This Privacy Policy explains how Oriia collects, uses, stores, shares, and protects your personal information when you use the Oriia mobile application ("the App") or visit oriia.app ("the Site"). Together we refer to the App and the Site as "the Service".
Oriia is operated by Fiorella Fonseca, an individual sole proprietor based in Italy ("we", "us", "our"). By using the Service, you acknowledge that you have read and understood this Privacy Policy.
| Who we are | Fiorella Fonseca, sole proprietor based in Italy |
| What we collect | Birth date / time / city, chronotype, focus preferences, email (if you create an account), chat messages with the Align feature, ritual feedback, usage analytics, device information, purchase records |
| Why we collect it | To calculate your birth chart, generate daily rituals tailored to your biological rhythm and today's planetary transits, power the Align AI guide, process subscriptions, and improve the Service |
| Where it lives | Google Firebase (Firestore, US region), Mixpanel (EU region), Apple StoreKit, Google Gemini API |
| Your rights | Access, correction, deletion, export, restriction, objection, complaint to a supervisory authority |
| How long we keep it | While your account is active. We delete personal data within 30 days of account deletion. Some records may be retained for legal or accounting obligations |
| Contact | [email protected] |
When you sign up and use the App you may provide:
If you submit your email or birth details through the Blueprint or Waitlist forms on the Site, those forms are presentational only at the time of this policy's effective date and do not transmit data. This policy will be updated before any backend submission is enabled.
device_calendar plugin to read your list of calendars (so you can pick one) and to write individual ritual events to the calendar you choose. We do not read your existing calendar events, we do not upload anything from your calendar to our servers, and you can revoke calendar access at any time in iOS Settings.Birth date, sleep needs, and chronotype are not "special categories of personal data" under Article 9 GDPR. We treat this data with the same care we would give to health-adjacent information, even though it is not strictly a special category.
We do not knowingly process biometric, genetic, racial, ethnic, religious, philosophical, political, sexual orientation, or trade-union data.
We use the information we collect to:
We do not use your personal information for behavioral advertising, profiling for credit, automated decisions with legal effects, or sale to third parties.
If you are in the European Economic Area, the United Kingdom, or Switzerland, our processing is justified under Article 6 GDPR as follows:
| Purpose | Legal basis |
|---|---|
| Calculate birth chart, generate rituals, run Align, run Synthesis | Performance of a contract (Art. 6(1)(b)): these are the core Service you signed up for |
| Process subscription and pack purchases | Performance of a contract (Art. 6(1)(b)) |
| Send transactional notifications | Performance of a contract (Art. 6(1)(b)) |
| Analytics through Mixpanel | Legitimate interest (Art. 6(1)(f)): improving the Service, with EU data residency |
| Edge analytics through Cloudflare Web Analytics | Legitimate interest (Art. 6(1)(f)): operating and securing the Site |
| Anti-abuse controls (App Check, rate limits) | Legitimate interest (Art. 6(1)(f)): protecting the Service from automated abuse |
| Comply with legal, tax, accounting obligations | Legal obligation (Art. 6(1)(c)) |
You have the right to object to processing based on legitimate interest. See Section 7.
api-eu.mixpanel.com servers.No security measure is perfect; we cannot guarantee absolute security, but we follow current industry practice.
Oriia is operated from Italy (European Union). Our service providers are located in the European Union (Mixpanel) and the United States (Google / Firebase, Apple, Google Gemini, Cloudflare).
When personal data is transferred from the EEA to the United States, we rely on the safeguards provided by each processor, which include the EU–US Data Privacy Framework (Google LLC and Apple Inc. are self-certified participants) and Standard Contractual Clauses as a fallback.
We share personal data only with the following processors. Each processes data on our behalf under the terms of its standard Data Processing Agreement.
| Component | Purpose | Data shared |
|---|---|---|
| Firebase Authentication | Anonymous + Apple/Google sign-in | UID, email (if linked) |
| Cloud Firestore | Primary database | All user-provided and Service-generated data |
| Cloud Functions / Cloud Run | Server-side calculations | Inputs to compute charts, rhythms, syntheses, sync |
| Firebase Cloud Messaging | Push notifications | Device token, notification payload |
| Firebase App Check | Anti-abuse | Per-request token |
Google's privacy policy: policies.google.com/privacy
The Align AI guide, daily-rhythm interpretation, weekly synthesis, insights, and Connections sync are powered by Google's Gemini 2.5 Flash model. The data we send to Gemini includes your astrological placements, today's planetary transits, your chronotype and focus preferences, your chat messages (for Align), and aggregated feedback patterns (for Synthesis).
Google's API terms govern what Google may do with content sent through the Gemini API. Refer to Google's Generative AI policies for the current terms.
Google's Gemini API terms: ai.google.dev/gemini-api/terms
Subscriptions and Align credit packs are sold through Apple's In-App Purchase. Apple processes all payment details; we never see your card, billing name, or billing address. We receive only the transaction identifier and product identifier, which we verify against Apple's App Store Server API.
Apple's privacy policy: apple.com/legal/privacy
The birth city / country you enter is sent to OpenStreetMap's Nominatim geocoding service to convert the city name to latitude and longitude (needed for timezone-accurate astrological calculations). The geocoding request does not include your name, email, or any other identifier.
