HopeGraph

privacy policy

What we collect, what we don't.

The honest version. We're a small operation; we collect what we need to give you readings, and very little else.

What we collect

For free readings:your birth date, birth time, and birth city. That's it.

For paid Deep Dives: the above, plus the email address you enter at Stripe Checkout so we can deliver the reading.

For the optional Almanac email subscription (coming soon): the email address you submit.

We do not collect: your name, phone number, address, IP address (beyond standard server logs), cookies, browser fingerprints, or anything used for advertising. We do not have user accounts.

Where it’s stored

Free readings:your birth info is stored in your browser's localStorageso you don't have to retype it when you move between pages. It never touches our database. When you submit a chart, the birth info travels to our server to compute the reading and is discarded; we keep no record of free readings.

Paid Deep Dives: the full reading (your chart math, the AI-written prose, your email, the Stripe session id) is saved to our database so you can return to the permanent URL anytime. We keep it indefinitely unless you ask us to delete it.

You can clear your local storage at any time via your browser's site settings for hopegraph.com.

Who else sees your data

We use these third parties to make the site work. Each only sees the slice of data described:

  • Anthropic (the AI that writes your readings) — receives your computed chart data, never your raw birth info or email. Bound by their privacy policy; they do not train models on API inputs.
  • Stripe (payments) — handles your card details directly; we never see them. They receive your email and the $9 charge. Bound by their privacy policy.
  • Resend(email delivery) — receives your email and the contents of the “your Deep Dive is ready” message. Policy.
  • Supabase (our database) — stores paid reading rows. Policy.
  • Vercel (hosting) — runs the site and may capture standard server-level access logs (IP, user agent, request path) for security and reliability. Policy.
  • OpenStreetMap Nominatim(geocoding) — receives the city you entered (e.g., “Chicago, IL”) to convert it to coordinates for the true- solar-time correction. No personal data attached.

We do not sell your data to anyone. We do not run advertising. We do not have a data-broker arrangement.

Cookies and tracking

We do not set cookies. We do not use analytics that fingerprint visitors. The only client-side storage is the localStorage key your browser saves to pre-fill your birth info (described above).

Your rights

You can ask us to delete your paid reading row at any time. Email admin@hopegraph.com with the URL of your reading (or just your buyer email) and we'll remove the row within 7 days.

If you're in the EU/UK, you also have GDPR rights to access, correct, or port your data. Same email; we'll respond within the legally required timeframe.

Security

We use industry-standard TLS for all traffic. Payment card details are handled exclusively by Stripe; they never reach our servers. Our database connections are over TLS, with row-level security policies that prevent public access to paid_readings rows except via the unguessable UUID slug.

No system is perfectly secure. If you become aware of a vulnerability, please email admin@hopegraph.com.

Children

HopeGraph is intended for adults. We do not knowingly collect data from anyone under 13.

Changes to this policy

If we change how we collect or use data, we'll update the date at the top of this page and, for material changes affecting paid customers, email everyone who has purchased a Deep Dive.

Last updated: May 27, 2026