OpenEphemeris · Spirit River Inc

Privacy Policy

Effective Date: March 13, 2026 · Last Updated: July 30, 2026

1. Overview and Scope

Spirit River Inc (“Spirit River,” “we,” “us,” or “our”), a Delaware corporation, operates the OpenEphemeris API (api.openephemeris.com), website (openephemeris.com), and Model Context Protocol (“MCP”) server (mcp.openephemeris.com, and the @openephemeris/mcp-server package distributed via npm) (collectively, the “Service”). This Privacy Policy describes how Spirit River collects, uses, stores, shares, and protects information in connection with your use of the Service.

This Policy applies to:

  • Registered API customers and their authorized account holders
  • Visitors to the openephemeris.com website
  • Recipients of transactional emails sent by Spirit River
  • Users who connect to the OpenEphemeris MCP server from an AI assistant or other MCP client, whether through the hosted endpoint or by running the npm-distributed package locally (see Section 2.5)

This Policy does NOT govern personal data that you, as a Developer, independently collect from your own end users. You are solely responsible for your own privacy compliance with respect to your end users' data.

2. Information We Collect

2.1 Account and Billing Data (Stored)

Data TypeStorageRetentionPurpose
Email addressSupabaseUntil account deletionAuthentication, billing
Hashed API keysSupabaseUntil revocation/deletionAPI authentication
Stripe customer IDSupabaseUntil account deletionPayment processing
Usage countersSupabaseMonthly rolling; 12-month summaryBilling, enforcement
API request logsFly.io stdout~7 days (ephemeral)Rate limiting, security

2.2 Computation Inputs — NOT Stored

Core Privacy Commitment: We Do Not Store Your Calculation Inputs

Birth dates and times, geographic coordinates (latitude/longitude), subject names, and any other parameters submitted to the API for ephemeris computation are processed entirely in working memory. These inputs are NEVER written to any database, cache, persistent log, file system, or third-party service. Spirit River retains no record of your computation inputs. This is a fundamental and permanent architectural commitment of the Service.

The API receives a request, performs mathematical computations, returns the structured response, and the input parameters are immediately and irrecoverably discarded from memory.

Request URLs in ephemeral infrastructure logs. For completeness, and in keeping with the retention table in Section 2.1: the great majority of computation inputs — including all birth data submitted to the natal, synastry, progression, Human Design, and other chart endpoints — are transmitted in the HTTP request body, and request bodies are never logged. A small number of endpoints accept parameters in the URL query string instead, specifically the eclipse-visibility lookup, the electional search endpoints, and the location-autocomplete lookup; these carry geographic coordinates or a place name. Because standard infrastructure access logging records the full request URL, those particular values appear in Fly.io's ephemeral platform log stream (approximately seven days' retention, as stated in Section 2.1) before automatic expiry. They are not written to any database, cache, persistent store, or third-party service, and Spirit River does not read, index, export, or analyze them.

One narrow exception exists: if you, as a visitor to a third-party website using an OpenEphemeris embedded widget, affirmatively consent to share your details with that website's owner through the widget's contact form, the birth details you entered are stored as part of that lead submission and handled as described in Section 13.

2.3 Website Data

The website uses functional session cookies provided by Supabase for authentication purposes only. These cookies are strictly necessary for the operation of the Service and do not track your browsing activity across other websites. Spirit River does not deploy analytics cookies, tracking pixels, or behavioral advertising technologies.

2.4 Communications

Support communications are retained for the purpose of responding to inquiries. Transactional emails are delivered via Resend (resend.com).

2.5 The MCP Server and AI Assistant Connections

The OpenEphemeris MCP server lets an AI assistant (such as Claude) call the Service's computation tools on your behalf. It runs in two modes, and the privacy characteristics differ:

  • Hosted (remote). You connect an MCP client to mcp.openephemeris.com. Authentication uses OAuth 2.1 with PKCE, or an API key. Requests are proxied to the OpenEphemeris API and are governed by Sections 2.1 and 2.2 exactly as direct API calls are.
  • Local (npm package). You install @openephemeris/mcp-server and it runs as a process on your own machine, calling the OpenEphemeris API directly. Spirit River operates no server in this path beyond the API itself.

