Orison

Privacy Policy

Version 2026-09c · Published 7 September 2026 · Applies to the Orison app in early access, from that date

care@orison.day

Orison writes you a personal daily prayer. To do that, you tell us a few intimate things: your birth date, time, and place, and the spiritual tradition you pray in. We use those details only to write your prayers, and nothing more. They live encrypted inside our European cloud. They are never sold, never used for advertising, and never fed to any analytics or tracking company. Each prayer is yours to keep or to let pass: a prayer you do not keep deletes itself after a seven-day grace period, and one you keep stays until you say otherwise. When you delete your account, we delete everything for real.

One thing that promise does not cover, and we would rather you learned it here than discovered it later: email you send to our support address is not part of your account, and deleting your account does not delete it. The section If you email us says so before you write, and How long we keep it explains why.

Where things stand. Orison is in early access. If you are using the app now, this policy is the one that applies to you, from the date above. It is also still being reviewed by our lawyers, so some of its wording may change. When it does, we will publish a new version on this page, and if the change matters to you, we will tell you in the app.

Who we are

Orison is made and operated by Orison Lab Pty Ltd, ACN 700 874 513, ABN 84 700 874 513, an Australian proprietary limited company registered in New South Wales, trading as Orison Lab. In this policy, “Orison”, “we”, and “us” mean the company.

We are the data controller for everything described below: we decide what is collected and why. The companies that process data on our behalf are listed under Who processes data for us.

For any privacy question or request about your data, write to care@orison.day. Before you do, please read If you email us.

What we collect

We collect only what personalisation needs. Two things shape everything here: we minimise by design (birth time is optional, and the app works without it), and the most sensitive data is used for one purpose only, writing your prayers.

The sensitive core: your birth details and your tradition

Under EU and UK data-protection law, data revealing religious or philosophical beliefs is special-category data and is given heightened protection (GDPR Article 9). Australian law draws the same line in its own words: under the Privacy Act 1988, information about a person's religious beliefs or affiliations is sensitive information. We treat all of the following as sensitive data and handle it accordingly, wherever you live:

  • Birth date. Computes your astrological and BaZi chart, which tunes the imagery and themes of your prayers.
  • Birth time (optional). Sharpens the chart. The app works without it.
  • Birth place, chosen from a city list bundled inside the app. Completes the chart and sets your birth time zone. Your birth place is never typed into a third-party map or geocoding service; you pick it from an offline list, and its time zone is read on your device.
  • Your spiritual tradition, the way you pray (for example non-denominational, Christian, Buddhist, Muslim, Hindu, or Jewish). Sets the voice and reverence of your prayers.
  • Your computed chart and daily influences. Derived from the above; the structured facts a prayer is written from.

The legal basis for all of this is your explicit consent. We ask for it with an affirmative toggle, off by default, during onboarding, immediately before your details are sent. The toggle's own label is the consent, and it reads:

Yes, use my birth date, time, and place, and my tradition, to write my daily prayers. Never to sell, advertise, or profile me.

That is a promise, not a flourish. We use these details to write your prayers. We never sell them, never use them for advertising, never share them with data brokers, and never use them to track you across other apps or services. Any future secondary use would need its own separate consent, which you could refuse on its own.

One honest clarification about the word “profile”. To write a prayer that fits you, the app does build a private, internal picture of you: it computes your birth chart and reads each day's sky against that chart to choose the emotional themes your prayer draws on (explained below). Under EU data-protection law, that automated shaping is itself a form of “profiling” (GDPR Article 4(4)). So the consent's phrase “never to profile me” is narrower than it may sound. It means we never build a commercial, advertising, or tracking profile of you, and never profile you to make decisions about you. It does not mean no personalisation is computed at all. The personalisation that shapes your prayer is the service itself. It stays inside our European boundary, it is never named in your prayer, and it is never used for anything but writing your prayer.

