Email and payment method via Stripe.
- To prevent abuse. IP rate-limiting on the free tier, token-based rate-limiting on AI calls.
- To respond to support requests. When you email
hello@arcanaorigin.comor use the in-engine Help modal. - To send transactional emails. Payment receipts, subscription notices, support replies. We do not send marketing emails without explicit opt-in.
Marketing emails. We do not send marketing emails by default. If we ever offer a newsletter or launch announcement, opt-in is via an explicit checkbox at the point of signup — never pre-checked. Every marketing email contains a one-click unsubscribe link, and you can also revoke consent at any time by emailing hello@arcanaorigin.com. Transactional emails (receipts, subscription renewal notices, support replies) are not optional because they are required to deliver the Service you purchased.
4. AI processing and automated decision-making
A core part of the Service is the AI-generated narrative interpretation of your name and birth data. We use Anthropic's Claude API as a data processor to synthesize the prose chapters of your reading. The deterministic calculations (Life Path number, planetary positions, hexagram selection, Tzolkin tone, etc.) are computed by our own engine in your browser or on our server. Only the results of those calculations — not your raw date or place of birth alone — are sent to Claude alongside your name so the narrative can address you personally.
Is this "automated decision-making" under GDPR Article 22? Technically yes — the Service uses automated processing to produce personalized output. However, the output is a symbolic and contemplative narrative intended for entertainment and personal reflection. It does not produce legal effects, employment outcomes, credit decisions, insurance decisions, eligibility for any benefit, or any other consequence that materially affects your rights or status. You are free to disregard, reinterpret, or disagree with any part of the reading.
If you object to AI processing of your data, please do not submit your information. You may also request deletion of any data we have processed by emailing hello@arcanaorigin.com. We do not currently offer a human-only alternative to the AI-generated narrative.
Anthropic does not use API customer data to train its models. See Anthropic's privacy policy for details on how they handle data they receive from us as a processor.
5. Legal basis for processing
For users in the EEA, the UK, Switzerland, and other jurisdictions that require an explicit legal basis (such as GDPR Article 6), we rely on the following:
| Activity | Legal basis |
|---|---|
| Generating and delivering your paid reading | Performance of a contract (GDPR Art. 6(1)(b)) |
| Generating and delivering your free trial reading | Consent, given by submitting your email (GDPR Art. 6(1)(a)) |
| Marketing emails (if you opt in) | Consent (GDPR Art. 6(1)(a)) |
| Rate-limiting, fraud and abuse prevention | Legitimate interest in protecting the Service (GDPR Art. 6(1)(f)) |
| Tax, accounting, and financial records | Legal obligation (GDPR Art. 6(1)(c)) |
| Responding to a lawful legal request | Legal obligation (GDPR Art. 6(1)(c)) |
| Processing of sensitive PI (date of birth) for the contracted reading | Explicit consent given by submitting it for that purpose (GDPR Art. 9(2)(a)) |
You may withdraw consent at any time by emailing hello@arcanaorigin.com. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
6. Who we share it with
We share data with a small number of vetted service providers, each acting as a data processor on our behalf:
| Provider | What they receive | Why |
|---|---|---|
| Anthropic | Your name and computed astrological / numerological data (e.g., "Life Path 7, Sun in Gemini") in the form of AI prompts; for an Oracle rite, additionally the photograph you submit, for that reading only | To generate the narrative interpretation. Anthropic does NOT train on API customer data. |
| Stripe | Email, name, payment method, billing address, IP | Payment processing |
| Cloudflare | Hosting and serverless function execution (Workers); your reading token and balance are stored in Cloudflare KV; DNS, email routing for Also Cloudflare Web Analytics: a cookieless page-view counter that records the page, referrer, browser type and country of each visit in aggregate. It sets no cookie and does not fingerprint your device; we cannot identify you from it.hello@arcanaorigin.com, and the account database and API (email, birth data, archived readings, journal) | Hosting, storage, email, CDN and account infrastructure |
| Apple | Purchase and subscription processing for the iOS app, and Sign in with Apple; Apple receives your payment details, we do not | In-app purchases and sign-in |
| Resend | Your email address, to deliver one-time sign-in codes and account emails | Transactional email |
| Google (Gmail) | Support inbox where Cloudflare forwards your emails | Customer support inbox |
We never sell your personal information. We have not sold or shared personal information with third parties for advertising or marketing in the past 12 months and we do not intend to.
We have entered into data processing agreements (DPAs) or equivalent contractual safeguards with each processor listed above, where required by law. Material changes to our list of sub-processors will be communicated through this page; we recommend you check the "Last updated" date periodically.