Your AI assistant is a separate controller. To ask for a chart, you supply birth details to your AI assistant, and the assistant passes them to the Service as tool arguments. That conversation — including any birth date, time, place, or name you type — is processed by the provider of that assistant under their privacy policy, not this one. Spirit River has no access to, and no control over, your conversation history with an AI assistant, how that provider retains it, or whether that provider uses it for model training. Please consult your AI provider's privacy policy. Spirit River's commitments in Section 2.2 govern only what reaches the OpenEphemeris Service.

Product telemetry from the MCP server. The MCP server emits basic usage telemetry to PostHog so that Spirit River can measure adoption and reliability. This telemetry is limited to: the name of the tool invoked, call duration, success or error status, the reported name and version of the connecting MCP client, and the server version. It never includes birth data, coordinates, subject names, tool arguments, or tool results. Events are attributed to a pseudonymous identifier derived by taking a truncated, non-reversible SHA-256 hash of your API credential; the credential itself is never transmitted, and the identifier cannot be used to authenticate.

Because the local (npm) mode runs on your own machine, these events are sent from your machine rather than from Spirit River's infrastructure. This processing is carried out on the basis of legitimate interest (Art. 6(1)(f) GDPR) in understanding and improving Service reliability. You may switch it off entirely, in either mode, by setting either OPENEPHEMERIS_TELEMETRY=0 or DO_NOT_TRACK=1 (the de-facto cross-tool standard, honoured here) before starting the server. When either signal is present, no telemetry event is transmitted at all.

3. Legal Bases for Processing (GDPR)

For individuals located in the EEA, United Kingdom, or Switzerland:

ActivityLegal Basis
Account registration and authenticationArt. 6(1)(b) — Performance of Contract
Billing and payment via StripeArt. 6(1)(b) — Performance of Contract
API usage metering and rate limitingArt. 6(1)(b) — Performance of Contract
Security monitoring, fraud preventionArt. 6(1)(f) — Legitimate Interest
Website server logs (Vercel)Art. 6(1)(f) — Legitimate Interest
MCP server usage telemetry (tool name, duration, status) — opt-out per Section 2.5Art. 6(1)(f) — Legitimate Interest
Compliance with legal obligationsArt. 6(1)(c) — Legal Obligation

4. How We Share Your Data

Spirit River does not sell, rent, or trade your personal data. We share information only with trusted service providers:

ProviderData SharedRole
StripeEmail, payment method, billing addressPayment processing
SupabaseEmail, hashed credentials, session tokensAuthentication & database
Fly.ioHTTP request metadata (IP, timestamp)API compute infrastructure
VercelHTTP request metadata for websiteWebsite hosting & CDN
ResendEmail address, transactional email contentEmail delivery
PostHogPage views; MCP tool-usage telemetry (tool name, duration, status, client name) keyed to a pseudonymous hashed identifier — never computation inputsProduct analytics

A current list of subprocessors is maintained at openephemeris.com/subprocessors and will be updated at least thirty (30) days before any new subprocessor is engaged.

5. International Data Transfers

Spirit River's infrastructure is located primarily in the United States. For transfers from the EEA, UK, or Switzerland, Spirit River relies on Standard Contractual Clauses (SCCs) adopted by the European Commission (Decision (EU) 2021/914). You may request a copy by contacting privacy@openephemeris.com.

6. Data Retention

DataRetentionDeletion
Account emailUntil deletion requestHard delete from Supabase
API keysUntil revocation/deletionHard delete from database
Usage countersMonthly reset; 12-month summaryAutomated reset & purge
Infrastructure logs~7 days (Fly.io)Automatic platform expiration
Support communications3 years from last interactionManual deletion on request
Computation inputsNOT RETAINEDN/A (never stored)

Upon receiving an account deletion request, Spirit River will delete your personal data from active systems within thirty (30) days. Residual copies in encrypted backups will be overwritten within ninety (90) days.

