OracleAI Privacy Policy

OracleAI Privacy Policy

This is a working public product text. Before commercial launch, the operator, jurisdiction-specific notices and contact details must be completed and reviewed by qualified counsel.

1. Who is responsible

Service operator: [insert legal entity, address and privacy contact]. OracleAI is a Telegram bot and Mini App for self-reflection, daily rituals, symbolic astrology and Tarot interpretation, journaling and AI-guided dialogue.

2. Data we process

For access we process signed Telegram authorization data and Telegram ID. Depending on the feature you choose, you may provide a name, language, timezone, birthplace, birth date and time, partner information, diary entry or question. Birth data is collected only for an astrology feature and is not an age-verification mechanism.

The 16+ age gate stores a self-confirmation fact, not a date of birth. We do not request identity documents or an exact date of birth for the age gate.

3. Memory and personal context

Memory is an explicit, controllable setting. When memory is disabled, new facts are not extracted, saved facts are not supplied to the guide, and the memory list is not shown. You can delete individual facts and request deletion of your account materials.

4. Purposes

5. AI providers

For generation, the server runtime may send the minimum context required for the selected scenario to an enabled LLM provider. OracleAI is not a medical, psychological, legal or financial service and does not present symbolic interpretations as guaranteed predictions.

6. Payments

Payment providers process card details. OracleAI receives the order status and data necessary to grant access and provide support; it does not store card numbers or CVV in its database. The provider’s own privacy policy also applies.

7. Retention

Account and selected materials are retained while needed for the feature or until deletion is requested, unless a longer period is required by law. In the current implementation, detailed product events and LLM usage are cleared after 120 days, safety incidents after 90 days, webhook evidence after 180 days, and admin audit records after 365 days. These periods, as well as the separate retention of encrypted backups, must be finally confirmed by the operator and qualified counsel before commercial launch.

8. Requests

Where applicable, you may request access, correction, deletion or restriction by contacting [privacy contact]. Include your Telegram ID for ownership verification and do not send diary text, secrets or payment details by email.

9. Security and changes

Controls include Telegram authentication, ownership checks, rate limits, CSP, log redaction, idempotent webhooks and encrypted backups. No internet service can guarantee absolute security. Material changes will be posted on this page with an updated date.