Privacy

Privacy Policy

Written to be read, not to be survived.

Last updated: 2 September 2026

Don't take our word for it — verify it yourself

The Ancient Cycle is built on data minimisation. We ask for the few details needed to cast your charts and write your weekly reading, and we ask for nothing else.

Where your data lives

Your data sits in two separate places, and the difference matters more than anything else on this page.

Your diary stays on your device. When you log a day — your flow, your symptoms, your mood, your energy, and a private note — that entry is written into storage inside your own browser. It is not sent to us. There is no sync and no upload. We cannot read it, we cannot search it, we cannot produce it if someone asks us for it, and we cannot recover it for you if you lose it. That last part is a real cost, and it is why there is an export button.

Your account and your chart inputs are on our server. A birth chart cannot be calculated without a birth date, and a weekly reading has to be written somewhere. So your identity, your birth details, your cycle dates and your readings do live in a database we run. The things we need in order to calculate something are with us. The diary is with you.

What we store

Nine tables. That is all of it.

  • Your profile — your email address, your first name, the date you joined, the language you read in, whether you want the Sunday email, and a private token used to build your unsubscribe and email links.
  • Your birth data — birth date, birth time if you know it and choose to give it, and your birth place with its latitude, longitude and the time-zone offset that applied there on that date. A chart cannot be calculated without these. We also keep the three charts calculated from them, so they do not have to be recomputed every time you open the app.
  • Your cycle settings — the start date of your most recent period, your average cycle length and your average period length.
  • Your period log — the date each period started and the date it ended. Dates only. Nothing else is recorded in that table: no symptoms, no notes, no descriptions.
  • Your reminder settings — whether you have reminders switched on, how many days ahead you want them, which weekday you prefer, and when we last sent one, so we do not send it twice.
  • Your subscription and entitlement records — your Stripe customer reference, your plan, its status, and the payment references that prove you have access. We never see or store your card number.
  • Your readings — the weekly readings we wrote for you, kept so you can re-read them.
  • Free chart emails — if you signed in and asked us to email a free birth chart to your verified account address, we keep that address, the language you used, where you came from, and whether you agreed to hear from us again. Your birth details are not stored with it.

Every one of those tables is protected by row-level security, so an account can only ever read its own rows.

Why we store it

One purpose only: to generate your charts and your weekly reading, and to keep your membership working. Birth details position the three skies. Cycle settings place you in your phase. The subscription row tells us what you can see. The one exception to that single purpose is the free-chart email address: it is stored so we can send you the chart you asked for, and — only if you agreed — occasional word from us. You can ask us to delete it at any time. Nothing here is used for profiling, scoring, targeting, or research.

What never reaches us

The app lets you log symptoms, moods, energy and a private note. Those features exist and we think they are useful. They are never sent to us. They are written to storage in your browser and they stay there.

This is deliberate, and it is enforced in the code rather than promised in prose: the file that defines that data carries an instruction at the top that nothing in it may ever be written to our database, sent through a server function, or included in any network request. It is kept out of the same cache that holds server data specifically so the two can never be confused.

We do not run third-party analytics. There are no third-party analytics tools, tracking pixels or advertising tools anywhere in this product. Our host counts page views for us, first-party and in aggregate — no profile of you, and nothing tied to your diary.

Legal basis: your consent

We process your data on the basis of the consent you gave in step three of onboarding. You can withdraw that consent at any time, and withdrawing it is simple: delete your account from Account & Privacy. Deletion is how consent is withdrawn, because once the data is gone there is nothing left to process. Withdrawing consent does not affect processing that already lawfully happened.

We do not sell or share your data

We do not sell your data. We do not rent, trade or broker it. We do not share it with advertisers, data brokers, insurers or employers. We do not publish it. The only third parties who touch it are the three processors below, each doing one narrow job on our instructions.

The processors we use

  • Supabase — hosts the database and handles sign-in. Your rows live here. supabase.com/privacy
  • Stripe — takes payment and holds your card details. We never see or store a card number; we keep only a customer reference and a status. stripe.com/privacy
  • Resend — delivers the Sunday reading email, if you asked for it. resend.com/legal/privacy-policy

Security

Our database is hosted by Supabase, which encrypts all customer data at rest with AES-256 and in transit with TLS. Every table has row-level security enabled, so one account cannot read another account's rows. Payments run through Stripe, and card details never touch our systems.

We want to be accurate about what that does and does not mean. Encryption protects your data on disk and while it travels. It does not make your data invisible to us, and it is not a shield against a valid legal order. Anyone who tells you their encryption puts them beyond the law is overselling.

Who can read your rows

Every table is protected by row-level security. A signed-in account can only ever read, change or delete rows belonging to that same account — including ours.

Feedback you send us

If you choose to send feedback — a rating on a weekly reading, or a note from the feedback page — it is stored with your account and used only to improve the app. It is never shared or sold, and it is never shown publicly unless you tick the box allowing us to quote it, in which case we would use your first name only. It is deleted when you delete your account.

If you choose to add your birth name, it is stored with your birth details and used only to calculate your numerology numbers. You can remove it at any time in settings.

Government and legal requests

As of 2 September 2026, we have received no government or law-enforcement request for user data. If that ever changes, this page changes with it.

If we do receive one, we will require valid legal process — we do not hand over data on an informal request. We will provide only what the order actually compels and nothing beyond it. And we will tell you, unless we are legally prohibited from telling you.

There is one thing we could not hand over even if we were compelled to: your symptoms, your moods, your energy and your notes. Those have never been on our server. They are in your browser, and a demand addressed to us cannot reach them.

What we could be compelled to produce is what we actually hold: your email address, your first name, your birth details and the charts calculated from them, your period start and end dates, your reminder settings, your payment references, and your readings.

How long we keep it

On our server: until you delete it. There is no fixed retention schedule and no archive. When you delete your profile it is a hard delete — no soft delete, no grace period, no shadow copy. We have nothing to restore it from, including for ourselves.

On your device: entirely up to you. The log stays in your browser until you clear it, either with the delete button in the app or by clearing your browser data. Deleting your account does not touch it, because we cannot reach it.

Your rights: export and delete

  • Download my data — on Account & Privacy, one button builds a JSON file containing every row we hold about you, generated fresh at the moment you ask.
  • Delete my account — the same page. It hard-deletes your profile, birth data, cycle settings, subscription record and every stored reading, cancels your Stripe subscription, and signs you out. No soft delete, no grace period, no shadow copy. This works even if a payment has failed; billing problems never lock you out of deleting your data.
  • You may also ask us to correct anything, or object to processing, by email. If you only ever asked for a free chart and never made an account, that is also how you have your address removed — write to us and it goes.

One more thing

The Ancient Cycle is for reflection and educational purposes only. It is not medical advice, not a contraceptive method, and not a diagnostic tool.

Contact

Write to privacy@ancientcycle.app with any question or request about your data. A person reads it.