Legal
Privacy Policy
Last updated: April 17, 2026.
This policy explains how Oracle Now handles personal data under GDPR, UK GDPR, CCPA, and Japan's APPI. It describes what we collect, why we collect it, and your rights.
Data Controller and Contact
Controller: Oracle Now. Contact email: support@askoraclenow.com.
Data Subject Access Requests (DSAR), deletion requests, and privacy complaints can be sent to the address above. We aim to respond within 30 days.
Data We Collect
- Question text you submit, which may include sensitive topics such as health, relationships, or emotional state.
- Email address collected during Stripe checkout.
- Birth date (optional), when provided by you.
- Payment metadata from Stripe (we do not store full card numbers).
- Usage and performance data for analytics, using PostHog with autocapture and session replay disabled.
Lawful Bases (GDPR and UK GDPR)
- Contract performance: generating and delivering readings and transactional email.
- Legitimate interests: service reliability, fraud prevention, and product analytics.
Japan Supplement (APPI / 個人情報保護法)
For users in Japan, Oracle Now handles personal information in accordance with the Act on the Protection of Personal Information (APPI). We use personal information only as necessary to provide readings, process payments, send transactional emails, prevent fraud, maintain service security, and comply with legal obligations.
Question text may include sensitive or intimate topics. We process that content only to generate the requested reading and operate the related service flow, and we do not sell that information for advertising.
If we entrust processing to service providers located outside Japan, we do so for payment, hosting, email, analytics, AI generation, and infrastructure operations, subject to contractual and operational safeguards.
How We Use Data
- Generate your reading and deliver paid unlock access.
- Send transactional reading summary emails.
- Operate, debug, and improve product quality.
- Produce aggregated analytics and performance reporting.
We do not sell personal data and we do not profile users for advertising based on question text.
Storage Location, Processors, and International Transfers
Data is stored in Supabase (region depends on project configuration). Our processors may process data in the United States or the European Union.
- Stripe (payments, US and other regions)
- Anthropic (AI generation, US)
- Resend (transactional email, US)
- PostHog (analytics, EU/US depending on setup)
- Vercel (hosting and logs, US)
For cross-border transfers, we rely on applicable safeguards such as Standard Contractual Clauses (and UK transfer addendum where required).
Retention and Deletion
Reading records and related metadata are retained for up to 12 months unless a shorter legal or contractual period applies.
You can request deletion via support@askoraclenow.com. We process valid requests within 30 days, subject to legal exceptions.
Requests From Users in Japan
Subject to APPI and other applicable laws, users in Japan may request notice of purpose of use, disclosure, correction, addition, deletion, suspension of use, erasure, or suspension of third-party provision for retained personal data where legally required.
To make a privacy request, contact support@askoraclenow.com. We may ask you to verify your identity before acting on a request.
Your Rights (GDPR and UK GDPR)
- Right of access
- Right to rectification
- Right to erasure
- Right to restriction of processing
- Right to data portability
To exercise these rights, contact support@askoraclenow.com.
Your Rights (CCPA)
- Right to know what personal information we collect and use
- Right to request deletion
- Right to non-discrimination for exercising privacy rights
- Right to opt out of sale/share (we do not sell personal data)
Cookies and Analytics
We use first-party cookies for essential functionality and analytics preferences. For visitors likely located in Europe, a cookie consent banner appears on first visit.
Analytics is run through PostHog with manual events, autocapture disabled, and session replay disabled.
Security Controls and Vendor Management
We apply administrative, technical, and organizational safeguards appropriate to the nature of the data we process. These may include access controls, least-privilege permissions, audit logging, contractual processor obligations, and vendor review before service providers are used in production.
Sensitive Topics and Children
Question text may contain sensitive personal topics. We use this content only to generate your requested reading and service-related operations.
Oracle Now is intended for adults 18 and older. We do not knowingly provide services to children.
Policy Changes
We may update this policy as the product evolves. Material updates will be reflected by a new “Last updated” date on this page.
Related legal terms: Terms of Service and 特定商取引法に基づく表記.