Your prayer intention

If you write an intention to shape a prayer, that is sensitive data too, because a person's own words can reveal health, relationships, or belief. So we do not fold it into the consent above. Instead, the first time you go to write an intention, we ask for a separate explicit consent, in context, at that moment. Its label reads:

What you write shapes today's prayer, and is gently checked to keep you safe. Never shared, never used for anything else. Writing one is always your choice.

Writing an intention is optional. The app works without one, and you can clear yours at any time. That one consent covers two inseparable purposes: weaving your words into that day's prayer, and the safety check described under Crisis, and an important boundary. The safety check cannot be switched off separately, because we will never leave a message of distress unseen. Your intention is never shared and never used for anything else.

Your intention is write-only over the network, with two small exceptions. Once saved, our servers never send your intention text back out, not even to your own device. The only things we keep alongside it are a marker that an intention is currently held and the time you last set it: no text, and never a history of past intentions. That marker exists so the app can show “an intention is held” instead of a worryingly empty field. It is deleted the moment you clear your intention, and it is never used for analytics. Second, so that you can see your own words after saving them, the app keeps a copy of your intention on your device only, in the device's secure storage (Keychain on iPhone, Keystore on Android). That copy is display-only. It is never included in device backups or synced to any cloud, and it is wiped when you sign out, clear your intention, or delete your account.

Your prayers

The prayer written for you is intimate content too. It is shaped by your tradition and your chart, so we treat it with the same care as the details it was written from. A prayer is ephemeral unless you keep it. If you keep one, it stays in your journal. If you let it pass, it is deleted automatically after a seven-day grace period (see How long we keep it).

When you keep a prayer, the only thing we record about that choice is the time you kept it. We never use your keeps for analytics: no counts, no keep-rates, no engagement signals of any kind. Nothing about what you keep is ever shown to anyone but you.

Your account

These are held because the service needs them to work for you, on the basis of our contract with you:

  • Email address. Identifies your account. Sent to us by Apple or Google when you sign in.
  • Account identifier. A random ID we generate to link your prayers to your account. We never store the identifier Apple or Google uses internally.
  • Subscription tier (free or premium). Delivers the right features.
  • Current time zone and country. Delivers your prayer at your local dawn, and shows the right support resources for your country. Your country is inferred from your device's language and region setting, never from location services.
  • Your prayer preferences. The way your prayer is written, whether it is written in your own voice for you to speak or spoken over you as a blessing, and the hour you chose for your morning reminder. We keep these with your account so your choices follow you to a new device. The reminder itself is scheduled by the app on your own phone and carries no prayer text.
  • A marker that you have chosen a way of writing. A single yes or no: that you chose, never what you chose. Until you choose for yourself, the app says plainly that we picked your way of writing to begin with. This marker is how it knows to stop saying that. Nothing that writes your prayers reads it, and it is never used for analytics.

What we do not collect

We think this list matters as much as the ones above.

  • No analytics or tracking. The app contains no analytics, advertising, or behaviour-tracking software of any kind.
  • No advertising, ever. We have no ad technology and share nothing with advertisers.
  • No location tracking. We never request your device's GPS. Your birth place is picked from an offline list; your current country comes from your device's language setting.
  • No cookies or web trackers in the app. The app is not a website and sets no tracking cookies.
  • No passwords. You sign in only with Apple or Google, so we never hold a password.

Why we use it, and how the app works with it

We think you should understand, in outline, the automated logic that shapes what you see. Two automated processes run on your data.

Personalising your prayer. From your birth date, time, and place we compute a birth chart in two systems at once: Western astrology and Chinese BaZi. For each day, the app reads the day's planetary positions against your Western chart, and the day's BaZi pillar against your BaZi chart, to select the emotional themes (a tension and a gift for the day) that your prayer is written from. This is deterministic maths and lookup, not a person's judgement. The underlying facts are never spoken in your prayer; they are prayed as felt weather. It shapes themes, never predictions. This computation is what the word “profiling” above refers to. It personalises your prayer and does nothing else: no decision is made about you, nothing is scored, nothing is shared.

