What we collect
First Look requests can include your name, email, and birth date.
Member registration can include your email, password authentication record, invitation code redemption, and buyer code.
Member intake can include your name, email, birth date, birth time, birth place, timing calculation sex, consent records, and an optional question about what you want to understand.
Member Room records can include intake status, estimate window, Type teaser status, report delivery status, report content, recognition score, and feedback you choose to send.
Site analytics. We use Vercel Web Analytics to count visits to this site. It sets no cookies, does not follow you across other sites, and records only the page viewed, the referring site, and coarse device, browser and country data.
How we use it
We use member registration and intake data only to prepare, QA, deliver, support, and improve your private UrNorth reading.
Birth data is used to calculate chart inputs and prepare your interpretive Blueprint. It is not used to make medical, financial, legal, clinical, or promised future claims.
Feedback is used for founding-period refinement only. Do not include health, legal, financial, religious, or third-party sensitive details unless UrNorth explicitly asks for a separate consent flow.
Consent and access
Founding Access keeps separate ticks for exact birth-data processing consent, AI-assistance consent, and the Founding Reviewer terms.
You must confirm you are 20 or older and that the birth data entered is your own or entered with clear permission.
Production consent records should store the consent version, timestamp, source, and linked order without exposing raw birth data in public logs.
How it is stored
First Look form entries stay on your device and are not sent to UrNorth by that form.
Member registration and intake are stored in UrNorth's access-controlled Supabase database with row-level security so the Blueprint can be prepared and delivered.
Member feedback is kept in your browser and, when your intake records AI-assist and data consent, is also sent to that same database, where the founder reads it. If it cannot be sent, the Member Room says so and keeps the browser copy.
Invite-code redemption runs through server-side logic before a member profile is created.
Public checkout and wider collection stay closed until the delivery loop and backend handling are approved.
Sharing and service providers
We do not sell your birth data.
Data may be handled only where needed to operate UrNorth, prepare or support your Blueprint, comply with lawful requests, or use approved infrastructure providers under appropriate controls.
Service providers can include Supabase, Vercel, GitHub, future payment or email providers, and approved AI providers. Some providers may process data internationally, which must be disclosed before production collection.
Your choices
You can ask to access, correct, or delete the personal data connected to your request.
You can also ask to withdraw future use where the product no longer needs the data to fulfill or support an active Blueprint.
Ask UrNorth to delete your record if you want UrNorth to remove or anonymize source intake data, delivered report copies, feedback records, and operational copies, while keeping minimal pseudonymous audit records where needed.
Retention and incidents
Founding Access should keep raw intake data only as long as needed for fulfillment, support, updates, legal obligations, or an active customer request.
If a data incident creates likely risk to users, UrNorth should assess it quickly, preserve evidence, and prepare PDPA notification within the required window.
For privacy requests, contact UrNorth through the private channel used for your order.