Privacy Policy
Version 1 · Last updated: August 10, 2026
Oracle Fate is an astrology-based reflection and prediction app for iOS, operated by Saba Riazi, based in the Netherlands ("we", "us"). We are the data controller for the information described here.
Contact address: De Boelelaan 1095 A, 1081 HV Amsterdam, the Netherlands.
What we collect, and why
Account details
Your name, the email address used to sign in (or the private relay address, if you use Sign in with Apple and choose to hide your email), and — if you choose to give it — your phone number. Your phone number is what lets friends who have your number find you in the app.
Birth data
Your birth date, time, and place. This is the foundation of your natal chart and of every personalized reading in the app. Astrology cannot work without it; neither can Oracle Fate.
What you add to your vault
Notes, conversations with the Oracle, goals, and files or photos you add across the four pillars — Career, Love, Money, Self. You decide what to share. The more context the Oracle has, the more specific your readings become, but every item here is voluntary. Images and documents you upload are processed to extract their text, which then becomes searchable context for your readings.
Charts you create for other people
If you create a profile for someone who does not use Oracle Fate — to read a bond or a compatibility — we store the name and birth details you enter for them. See Other people's information below.
Approximate location
Your daily Sky Reading is cast from the sky above where you are now. To find that place, our server derives an approximate, city-level location from your connection's IP address, using a database stored on our own server. Your IP address is not sent to any third party for this, and is not stored alongside your location. We never access your device's GPS, and the app never shows an iOS location prompt.
Contacts, only if you allow it
If you grant contacts access to find friends, your device sends us an irreversible (SHA-256) hash of each phone number, together with the name you have saved for that contact. The hash lets us tell you which of your contacts already use Oracle Fate without us ever holding their phone numbers. The saved name is stored so the suggestion can read "Maya" instead of a row of characters. You can decline contacts access and use the whole app without it, and you can clear what was synced at any time.
Purchases
Subscriptions and one-time purchases are processed by Apple. We receive your subscription and purchase status — never your card details — so the app knows what to unlock.
Device and diagnostic data
A push notification token so we can tell you when a Vision or Omen arrives; your device's time zone so those arrive at the right hour; app version and basic device information; an Apple DeviceCheck token, which lets us tell whether a device has already used a free trial without identifying the device to us; and crash and error diagnostics when something goes wrong.
How you use the app
We record in-app sessions to understand where the app is confusing — see Session recording, which explains what we deliberately exclude.
Sending your content to an AI provider
This is the most important thing on this page, so it gets its own section.
To generate your Omens, Visions, readings, and chat replies, we send the relevant material — your birth details, your questions, and the vault context that applies — to OpenAI through its API. Under the API terms we use, your content is not used to train OpenAI's models. We tell you this at sign-up, and continuing to sign up is how you consent to it. If you would rather not have your content processed this way, the core reading features cannot function, and the honest answer is that Oracle Fate is not the app for you.
When the Oracle needs current information to answer a question, it may run a web search. The search query is derived from your question and sent to our search provider; your identity, birth data, and vault are not.
Session recording, and what we exclude from it
We use Smartlook to record how people move through the app — taps, scrolls, hesitation, where a flow loses someone. In the first months this is how we find and fix what is confusing.
Because Oracle Fate holds a personal journal, the following are masked out of these recordings, so they are never transmitted to or stored by Smartlook:
- Your vault entries — their titles and their contents.
- Your conversations with the Oracle, both what you ask and what it answers.
- The text of your predictions and readings.
- Your birth date, birth time, and the zodiac sign derived from them.
- Everything typed into a text field, including sign-in details and your place of birth.
Recordings are linked to an opaque account identifier and nothing more — we do not send Smartlook your name or your email address. This is product analytics for our own app; it is not cross-app tracking, and Oracle Fate carries no advertising identifier.
Who else processes your data
We share data only with providers who process it on our behalf, under contract, for the purposes below. We do not sell personal data, and we do not share it for advertising.
| Provider | What it receives | Why |
|---|---|---|
| OpenAI | Birth data, questions, relevant vault context | Generating readings and chat |
| Supabase | Your account and everything stored in it | Database and authentication |
| Hetzner | Server traffic for our API | Hosting, in Germany |
| Smartlook | Masked session recordings, opaque account id | Usability analytics |
| RevenueCat, Superwall | Purchase status, subscription events | Subscriptions and paywalls |
| Google (Firebase) | Push token, crash diagnostics | Notifications and stability |
| Mapbox | The place name you type when searching for a birthplace | Finding coordinates for that place |
| Brave Search, DuckDuckGo | A search query derived from your question | Answering questions that need current information |
| Cloudflare | Generated images and audio | Private storage, served by short-lived signed links |
| Apple | Payments, Sign in with Apple, DeviceCheck | Purchases, sign-in, trial integrity |
Where your data is held, and transfers
Our API runs on servers in Germany. Some of the providers above operate outside the European Economic Area, chiefly in the United States. Where data leaves the EEA we rely on the European Commission's Standard Contractual Clauses, or on an adequacy decision where one applies, as the transfer safeguard.