7. How long we keep it
| Data | Retention period |
|---|---|
| Free-tier token + email hash | 30 days from issuance, then auto-deleted |
| Paid-tier token + email | Up to 1 year from last activity, or until you request deletion — except that a token still holding unused paid credits is kept until those credits are used or you ask us to delete it, so that credits you paid for never expire |
| Payment records (Stripe) | 7 years per US tax retention requirements |
| Support emails | 2 years from last reply |
| Birth data submitted in the engine | Stored in your browser's local storage only. We do not retain your birth data on our servers after the reading is generated, unless you have an active paid subscription where the token is tied to your purchase, or you have created an account (Section 2a), in which case it is stored in your account until you delete the account. |
| Account data (email, birth data, archived readings, journal) | Until you delete the account from the app, the website, or by email |
| Oracle rite photographs | Not retained |
8. Your rights and how to exercise them
Regardless of where you live, you have the following rights:
- Right to access — ask what data we hold about you and receive a copy
- Right to correct inaccurate data
- Right to delete — request deletion of your data (the "right to be forgotten")
- Right to object to certain uses of your data, including profiling
- Right to portability — receive a copy of your data in a portable, machine-readable format
- Right to withdraw consent at any time where we rely on consent
- Right to lodge a complaint with your national data protection authority (EEA/UK) or other supervisory authority that has jurisdiction over your data
How to submit a request
Email hello@arcanaorigin.com with the subject line "Privacy Request: [type]" — for example, "Privacy Request: Delete my data" or "Privacy Request: Export my data." Please tell us in the body which right you want to exercise and any context that helps us locate your information.
How we verify your identity
To prevent unauthorized requests, we verify your identity before acting. The simplest method: reply to our acknowledgement email from the address registered with your account, or include a copy of your Stripe receipt or the Checkout Session ID from your purchase. We will never ask for a password, government ID, or banking information to verify a privacy request.
Response timeline
We acknowledge every request within 5 business days and complete it within 30 days. For complex requests we may extend by up to 60 additional days (90 days total) and will tell you why before the original 30-day window expires. We never charge you for exercising these rights.
If we cannot fully fulfill a request
Some data is retained for legal reasons (for example, Stripe payment records held seven years per US tax law). If we cannot delete a particular item, we will tell you exactly what was deleted, what was retained, and the legal basis for retention.
Account deletion specifically
Deleting your account removes: your authentication token, your free-key index entry (the hashed email and the truncated /24 IP), and any cached profile data tied to your token. Retained: Stripe payment records (seven years, held by Stripe), anonymized audit logs (one year, no personal identifiers). You will receive a confirmation email when deletion is complete.
Escalation
If you are unhappy with our response, you may lodge a complaint with the data protection authority in your country (such as the UK Information Commissioner's Office, the Portuguese CNPD, the French CNIL, the German Bundesbeauftragte für den Datenschutz, the California Attorney General, or any other supervisory authority that has jurisdiction over your data).
9. California residents (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act ("CCPA") as amended by the California Privacy Rights Act ("CPRA"):
- Right to know — the categories of personal information we collect, the sources, the purposes, and any third parties with whom we share it (all disclosed above).
- Right to delete — request deletion of your personal information, subject to certain exemptions (e.g., tax records).
- Right to correct — request correction of inaccurate personal information.
- Right to opt out of sale or sharing — we do not sell or share personal information. No opt-out is required.
- Right to limit use of sensitive personal information — under the CPRA, your date of birth combined with your name is classified as "sensitive personal information." We use it only to generate your reading and to watermark your PDF. We do not use sensitive PI to make inferences about your characteristics, to profile you for marketing, to share with any party other than the processors named in section 6, or to process it beyond the bounded purpose for which you submitted it. You may ask us at any time to limit further use of your sensitive PI by emailing hello@arcanaorigin.com with the subject "California Privacy Request — Limit Sensitive PI."
- Non-discrimination — we will not deny service, charge different prices, or provide a lower quality of service because you exercised any of your CCPA rights.
To exercise a California right, email hello@arcanaorigin.com with the subject line "California Privacy Request" and the right you want to exercise. We verify identity by replying to the email address associated with your account.
10. EEA / UK residents (GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, in addition to the rights described in section 8:
- Our legal bases for processing are itemized in section 5.
- You have the right to lodge a complaint with your national data protection authority.
- Personal data is transferred to the United States. Anthropic, Stripe, and Cloudflare provide appropriate safeguards under the EU–US Data Privacy Framework and/or Standard Contractual Clauses.
