Privacy Policy
Who we are and how to contact us
Account, contact, and payment information
We collect the email address you provide, email-code verification and session records, account preferences, and a recovery contact if you set one up. We use these for sign-in, account recovery, service messages, and your communication choices. SchemaSeek uses email codes rather than account passwords. For purchases, we receive subscription status, payment and refund records, and related billing information from you and Stripe to process payments, provide access, and resolve billing issues. Stripe handles payment-card entry. For each card payment we also store the card fingerprint Stripe assigns, a code that identifies the card without revealing its number, to apply the once-per-person and per-payment-method rule of our satisfaction guarantee and to prevent refund abuse; it is deleted with your account except as described under retention. When you ask a Big Question, pay for a faster Big Question turnaround, or request a refund, we also keep a keyed, one-way code made from the network (IP) address you used, never the address itself, to detect repeated or unusually frequent refunds and prevent refund fraud; we delete it 3 years after we record it. We keep payment, refund, dispute, consent, and delivery records needed to respond to a payment dispute. Our support form accepts an optional receipt number from a Stripe receipt email, but no card numbers or card digits.
Birth details, content, and inferences
You provide birth date, birth time or its uncertainty, birth place and related coordinates, the sex input used for chart calculation, and onboarding answers. We use these to check age, save progress, compute your chart, and personalize your Schema. Place suggestions use geographic reference data; if our local lookup does not find a match, a place-lookup provider may receive your search text to resolve the location and time zone. We create derived chart data, profiles, and readings from your inputs. We also store content you choose to use or save in available features, such as questions and context, answers, reflections, and relationship interactions. This information can reveal personal interests or sensitive details, particularly in free text. Please do not submit another person's private information without permission, or include financial-account numbers, government identifiers, or other sensitive information that the feature does not need.
Usage, device, and support information
We collect your IP address, browser and device information, identifiers that recognize your account or visit, pages and features used, when you use them, and referral or campaign information. We use these records to operate and protect the service, troubleshoot problems, and measure usage. Usage records may be linked to you; they are not necessarily anonymous. Our analytics exclude reading content, raw birth details, and question or search text.
If you contact us, report an error, or request a refund, we collect your message, contact details, and relevant account, billing, or diagnostic information. Our support form accepts an optional Stripe receipt number, not card digits. If you enable push notifications, we store the information needed to deliver them to your device and remember your preferences.
Automated processing
Our automated software generates a personalized interpretation from the details you provided. It does not provide a factual forecast. Automated chart calculations and AI-generated text use the inputs and derived information needed for the requested feature. AI service providers, including routing services and the model providers behind them, process that information to generate or check responses. Your Schema is for entertainment and reflection, not a decision about employment, credit, insurance, housing, healthcare, or another legal or similarly significant matter. Privacy controls for product analytics do not turn off AI processing needed to deliver a reading you request.
Human review of Big Questions
Our software prepares answers from your saved Schema and question. A person reads and approves each answer for safety and grounding before release. Use the answer for reflection; it does not provide professional advice. AI service providers process your question and optional context, clarification exchanges, saved Schema-derived profile, reviewer guidance when a draft is regenerated, and the drafted answer to prepare and cross-check the response. Authorized reviewers can access the submission and review materials to assess and release the answer. We retain drafting and review records, including review activity. This is not a confidential professional consultation, so avoid including information the question does not need.
Public profiles and sharing you choose
Publishing a profile is optional. While published, your chosen profile content and reading sections are visible to anyone with the link, including people without a SchemaSeek account. Search engines may index a public page, subject to your indexing setting and the search engine's behavior. We do not automatically publish your private birth-input, account-email, location, or timing fields. Personal information you include in a name, biography, link, image, or other published content is visible to others. Unpublishing stops us serving the public profile, but does not erase screenshots, downloaded share cards, third-party copies, or search-engine caches. Review the selected content before publishing or sharing it.
Analytics and communication choices
Who receives information
We disclose information needed to operate the service to these provider categories:
- Cloud hosting and database storage for application records
- Image-safety services for automated checks when uploads are enabled
- Place-lookup services for location searches
- AI routing and model services for generation and checking
- Stripe for payments and billing
- Email delivery services for authentication and communications
- Push delivery services for device subscriptions and notifications
- Error-monitoring services for diagnostics
- Support tooling for correspondence
Providers receive only the information categories relevant to their role.
Authorized staff and reviewers use relevant records for support, safety review, security, and administration.
We disclose content you direct us to publish or share to its intended audience.
We may also disclose relevant information when legally required, to protect rights and safety or investigate abuse, or in connection with a business transaction, subject to applicable law. These operational disclosures are distinct from selling personal information or sharing it for cross-context behavioral advertising.
Where your data lives
We operate SchemaSeek from the United States. Our main database is in Virginia, and we also retain data in Canada.
