Sthitiin · up · out

Privacy

Your practice is yours.

Last updated: 25 June 2026.

This policy covers both products of the 3iMOOX ecosystem: the Sthiti web app and the My Oracle mobile app. Both are projects of 3imoox foundation, which is the data controller for the information described here. We are a Dutch public-benefit foundation: Stichting Foundation 3iMOOX.org, registered with the Netherlands Chamber of Commerce (KvK) under no. 73363839, at Rijksweg Zuid 117, 6161 BJ Geleen, the Netherlands.

Because we are based in the Netherlands, the EU General Data Protection Regulation (GDPR) applies to us. If you are in the UK, the UK GDPR also applies. The two products handle data differently, so the details are split into a section for each — jump to Sthiti (web) or My Oracle (app) — with shared sections on your rights below.

The short version

  • Sthiti keeps your saved practice only in your browser unless you sign in; if you sign in, we store your email and the practice you save so you can return to it across devices.
  • My Oracle keeps what you create on your own device. Signing in is optional; if you do, Google gives us your name and email to identify your account.
  • What you write is used only to give you the practice and to save it for you. We never sell it or use it for advertising.
  • You can delete your data at any time — from your account page (Sthiti) or from the app’s Settings screen (My Oracle).

Sthiti · web app

What Sthiti collects

If you use Sthiti without an account: your practice (the day’s reflection, what you write, the line you carry) is saved only in your own browser, and we don’t keep it. If you ask the Oracle for a personalised response, the words you send it are still processed by Anthropic to generate that response (see below), and loading the site sends basic technical information to our hosting provider — but your saved practice is not stored by us unless you sign in.

If you sign in: we store, against your account:

  • Your email address — used only to sign you in (a one-time link, not a password) and to contact you about your account.
  • Your daily practice — the tags you pick, the note you write in your own words, the suggestion shown to you, the Oracle’s response, the line you carry, and your evening reflection. This can be personal, and we treat it that way.
  • Your settings and activity — your chosen guidance voice, your pause times, the pauses you log, and a daily count of Oracle requests (to prevent misuse).
  • If you subscribe — payment is handled by Stripe. We store only a reference to your Stripe customer and subscription and its status. We never see or store your card details.
  • If you bring your own Anthropic API key — it is stored encrypted (AES-256-GCM). We cannot read it back, and only the last four characters are shown to you.

What you write, and where it goes

To personalise the Oracle, the note you write and the day’s reflection are sent to Anthropic, whose Claude model generates the response. Under their API terms they do not use it to train their models, though they may retain it briefly for their own trust-and-safety purposes. We use it only to give you the practice and to save it to your account.

If what you write appears to signal a crisis, we show you support resources (see our urgent help page). So the feature keeps working, we record only that this happened — a timestamp and which wording triggered it — never your words and never anything identifying you. We check for these signals, and keep this minimal safety record, to protect people in a possible crisis — in the language of the law, the vital interests of you or others.

Who else processes Sthiti data

  • Supabase — hosts our database and handles sign-in and the sign-in email.
  • Anthropic— generates the Oracle’s response from what you write.
  • Stripe — processes payments if you subscribe.
  • Vercel — hosts the app and processes basic technical logs (such as IP address) needed to serve and secure it.

My Oracle · mobile app

What My Oracle collects

Most of what you create stays on your device. Your mood check-ins, reflections and journal entries, intentions, qualities, personal knowledge notes, pilots and progress are stored locally in the app’s storage on your phone. We do not upload this content to our servers, and we cannot read it. If you uninstall the app or clear its data, this information is permanently removed.

Account information we receive. Signing in is optional and uses Google Sign-In. If you choose to sign in, Google provides us with your name, email address and your Google account identifier. We use this only to identify your account, personalise the app (for example, to greet you), and — if you choose to link it — to connect your experience across the 3iMOOX ecosystem. We do not request access to your Gmail, Calendar, contacts or files.

Notifications and biometrics

With your permission, My Oracle schedules reminders as local notifications on your device; their content is not sent to or stored on our servers, and you can disable them at any time. If you enable the biometric lock, authentication is handled entirely by your device’s operating system — the app only receives a success or failure result, and we never collect, see or store your fingerprint or face data.

