Private-beta review draft — unapproved
Read the Privacy Notice
Source language: English.
Version: beta-privacy-review-2026-10-04-01
Prepared: 4 October 2026 (Sydney). Status: UNAPPROVED REVIEW DRAFT — NOT AN OPERATIVE CUSTOMER PRIVACY NOTICE. No effective date, release approval or acceptance has been assigned. Reading or requesting revisions is not agreement or permission to process new information. Current disabled processing and possible separately authorised future processing are distinguished below.
1. Current phase and cancellation
Only Richardt Dannhauser currently tests ORACLE ONE, in Australia. Fifteen possible later-stage testers are not enrolled or enabled; their countries are unknown and require separate participation/readiness review. This is a founder-only development Preview, not a public, international or paid service.
Existing-account sign-in is connected; normal protected use remains paused by operative agreement prerequisites. Separately authorised owner-preview access is not legal acceptance or release approval. Current Tarot, Dream Analysis, Journal reflection and other paid generation remain disabled. The founder cancelled the 20-minute AI test on 4 October 2026 at 22:03 Australia/Sydney (AEDT). Earlier authorisation/auto-start intent cannot reopen it: a fresh founder request and all further required gates are necessary. This revised draft is not that request.
New participant enrolment, billing actions, analytics delivery and unfinished private sharing are disabled. Historical accounts, saved readings, Journal material, receipts and spending records are not removed or rewritten by disabling generation. Previously authorised offline work and document preparation do not authorise new model requests.
2. Operator and contact
ORACLE ONE is the product/brand operated personally by Richardt Dannhauser under ABN 28 432 806 473. The founder confirmed ASIC business-name registration, operator/ABN association, correspondence address 3/359 Rankin Street, Bathurst NSW 2795, Australia, and that info@oracleone.org is monitored for support and privacy requests. These are founder-confirmed facts, not independent registry verification, incorporation or tested mailbox delivery.
Earlier registration/payment/operator/address/contact questions are superseded. No further fee or confirmation is requested. The brand is not represented as a separate incorporated company.
Applicable privacy/consumer obligations and processing bases depend on the operator, activity, participants and actual data flow. Australian location alone does not establish universal APP coverage or universal application of every listed right. The later fifteen-tester stage requires its own assessment.
3. Information handled now and source purposes
Account access: submitted email/password is passed to Supabase Auth, which manages authentication and sessions. The app uses account identifiers/session cookies to check access; it does not claim to store plaintext passwords in its own content tables. Do not send passwords in narratives or support messages.
Agreement/access: source records the account, exact document texts/versions, acceptance time/channel and 18+ attestation for receipt integrity and access checks. Connected genuine receipt persistence is not established by these review pages; the checkbox is not a birth date or independent age verification. Language, membership/access, attempt/idempotency, status and usage/cost information support feature eligibility, retries, duplicate protection and safe accounting. Random identifiers are linkable, not automatically anonymous.
Tarot: supported input includes spread/cards/positions/orientations, language, question/intention/context where entered, subject choice, first name/nickname and permission decisions. Save/reopening uses owner-scoped stored content and access state. Deterministic Daily/reference material is distinct from new generated prose. No new provider request is enabled now.
Dream Analysis: source handles dream description, optional waking feeling and personal associations, language, permitted subject/nickname and attempt identifiers, plus outputs, depth/access state and Save choices for supported interpretation/expansion/reopening. New generation/expansion is disabled.
Journal and Notes: saved reading references, source material, times, private Note title/body, tags and source references support an owner archive, editing/organisation and source-implemented reflection. Journal is not a public feed. Monthly and Ongoing reflection are separate implemented AI workflows, currently disabled and not authorised by the cancelled test. Historical Weekly records are retained as legacy read-only material.
Optional profiles: source supports nickname, language preference, optional birth date, confirmed birthplace/country/region, IANA timezone and known/approximate/unknown birth time with uncertainty and ambiguous-time decisions. Reusable other-person profiles have separate storage permission and revision state. Full profile payloads are encrypted in an owner-scoped store; all connected profile persistence is not verified. A profile is not another person's account or a full natal-chart service.
Optional guidance choices affect wording and priorities. They do not create verified knowledge of biography or hidden thoughts. Tarot birth context is default-off; source supplies only the selected recipient's minimal confirmed symbolic sign context where data is sufficient, not the full stored birth profile.
Service operation: Supabase/Replit receive network and connection information, potentially IP addresses, URLs/status/authentication events and security metadata. App-owned lifecycle/telemetry source uses bounded fixed fields and suppresses incoming URLs in its own reviewed paths. This does not audit upstream hosting/proxy/auth logs, prove zero logging or establish their retention.
