Privacy
Last updated 23 August 2026
Ninesum asks for very little: an email address, the name you’re considering, a date, and five optional answers. This page says what happens to each of them. It describes what the site does today, not what it might do one day.
Who holds it
Ninesum is run by Mateusz Kozak, a sole trader registered in Poland (CEIDG), NIP 6472465040. Under the GDPR that makes us the controller of everything described here. You can reach us at readings@ninesum.co.
What we hold
- Your email address. Asked for before payment, because the reading is delivered by email and your credits are attached to that address. It is the only way we recognise you: there are no accounts and no passwords.
- The name and the date. The full name you’re considering and the birth date or due date. Both go into the calculation, and both are stored with the reading so its link keeps working.
- Your five answers. The preference pairs, including the ones you leave open.
- The reading. The calculated chart and the text written from it.
- The purchase. What you bought, what it cost, and Stripe’s reference for the payment. Card numbers never reach us — they go from your browser to Stripe.
- Your credit balance, held against your email address.
- Product events. Which step of the flow was reached, whether an order bump was taken, how far a report was read. They record what happened, not who you are: the reading id where there is one, and never the name, the date or your address.
What we don’t hold
- No accounts and no passwords, so nothing to be breached.
- No cookies on the customer side. What you type before paying is kept in your own browser’s session storage so a refresh doesn’t lose it. The only cookie this site sets belongs to the operator login, and only an operator ever gets one.
- No IP addresses, device fingerprints or user agents in our database. Our hosting provider keeps short-lived operational logs that can include an IP address, as every web server does; they are used to keep the site up and for nothing else.
- No third-party analytics, no advertising pixels, no social buttons, nothing that follows you to another site. Even the fonts are served from our own server, so loading a page tells nobody else you were here.
- Your data is never sold, never rented, never shared for advertising, and never used to train an AI model.
What happens before you pay
When you enter your email at checkout we save it straight away, together with the name, the date and your answers — before you pay, and whether or not you go on to pay. It is what lets the order be picked back up, and if you leave without finishing we send one reminder about four hours later. One, never a series.
If you would rather we didn’t keep an order you abandoned, reply to that reminder or write to us, and we will delete it.
Why we’re allowed to hold it
- To do what you paid for. The email address, name, date, answers, reading, purchase record and credit balance all exist to deliver the thing you bought.
- Because we have a legitimate interest, weighed against your privacy: the single abandoned-order reminder; two neutral reminders, about a week and about a month later, if credits are sitting unused; a cap on how many readings one address can generate in an hour, which protects you and our costs alike; and counts of how the product is used. You can object to any of these.
- Because the law requires it. Purchase records are kept for accounting and tax.
Who else sees it
Four companies process data for us. Each is bound by a contract, and none of them may use your data for their own ends.
- Stripe — payment. Receives your email address and the amount. Card details go from your browser to Stripe directly, never through our server.
- Anthropic — the model that writes the reading. Receives the name, the date and your five answers, and returns the text. It is not used to train models.
- Resend — email delivery. Receives your address and what the email says.
- Fly.io — hosting. The application and the database it writes to both run on their infrastructure.
All four are US companies. Sending data to them relies on the European Commission’s standard contractual clauses or, where the company is certified, the EU–US Data Privacy Framework. Ask us and we will tell you which applies to which.
Your report link
Every reading lives at its own permanent address with no login. That is deliberate: it is what lets you send a reading to a partner or a grandparent. The address ends in a long random string, so it will not be guessed — but anyone with the link can open the reading, and the page shows how many credits are left on the account.
So treat the link as private, and share it only with people you would show the reading to. If you want a reading taken down, ask us: we delete it and the link stops working.
How long we keep it
- The reading and its link: until you ask us to delete them. They are meant to last, because a permanent link is the product.
- An order you abandoned: until you ask us to delete it.
- Purchase records: for as long as Polish accounting and tax law requires, which is five years from the end of the accounting year. This is the one thing we cannot delete on request.
- Product events: kept as counts, with no name, date or address in them.
Your rights
Wherever you live, you can ask us for a copy of what we hold (access), to correct it, to delete it (erasure), to restrict what we do with it, to hand it over in a portable file (portability), or to stop the uses that rest on our legitimate interests (objection) — the reminder emails included. Write to readings@ninesum.co. We answer within 30 days and charge nothing for it.
There is no newsletter to unsubscribe from; the only emails we send are the reading itself and the reminders described above, and replying to any of them stops the rest.
If you think we have handled your data badly, you can complain to your national supervisory authority. Ours is the President of the Personal Data Protection Office (UODO) in Warsaw.
The child in the reading
A reading is about a child, often one who has not been born yet. The name and the date come from you, an adult — we never collect it from the child, we build no profile of them, we advertise to nobody, and nothing about them goes anywhere beyond the four processors above. Deleting the reading deletes it.
Ninesum is for adults: you must be 18 or older to buy.
If you are in the United States
California residents: in the past twelve months we have collected identifiers (your email address), commercial information (what you bought) and the content you typed (the name, the date, your answers). We have not sold or shared personal information, and we do no cross-context behavioural advertising — there is no advertising here at all. You may ask what we hold, have it corrected or deleted, and we will not treat you differently for asking. Write to readings@ninesum.co.
Changes
If this policy changes, the date at the top changes with it. If a change actually matters — a new processor, a new use for something you already gave us — we will say so here in plain words rather than expect you to spot the difference.
Getting in touch
readings@ninesum.co. A real person reads it.
For entertainment and reflection. Not advice. 18+.