Legal
Privacy Policy
Last updated: July 31, 2026
1. Who We Are and Scope
Fortuna Matata operates the website and services described here and is the controller of personal data processed for those services. The operator details are listed in our Imprint. This notice covers our public website, accounts, readings, chat, memory and personalization features, community features, shared content, waitlist and newsletters, payments, notifications, and support. Privacy questions and requests can be sent to privacy@fortunamatata.com.
2. How We Obtain Data
We obtain personal data from the following sources:
- From you: when you create an account, complete a profile, submit content, buy a product, join a list, change settings, contact us, or otherwise use the Service.
- Automatically: from your browser, device, cookies, local storage, security logs, and interactions with the Service.
- Generated or inferred: when the Service creates readings, summaries, moderation results, personalization memories, usage records, or derived astrology and numerology fields.
- From service providers and other users: such as payment and delivery status, referral information, gift or compatibility details supplied by another user, and reports about community content.
3. Data We Collect
Depending on the features you use, we collect:
- Account and authentication data: name, email address, protected authentication credentials, verification and recovery records, account status, session identifiers, IP address, and user agent.
- Profile and preference data: display name, handle, biography, birth date, birth time and location, timezone, current location, gender, zodiac and numerology fields, occupation, relationship status, partner details, interests, focus areas, language, reading preferences, notification choices, and phone number if provided.
- Content and inferred data: questions, prompts, reading inputs and results, chat messages and history, feedback, comments, contact messages, memory items and summaries, and inferred themes, preferences, events, emotions, relationships, goals, or patterns.
- Community and sharing data: public-profile choices, posts, comments, reactions, reports, shared-reading visibility and engagement, and the identity connected internally to content posted as anonymous.
- Purchase and referral data: subscription, transaction, credit-ledger, gift, challenge, referral, regional-offer, and payout records. The payment provider collects full card or payment-account details; we generally receive identifiers and transaction status rather than the full card number.
- Communications data: newsletter and waitlist status, support correspondence, sent-message metadata, and delivery, bounce, complaint, and suppression events. We also record when our emails are opened and when links inside them are clicked.
- Technical and usage data: browser and device details, approximate country derived from network headers, IP address, pages and features used, timestamps, security and audit logs, model-request metadata, cookie choices, and analytics events collected after consent where required.
Free-text content may reveal sensitive information. Please do not submit health, financial-account, government-identifier, password, precise-location, or other highly sensitive data, or another person's data unless it is necessary and you are authorized to provide it.
4. AI Processing and Automated Features
- AI providers: We send prompts to OpenRouter and Together AI, which may route them to an underlying inference provider. Prompt data can include your submitted content, relevant chat or reading history, birth and profile details, preferences, and enabled memory context. A provider can therefore receive personal data contained in that context.
- Privacy controls: OpenRouter requests ask the router to exclude providers marked as collecting data. Provider-side processing, temporary caching, abuse monitoring, and technical metadata are still governed by the applicable provider terms and account settings. We do not use your content to train our own general-purpose AI model.
- Memory and personalization: When memory is enabled, AI may extract and store useful facts or inferences from your interactions and reuse them in later prompts. You can disable memory and delete stored memory items in settings.
- Moderation: Community posts and comments are sent to an AI model for automated safety screening. Flagged content may be held for staff review. We store the content, moderation result, and related status needed to operate and enforce the community rules.
- Regional offers: We use an approximate country supplied by our hosting or proxy infrastructure to place a visitor in a regional pricing group. This can automatically change the displayed price and included credits before checkout.
- Effects: AI readings and chat are entertainment, not professional advice. Automated moderation can affect whether community content is published, with staff review for flagged content. Regional pricing changes the commercial offer shown before checkout; it does not use profile or reading content.
5. Purposes and Legal Bases
Where the GDPR or similar law applies, we rely on the following legal bases:
- Contract: to create and secure your account, provide requested readings, chat, sharing and user-directed disclosures, community, support, billing, credits, gifts, and other Service features.
- Legitimate interests: to secure and improve the Service, prevent fraud and abuse, diagnose failures, keep proportionate audit records, moderate content, understand aggregate use, defend legal claims, and communicate about requested or closely related Service features. We balance these interests against your rights, and you may object.
- Consent: for optional analytics, newsletters or marketing where required, public-profile choices, push or SMS notifications where required, and other optional processing presented with a consent choice. Consent can be withdrawn without affecting earlier lawful processing.
- Legal obligation: for tax, accounting, consumer-protection, lawful-request, sanctions, and other compliance duties.
6. Recipients and Disclosures
We do not sell personal data or use it for cross-site targeted advertising. We disclose data only as needed to:
- AI inference providers: OpenRouter, Together AI, and an underlying model host selected through them, for generation, summarization, memory extraction, and moderation.
- Infrastructure and operations providers: hosting, database, storage, content-delivery, security, logging, and error-monitoring operators that process data for us.
- Payment and payout providers: the provider presented at checkout or payout setup, which may be Stripe, Paddle, Polar, or Lemon Squeezy depending on configuration and location.
- Communications providers: the configured email provider, which may use Cloudflare Email, Resend, Amazon SES, or SMTP infrastructure; Twilio if SMS is enabled; and the browser push provider if you enable push notifications.
- Analytics and diagnostics: our self-hosted Plausible service after consent and Sentry if error monitoring is enabled. These services receive only the data needed for the relevant purpose.
- People you choose and the public: recipients of share links, gifts, invitations, public profiles, public readings, and community content according to your choices.