When your prayer is written, and how often your chart is read. Prayers are written ahead of time in scheduled batches, so that a prayer is waiting for you when you wake. The batches run on a fixed schedule anchored to Central European Time, with a second pair timed for the Asia-Pacific day. Depending on where you live, your prayer may have been written the previous evening in your local time. Your chart is also computed again, on the spot, whenever we need to write a prayer outside a batch: when you first set up your account, each time you tap “Pray more” for a further movement, when a failed prayer is retried, and after you change your time zone. Each of those is a fresh read of your birth data. It never leaves our environment.

Days when the chart shapes less, or nothing at all. If what you write in your intention suggests you are having a hard time, the app deliberately switches to a gentler mode. On those days we do not read your chart against the day at all: the day's influences are left out entirely, and the prayer is written from your birth chart's standing themes only. We do this because a prayer that appears to comment on a difficult day you have just disclosed is the wrong thing to receive. If the safety check flags a possible sign of crisis, no prayer is generated at all. Your chart may have been computed moments earlier in the same process; it then shapes nothing. You are shown support resources instead. On both kinds of day your birth data is still processed; what changes is how much of it influences your prayer.

The safety check. When you write an intention, before it shapes a prayer it passes an automated check for signs of crisis or self-harm. It is best-effort software, not a person and not reliable detection. No human reads your intention. If it flags a possible sign of crisis, the app shows real support resources instead of a generated prayer. This is the one place an automated check changes what you receive, which is why we describe it plainly here and under Crisis, and an important boundary.

Where your data lives

Your data lives inside our Amazon Web Services environment in the European Union, in Frankfurt, Germany. Concretely:

  • Encrypted at rest. Your data is stored encrypted with an encryption key we control.
  • Sensitive data never leaves the EU. Both storage and the AI generation that writes your prayers happen inside EU infrastructure. Your prayers are written by Claude, an AI model running on Amazon Bedrock using EU-only inference, so your birth details and tradition stay in EU geography at rest and while your prayer is being written.
  • Your prayer prompt goes to one place only. The prompt that contains your personal details is sent to Amazon Bedrock, inside our EU boundary, to generate your prayer and to run the safety check. It is never sent to any logging service, analytics tool, or other third party. The AI is not trained on your inputs.
  • We do not put your sensitive data in logs or error messages. This is a hard engineering rule across our systems, not a best-effort aim.

If you live outside the EU, including in the United States, the United Kingdom, or Australia: we run a single EU home region today and serve everyone from it, so your data is stored and processed in the EU under the same protections.

Not yet in effect. The paragraph below describes subscription billing through our subscription processor. It becomes part of this policy only when Orison Premium goes on sale and that processor is switched on in the app, and not before.

One thing sits outside that boundary, and we would rather say it plainly: subscription billing. If you subscribe to Orison Premium, the purchase is made through the Apple App Store or Google Play, and our subscription processor, RevenueCat, keeps track of it for us in the United States. What they see is an anonymous account code (a random identifier created only for this purpose) and your purchase records. Never your birth details, your tradition, your intentions, your prayers, your email, or your name. Who processes data for us lists exactly what RevenueCat receives, and Deleting, and withdrawing consent says what happens to it when you delete your account.

How long we keep it

Your profile, meaning your birth details, tradition, and account data, is kept for the life of your account, because the app needs it to write tomorrow's prayer. It is erased when you delete your account.

Your daily prayer is yours to keep, or to let pass. If you do not keep a prayer, it is deleted automatically after a grace period of seven days. The automated deletion then completes within a few days after that window ends, and never before it. A prayer you keep stays in your journal until you release it, delete it yourself, or delete your account. Deleting your account removes all of your prayers, kept and un-kept alike.

The safety-check record. When the safety check responds to an intention with support resources instead of a prayer, we store a small record that a crisis response was shown to you on that date, so the app knows what it did that day. This record holds none of your intention text, only the fact that a crisis response occurred. Because it reflects a sensitive moment, we keep it no longer than an un-kept prayer: it carries the same seven-day grace period and then deletes itself, and it is erased with everything else when you delete your account.