4. Proposed future AI processing — not enabled or approved
The configured provider is OpenAI, using its Responses API at https://api.openai.com/v1 with model gpt-5-mini. Non-secret configuration and request source support that description; no paid request was made to verify output. Before any separately authorised future phase, the actual selected model/endpoint/account settings must match the operative disclosure.
The server constructs prompts and sends their content to OpenAI over HTTPS in a processable form. Encryption at rest does not prevent the server or provider processing the submitted text. Technical request settings and duplicate-handling/request identifiers accompany requests; response/usage identifiers support accounting and recovery. This source flow is text/structured text, not automatic microphone, video or image generation.
Tarot purpose/input: create the requested reflection from relevant cards, positions/orientations, spread/mode, chosen language, supplied question/intention and included permitted subject/context. Selected guidance and an explicitly chosen minimal birth-context instruction can affect wording. A follow-up can send the relevant original interpretation and follow-up question. Cards/draw are not secretly changed by profile context.
Dream purpose/input: reflect on the submitted dream, optional waking feeling and associations, selected language, permitted subject/first name or nickname and included guidance preferences. Eligible expansion uses relevant Dream inputs/context; repeated/deeper processing is not authorised merely by reopening a saved result.
Monthly Journal purpose/input: synthesise eligible saved Tarot, Dream and Note source material captured for the selected calendar month up to capture time. Request content includes period, entry count, saved-entry inputs, language and applicable guidance. Source/source-index evidence constrains supported claims; it does not certify that every generated statement is correct.
Ongoing Journal purpose/input: develop an incremental reflection from supported previous saved Ongoing claims plus genuinely new eligible saved entries, relevant period/source information and previous version/provenance identifiers. This is not just a new-input-only request and not automatic transmission of every Journal record simply because an account exists. Removing/changing evidence affects future supported-claim selection; it does not necessarily erase previous saved versions or provider copies.
OpenAI would return interpretive text and response/usage metadata. The server validates expected structure and uses available access, encrypted storage, Save and reopening paths. Returned text may still be inaccurate or in an unintended language; validation and recorded language are not proof of semantic quality. Connected persistence/readiness must be separately checked.
Journal is explicitly excluded by the current owner AI-test authority. A future Tarot/Dream request cannot silently authorise Journal processing. Each future feature needs its own scope, genuine legal/technical readiness, budget protections, expiry and explicit authority. No whole-account narrative collection or new third-party disclosure is authorised by this draft.
5. Provider data use, retention and international processing
OpenAI: all reviewed Tarot, Dream, Monthly and Ongoing request builders specify store:false. This requests no normal Responses application-state storage; it is not a universal zero-retention guarantee. OpenAI's current official API documentation states that API data is not used for training by default unless the organisation/account explicitly opts into sharing. Default abuse-monitoring logs may contain prompts, outputs and derived metadata and are ordinarily kept up to 30 days, with longer retention possible for legal/safety reasons.
Zero Data Retention and Modified Abuse Monitoring require OpenAI approval and have feature/exception limits. This app's actual organisation/project sharing choice, special retention approval, applicable provider contracting arrangements and residency settings are not verified. Do not treat store:false as proof of those settings or claim Australia-only processing. The operator's proposed limited-use policy does not override an external provider's actual terms/settings.
Supabase: supplies existing authentication and primary database backend. Available primary-project evidence records Sydney, Australia (ap-southeast-2); this is existing region evidence, not a new privileged management check or a guarantee about every auth service, support access, backup/log or future resource. Reviewed Supabase Terms/DPA identify Supabase Pte. Ltd. in Singapore and describe regional storage with exceptions and worldwide facilities. Support and other subprocessors can operate internationally.
Supabase's reviewed official subprocessor material includes hosting/network, monitoring and email providers, such as AWS, Google, Cloudflare, Fly, Sentry, Braintrust and Postmark. A general subprocessor list does not prove each supplier receives this app's narratives or locate every app-specific activity. Exact supplier access/locations remain unverified.
Replit: hosts the development Preview and its web requests/development infrastructure. Exact Workspace region is unknown from available authorised evidence. Official development-geography documentation lists North America, Europe and Asia; a founder's Australian location or a published deployment region does not identify this development region. General Replit privacy/DPA/subprocessor materials describe international infrastructure/support and do not establish each app-specific recipient or transfer.
Replit's reviewed DPA describes return/deletion after request/contract termination, including up to 90 days after termination; that is not an app-user purge deadline. Documentation describing 30-day published-app log retention must not be applied as a guarantee about development Preview logs.
Other integrations: PostHog source supports optional fixed-value, opt-in analytics but delivery remains disabled. Stripe source supports billing, but new checkout, portal and webhook actions remain disabled. Historical subscription/billing/entitlement identifiers may exist; disabled actions do not delete those records or cancel an external subscription. No new activation is permitted here. General platform AI/subprocessor listings are not evidence this app sends narratives to each listed service.