- Authorities, advisers, and transactions: when required by law, needed to protect rights or safety, supported by a valid legal claim, or necessary for a merger, financing, acquisition, or asset transfer subject to appropriate safeguards.
7. International Transfers
Some providers operate in the United States or other countries outside your own. The applicable destination and transfer mechanism depend on the provider used. Where data-protection law restricts a transfer, an adequacy decision or appropriate contractual safeguard, such as approved Standard Contractual Clauses, must cover it. Contact privacy@fortunamatata.com to request information about the safeguard applicable to your data.
8. Cookies, Local Storage, and Analytics
Necessary and preference technologies may operate without analytics consent. Optional analytics operates only after consent:
- fm_consent: stores accepted or declined analytics choice for 1 year. Necessary to remember your choice.
- Authentication session: keeps an account signed in for up to 30 days unless you sign out or the session is revoked. Necessary for account features.
- fm-locale and local storage: remember the language you selected for up to 1 year. Functional preference storage.
- fm_anon_session: an opaque random identifier used on shared readings for consented unique-view analytics. Set only after analytics consent and kept for up to 30 days.
- ref_welcome_dismissed: remembers that an account holder dismissed a referral welcome message for up to 1 year. Functional preference storage.
- Interaction flags in local storage: remember one-time share or referral interface actions until browser storage is cleared. Functional preference storage.
- Self-hosted Plausible: loads only after acceptance. It is configured without analytics cookies or cross-site advertising tracking, but its server necessarily receives technical request data such as an IP address transiently when serving the request.
Use the persistent Cookie settings button to accept or withdraw optional analytics consent at any time. Withdrawal removes our optional analytics identifier and stops future consent-based analytics. We do not track you across third-party websites for targeted advertising, so we do not take a separate action in response to legacy browser Do Not Track signals.
9. Shared, Public, and Third-Party Data
An unlisted reading is available to anyone who has its secret link but is marked not to be indexed. A reading you deliberately make public may appear in discovery pages and search engines. A public-profile choice may connect your handle to public readings. Community posts and comments are visible according to their status, while an anonymous label does not remove the internal account link. Recipients and search engines may copy public or shared content, so do not include information you do not want those audiences to see. If you provide partner, gift-recipient, invitee, or other third-party data, you must be authorized to do so and should direct that person to this notice.
10. Retention
We use the purpose, account status, legal duties, security needs, and relevant limitation periods to decide how long data is needed:
- Accounts and content: kept while the account or requested feature is active, then deleted or anonymized after a valid request unless a narrower record must be kept for law, fraud prevention, disputes, or legal claims.
- Authentication sessions: expire after 30 days and are deleted by the cleanup process after an additional grace period of up to 7 days.
- User-deleted memory: removed from the active database when you delete an item or reset memory. A protected backup may retain a copy until its normal rotation completes.
- Newsletter, waitlist, and communications: active contact data is kept while the subscription, waitlist request, support matter, or delivery need continues. A limited suppression or consent record may remain after unsubscribe to honor the choice and establish compliance.
- Payment and compliance records: kept for the period required by tax, accounting, consumer, anti-fraud, chargeback, and legal-claim rules.
- Operational records: email-delivery, security, audit, analytics, moderation, webhook, and model-request records are kept only while needed for delivery, integrity, abuse prevention, troubleshooting, reporting, disputes, or legal duties. The exact period varies with the record and incident.
- Cookies and browser storage: use the periods listed above or remain until you clear them. Public copies and third-party caches may persist outside our direct control.
11. Your Privacy Rights
Depending on the law that applies, you may request:
- Access: confirmation and a copy of personal data we process about you.
- Correction: correction or completion of inaccurate data.
- Deletion: erasure where no legal exception requires continued processing.
- Restriction: temporary limits on processing in qualifying circumstances.
- Portability: data you provided in a structured, commonly used, machine-readable format where applicable.
- Objection: objection to processing based on legitimate interests and an unconditional objection to direct marketing.
- Consent withdrawal: withdrawal for future consent-based processing at any time.
Send a request to privacy@fortunamatata.com. We may verify your identity and ask for details needed to locate the data. GDPR requests are generally answered within one month, subject to lawful extensions and exceptions. You may complain to the Information Commissioner of the Republic of Slovenia or the supervisory authority where you live or work.
12. Required and Optional Data
Account email, authentication information, age confirmation, acceptance of the Terms, and data required for a requested transaction or feature are contractual or necessary fields. Without them, we may be unable to create an account, secure access, process a purchase, or provide that feature. Profile details, memory, public-profile participation, newsletters, optional analytics, and most notification channels are optional unless a screen clearly says otherwise.
13. Security
We use safeguards appropriate to the service and risk, including TLS for data in transit, authentication controls, role-based access, rate limits, and audit records for sensitive administrative actions. Access by authorized staff is limited to operating, supporting, securing, and enforcing the Service. No internet service or storage system is completely secure, so we cannot guarantee absolute security.
14. Children
The Service is intended only for people aged 16 or older. We do not knowingly provide it to or collect personal data from a child under 16. If you believe a child has provided data, contact privacy@fortunamatata.com so we can investigate, disable access, and delete data where required.
15. Changes to This Notice
We may revise this notice when the Service, providers, or law changes. We will post the revised notice, update the "Last updated" date, and provide additional notice when a change materially affects your rights or choices. We review the notice at least annually.
16. Contact
Questions, complaints, and privacy-rights requests can be sent to privacy@fortunamatata.com. Please do not send passwords, payment-card details, or other unnecessary sensitive information by email.