How long we keep it
- Your account, birth data, and vault — for as long as your account exists. Deleting your account removes them.
- Synced contact data — until you clear it, revoke contacts access, or delete your account.
- Session recordings — retained by Smartlook on a rolling window and then deleted automatically.
- Crash diagnostics — retained on Firebase's standard schedule, currently up to 90 days.
- Purchase records — kept as long as tax and accounting law requires, which in the Netherlands is seven years.
Our legal bases
If you are in the EEA or the UK, we rely on the following under the GDPR:
- Performance of our contract with you — your account, birth data, vault, readings, purchases, and the AI processing that produces the readings you asked for.
- Your consent — contacts access, push notifications, and the camera and photo access you grant. You can withdraw any of these in iOS Settings, or in the app, at any time.
- Our legitimate interests — approximate location for the Sky Reading, session analytics and crash diagnostics to keep the app working, and trial-abuse protection. We have weighed these against your interests; you can object at the address below.
- Legal obligation — retaining purchase and tax records.
Your readings are generated automatically, but they are reflective content, not decisions about you. Nothing in Oracle Fate produces a legal or similarly significant effect within the meaning of Article 22.
Sensitive subjects
What you write in the Love and Self pillars may touch on health, relationships, sexuality, or belief. We do not ask for this, and we do not analyze it for any purpose beyond generating the readings you requested. Where that content falls into a special category under Article 9, we process it on the basis of your explicit consent, given when you choose to write it into your vault. You can delete any entry, or your whole account, at any time.
Your rights and control
- Access and correction. Your profile, birth data, and vault are visible and editable in the app.
- Deletion. Settings → Delete Account permanently deletes your account and its data, including your sign-in identity. It is immediate and irreversible.
- Portability, restriction, objection. Email us and we will action it.
- Notifications and permissions. Push, contacts, camera, and photo access can each be withdrawn in iOS Settings without losing your account.
- Complaints. If you are in the EEA you may lodge a complaint with your local supervisory authority. Ours is the Dutch Autoriteit Persoonsgegevens. We would rather you told us first.
California privacy rights
If you are a California resident, you have the right to know what personal information we collect and why, to request its deletion or correction, and not to be discriminated against for exercising those rights. The categories we collect, and our purposes, are set out above.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising — including of anyone under 16. We do not use or disclose sensitive personal information for any purpose beyond providing the app, so there is nothing to limit. To exercise any right, email us at the address below.
Other people's information
Two features involve someone other than you: syncing contacts, and creating a chart for a person who does not use the app. When you use them, you are asking us to process another person's details, and you confirm you are entitled to share them. We use those details only for the feature you asked for — never to build a profile of that person, never to contact them, never for marketing. If someone believes their details are in Oracle Fate and wants them removed, email us and we will remove them.
Security
Data is served over encrypted connections end to end, stored with our database provider under row-level access rules that scope every record to its owner, and your sign-in session is held in the iOS Keychain rather than in plain storage. Generated imagery and audio live in private storage reached only through short-lived signed links. No system is perfect, and we will tell you promptly if a breach affects you.
Things we do on your device that never leave it
For completeness: the first time you open the welcome screen, the app checks the clipboard once for an Oracle Fate invite code. Nothing is transmitted unless an invite code is actually found. The app also detects when you take a screenshot, so it can offer to make a nicer shareable card — the detection is local and tells us nothing about what you captured.
Children
Oracle Fate is not for children. You must be at least 16 to use it. We do not knowingly collect data from anyone under 16, and if you believe someone younger has created an account, contact us and we will delete it.
Changes
If this policy changes materially we will update this page and note it in the app. The date at the top always reflects the current version.
Contact
Questions, requests, or complaints about privacy: support@oraclefate.com, or Saba Riazi, the Netherlands.
Attribution
IP geolocation uses the DB-IP City Lite database, used under CC BY 4.0.