Umbra · service information
Your data, explained.
What the current Umbra web service processes, what you can control, and what still needs owner confirmation.
Updated
Who to contact
Contact admin@umbra.wiki about privacy, access or deletion. The legal identity and contact address of the service operator have not yet been confirmed for publication. This draft is not a completed legal privacy notice.
Account and sign-in
Umbra stores account identifiers, your email where supplied, display name, linked sign-in providers, consent records and account timestamps. Email links and password verification use temporary tokens. Passwords are stored as salted hashes, not readable passwords. Sessions use an essential browser cookie to keep you signed in.
Google sign-in shares identity information with Umbra when you choose it; Umbra does not receive your Google password. Resend delivers sign-in, verification and password-reset emails and receives the recipient address and message needed for delivery. Available sign-in methods are shown in the login window.
Your private record
After you enable your private record, Umbra stores the profile details you provide: preferences, timezone and any birth date, time and place you enter. It also stores saved charts and their calculation inputs and results, readings, reflections, journal tags and daily-card receipts.
When your private record is enabled, requesting a question reading creates an account-linked reading receipt, including the original question and result, even before you add it to your Library. A daily draw is also recorded so it can stay consistent for your day. The Save action is not the only point at which data is stored.
Guest question previews are processed by the server but are not saved as account reading receipts. Do not enter passwords, documents, or unnecessary sensitive information about yourself or other people. A private record is access-controlled, not an end-to-end encrypted vault.
Services involved
Fornex hosts the application, database, backups and support mailbox. Cloudflare is used for domain DNS. Searching for a city sends the search text through Umbra to Open-Meteo geocoding. Astrology calculation inputs, including dates, times and coordinates, are sent to the separate Swiss Ephemeris calculation service; email and journal text are not needed for those calculations.
The current tarot interpretation path composes results from the editorial catalogue and rules; it does not send your question to a generative AI provider. If this changes, the data description must be updated before that processing is introduced.
Application diagnostics record a route label, request identifier, response status and duration, rather than question text, birth details or authentication tokens. Hosting, DNS and email providers may process technical connection or delivery information under their own policies. This is not a promise that no infrastructure logs exist.
Storage and deletion
Your account and private records remain in the live database until removed through the available controls or account deletion. No fixed automatic expiry for all private records is currently promised. Signing out ends the device session; it does not delete the account.
Profile contains Download my data and Delete account controls. Account deletion removes the live account and its linked private records. Backup copies are separate and are not immediately rewritten by account deletion. Backup rotation, infrastructure-log retention and the handling of deletion requests after a restore require a confirmed operator policy; no specific retention period is claimed here.
Messages you send to support and delivery records held by email providers are separate from the in-app private record. Contact support about these records rather than assuming the account-delete button removes them.
Your controls and privacy requests
You can choose not to enable a private record, edit your profile, download your account data, or delete the account from Profile. Contact admin@umbra.wiki for access, correction, deletion, restriction, objection or other applicable privacy requests, including withdrawing permission to keep your private record. We may need to verify that the account is yours without asking for your password.
The existing private-record declaration requires you to be at least 16. It is not a marketing opt-in. The operator must still confirm applicable legal grounds, regional age requirements, international-transfer arrangements and the relevant privacy authority before this draft becomes a final notice.