Skip to the policy
ORRERYReturn to Charter

Orrery / Data practice

Privacy

A small service should ask for little, explain it plainly, and let it go.

Effective August 11, 2026

What this notice covers

This notice covers the Orrery Founding Moment Charter at /moment. It does not replace the separate privacy notice for the free Orrery app.

What Orrery asks for

The founding intake asks only for information needed to review and fulfill one Charter:

  • Your reply email.
  • The general category and short action statement for the moment.
  • Your timezone.
  • Two to six candidate dates within 90 days, or a 7-, 14-, or 30-day search window fully contained within that horizon.
  • Practical constraints and your optional initial preference.
  • If verified Personal timing is available and you choose it, your birth date and birth city with region or country. Exact local birth time is optional.

Sky timing does not ask for birth details. This founding intake does not collect a partner's birth data. Do not submit health records, legal documents, payment-card details, precise addresses, crisis narratives, or another person's private information.

What happens in your browser

The intake runs in your browser. Its answers are not posted to an Orrery database or analytics service. If you open Stripe Checkout, the draft is saved to this tab's session storage so it can be restored after the checkout return.

The saved browser copy is cleared when you successfully copy the formatted request or prepare the email handoff, when you use the clear control, or when the browser session ends. Birth details are also cleared from the visible page after a successful copy or email handoff, and immediately if you switch from Personal timing to Sky timing. If Personal timing is disabled before a reservation return, Orrery removes the restored Personal selection and every birth field, clears that stored draft, and requires you to choose Sky timing explicitly. Your browser settings can affect exactly when session storage is removed.

Email and fulfillment

You choose whether to send the formatted intake through your email application. Your own email provider handles it on the way out, and Microsoft 365, which hosts Orrery's mailbox, receives and stores it — so it holds whatever you decide to send.

During fulfillment, Orrery may use the Kairos engine's calculation and text-rendering infrastructure. Those systems receive only the minimum scheduling inputs needed for analysis—such as a neutral order code, category, timezone, and dates. When Personal timing is enabled, a local deterministic natal calculator also uses the birth date and birthplace you deliberately provide, plus exact birth time when known. Orrery predeclares one action-relevant planet before viewing results, calculates its natal longitude, and compares the transiting Moon’s geometry to that fixed longitude for each candidate under a pinned method. The base Orrery result is unchanged; the overlay remains a separate calculated and interpretive layer.

If birth time is unknown, the calculator evaluates the full valid local birth-day range. If the sole predeclared target is not stable across that range, Orrery does not use the Personal result: you may agree to Sky timing or receive a full refund. Calculation tools do not need your payment-card data, email address, action statement, or private backstory.

Houses. Whole Sign houses and the Ascendant belong to one optional layer that requires an exact birth time, because the rising degree moves about one degree every four minutes and cannot be estimated honestly from an approximate time. That layer is not enabled in this beta, so no houses are used in your Charter today. If it is ever offered and you choose it, it needs no new detail from you: the birth city you already provided is converted to coordinates, and Orrery asks for a city rather than an address or a hospital for exactly that reason. If the rising sign is not stable across the plausible time-and-place range, the layer is withheld and said so plainly rather than guessed. No other chart angle—Midheaven, Descendant, IC, or Vertex—is used at any time.

Payment

Stripe processes the reservation and any balance payment. Orrery receives transaction information such as payer contact details, amount, status, and Stripe transaction identifiers. Orrery does not receive your full card number. Stripe's own privacy terms govern its processing.

Who else handles it

Orrery is one person using four services. Named, so you can judge them yourself rather than take a word for it:

  • Vercel serves these pages. Because the intake runs entirely in your browser, Vercel never receives your answers.
  • Microsoft 365 hosts the mailbox that receives your intake email and any correspondence about your order.
  • Stripe processes the reservation and balance, as described above.
  • Anthropic is involved only if a Charter's wording is drafted through the Kairos render path, and receives only computed scheduling material — never your email address, birth details, payment data, or private backstory.

That is the whole list. Working analysis files never reach a fifth service: they are kept under a neutral order code on the operator's own computer — not in a cloud drive, not in a notes or project app, and not in any analytics or advertising service. The natal calculator used for Personal timing runs on that same machine and sends birth details nowhere.

What is not happening

  • No sale of intake data.
  • No advertising profile built from the intake.
  • No cross-site tracking added to the intake.
  • No automatic enrollment in a subscription.
  • No partner birth data collected in this founding intake.
  • No natal profile inferred from information you did not provide.

Retention and deletion

Birth details go first. Once your Charter is delivered, Orrery deletes the birth date, birth time, and birth city you supplied, along with the temporary derived calculator output — natal-longitude samples, birth-time stability checks, and candidate-geometry comparisons — within 7 days. Nothing about a revision requires them: a revision reworks the Charter from the same inputs, and if a birth detail was itself wrong, you supply the correction then.

The rest — the intake email, working analysis files, and the delivery copy — is kept while your included revision is still available, then deleted within 30 days after that window closes. On cancellation or refund everything goes within 30 days of that event instead, since no revision is pending. You may ask for earlier deletion of anything no longer needed to fulfill or resolve the order.

Minimal transaction and order records may be retained longer when reasonably necessary for tax, accounting, fraud prevention, payment disputes, or other legal obligations. Those records are kept separate from private narrative and working analysis wherever practical.

A privacy, security, or wrong-recipient incident pauses new fulfillment until it is contained and the affected customer can be contacted.

Your choices

You may ask what Orrery holds about you, request a correction or deletion, withdraw before analysis begins, or raise a privacy concern. Applicable law may give you additional rights.

Send a request to orrery@kristenmartino.ai. Orrery may need to verify that the request comes from the same email used for the order.

Changes

If the intake, vendors, retention period, or fulfillment method changes, this notice must change with it. Material changes are dated and apply prospectively.

Changed August 11, 2026: the services Orrery relies on are now named rather than described, and retention was split rather than treated as one clock. Birth details and derived calculator output now go within 7 days of delivery instead of 30; the intake email, working files, and delivery copy are kept until the included revision window closes, so a revision asked for late in that window can actually be honoured. Orders reserved before this date are covered by the notice in effect when they were placed.