Dolya

Privacy

Last updated 12 August 2026.

Dolya asks for a birth date, and if you buy the full version, for an email address. This page says what happens to both. There are no cookies, no analytics and no tracking on this site.

Who is responsible

Magnetis OU is the controller of the personal data described here.

Email is the fastest way to reach us and the address to use for anything about your data. Post reaches us at the registered address above.

What is collected, and why

Your birth dateTyped on the first screen. It is what the chart is made from, so without it there is nothing to read. It is sent to Anthropic to write the reading, stored in our cache against the reading it produced, and, if you buy the full version, recorded against the purchase so that the link knows which reading it opens. The basis is performing our contract with you, or taking steps at your request before one - article 6(1)(b) GDPR.

Your email addressCollected by Stripe at the checkout, and passed back to us. We use it for one thing: sending you the link to the reading you bought. The basis is performing the contract - article 6(1)(b).

Your IP addressRead from the request while you are on the site, and used only to count how many readings and how many payment pages one address has opened in the current hour. It is not attached to your birth date, your email address or your purchase, and it goes nowhere else. The basis is our legitimate interest in keeping a free service, and the bill behind it, from being drained - article 6(1)(f).

The consent you gave at the checkoutThe sentence about the fourteen-day right, which version of it you were shown, and the moment you ticked it. Recorded against the payment at Stripe and in our own record of the purchase, because consumer law requires us to be able to show it. The basis is a legal obligation - article 6(1)(c) - and our legitimate interest in being able to answer a dispute about it - article 6(1)(f).

What was paidThe amount, the currency and Stripe's reference for the payment session. The basis is a legal obligation: accounting and VAT - article 6(1)(c).

We do not ask for your name. Nothing here asks you to make an account, because there are no accounts.

Your birth date goes to the United States

This is the part a reader may not expect, so it is here in plain words. The reading is written by Claude, a language model run by Anthropic, and to write it your birth date and the nine numbers it makes are sent to Anthropic's API in the United States. There is no European-only version of that API for us to use. Nothing else travels with it: not your email address, not your IP address, and there is no name to send.

Anthropic deletes inputs and outputs within 30 days of receiving or generating them, with exceptions for features that retain for longer, for arrangements agreed separately, and for enforcing its usage policy. Anthropic does not train its models on data from its commercial API.

Who else sees it

StripeTakes the payment, on its own page. No card number, expiry or security code ever reaches us. Stripe collects your email address and the country detail it needs to work out the VAT, and it receives the birth date the reading is for and the consent sentence you ticked, both stored against the payment. For much of what it does with payment data Stripe is its own controller, under its own privacy policy.

AnthropicWrites the reading, and receives the birth date and the chart, as above.

ResendSends the one email. It receives your email address, the birth date - which is in the subject line and in the message - the link to your reading, and the confirmation the message carries below it: what was bought, what it cost, and the consent you gave at the checkout with the moment you gave it.

VercelHosts the site and runs its code. Every request passes through Vercel, which sees your IP address and the ordinary details of a request, and our own server logs are held there.

UpstashUpstash Redis, connected through Vercel and run on AWS in us-east-1, N. Virginia, United States. It holds the record of your purchase, the hourly counters behind the rate limit, and the cached readings.

Nobody is sold this data and nobody is sent it for advertising.

Where it goes

Our functions run in the United States: a request made in Europe is received in Europe and answered from Washington DC. Anthropic's API, Resend and Upstash - the key-value store behind it, run on AWS in us-east-1, N. Virginia - are in the United States too. Those are transfers of personal data outside the EU, and they are how the product works rather than an incident.

The safeguard relied on in each case is the European Commission's standard contractual clauses, the 2021 set adopted in decision 2021/914. Anthropic incorporates them through the data processing addendum built into its commercial terms; Vercel, Resend and Upstash through their own data processing addenda; Stripe through its data transfers addendum.

How long it is kept

The record of a purchaseThe birth date, your email address, the payment reference, the amount and the consent. Two years from the purchase, after which it deletes itself. That is also how long your link keeps opening the reading.

The note that a reading was refundedTwo years. It holds the birth date and the payment reference, so that a link opened afterwards can say what happened rather than nothing.

The rate-limit countersOne hour - the length of the window they count. They expire on their own and nothing renews them.

Cached readingsOne year. A cached reading is stored under the birth date alone, with nothing attached to say who asked for it.

Our server logsThey record birth dates and payment references, never email addresses and never IP addresses. We have not set a period of our own for them; they are held by Vercel under its own schedule.

Stripe, Resend and Anthropic each keep their own records under their own schedules. Anthropic's is the 30 days above. Stripe keeps the payment record for as long as its own legal obligations require, which is longer than any period above.

Your rights

If you are in the EU you can ask us for a copy of what we hold about you, to correct it, to delete it, to restrict what we do with it, to have it handed to you in a portable form, and to object to anything we do on the basis of our legitimate interests. You can withdraw any consent you have given, without that affecting what was done before.

Write to readings@dolya.app. What lets us find you is the email address you bought with, or the payment reference from Stripe's receipt. A birth date on its own will not find anything, because a cached reading is not attached to a person.

One thing is worth saying plainly. Our record of your purchase is what makes your link work, so deleting it stops the link opening the reading. We will say so before we do it.

Complaining

If you think we have handled your data badly, tell us first at readings@dolya.app and we will try to put it right.

You can also complain to a supervisory authority. Ours is the Estonian Data Protection Inspectorate, Andmekaitse Inspektsioon, at Tatari 39, 10134 Tallinn, Estonia, info@aki.ee, aki.ee. You may complain to the authority in the country you live in instead.

What this site does not do

Dolya's own pages set no cookies. There is no analytics, no advertising, no tracking pixel and no third-party script; the fonts are served from this site rather than fetched from anybody else. The email we send carries no image and no tracking pixel. Stripe's payment page is Stripe's own, and what it does there is covered by Stripe's privacy policy.

Read a chart