Privacy Policy

How Your Data Is Held

AI Tech Magic LLC (“we,” “our,” “us”) operates Soul Convergence at soulconvergence.io. This Privacy Policy explains what we collect, why we collect it, and the boundaries we keep around it. We treat birth data as sacred — we hold it only as long as needed to serve you, and we do not sell it, rent it, or use it for advertising.

1. Information We Collect

To generate your reading, we collect:

  • Your name — used to personalize your blueprint.
  • Email address — used to deliver your reading and respond to support requests.
  • Date of birth — required to compute your natal chart.
  • Time of birth (optional) — enables Ascendant, Midheaven, and house calculations.
  • Place of birth — geocoded to latitude/longitude for astronomical accuracy.
  • Technical log data — IP address, browser type, request timestamps. Used for security and abuse prevention.

We do not see, store, or process your payment card numbers. All payments are handled directly by Stripe; we receive only a confirmation that payment succeeded and the order metadata associated with it.

For two-person readings, we collect the same categories for both parties. The second party’s email address is provided by that party directly, not by the purchaser.

2. How We Use Your Information

  • To compute your natal chart and transit forecast from real ephemeris data.
  • To generate the personalized synthesis that makes up your reading.
  • To deliver your reading by email and respond to support inquiries.
  • To process payment for your purchase via Stripe.
  • To detect abuse, fraud, and security incidents.

3. Third-Party Services

Soul Convergence runs on a small number of vetted service providers. Each receives only what it needs to do its specific job:

  • Stripe — payment processing. Receives card data directly from your browser; we never see it. Subject to Stripe's privacy policy.
  • Anthropic — large-language-model synthesis. Receives your verified chart data (degrees, signs, dates) and your first name. Does not receive your email or payment information.
  • Resend — transactional email delivery. Receives your email address and the rendered reading.
  • Mapbox — geocoding birthplace. Receives the place name you enter, returns coordinates.
  • Supabase — database hosting, in the United States. Stores your finished reading and the birth details it was computed from, so your link keeps working and your reading can be re-delivered if you ask. Also holds editorial-letter subscriptions, and for gift purchases the buyer and recipient names and any message written at checkout.
  • Vercel — hosting and request routing. Receives standard server logs.

4. Data Retention

We retain the data needed to deliver and, if requested, re-deliver your reading. You may request deletion of your data at any time by emailing hello@soulconvergence.io. We honor deletion requests within thirty (30) days, except where retention is required by law (for example, financial records related to your purchase).

5. Your Rights

Depending on where you live (notably under GDPR in the EU/UK and CCPA in California), you may have the right to:

  • Access — request a copy of the data we hold about you.
  • Correct — ask us to fix inaccurate data.
  • Delete — ask us to erase your data.
  • Object — object to certain processing of your data.
  • Withdraw consent — at any time, where processing is based on consent.
  • Portability — receive your data in a portable format.

To exercise any of these rights, email hello@soulconvergence.io. We may ask you to verify your identity before fulfilling the request.

6. International Data Transfers

Soul Convergence is operated from the United States and hosted on infrastructure located primarily in the United States. If you access the service from outside the US, your information will be transferred to, processed in, and stored in the US. We rely on Standard Contractual Clauses and equivalent safeguards where required by law.

7. Cookies & Analytics

We use minimal first-party cookies to keep your shopping session and payment intent connected during checkout. We do not use third-party advertising cookies, pixel trackers, or cross-site behavioral profiling. We may use a privacy-respecting analytics tool to count aggregate page views and identify broken pages, never to profile individuals.

8. Children

The service is for adults aged 18 or over. For two-person readings, both parties must be 18 or over. We do not knowingly process the data of anyone under 18 and will delete it on report.

9. Security

We protect data in transit with TLS and at rest with provider-level encryption. We limit internal access to data on a need-to-know basis. No system is perfectly secure, but we treat your birth data with the same care we would expect for our own.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be announced on this page with a new effective date. Your continued use of Soul Convergence after changes take effect indicates acceptance of the revised policy.

11. Two-Person Readings

A Bond Blueprint involves two data subjects. Both have the full set of rights described in §5, exercisable independently, and both may contact us directly at hello@soulconvergence.io without going through the other party.

Our lawful basis for processing each party’s birth information is that party’s own consent under Article 6(1)(a) GDPR, given separately. A purchaser’s assertion of authority over another person’s data is not a lawful basis and we do not treat it as one.

After consenting, the second party receives a confirmation email containing the consent text and a link to withdraw. Withdrawal is absolute under Article 7(3) GDPR and non-retroactive: processing up to the point of withdrawal remains lawful, and withdrawal terminates processing prospectively. We do not require a reason and we do not tell the purchaser it happened.

After generation, either party may request deletion. When the second party withdraws consent, we erase their data under Article 17(1)(b) GDPR (no remaining lawful basis). We also erase the purchaser’s data as part of the same operation, on the disclosed contractual term the purchaser acknowledges at checkout under Article 6(1)(b) GDPR — the purchaser is not exercising an Article 17 right in this case, but is receiving a promise we made. Financial transaction records are retained per Article 17(3)(b) under our legal-retention obligations, disclosed in §4.

A Bond Blueprint’s comparative sections are a joint synthesis of both parties’ data and cannot be redacted without producing something other than what was purchased. Standalone per-person sections could in principle be preserved after one party’s withdrawal, but we choose to erase the whole document rather than deliver a mutilated reading. This is a disclosed design choice.

Deletion removes the reading from our production database and revokes access via any Soul Convergencesurface. Subprocessors listed in §3 have their own retention policies, which we are auditing and disclose per-subprocessor in §3 once findings are complete. Where erasure requires notification to a subprocessor under Article 19 GDPR, we send that notification through the subprocessor’s documented erasure mechanism and log the notification internally. Copies of the reading already downloaded, saved, forwarded, or printed by either party are outside our reach and no operator’s promise can retrieve them. We tell both parties this before either consents.

Where the reading is deleted after generation by either party, the purchaser is refunded per our Refunds policy. We do not disclose either party’s contact details to the other.