Potential recipients therefore include the operator through authorised handling, Replit and Supabase and their applicable processors for current operation, and OpenAI/its applicable processors only for a separately authorised future generation. Public posting, advertising with narratives or resale of personal entries is not a proposed purpose. Exact actual access, service locations and transfer safeguards must be checked for the phase rather than inferred from headquarters or generic lists.
6. Cookies, browser storage and user choices
Session cookies support authentication. Language preferences, retry/attempt state and optional installed/offline browser features have separate purposes. Some entered form text/attempt identifiers can survive in-tab recovery; private generated narratives are not intentionally treated as an automatic draft-recovery cache. A shared browser may retain entered information.
The service worker is designed to cache a public offline shell/icons, not protected pages, authentication or APIs. That design is not certification of every browser, device, proxy cache or PWA state. Real-device acceptance remains separate.
Analytics source is default-off and explicitly opt-in, with allowlisted fixed events and a random per-tab identifier/local preference. It does not use automatic page capture, session replay, person profiles or the PostHog SDK; its payload allowlist excludes emails/names, narratives, birth details, raw URLs/referrers and raw exception text. Delivery is disabled even if a stored preference exists. Any future analytics choice must remain separate from required agreement; withdrawing a preference would stop future app capture, not prove erasure of past provider data.
Actual source controls include choosing inputs/language/guidance, leaving birth context off, separate third-party request/Save/profile permissions, explicit Save and eligible reopening, Note editing/deletion, profile editing/deletion/withdrawal where connected, opting out of optional analytics and signing out. These are not all equivalent to deleting all copies. Do not assume stopping generation, declining Save, withdrawing permission or signing out erases attempts, previously saved outputs, ledger records, logs/backups or provider data.
7. Sensitive information, spiritual reflection and security
Dreams, questions and notes can reveal relationships, health, beliefs and other sensitive matters. Include only necessary details. Respect spiritual meaning and higher-self beliefs while recognising that AI processes prompts and does not verify spiritual contact, past lives, hidden intentions or a diagnosis. You may reject an interpretation.
Other-person attestations are requester statements, not independently verified consent from that person. Reusable profile storage has distinct permission; source withdrawal is intended to stop future reuse. PROPOSED FOR OWNER REVIEW: no new identifiable third-party inputs during this rehearsal, with fictional fixtures for other-person tests. This is not a new technical block or permission to process historical information.
Source authenticates protected requests and applies owner, agreement, entitlement and permission checks. Selected Tarot narratives, Dream input/output, Note title/body and full private-profile payloads use identity-bound application-level AES-256-GCM and key-version handling. Not every nickname, tag, card/subject field, identifier/time, account/legal, usage/billing record, log or backup is covered. This is not end-to-end encryption or a guarantee against all authorised administrative access.
Source safeguards reduce risk but do not certify key custody, connected isolation, provider logs, backups or every physical device. No credentials should be sent in narratives/support.
8. Storage, deletion and retention limits
There is no approved global/category retention schedule or universal automatic purge/verified backup-erasure arrangement. Saved content is intended for reopening until an available owner-authorised removal, subject to legal/security needs. This intent is not a fixed retention deadline.
Source Note deletion overwrites encrypted title/body and soft-deletes a retained row; metadata/backups can remain. Saved Tarot/Dream readings have no self-service delete control. No complete whole-account export/erase facility is implemented.
Source profile deletion hard-deletes the profile row; permission withdrawal instead overwrites the encrypted payload and marks it withdrawn. Connected profile deployment/deletion is not established for every path. Removing/withdrawing a profile does not remove separately saved prose or historical evidence.
Tarot's 24-hour unsaved recovery window and Dream's 48-hour free-origin access window are access rules, not purge guarantees. Dream source cleanup is service-only, targets eligible succeeded unsaved expired free-origin material and preserves saved pairs/cost accounting. No scheduled invocation is established; this is not universal cleanup. Journal versions/archives and source lineage can persist separately from source-entry changes.
Official Supabase documentation describes daily backups for paid plans, accessible for seven days on Pro, fourteen on Team and up to thirty on Enterprise. PITR is separately configured. Database backups do not include Storage API objects. Actual project plan, PITR/backup configuration/inventory and log categories/retention/drains remain unverified; no plan or feature is inferred from service-role credentials.
Replit checkpoints snapshot workspace files/conversation and supported Replit resources; they do not establish backup of the external Supabase store. The exact development-region/log/checkpoint handling and all upstream copies have not been audited. App-owned bounded lifecycle records are not a contractual deletion service level.
Accordingly, app deletion is not instant permanent deletion from every database, log, backup, provider, device or legal/security record. No provider purge deadline is promised. Technical gaps are the operator/engineering team's work, not requests for the founder to research providers or supply a new registration payment.