Backups, the one place “immediately” needs a longer answer. When you delete something, it is gone from our live systems at once. But like any service that could lose a database to a bad deploy, we keep a rolling backup of the whole database, and for a while after your deletion that backup still contains a picture of the world from before you deleted. We would rather give you the honest number and the honest safeguard than let “immediately” carry more weight than it can.

Our only backups are encrypted point-in-time recovery copies of our database, retained for a maximum of 35 days. When you delete a prayer or your account, the data is removed from our live systems immediately; because backup copies expire on that rolling schedule, deleted data becomes unrecoverable from backups no later than 35 days after deletion, automatically, with no step we can forget. If we ever restore a backup to recover from a failure, re-applying account deletions made after the backup point is a mandatory step of that procedure. It is a written step our engineers must follow, it runs before the restored data is allowed to serve anyone, and it is possible because we keep a small record of which accounts were deleted (timestamps only, nothing about you) for slightly longer than the backup window. Restoring a backup to bring a deleted account back is something we will not do, even if the person asks.

The longest each kind of data can survive a deletion request. 35 days is the steady-state maximum for your personal data. It is the outer bound, not the usual case.

  • Birth details, chart, prayers, intentions: gone from live systems immediately; unrecoverable from backups within 35 days.
  • Your sign-in identity (email address): immediate. It is held by a separate service that we do not back up and never export.
  • Operational logs, which carry an account identifier and never your birth data, prayers, or intentions: 30 days; 60 days for the record of deletions themselves, so it always outlasts the backup window.
  • Messages that failed to process and are waiting for an engineer: 14 days.
  • The marker that an account was deleted (a status and timestamps, nothing about you): about 3 days.
  • The record that a prayer was deleted (its date and the time of deletion, never its text): 35 days, matched to the backup window so a restore can always be corrected.

One exception we will not put in that list: email you send us. Email you send to our support address is kept in our support mailbox, is not linked to your Orison account, and is not deleted when you delete your account. There is no window on it. If you want a message you sent us deleted, ask us and we will delete it from the mailbox. If you email us says all of this before you write to us, which is where we think you should meet it.

Your rights

Under EU and UK data-protection law you have the following rights over your data. You can exercise any of them by writing to care@orison.day, and we will respond within the legally required time, generally one month. Anything you send to that address is email, and If you email us applies to it: you do not need to include your birth details or anything sensitive to make a request.

  • Access. Get a copy of the data we hold about you.
  • Rectification. Correct anything inaccurate. The app lets you update your profile; if something cannot be changed in the app yet, write to us.
  • Erasure. Delete your account and data. In the app this is one action, and you can also delete any single prayer on its own, at any time. One limit, stated plainly: deleting your account does not delete email you have sent to our support address. You can ask us to delete support email and we will delete it from the mailbox, but we will not pretend that is the same thing as the automatic, verified deletion your account data gets.
  • Restriction. Ask us to pause processing in certain circumstances.
  • Data portability. Receive your data in a portable format. There is no self-serve export in the app yet; write to us and we will provide one.
  • Objection. Object to certain processing.
  • Withdraw consent. At any time, and it is as easy to withdraw as it was to give. Because your sensitive data is held only on the basis of your consent, withdrawing it means we can no longer write your prayers, so withdrawing consent means deleting your account (see Deleting, and withdrawing consent). Withdrawal does not affect processing that already happened lawfully before you withdrew.
  • Complain to a regulator. You may lodge a complaint with a data-protection authority: in the EU, your national authority; in the UK, the Information Commissioner's Office; elsewhere, the privacy regulator for the place you live.

About the AI that writes your prayers. Your prayer is generated automatically from your chart, by the logic described under Why we use it. We do not believe this is the kind of automated decision with legal or similarly significant effects that GDPR Article 22 restricts: writing you a prayer is creative output, not a decision about your rights, money, or access to anything. The one automated process that does change what you receive is the safety check. If it flags a possible crisis signal, you see support resources instead of a prayer. That outcome is protective rather than adverse, and we also hold your explicit consent for it.