No advertising, and third-party services

My Oracle contains no advertising, and we do not use third-party advertising or analytics SDKs to track you. The app uses Google Sign-In for optional authentication. It may show a public, anonymous market-sentiment index fetched from a third-party source; no personal data is sent in that request. The app also links out to Brahma Kumaris online learning and to crisis-support resources, which open in your browser and are governed by their own privacy policies.

Why we’re allowed to use your data

Data protection law asks us to have a clear legal basis for each thing we do with your data. Across both products we rely on:

  • Our agreement with you (a contract) — to create your account, sign you in, and save the practice you choose to keep.
  • Our legitimate interests in a service that works and stays secure — to hold your settings, count daily Oracle requests, prevent misuse, and keep the basic technical logs needed to run and protect the service.
  • A legal obligation — to keep a minimal payment record if you subscribe to Sthiti.
  • Your explicit consent — to process the reflections you write in Sthiti. Because a reflective practice rooted in a wisdom tradition can reveal sensitive things, such as your wellbeing or your beliefs, the law treats it as a special category of data and asks us to rely on your explicit consent. You give that consent when you create your account and agree to this policy. You can withdraw it at any time — you do not have to delete your account to do so — by contacting us, and you can separately delete your data whenever you wish. What you create in My Oracle stays on your device and is not processed by us, so this consent concerns Sthiti and any account record we hold.

We use what you do in our products to personalise your experience — for example, which practice, suggestion or nudge to show you next. We do not make solely automated decisions that produce legal or similarly significant effects about you.

International transfers

Some providers (including Google for My Oracle sign-in, and Supabase, Anthropic, Stripe and Vercel for Sthiti) process data outside the Netherlands, including in the United States. For users in the EU or EEA, those transfers rely on the European Commission’s Standard Contractual Clauses or, where the provider is certified, the EU–US Data Privacy Framework. For users in the UK, they rely on the UK’s International Data Transfer Agreement or Addendum. You can ask us for a copy of the safeguards that apply.

How long we keep it

Sthiti:we keep your practice for as long as your account is open. When you delete your account, your profile, settings, daily entries, pauses, and usage records are deleted from our live systems straight away and purged from our hosting provider’s backups within 30 days; we keep one anonymous account identifier for up to 30 days to make a deletion stick across a backup restore, then remove that too. We keep a minimal Stripe payment record where Dutch law requires it for the foundation’s accounting — for 7 years — and it holds no practice data.

My Oracle:because your content is stored on your device, it lasts until you delete it in the app’s Settings, clear the app’s data, or uninstall the app. If you signed in, you can ask us to delete any account record we hold via the contact below.

Your rights

You can access, correct, export, or delete your data. Deletion is self-service; access, correction and a copy of your data are handled by us on request — email us and we will send it. In Sthiti, deletion is available directly from your account page and takes effect immediately; in My Oracle, you can delete on-device data from the app’s Settings screen or by uninstalling. If you are in the UK, EU, or EEA, you also have the statutory rights of access, rectification, erasure, portability, restriction, and objection under the GDPR, the right to withdraw any consent you have given, and the right to complain to a data protection authority — our lead authority is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), and UK users may also complain to the Information Commissioner’s Office (ICO). To exercise any of these, or to ask a question, contact contact@3imoox.org.

Cookies

The Sthiti website uses a small number of strictly necessary first-party cookies to keep you signed in and to keep the site secure. We don’t use advertising or tracking cookies, and we don’t run third-party analytics. The My Oracle mobile app does not use cookies.

How we protect it

In Sthiti, every row of your data is protected by database-level access rules so that only you (when signed in) can read or write it; API keys are held on the server and never sent to your browser, and any key you bring is encrypted at rest. In My Oracle, your content stays on your own device, so securing it with a screen lock and the app’s biometric lock is the most effective protection. No system is perfectly secure, but we collect the minimum we need and guard it accordingly.

Children

Neither product is intended for anyone under 16. We do not knowingly collect data from children under 16. If you believe a child has provided us data, contact us and we will delete it.

Changes & contact

If we change this policy, we will update the date above and, for material changes, tell you. Questions or requests: contact@3imoox.org. See also our Terms of Use.