Privacy Policy — Lukumi Odu Guide

DRAFT v0.9 — pending counsel review.

What we store

- Account data: email, display name, password hash, language preference. - Billing: handled by Stripe; the platform never stores card data. - Consultation records: the reading's steps and outcome, authored by the priest. - Consultation subjects: name and optional date of birth, encrypted at the application layer — database operators cannot read them. - Security telemetry: sign-in events, content-access logs (retained 13 months), and an audit trail of privileged actions (retained indefinitely).

About people who never signed up for this platform

This is the unusual part of this policy, and we want to be direct about it: the platform holds data about people who never created an account and never agreed to anything here. A priest of the Church of the Lukumi Babalu Aye records a consultation about a client — their name, sometimes a date of birth, and the outcome of the reading. That person is the subject of the record, not necessarily its author or a party to this agreement. The priest is responsible for obtaining that person's consent to being recorded, the same responsibility any pastoral counselor has for a written record of a private conversation. The platform's role toward that record is custodian, not decision-maker: we store what the priest records, encrypted, and we give the named person a direct path — set out below — to have their identity separated from it, whether or not they ever open an account of their own.

What we never do

No advertising, no sale of data, and no third-party analytics beyond privacy-restricted product analytics (PostHog) and aggregate traffic analytics (Cloudflare Web Analytics), both configured without advertising features. No AI training on consultation records.

Who can see a consultation record

The recording priest, and the consultation subject through their own portal account, if they have one. Administrators cannot read consultation contents; an administrator's access to a subject's name is itself logged.

Deletion and identity-severance requests

Any person named in a consultation — again, whether or not they ever created an account — may request severance of their identity from that record by contacting the Church at [email protected]. See Terms of Service §5 for exactly what anonymization does: the name and date of birth are removed and any linked account is deactivated, while the underlying pastoral record (the reading itself) persists without a name attached.

Where data lives

On infrastructure operated for the Church (a dedicated host with encrypted backups). Transport is always TLS.

Version 0.9 (draft), 2026-08-16.