Skip to the policy
ORRERYReturn to Charter

Orrery / Data practice

Privacy

A small service should ask for little, explain it plainly, and let it go.

Effective July 27, 2026

What this notice covers

This notice covers the Orrery Founding Moment Charter at /moment. It does not replace the separate privacy notice for the free Orrery app.

What Orrery asks for

The founding intake asks only for information needed to review and fulfill one Charter:

  • Your reply email.
  • The general category and short action statement for the moment.
  • Your timezone.
  • Two to six candidate dates within 90 days, or a 7-, 14-, or 30-day search window fully contained within that horizon.
  • Practical constraints and your optional initial preference.
  • If verified Personal timing is available and you choose it, your birth date and birth city with region or country. Exact local birth time is optional.

Sky timing does not ask for birth details. This founding intake does not collect a partner's birth data. Do not submit health records, legal documents, payment-card details, precise addresses, crisis narratives, or another person's private information.

What happens in your browser

The intake runs in your browser. Its answers are not posted to an Orrery database or analytics service. If you open Stripe Checkout, the draft is saved to this tab's session storage so it can be restored after the checkout return.

The saved browser copy is cleared when you successfully copy the formatted request or prepare the email handoff, when you use the clear control, or when the browser session ends. Birth details are also cleared from the visible page after a successful copy or email handoff, and immediately if you switch from Personal timing to Sky timing. If Personal timing is disabled before a reservation return, Orrery removes the restored Personal selection and every birth field, clears that stored draft, and requires you to choose Sky timing explicitly. Your browser settings can affect exactly when session storage is removed.

Email and fulfillment

You choose whether to send the formatted intake through your email application. Your email provider and Orrery's mailbox provider then process that message.

During fulfillment, Orrery may use the Kairos engine's calculation and text-rendering infrastructure. Those systems receive only the minimum scheduling inputs needed for analysis—such as a neutral order code, category, timezone, and dates. When Personal timing is enabled, a local deterministic natal calculator also uses the birth date and birthplace you deliberately provide, plus exact birth time when known. Orrery predeclares one action-relevant planet before viewing results, calculates its natal longitude, and compares the transiting Moon’s geometry to that fixed longitude for each candidate under a pinned method. The base Orrery result is unchanged; the overlay remains a separate calculated and interpretive layer.

If birth time is unknown, the calculator evaluates the full valid local birth-day range. If the sole predeclared target is not stable across that range, Orrery does not use the Personal result: you may agree to Sky timing or receive a full refund. Houses and chart angles are excluded. Calculation tools do not need your payment-card data, email address, action statement, or private backstory.

Payment

Stripe processes the reservation and any balance payment. Orrery receives transaction information such as payer contact details, amount, status, and Stripe transaction identifiers. Orrery does not receive your full card number. Stripe's own privacy terms govern its processing.

What is not happening

  • No sale of intake data.
  • No advertising profile built from the intake.
  • No cross-site tracking added to the intake.
  • No automatic enrollment in a subscription.
  • No partner birth data collected in this founding intake.
  • No natal profile inferred from information you did not provide.

Retention and deletion

Orrery deletes intake emails, optional birth details, temporary derived calculator output, working analysis files, and delivery copies within 30 days after delivery, cancellation, or refund. Temporary derived output includes natal-longitude samples, birth-time stability checks, and candidate-geometry comparisons created to fulfill a Personal request. You may request earlier deletion when the information is no longer needed to fulfill or resolve the order.

Minimal transaction and order records may be retained longer when reasonably necessary for tax, accounting, fraud prevention, payment disputes, or other legal obligations. Those records are kept separate from private narrative and working analysis wherever practical.

A privacy, security, or wrong-recipient incident pauses new fulfillment until it is contained and the affected customer can be contacted.

Your choices

You may ask what Orrery holds about you, request a correction or deletion, withdraw before analysis begins, or raise a privacy concern. Applicable law may give you additional rights.

Send a request to [support address not configured]. Orrery may need to verify that the request comes from the same email used for the order.

Changes

If the intake, vendors, retention period, or fulfillment method changes, this notice must change with it. Material changes are dated and apply prospectively.