Our promise
We collect the smallest amount of data required to run XIX84 well and we never sell it. This policy explains what we collect, how we use it, and the rights you have under the EU GDPR, the UK GDPR, and the California Consumer Privacy Act (CCPA/CPRA).
1. Data we collect
- Account data — name, email, avatar, tier, Google OAuth identifier, language preference.
- Content data — journal entries, remedies you create, Legacy Scrolls, uploaded images, voice recordings, saved bookmarks, offline first-aid downloads.
- Usage data — device type, browser, IP address (truncated), routes visited, feature timings. Used only for reliability and abuse prevention.
- Payment data — handled entirely by Stripe. We store only the last-four digits and expiry of your card and your Stripe customer/subscription IDs.
- Location data — only when you explicitly enable features like Foraging, Nature Quests, Hyperlocal Edibles, or the AR Sky Viewer. Location is used at time-of-request and not retained beyond the session unless you save a place.
2. How we use your data
- Operate and personalise the Service.
- Process payments and creator payouts (via Stripe).
- Send transactional email (via Resend) for signup, receipts, security notices, and an optional weekly Digest.
- Improve XIX84 through aggregated, anonymised analytics.
- Detect abuse and secure the platform.
3. AI processing
Some features (Voice Herbs, Remedy generation, Plant/Star/Song identification) send content to third-party AI providers (OpenAI, Anthropic, Google Gemini) via the Emergent gateway. Providers process content transiently to return a result and do not use your content to train their models under our agreements. Voice recordings are transcribed and then deleted unless you save the entry.
4. Legal bases (GDPR)
- Contract — to provide the Service you signed up for.
- Legitimate interest — security, abuse prevention, service improvement.
- Consent — for optional cookies, marketing email, location, camera and microphone.
- Legal obligation — tax, accounting, lawful requests.
5. Data sharing
We share data only with the processors necessary to run XIX84: MongoDB Atlas (database), Emergent Platform (AI gateway), Stripe (payments), Resend (email), Cloudflare (WebRTC TURN + edge), and our hosting provider. All processors are bound by data-protection agreements. We do not sell personal data.
6. Your rights
- Access — request a copy of your data.
- Rectification — correct inaccurate data.
- Erasure — delete your account and all associated content (Settings → Delete Account, or email us).
- Portability — export your journals, formulas, Legacy Scrolls, and Bloom cards in JSON.
- Objection & restriction — pause processing beyond what's needed to run the Service.
- CCPA rights — California residents may request disclosure of categories collected, opt out of any "sale" (we do not sell), and be free from discrimination for exercising rights.
Contact GQ@xix84-qds.com to exercise any right. We respond within 30 days.
7. Retention
We keep account data as long as your account is active. Deleted accounts are purged within 30 days, except where retention is required by law (tax records ≤ 7 years).
8. International transfers
Data may be processed in the United States and other jurisdictions. We rely on Standard Contractual Clauses (or equivalent safeguards) for transfers out of the EU/UK.
9. Cookies
XIX84 uses strictly-necessary cookies to keep you signed in and to remember your tier, language, and Sacred Overlay choice. We do not set advertising cookies. You may manage cookies in your browser settings.
10. Children
XIX84 is not directed at children under 13. If you learn a child has created an account, contact GQ@xix84-qds.com and we will delete it.
11. Changes
We will announce material changes in-app at least 14 days before they take effect.
12. Contact & Data Controller
XIX84-QDS · Qathedral of Quantum D Solutions is the data controller. Email GQ@xix84-qds.com.