Skip to main content

Privacy Policy

Last updated 2026-07-29

We collect the minimum we need to run the chat, store it on third-party services we trust, and give you a one-click way to delete everything.

What we collect

  • Account info

    your email address and provider profile name (when available), used to identify your session. We don't collect a password; sign-in goes through Supabase Auth.

  • Conversations & bookmarks

    the questions you ask, the answers we generate, and the passages you save. These are tied to your account so you can return to them later.

  • Rate-limit counters

    a running count of requests per day, scoped to your account, used to enforce the daily limit shown in Settings.

  • Server logs

    standard application logs that include IP addresses, user-agent strings, and request paths, kept for up to 30 days for debugging and abuse defense.

We use Vercel Web Analytics for aggregate, cookie-free usage measurement. After you consent, it records redacted page routes, coarse acquisition categories, primary Oracle CTA clicks, reference-page engagement, anonymous account creation, and contribution or affiliate outbound clicks. We also use Vercel Speed Insights for anonymous real-user performance measurement: Web Vitals such as LCP, CLS, INP, FCP, and TTFB, together with the coarse route and path and with network, browser, device, operating-system, country, and Web Vital attribution data. Dynamic route identifiers and query strings are removed before sending. We never send your query text, answer text, source passages, email, user ID, account ID, conversation ID, or share token to either Vercel product. These events are never tied to your account or signed-in identity. Vercel Web Analytics and Vercel Speed Insights are both opt-in: they are disabled by default and only run after you accept the consent banner.

We also use Sentry to find and fix bugs, and it works in two separate ways. Operational error reports and sampled performance traces run whenever Sentry is configured, including before you answer the consent banner and after you decline it. We treat them as reliability monitoring rather than measurement, so the banner does not control them. They carry the error and its stack trace, the release and environment, sampled request timings, and route fields that pass through the same redaction as our analytics: a concept slug, conversation ID, or share token becomes a placeholder, and query strings and fragments are dropped. Our own code then strips the credential-bearing parts of an error report before it is sent: the authorization and cookie headers, and the parsed cookie map that would otherwise carry your session. We do not turn on Sentry's optional collection of request bodies or account identifiers. Sentry still receives the metadata any web request carries, including your IP address.

On-error session replay is the second behavior, and it is opt-in. It captures a short clip of the page when an exception occurs, it stays disabled until you accept the consent banner, and when it does run it masks all text, masks all inputs, and blocks all media. It records layout and interaction, not your content. One limit worth stating plainly: a replay recording also stores the address of the page it recorded. We redact the dynamic parts we can reach, but the recording format keeps its own copy of the address, so if you accept replay and then open a conversation someone shared with you, that link can appear in the recording. Decline the consent banner if you would rather that never happen. We do not embed third-party advertising or cross-site tracking, and we don't sell data to anyone.

Where your data lives

  • Supabase

    stores your account, conversations, bookmarks, and rate-limit counters. Hosted in the US.

  • Qdrant Cloud

    stores the corpus index that retrieval runs against. Our own servers turn your question into dense and sparse search vectors, plus optional derived vectors for a rephrased version of it, and the request we send Qdrant carries those vectors together with retrieval filters and a result limit. Qdrant returns the matching corpus passages. Your question text is not the query parameter Qdrant receives in this retrieval path, and the corpus itself is not personal data.

  • Language-model providers

    run the models that interpret your question, rerank the retrieved passages, and write the answer. The configured provider receives your question, a limited amount of earlier conversation when the answer depends on it, and the retrieved passages, all inside the prompt. DeepSeek is the default in our code. Anthropic is the default failover when a provider request fails with a transient error and its key is configured. An operator can select Groq, Google Gemini, OpenAI, or Cerebras for any of these roles instead, and adding a provider beyond that list requires an update to this page. Each provider's standard data policy applies to that traffic, and we do not enable optional model-training data sharing with any of them.

Each of these vendors has its own privacy policy and security posture. Linking out to each: Supabase, Qdrant, DeepSeek, Anthropic, Groq, Google, OpenAI, Cerebras, Sentry.

Cookies and tracking

We use cookies only for the session token that keeps you signed in. No advertising or third-party tracking cookies. We do not embed analytics that follow you across the web. When you first visit, a consent banner asks whether you agree to non-essential telemetry. Your answer controls three things: Vercel Web Analytics, Vercel Speed Insights, and Sentry on-error session replay. All three are disabled by default and run only if you accept. It does not control Sentry's operational error reports and sampled performance traces, which are described above and run whenever Sentry is configured. Your choice is stored locally in your browser and does not require an account.

Your rights

Regardless of where you live, you have these rights:

  • Access

    ask us what data we hold about you, and we will tell you.

  • Deletion

    delete every piece of data tied to your account with one click from Settings → Danger zone → Delete account. This cascades through conversations, messages, bookmarks, rate-limit counters, and finally your auth record itself. It is irreversible.

  • Portability

    export your conversations as JSON or markdown from the conversation header menu.

  • Correction

    sign-in name comes from your auth provider profile; update it there and it will propagate on next sign-in.

EU and UK residents also have the right to lodge a complaint with their supervisory authority. We are not required to appoint an EU representative under GDPR Art. 27 at our current scale, but if that changes this page will be updated.

Retention

We keep your data as long as your account exists. If you delete your account, the cascade runs immediately and the data is gone from our application database within seconds. Upstream backups (Supabase's point-in-time recovery, where applicable) may retain a copy for up to 7 days before the backup itself rotates.

Children

The service is not directed at children under 16. We do not knowingly collect data from anyone under that age. If you believe a minor has signed up, contact us and we will delete the account.

Changes to this policy

When the policy changes meaningfully, the “Last updated” date at the top of this page will change and the first-signin acknowledgment modal will reappear so you can review and re-accept.

Contact

For privacy questions or to exercise the rights listed above, email contact@bioenergeticoracle.com. Most rights requests are also self-serve from Settings.

Analytics and on-error session replay stay off until you accept. See our Privacy Policy.