Deleting, and withdrawing consent

You can delete any single prayer yourself, at any time. Deleting a prayer in the app removes it, the prayer and everything written as part of it, from our live systems immediately. It is a real deletion, not a “marked as deleted” flag.

When you delete your account, we delete for real. Deletion removes your identity and erases your entire data record, meaning your profile, birth details, prayers, and everything derived from them, from our live systems immediately, in one operation. After deletion, we refuse any attempt to write your data back. The only residue is the backup window described under How long we keep it, and the support-email exception described there.

Consent and account are one and the same. Your birth details and tradition are held only because you consented, for the single purpose of writing your prayers. You can withdraw at any time, and doing so deletes your account and erases your data. There is no half-state where we keep your sensitive data without a live consent behind it.

Not yet in effect. The paragraph below applies only once Orison Premium is on sale and our subscription processor is switched on in the app.

If you subscribed, two honest limits. When you delete your account, we also delete your record at RevenueCat as part of the same deletion. But Apple's and Google's own billing records for purchases made through their stores belong to them, under their own privacy policies, so deleting your Orison account cannot erase store-side billing history. And deleting your Orison account does not cancel your subscription: subscriptions are cancelled in your Apple or Google account settings, not in Orison, so if you are subscribed the app will show you how to cancel before you confirm deletion. Otherwise the store would keep billing you for an account that no longer exists, and we will not let that happen quietly.

The app on your device

What sits on your phone, and what signing out removes. While you are signed in, the app holds a working copy of your recent prayers and your details on your device so it can show them to you. Signing out removes that copy from that phone: your prayers, your birth details, your intention, and your reminder. Your account is untouched. Your prayers, including any you have kept, stay in your account and return when you sign back in. Signing out is not deletion and is not a withdrawal of consent; Deleting, and withdrawing consent covers those.

Your intention, on this device. As described under What we collect, a display-only copy of your saved intention lives in your device's secure storage, and only there. It is never backed up, never synced, and it is wiped on sign-out, on clearing the intention, and on account deletion.

Your morning reminder. If you choose one, the reminder is a notification the app schedules on your own phone. It carries a greeting and nothing else: no prayer text, no birth details.

Sending a prayer to someone. When you choose to send a prayer, the app makes an image of it on your device and hands that image to the app you pick (Messages, Mail, and so on). From that moment it is outside Orison and in that app's hands; we never see where it went. The image is removed from your phone as soon as the hand-off is done.

To be precise about what we are and are not claiming: we are describing what the app removes from its own storage. We are not making a claim about your phone's backups, about screenshots you may have taken, or about the security of the device itself.

If you email us

Everything above is about data inside your account. Email is different, and we want you to know how before you write to us, not after.

When you send a message to care@orison.day, we receive the whole email: your email address, your name if you sign it, the subject, and whatever you write. We use it for one thing, to answer you.

The honest part. Support email is not linked to your Orison account, and it is not deleted when you delete your account. Your prayers, chart, and birth details are erased when you ask; an email you sent us is not, because it lives in our support mailbox rather than in your account record, and nothing connects the two. That mailbox is a normal email inbox. It is not inside the protected European boundary the rest of this policy describes, and messages in it are kept indefinitely unless we delete them by hand.

What we suggest. Please do not put your birth details, your intentions, or anything you would not want kept in an ordinary inbox into an email to us. You do not need to: we can help with almost anything without them, and we will never ask for them by email. If you want an email you have already sent us deleted, ask, and we will delete it from the mailbox.

Crisis, and an important boundary

Orison is prayer. It is not medical care, therapy, counselling, or crisis support, and it is not a substitute for any of them. Please do not rely on Orison in an emergency.