- We do not appoint a UK or EU representative because our processing volume is below the regulatory threshold and we do not target the Service exclusively at EU users. If this changes, this policy will be updated.
11. Children
The Service is not directed to children under 13 (or under 16 in the EEA). We do not knowingly collect personal information from children. If you believe a child has provided us information, please email hello@arcanaorigin.com and we will delete it promptly.
12. Security
We implement industry-standard safeguards:
- HTTPS / TLS encryption in transit on every page and API call
- Strict Content Security Policy and HTTP Strict Transport Security
- Token-based authentication for paid features, never password-based
- Stripe handles all card data; we never see, store, or transmit it ourselves
- Server-side credit storage with atomic decrement to prevent fraud
- Per-token rate limits to prevent automated abuse
No system is perfectly secure. In the unlikely event of a data breach affecting your personal information, we will notify you and the relevant authorities within 72 hours of discovery as required by applicable law.
13. Cookies and local storage
We set no third-party analytics or advertising cookies. The website keeps the following in your own browser's local storage. None of it is a cookie, none of it is sent to a third party, and all of it is removed when you clear site data for arcanaorigin.com. Where an entry holds personal data, that data stays in your browser unless you sign in to an account or spend a key, in which case Section 2a and Section 7 describe what reaches our servers.
| Key | What it holds | Lifetime |
|---|---|---|
ao_token, sym_token | Your reading token — the identifier your key balance is attached to. Two names for the same thing; older sessions carry sym_token | Until cleared or expired |
ao_session, ao_account_email | If you sign in, your account session secret and the email address you signed in with. Personal data | Until you sign out or clear |
ao_device_id | A random identifier this browser generates for itself, sent to our API as X-AO-Device so one free key cannot be claimed repeatedly from the same browser. It is not a hardware or advertising identifier, is not shared with anyone, and is regenerated if you clear it | Until cleared |
ao_name, ao_dob, sym_profile_v1 | The name, date of birth and full profile (time and place of birth, if given) you typed into the engine, so a return visit does not ask twice. Personal data | Until cleared |
sym_report_data, sym_reading_history_v1 | The reading last generated for you and your local reading history, so the report and PDF views can render without recomputing. Personal data | Until cleared or replaced |
ao_oracle_history, oracle_history_v1, _R | Your Oracle conversation and the chart it is answering about, so a chat survives a page reload. Personal data | Until cleared |
ao_wait_email, ao_wait_code, ao_waitlist | The email address and confirmation code you gave the waitlist, and its local state. Personal data | Until cleared |
ao_ref_source, sym_ref_code, sym_ref_from | The referral code you arrived with and your own code, so the person who invited you can be credited when you claim a key. First-party only; not advertising or cross-site tracking | Until cleared |
sym_lang, sym_tier, ao_launch, ao_pwa_dismissed | Preferences and display state — chosen language, the plan the interface should show, whether the engine has been opened before, whether you dismissed the install prompt | Until cleared |
sym_owner, sym_owner_key, ao_owner_key, sym_master_key, sym_pract, sym_pbrand, sym_stripe_basic | Operator and practitioner mode: whether this browser runs in white-label mode, under which brand, and the practitioner's own payment link. Set only for practitioner subscribers and the site operator | Until cleared |
arcana_validation_stats_v1 | Counters for the accuracy figures shown on the methodology page. No personal data | Until cleared |
| Stripe Checkout cookies | Necessary for completing payment | Per Stripe's policy |
| Cloudflare cookies | Necessary for DDoS protection and CDN routing | Per Cloudflare's policy |
The iOS app stores your birth data, cached readings, Oracle chat history, journal and preferences in the app's sandbox, and your sign-in session and key token in the iOS Keychain. Uninstalling the app removes the sandbox; the Keychain items are removed when you sign out or delete the account.
Every entry above is first-party and either strictly necessary to deliver something you asked for or a preference you set yourself, so no consent banner is required under the EU ePrivacy Directive or the CCPA. We set no third-party, advertising or cross-site tracking storage of any kind. If we ever add analytics or marketing storage that is not strictly necessary, we will publish a separate cookie policy and ask for your consent before setting it.
You can remove all of it at any time by clearing site data for arcanaorigin.com in your browser. Doing so also clears your reading token, so save or export any reading you want to keep first.
14. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent revision. Material changes will be communicated by email to active subscribers and via a banner on the website. Continued use of the Service after a change takes effect constitutes acceptance.
15. Contact
For any question about this policy, your data, or a complaint:
Alex Costa (doing business as Arcana Origin)
Attn: Privacy
1057 Saratoga St
Boston, MA 02128
United States
Email: hello@arcanaorigin.com