7. Your Rights

7.1 Rights for All Users

7.2 Rights Under GDPR (EEA, UK, Switzerland)

RightGDPR ArticleHow to Exercise
AccessArt. 15Email privacy@openephemeris.com
RectificationArt. 16Dashboard or email
ErasureArt. 17Email privacy@openephemeris.com
Data PortabilityArt. 20JSON format via email
ObjectArt. 21Email privacy@openephemeris.com

Spirit River will respond to GDPR requests within one (1) calendar month of receipt.

7.3 Rights Under CCPA/CPRA (California Residents)

Spirit River does not “sell” or “share” personal information as defined under CCPA/CPRA. California residents may submit verifiable requests by emailing privacy@openephemeris.com with the subject line “CCPA Rights Request.” Spirit River will respond within forty-five (45) calendar days.

8. Children's Privacy

The Service is not directed to individuals under the age of eighteen (18). Spirit River does not knowingly collect personal information from children under thirteen (13). If you believe a child under 13 has provided data, contact privacy@openephemeris.com.

9. Security

  • API keys are stored exclusively as irreversible cryptographic hashes; plaintext keys are never stored or logged
  • All data transmission is encrypted using TLS 1.2 or higher
  • Data at rest in Supabase is encrypted using AES-256
  • Access to production systems is restricted via role-based access controls
  • Spirit River conducts periodic security reviews

10. Data Breach Notification

In the event of a personal data breach, Spirit River will:

  • Notify relevant supervisory authorities within seventy-two (72) hours (GDPR Art. 33)
  • Notify affected individuals where the breach poses high risk (GDPR Art. 34)
  • Comply with applicable U.S. state breach notification laws (Virginia, Delaware, and others as applicable)

11. Automated Decision-Making

Spirit River does not use personal data for automated decision-making or profiling that produces legal effects. API usage metering and rate limiting are automated functions necessary to enforce subscription terms and do not constitute profiling.

12. Changes to This Policy

For material changes that expand the scope of data collection, alter the purposes of processing, or reduce your rights, Spirit River will provide at least thirty (30) days' advance notice by email and through the customer dashboard.

13. Embedded Chart Widgets on Third-Party Websites

OpenEphemeris offers an embeddable chart widget that subscribers ("Widget Owners") can place on their own websites. If you encounter one of these widgets as a visitor to a Widget Owner's site, this section describes how your data is handled.

Chart calculation is transient. Birth details you enter into a widget (date, time, and place of birth) are transmitted to our API solely to compute and render your chart. Consistent with our core commitment in Section 2, these calculation inputs are processed in memory and are not stored by Spirit River unless you submit the widget's optional contact form. The widget itself sets no cookies and uses no browser storage.

Optional lead capture — the Widget Owner is the controller. A Widget Owner may enable a contact step that asks for your email address (and optionally your name) so they can follow up with you. This step always requires your affirmative consent via a checkbox that names the Widget Owner. If you consent and submit, Spirit River stores your email, name (if provided), and the birth details you entered, and delivers them to the Widget Owner by email, webhook, and their dashboard. For this data, the Widget Owner is the data controller and Spirit River acts as their processor under a Data Processing Addendum. The Widget Owner's own privacy policy governs their use of your information.

Retention. Lead records are retained on our systems for 90 days by default and then automatically deleted; the Widget Owner's copy (their inbox, CRM, or webhook destination) is theirs to manage. To exercise privacy rights over a lead submission, contact the Widget Owner directly; you may also contact privacy@openephemeris.com to have the record removed from Spirit River's systems.

Widget Owners are independently responsible for their own privacy compliance toward their site visitors, including providing any notices required in their jurisdiction. A standard Data Processing Addendum covering widget lead data is available to Widget Owners on request at legal@openephemeris.com.


14. Contact Information and Data Controller

Spirit River Inc is the data controller for personal data processed in connection with the Service.

CompanySpirit River Inc (Delaware corporation)
General Supportsupport@openephemeris.com
Privacy & Data Rightsprivacy@openephemeris.com
Legal Noticeslegal@openephemeris.com

EEA individuals may lodge a complaint with their local supervisory authority (edpb.europa.eu). UK individuals may contact the ICO (ico.org.uk). Swiss individuals may contact the FDPIC (edoeb.admin.ch).

— End of Privacy Policy —