Privacy Policy
Effective Date: August 26, 2026
1. Introduction
Divinity Code, operated by Pandora Ninety LLC ("we," "us," or "our"), respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our numerology service at divinitycode.net ("the Service").
By using the Service, you consent to the data practices described in this policy. If you do not agree with this policy, please do not use the Service.
2. Information We Collect
2.1 Information You Provide
- Account Information: Email address and authentication data when you create an account
- Profile Information: Birth name, current name (if different), and birthdate for numerology calculations
- Reading Context: Optional personal context you provide for AI-generated readings
- Payment Information: Processed securely by Stripe; we do not store your payment card details
2.2 Information Collected Automatically
Some information is collected from the moment you first visit the Service, before and whether or not you create an account:
- Usage Data: Pages visited, features used, and interactions with the Service
- Device Information: Browser type, operating system, and device identifiers
- Log Data: IP address, access times, and referring URLs
- Referral and Campaign Data: The page you first landed on, the site or advertisement that referred you, and any campaign parameters in the link you followed (for example
utm_source, utm_medium, utm_campaign). This is stored in a cookie on your first visit and retained for up to 30 days. If you later create an account, it is attached to that account so we can understand which channels bring people to the Service. - Approximate Location: Country, region, and city derived from your IP address at the time you create an account
- Cookies: See Section 8 for the full list of cookies we set and what each one does
3. How We Use Your Information
We use your information solely to:
- Provide and maintain the Service, including generating numerology charts and readings
- Process transactions and manage your account
- Authenticate your identity and maintain session security
- Send you a daily reading reminder email, which new accounts receive by default. You can switch it off at any time under Daily Email Reminder in Settings, or through the unsubscribe link at the bottom of every one of those emails
- Respond to your inquiries and provide customer support
- Improve and optimize the Service
- Measure how the Service is used and which channels or referrals bring visitors to it, so we can understand what is working
- Detect and prevent fraud, abuse, or security incidents
- Comply with legal obligations
4. Data Sharing and Disclosure
WE DO NOT SELL, RENT, OR TRADE YOUR PERSONAL INFORMATION TO THIRD PARTIES.
We may share your information only in these limited circumstances:
- Service Providers: With trusted third parties who assist in operating the Service (e.g., Stripe for payments, hosting providers), bound by confidentiality obligations
- AI Processing: Names and birthdates are sent to AI providers (Anthropic) to generate readings; this data is processed according to their privacy policies and is not used to train their models
- Analytics and Advertising Measurement: Usage and device data is shared with Google Analytics and Meta (Facebook) so we can measure traffic and the performance of our advertising. These providers may combine it with data they hold about you from other sites. See Sections 8 and 9.
- Session Recording: Mouseflow records how you interact with the Service — pages viewed, clicks, scrolling, mouse movement, and the fields you interact with — so we can find and fix usability problems. Recordings are tied to an account identifier when you are signed in. See Sections 8 and 9.
- Legal Requirements: When required by law, court order, or governmental authority
- Protection of Rights: To protect our rights, privacy, safety, or property, or that of our users or the public
- Business Transfers: In connection with a merger, acquisition, or sale of assets, with notice to affected users
5. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:
- Encryption of data in transit (TLS/SSL) and at rest
- Secure authentication mechanisms
- Regular security assessments
- Access controls limiting data access to authorized personnel
- Secure payment processing through PCI-compliant providers
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
6. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy:
- Account Data: Retained while your account is active and for a reasonable period thereafter
- Charts and Readings: Retained until you delete them or your account
- Transaction Records: Retained as required for accounting and legal compliance (typically 7 years)
- Deleted Data: Soft-deleted items may be retained for up to 30 days before permanent deletion
You may request deletion of your data at any time by contacting us.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data
- Portability: Request transfer of your data in a machine-readable format
- Objection: Object to certain processing of your data
- Withdrawal of Consent: Withdraw consent where processing is based on consent
To exercise these rights, contact us at the email address below. We will respond within the timeframe required by applicable law.
8. Cookies and Tracking
We use cookies and similar technologies in the following categories. Some are set by us, and some are set by third-party analytics and advertising providers.
- Session Cookies: Required for authentication and security
- Preference Cookies: Store your language, timezone, and display preferences
- Attribution Cookies: Set on your first visit and retained for up to 30 days. They record the page you landed on, the referring site, any campaign parameters in the link you followed, your IP address, and your browser user agent, so that a later signup can be attributed to the channel that produced it.
- Referral and Promotional Cookies: Record a referral or promotional code from a link you followed, so the correct credit or bonus is applied if you create an account
- Analytics and Advertising Cookies: Google Analytics and the Meta (Facebook) pixel set their own cookies to measure traffic and advertising performance. These are third-party cookies and are not strictly necessary for the Service to function.
- Session Recording Cookies: Mouseflow sets cookies to recognize your browser across pages and stitch your activity into a single session replay. It records pages viewed, clicks, scrolling, mouse movement, and which form fields you interact with. These are third-party cookies and are not strictly necessary for the Service to function.
You can control cookies through your browser settings, but disabling essential cookies may affect the functionality of the Service. You can opt out of Google Analytics using the Google Analytics Opt-out Browser Add-on, and manage Meta's advertising cookies through your Facebook ad preferences. You can opt out of session recording using Mouseflow's opt-out page, which stores the preference in a cookie and so must be set again on each browser and device you use.
9. Third-Party Services
The Service integrates with the following third-party services:
- Stripe: Payment processing (Privacy Policy)
- Google: Authentication and, where enabled, Google Analytics traffic measurement (Privacy Policy)
- Meta (Facebook): Advertising measurement through the Meta pixel, where enabled (Privacy Policy)
- Mouseflow: Session recording and heatmaps, where enabled (Privacy Policy)
- Anthropic: AI-generated readings (Privacy Policy)
- Resend: Delivery of sign-in links, account emails, and daily reading reminders (Privacy Policy)
- Firebase (Google): Phone number verification, where phone sign-in is enabled (Privacy Policy)
These services have their own privacy policies governing their use of your data.
10. Children's Privacy
The Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately, and we will take steps to delete such information.
11. International Data Transfers
Your data may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have different data protection laws. By using the Service, you consent to such transfers. We take appropriate safeguards to ensure your data remains protected in accordance with this policy.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Effective Date." Your continued use of the Service after any changes constitutes acceptance of the updated policy.
13. California Privacy Rights
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected, used, shared, or sold
- Right to delete personal information held by businesses
- Right to opt-out of sale of personal information (we do not sell your data)
- Right to non-discrimination for exercising your privacy rights