9. Requests and proposed response policy
Depending on applicable law/circumstances, rights may include information/access, correction, deletion, objection/restriction, portability, withdrawal of consent or regulator complaint. Applicability/exceptions must be assessed; no universal right to immediate erasure is asserted.
Use info@oracleone.org or 3/359 Rankin Street, Bathurst NSW 2795, Australia. A monitored mailbox is not independently tested delivery, a ticket queue or a complete export facility.
PROPOSED FOR OWNER REVIEW — NOT APPROVED OR OPERATIONALLY VALIDATED: acknowledge within five NSW business days, then give an outcome or progress update within 30 calendar days after proportionate verification, with shorter applicable legal deadlines prevailing. Use authenticated account/verified email evidence where sufficient; clarify disputed/suspicious authority. Do not send passwords, narrative dumps or unnecessary identity-document copies.
Any separately authorised retrieval/export would be limited to verified owner-scoped material actually obtainable and delivered by a restricted method, not a public link. Record scope, actions, exceptions and known remaining copies. This proposal does not itself implement a request queue, erase workflow, provider instruction, complete export or validated response service level. Signing out does not remove records or cancel a subscription.
10. Other proposed owner policies
FOR OWNER REVIEW ONLY — none is accepted, implemented as a new workflow or a grant of activation/data-mutation authority:
- Keep this phase founder-only in Australia, with no new participant enrolment, billing or analytics delivery. All paid AI remains cancelled/off; any future test needs fresh specific authority and all legal/technical gates. Introduce no new identifiable third-party inputs; use fictional fixtures where needed.
- Review data at phase closure and every 90 days while it continues. Review account/receipt/attempt/usage needs for testing, integrity, duplicate/cost protection and narrow documented legal/security needs; minimise support correspondence. Keep saved content for reopening until owner-authorised removal, subject to documented exceptions. This is a review interval, not a 90-day purge or authority to change existing retention/data.
- Pause unsafe/under-age/unauthorised testing or collection, investigate with minimum necessary incident data, notify when safe and allow review via the monitored contact. Destructive remediation requires separate scope/authority. The 18+ attestation is not independent age verification and cannot guarantee no information about a child is entered.
- Explain material processing/feature changes and identify revised operative versions before renewed agreement where required. Preserve original receipt integrity; do not overwrite historical receipts as consent to a new purpose.
The proposed NSW/Commonwealth law and non-exclusive NSW-court policy appears in the Terms draft and remains a separate owner choice, preserving non-excludable rights. No proposal admits the later fifteen testers or promises universal legal compliance.
11. Automated processing and exact status
AI reflections are intended for personal meaning, not eligibility, credit, employment, medical or other consequential automated decisions. Deterministic draws are not verified predictions. Applicable sensitive-data/profiling/automated-decision rules require assessment against actual later use.
Current AI is disabled and the test cancelled. This review has no effective date, approval or acceptance. Future material processing needs accurate operative disclosure and any required genuine agreement/permissions before activation; reviewing these pages alone never supplies them.
12. Verified basis, technical unknowns and sources
Verified for review: disabled generation/owner-test flags and absent window timestamps; configured OpenAI provider/model/endpoint; source request construction and store:false; source Save/encryption/deletion/control semantics; founder-confirmed operator facts; current official general API/backup/log/Workspace documentation. Connected feature execution and comprehensive deletion are not certified.
Remaining technical unknowns: exact Replit Workspace geography and development-log/backup retention; actual Supabase plan, PITR/backup inventory, log/drain retention and supplier-specific access/locations; fresh verification of every resource's region; OpenAI account sharing, special retention approval, residency and applicable account terms; complete infrastructure-copy deletion behaviour; connected profile/receipt/Journal reflection readiness and operational request handling. No expired database was reopened or service settings changed to investigate.
Official source material:
- OpenAI API data controls: https://platform.openai.com/docs/guides/your-data
- Supabase regions: https://supabase.com/docs/guides/platform/regions
- Supabase backups: https://supabase.com/docs/guides/platform/backups
- Supabase logs: https://supabase.com/docs/guides/platform/logs
- Supabase DPA/subprocessors: https://supabase.com/legal/customer-resources/data-processing-addendum and https://supabase.com/legal/customer-resources/subprocessor-list
- Replit Workspace geography: https://docs.replit.com/features/collaboration/workspace-geography
- Replit privacy/DPA/subprocessors: https://replit.com/privacy-policy, https://replit.com/dpa and https://replit.com/subprocessors
- OAIC privacy-policy guidance: https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/more-guidance/guide-to-developing-an-app-privacy-policy
The /legal/review checklist separates owner wording/policy decisions from engineering unknowns. No operative setting, provider configuration, acceptance, spending record or saved content is changed by this draft.