We take one deliberate exception to “just write a prayer”. If something you write signals that you may be in crisis or considering self-harm, Orison does not answer with a generated prayer. Instead it shows warmth and real support resources appropriate to your country, for example a national helpline. This safety behaviour is built into every path that generates a prayer. To do this, the app briefly checks the text of your intention for signs of crisis; that check happens inside our EU boundary, like everything else. It is automated and best-effort, not a person and not reliable detection.

When the check responds with support resources, we keep a small record that this happened on that date. It holds none of your intention text, deletes itself after the same seven-day grace period as an un-kept prayer, and is erased when you delete your account.

This safety check is part of what you consent to when you first write an intention. That consent covers two inseparable purposes, shaping your prayer and this safety screening, and the safety part cannot be turned off on its own, because we will never process what you wrote and leave a signal of crisis unseen. The only way to avoid the screening is not to write an intention, which is always your choice, or to clear one you have written. The screening never runs on text you did not choose to give us.

If you are in immediate danger or thinking about harming yourself, please contact your local emergency services or a crisis helpline right now.

Age

Orison is not directed to children. You must be at least 16 years old to use it. The app checks your birth date before any of your details are stored, and refuses to go further if you are under 16.

Who processes data for us

We use a small number of service providers who process data on our behalf and under contract. We do not sell your data to anyone.

  • Amazon Web Services (AWS), EU (Frankfurt). Hosts our database and servers, and runs the Amazon Bedrock AI (the Claude model) that writes your prayers.
  • Amazon Cognito, an AWS service, EU (Frankfurt). Manages your account and sign-in. Holds your email; never holds your birth data or tradition.
  • Apple, Sign in with Apple, on Apple's infrastructure. Verifies your identity when you choose Apple sign-in, and sends us your email.
  • Google, Sign in with Google, on Google's infrastructure. Verifies your identity when you choose Google sign-in, and sends us your email.
  • Google, our support mailbox, on Google's infrastructure, outside our EU boundary. Mail you send to our support address is received inside our EU boundary, then forwarded to a Google-hosted inbox we read, which is where the lasting copy of your message sits. This provider sees the full content of any email you send us. See If you email us.

Not yet in effect. The entry below is for our subscription processor. It joins the list above only when Orison Premium goes on sale and the processor is switched on in the app, and not before.

RevenueCat, Inc., United States, under a data-processing agreement with EU standard contractual clauses. Subscription and entitlement management: keeps track of your Orison Premium purchase so the app knows what you have paid for, on every device you sign in on. Receives an anonymous account code (a random identifier created only for this purpose), purchase records from the app stores, and device and app details, which, like any internet service, includes your IP address in transit. Never receives your birth details, your tradition, your intentions, your prayers, your email, or your name. Deleted when you delete your account.

This website

This policy is mostly about the app. The website you are reading is simpler: there is nothing to type, no account, and no sign-in. Here is what the site itself does and does not record about your visit.

This website counts, and that is all. When a page is sent to you, our own servers write one line: the time, the page, which of our links brought you here if one did (the prayer card, the app, or a store listing; a label shared by everyone who follows that link, never a name or a number for you), the site you came from, your country, whether you are on a phone or a computer, and whether the page loaded. Your internet address is needed to send you the page and is dropped before that line is written; we keep none of it. There are no cookies, nothing stored on your device, no third-party scripts, and nothing that could tell us who you are or connect a visit to an Orison account. The lines are kept for ninety days, then deleted. The two store links pass straight through to the App Store and Google Play; the store then knows you clicked, under its own privacy policy, and tells us only totals.

If you write to us from this site, If you email us applies.

Changes to this policy

If we change how we handle your data, we will publish a new version of this policy here, with its version and date at the top, and for material changes we will tell you in the app. If a change means we want to use your data in a genuinely new way, we will ask for fresh consent. We will not quietly widen what “and nothing more” means.

Contact

Orison Lab Pty Ltd, ACN 700 874 513, ABN 84 700 874 513, registered in New South Wales, Australia.

Write to care@orison.day. There is a person on the other end. For everyday questions about the app, the Help page may be quicker.