Nominatim usage policy: operations.osmfoundation.org/policies/nominatim
We use Mixpanel for product analytics on the EU server (api-eu.mixpanel.com) so usage events stay in the EU. Mixpanel receives:
Onboarding Completed, Daily Rhythm Viewed, Ritual Marked Helpful, Question Asked, Paywall Viewed, Subscription Started).app: oriia, platform: ios, app version).We do not send your name, birth date, birth city, birth time, email, chat messages, or birth chart placements to Mixpanel.
Mixpanel's privacy policy: mixpanel.com/legal/privacy-policy
oriia.app is hosted on Cloudflare Pages. Cloudflare provides edge content delivery, DDoS protection, and Cloudflare Web Analytics (server-side, no JavaScript beacon, no analytics cookies). Cloudflare may set a small number of operational cookies (e.g. __cf_bm) for bot detection, which expire within 30 minutes.
Cloudflare's privacy policy: cloudflare.com/privacypolicy
You can sign into Oriia using Sign in with Apple or Sign in with Google. The chosen provider authenticates you and may share your email and display name with us. With Apple Sign In you may choose "Hide my email"; in that case we receive only the Apple-relay address (@privaterelay.appleid.com) and emails we send pass through Apple's relay.
We use the provider only for sign-in. We do not request any additional scopes (contacts, calendar, photos, etc.) from Apple or Google.
Depending on where you live, you may have some or all of the following rights:
To exercise any of these rights, email [email protected] with the subject line "Privacy Rights Request". We will respond within 30 days (with a possible extension of up to two further months for complex requests, as permitted by GDPR).
We will not discriminate against you for exercising any of these rights.
You can delete your account and all associated personal data directly inside the App:
This invokes a server-side Cloud Function that immediately deletes every Firestore document keyed to your user ID and deletes your Firebase Authentication record. The deletion is irreversible and signs you out automatically.
Alternatively, email [email protected] with the subject "Delete My Account". We process the email request within 30 days.
When you delete your account:
deletions collection for legal and accounting compliance under Italian law. This entry contains no personal identifier.| Data | Retention period |
|---|---|
| Account record, birth chart, daily rhythms, conversations, connections, feedback, syntheses | While your account is active; deleted within 30 days of deletion request |
| Mixpanel analytics events | 12 months from creation, then automatically purged |
| Diagnostic / function logs | 30 days, then auto-rotated |
| Apple purchase transaction records (on Apple's side) | Per Apple's own policy |
| Deletion request audit log | As required by applicable Italian law and accounting obligations |
| Customer support emails | Up to 3 years from last contact |
The App does not use web cookies. It uses local device storage (SharedPreferences on iOS) to remember a small number of preferences, such as your selected calendar ID and language. None of this contains personal data shared with us.
The Site is a static React application with no analytics JavaScript beacon. The cookies that may be set are operational cookies issued by Cloudflare for content delivery, bot protection, and security (e.g., __cf_bm, typical lifetime 30 minutes). These are strictly necessary for the Site to function and are not used for advertising or cross-site tracking.
If we add any non-essential cookies in the future, we will present a consent banner before they are set, in compliance with the ePrivacy Directive and the Italian Cookie Guidelines.
The Service is not directed to children under 14.
We do not knowingly collect personal data from children below the applicable age. If you believe a child has provided us with personal data, contact us at [email protected] and we will delete it.
The Connections feature lets you save a person's name, sign, and chronotype to generate a compatibility read. By entering another person's information, you confirm that you have a legitimate basis to do so (for example, their explicit consent or your prior relationship with them).
If a person whose data you have entered asks us to delete that record, they can email [email protected] and we will remove it.
The Align AI guide, daily rhythm interpretation, and weekly synthesis are generated by Google Gemini, a large language model. The output is suggestive, not prescriptive: it does not produce decisions with legal or similarly significant effect on you, and does not constitute medical, psychological, financial, or legal advice.
Oriia does not perform automated profiling for credit, employment, insurance, or any decision with legal effect. Article 22 GDPR (rights related to automated decision-making producing legal effects) does not apply to the Service.
If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Italian Garante within 72 hours, and notify affected users without undue delay, as required by Articles 33 and 34 GDPR.
If you are a California resident, you have additional rights under the California Consumer Privacy Act / California Privacy Rights Act:
In the previous 12 months we have collected the categories of personal information described in Section 1, including identifiers, internet activity, geolocation (city level), inferences drawn from the foregoing, and content of communications (your Align messages). We have not sold or shared this information.
To exercise these rights, email [email protected] with the subject "California Privacy Request". You may designate an authorized agent to make a request on your behalf with appropriate proof.
We have not appointed a Data Protection Officer. The Service is operated by an individual sole proprietor at a scale of processing that does not require a DPO under Article 37 GDPR. For any data-protection question, contact [email protected] directly.
We may update this Privacy Policy from time to time. When we make material changes:
Continued use of the Service after the effective date constitutes acceptance of the revised policy. If you do not agree, you can delete your account at any time (Section 8).
For any question about this Privacy Policy, your data, or to exercise any of your rights:
By using Oriia, you acknowledge that you have read and understood this Privacy Policy.