Privacy Policy
Last updated: July 3, 2026
Self: Prime ("we", "us", "our") operates the Self: Prime web application at selfprime.net. This Privacy Policy describes how we collect, use, store, and protect your personal information.
1. Information We Collect
We collect the following categories of personal data:
- Account Information: Email address and password (hashed, never stored in plaintext).
- Birth Data: Date of birth, time of birth, and place of birth. This data is used solely for chart calculations and profile generation.
- Payment Information: Processed and stored by Stripe, Inc. We do not store credit card numbers on our servers. We retain Stripe customer IDs and subscription status.
- Usage Data: Pages visited, features used, check-in entries, diary entries, and chart generation history.
- Device Information: Browser type, device type, and IP address (for rate limiting and security only).
2. How We Use Your Information
- Chart Calculation: Birth data is used to compute your energy blueprint chart using astronomical algorithms.
- Self: Prime Profile Generation: Your birth data, chart results, and the text of your readings are sent to third-party language-model providers to generate your personalized Synthesis reading. Depending on availability and load, this may include DeepSeek, Anthropic, Groq, and xAI (Grok). These providers process this data transiently to return the generated text; see Section 3 for the full list and what each receives.
- Voice Narration: Where a reading is delivered as audio, the reading text is sent to ElevenLabs to synthesize the spoken narration.
- Transit Updates: Birth chart data is used to calculate daily transit interactions.
- SMS Digests: If you opt in, your phone number is shared with Telnyx for daily transit digest delivery.
- Account Management: Email is used for authentication, password reset, and service communications.
- Payment Processing: Subscription management via Stripe.
3. Third-Party Data Sharing
We share personal data with the following third-party service providers, strictly for the purposes described:
- Stripe, Inc. — Payment processing and subscription management.
- Language-model providers (Anthropic, xAI, DeepSeek, Groq) — Used to generate your Self: Prime Profile and readings. Your birth data (date, time, location), chart results, and reading text are sent to these providers, which process the data to return the generated text. Which provider handles a given request depends on availability and routing. Each provider processes this data under its own privacy terms and data-processing terms, which govern how it retains and uses data; we send only what is needed to produce your reading.
- ElevenLabs, Inc. — Text-to-speech voice narration. Where a reading is delivered as audio, the reading text is sent to ElevenLabs to synthesize the narration.
- Sentry (Functional Software, Inc.) — Application error and performance diagnostics. When the app encounters an error, technical diagnostic data (error messages, stack traces, browser/device information, and limited context about the action being performed) is sent to Sentry to help us fix faults. We aim to avoid sending birth data or reading content to Sentry.
- Telnyx — SMS delivery for users who opt in to daily transit digests.
- Resend — Email delivery for transactional emails (welcome, notifications).
- Cloudflare — Infrastructure hosting, CDN, DDoS protection, and Workers runtime.
- Neon, Inc. — Managed PostgreSQL database hosting. Account data, chart data, session notes, and messages are stored in Neon's serverless Postgres service.
- Plausible Analytics — Privacy-first web analytics (selfprime.net public pages only). Collects anonymised, aggregated page-view data. No cookies; no personal data transmitted.
We do not sell your personal data to any third party.
3b. Push Notifications
If you grant permission, we send push notifications about session updates, practitioner messages, and relevant content changes. To enable this, we store a push subscription endpoint (for web browsers) or a device token (for iOS/Android) associated with your account. You can withdraw permission at any time through your device settings or through the app's notification preferences, at which point we delete your push token from our servers.
3d. Practitioner Access to Your Data
Self: Prime includes a directory of independent practitioners. If you choose to engage a practitioner — for example by booking a session, becoming a managed client, or accepting an invitation from a practitioner — that practitioner is given access to certain of your personal data so they can deliver their service to you. Depending on what you request, this may include your name, birth data (date, time, and place of birth), your generated charts and readings, session notes, and messages you exchange with that practitioner.
- A practitioner can see this data only for accounts that are connected to them as their client, and only to provide the service you have asked for.
