Trust & Privacy
Your spiritual data is sacred. We treat it that way. Here's how we protect your information and ensure responsible AI guidance.
Our Commitments
The principles that guide how we handle your data.
Data Minimization
We only collect what's needed for your reading. Birth data stays birth data.
Encryption at Rest
All personal data encrypted with AES-256. Your chart is your secret.
Retention Limits
Session data auto-deletes after 30 days unless you explicitly save it.
Private Mode
Generate readings without any data persistence. Ephemeral by design.
Safety Boundaries
AI refuses harmful advice. No medical, legal, or financial directives. Spiritual guidance only.
Data Practices
Specific details on how we collect, use, and protect your information.
What We Collect
- Birth date (required for readings)
- Birth time (optional, improves accuracy)
- Birth location (optional, enables house calculations)
- Email (only if you submit a partner request)
What We Don't Collect
- Real names (not needed for readings)
- Payment information (handled by third-party processors)
- Browsing history or tracking cookies
- Social media data or contacts
How We Use Your Data
- Generate personalized spiritual readings
- Calculate astrological positions (deterministic math, not stored)
- Respond to partnership inquiries
- Improve our AI models (anonymized, aggregated only)
API Enterprise Trust
Public security controls and buyer-review evidence for teams integrating The Leo King API.
Security Controls
Server-Side API Keys
liveStore keys in a backend secret manager or server env. Never ship keys in browser, mobile, or client-side code.
Dedicated HTTPS Gateway
livePin production clients to the dedicated gateway and keep the legacy website host only for alpha compatibility.
Scoped Endpoint Access
betaRequest only the lanes and endpoints needed for the customer workflow.
Retry-Safe Usage Records
betaSend stable idempotency keys for retries and include request_id in support tickets.
No Fallback Success For AI Output
liveTreat `INVALID_RESPONSE` or `UPSTREAM_FAILED` as retry/escalation conditions instead of rendering degraded content.
Data Handling
API Request Metadata
Do not include full secrets or raw payloads in support tickets; provide request_id and sanitized payload shape.
Birth Data Payloads
Use customer ids and only the birth fields needed for the route. Avoid names and unrelated personal profile data.
Generated AI Outputs
AI output must meet the same product contract after retries; fallback-shaped output should be escalated as a quality incident.
Billing And Entitlement Records
Payment instruments are handled directly by Stripe rather than stored in this API surface.
Support Evidence
Never send raw API keys, bearer tokens, payment details, or complete private payloads in email or chat.
Subprocessor Scope
Vercel
Next.js hosting, edge routing, logs, and deployment rollback.
Convex
API key validation, usage ledger, entitlement state, and billing/event records.
WorkOS
Production AuthKit authentication and organization identity for the customer console.
Stripe
Direct Checkout, subscription billing, invoices, and Customer Portal access.
Clerk
Temporary customer-console authentication rollback provider; not the active production authority.
OpenAI Or RunPod
Model-backed generation for AI Intelligence routes when enabled by production config.
AI Safety
Responsible boundaries for AI-generated spiritual guidance.
Our AI provides spiritual guidance, not professional advice. We've implemented strict boundaries to ensure our systems remain helpful without overstepping.
Our AI will never:
- Provide medical diagnoses or treatment recommendations
- Offer legal advice or financial investment guidance
- Predict specific future events with certainty
- Encourage harmful or illegal actions
- Replace professional therapy or counseling
Our AI is designed to:
- Provide perspective and reflection prompts
- Offer timing insights based on astrological cycles
- Suggest areas for personal exploration
- Encourage self-awareness and growth
- Point toward professional resources when appropriate
Questions about privacy?
We're happy to discuss our data practices in more detail.
privacy@theleokingai.com