Our service providers, including AI providers, may store and process information in other countries. U.S.-only service availability does not mean all information stays in the United States.
We use your approximate country and state, based on your internet connection, and your billing address to determine service and paid-feature availability. We do not use this eligibility information for advertising.
Security
We use safeguards such as authenticated access, server-side authorization, restricted database access, and validation of submitted data to protect personal information. Access to account records and administrative tools is restricted according to their function. No internet service or storage system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur. Protect the email accounts used for sign-in and recovery, and do not share verification codes. Contact us if you suspect unauthorized access.
Onboarding and unverified accounts
We schedule unclaimed onboarding sessions for deletion after 30 days of inactivity. Reaching account creation links the session to account retention.
We schedule accounts that never verify their email for cleanup after 30 minutes if empty, or after 7 days if they hold onboarding data.
Scheduled cleanup does not guarantee that every copy disappears at the exact deadline.
Waitlist
If you join the waitlist, we store your email address, a short signup-source label, and signup and expiry timestamps to record your interest and manage the waitlist. The record expires 30 days from the first accepted signup and is removed by scheduled cleanup; submitting the same address again does not extend that period. Joining does not change your account's marketing preferences. If your account has the same email verified, its export includes the waitlist record and account erasure deletes it. Otherwise, email us for access or deletion; we verify ownership before acting.
Account deletion and retention
We generally keep account information, birth inputs, and saved content while your account exists.
Cancel any renewing subscriptions before requesting deletion through Account settings. Scheduling cancellation at the end of the paid period is enough; you do not need to wait for that period to end.
Once we accept your deletion request, you have 14 days to restore your account before scheduled permanent deletion. Billing or technical problems may delay completion. Contact support if you cannot use these controls, need confirmation, or want to exercise a privacy right.
Permanent erasure removes account-linked readings, birth data, usage events, and support-form requests.
For accounts with verified email, we keep records of your consent for 6 years after account deletion. We remove the account link, IP address, and browser details, but may keep a coded reference based on your email to address later disputes. We delete consent records for accounts that never verified their email. We may retain privacy-request records and deletion confirmations to document how we handled your request.
Payment records held by Stripe are subject to its retention practices and applicable legal obligations; deleting your SchemaSeek account does not erase all provider-held transaction records.
If you use a satisfaction guarantee refund, we keep a one-way coded version of your email address, your payment-processor customer reference, and the card fingerprint the processor assigns (never a card number) after account deletion. We keep them only to apply the once-per-person rule of the guarantee and to prevent repeat refund abuse, a security and fraud-prevention purpose, we remove the link to your deleted account, and we delete them 3 years after the refund.
If we issue you a refund, we keep the coded network reference described above with a record of that refund after account deletion, without the link to your account, only to prevent refund fraud and repeat refund abuse, and we delete it 3 years after the refund.
Other retention periods and limits
We schedule usage analytics and submitted error reports for deletion after 90 days. Account deletion removes account and browser details, submitted descriptions, and related diagnostic details from linked error reports. Limited records of the error type and how it was handled may remain until scheduled deletion. Reports not linked to your account require a separate verified request.
We schedule support-form requests for deletion 90 days after they are resolved or rejected. Open requests have no fixed expiry. Requests not linked to your account are not automatically included in account deletion or your data copy; contact support about those records.
Email correspondence, provider-held records, security logs, and backups have separate retention periods. Retention depends on the purpose of the record, the provider's practices, and applicable legal requirements. The deletion periods above do not apply to every copy held by a provider.
Your U.S. privacy rights
Depending on your state, applicable law, and any exemptions, you may have rights to confirm processing, access personal information, obtain a portable copy, correct inaccuracies, delete information, learn about categories of information and recipients, and opt out of sale, targeted advertising or cross-context behavioral sharing, or certain consequential profiling. Some laws also provide rights concerning sensitive information. We do not use your readings to make legally or similarly significant decisions about you. You can ask us about these rights even if a particular account control is unavailable. We will not discriminate against you for exercising an applicable privacy right; deleting information necessary to provide a feature may mean that feature can no longer work.
Making, verifying, or appealing a request
Account privacy tools
Children
SchemaSeek is for adults aged 18 and over, and is not directed to children. We do not knowingly permit a child to create an account or ask a parent to provide a child's information on the child's behalf. The onboarding age check rejects under-18 birth inputs and marks the session for early cleanup; the under-13 path requests immediate session deletion. If you believe a child has provided personal information, contact us so we can investigate and take appropriate deletion action.
Changes to this policy
We will update the date at the top when we revise this policy. For material changes, we will provide additional notice through the service or an appropriate contact channel as required by applicable law, and obtain consent where required. An update to this policy does not by itself authorize uses of previously collected information that require additional permission.