- Practitioners are independent professionals, not employees of Self: Prime. They are bound by our Practitioner Agreement, which requires them to keep your data confidential and to use it only to serve you.
- Sharing of sensitive surfaces such as your private diary with a practitioner is off by default and only occurs where you explicitly enable it for a given practitioner relationship.
- You can end a practitioner relationship, and you can delete your account and data, at any time (see Sections 4 and 5).
3c. Google User Data (Google API Services)
If you choose to connect your Google Calendar, Self: Prime requests the Google Calendar scope (https://www.googleapis.com/auth/calendar) through Google's OAuth consent flow. We access this data only after you explicitly grant permission, and only to provide the calendar features you have asked for.
- What we access: your Google Calendar events, so we can display them in Self: Prime and keep them in two-way sync (events you create in Self: Prime are added to your Google Calendar, and your existing Google Calendar events are imported into Self: Prime).
- How we store it: your Google OAuth access and refresh tokens are encrypted at rest and stored only on our infrastructure, associated with your account. Synced event data is stored in your Self: Prime account (Neon database).
- How we use it: solely to operate the calendar-sync feature you enabled. We do not use Google user data for advertising, and we do not use it to train, develop, or improve generalized AI or machine-learning models.
- Sharing: we do not sell or transfer your Google user data to third parties, and human access is limited to what is required for security, abuse prevention, legal compliance, or with your explicit consent.
- Revoking access: you can disconnect Google Calendar at any time inside Self: Prime, which deletes the stored tokens and synced events. You may also revoke access directly at myaccount.google.com/permissions.
Self: Prime's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. Data Retention
- Account data: Retained for the life of your account.
- Chart and profile data: Retained for the life of your account.
- Payment records: Retained as required by financial regulations (typically 7 years).
- Usage analytics: Aggregated and anonymized after 90 days.
When you delete your account, all personal data (birth data, charts, profiles, diary entries, check-ins) is permanently deleted. Payment records are retained per legal requirements.
5. Your Rights (GDPR / CCPA)
Regardless of your location, we extend the following rights to all users:
- Access: Request a copy of all personal data we hold about you.
- Rectification: Correct inaccurate personal data.
- Erasure: Request deletion of your account and all associated data.
- Data Portability: Export your data in machine-readable format (JSON).
- Objection: Opt out of non-essential data processing.
- Restriction: Request that we limit processing of your data.
- Withdraw consent: Where we rely on your consent (for example marketing email or optional integrations), you may withdraw it at any time, without affecting processing already carried out.
Legal bases (EU/UK). Where GDPR or UK GDPR applies, we process your data on these bases: to perform our contract with you (providing charts, readings, and account features); your consent (marketing email, SMS digests, and optional integrations such as Google Calendar); our legitimate interests (security, abuse prevention, and improving the service); and to comply with legal obligations (for example retaining payment records). Because birth data is used to infer characteristics about you, we treat it as sensitive and process it only to provide the service you request.
Complaints. If you are in the EU/EEA or UK, you have the right to lodge a complaint with your local data-protection supervisory authority. We would appreciate the chance to address your concern first — please contact us.
To exercise any of these rights, contact us at privacy@selfprime.net.
6. Data Security
We implement appropriate technical measures to protect your data:
- Passwords are hashed using PBKDF2-SHA256 with cryptographic salt.
- All data transmitted over HTTPS/TLS encryption.
- JWT authentication with secure token rotation.
- Rate limiting to prevent abuse.
- Parameterized SQL queries to prevent injection attacks.
7. Cookies and Local Storage
We use browser local storage to maintain your session (authentication token) and user preferences (sidebar state, language). We do not use third-party tracking cookies. Cloudflare may set functional cookies for security purposes.
8. Children's Privacy
Self: Prime is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
9. International Data Transfers
Your data may be processed in the United States and other countries where our service providers operate. We ensure appropriate safeguards are in place for international transfers.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes via email. Continued use after changes constitutes acceptance.
11. Contact
For privacy inquiries, data requests, or complaints:
Email: privacy@selfprime.net
Website: https://selfprime.net