Legal
Privacy Policy
Last updated: April 20, 2026
This Privacy Policy explains how Divinathor ("we", "our", "us") collects, uses, and safeguards personal information when you use our website and waitlist at divinathor.com. We believe in keeping this simple: we collect the minimum we need, we do not sell your data, and you control what we keep.
1. Data we collect
When you join the waitlist through Google OAuth, we collect the following directly from Google:
- Email address
- Basic Google profile information (name, profile picture)
- Locale (language and region set on your Google account)
When you browse the site, our hosting provider automatically receives standard technical data: IP address, user agent, and timestamps. We may also collect anonymous usage data (pageviews, clicks) through privacy-respecting analytics to understand how the site is used.
If you arrive through a link that carries UTM parameters or a referring site, we record those so we know which channels are working. We do not combine this with your identity unless you sign in.
2. How we use your data
We use the data above only to:
- Manage your waitlist account and identify you on return visits
- Notify you about product launch, access invitations, and material updates to the service
- Operate and secure the site (fraud prevention, abuse detection)
- Understand overall usage patterns in aggregate
We do not sell, rent, or share your personal data with third parties for their own marketing. We do not use your data to train third-party advertising models.
3. Who has access
Access to personal data is limited to the operational team behind Divinathor. We rely on a short list of infrastructure providers that process data strictly on our behalf:
- Supabase — authentication and database hosting
- Vercel — website hosting, analytics, and edge delivery
- Google — OAuth sign-in provider
These providers are bound by their own privacy obligations and only process data as needed to deliver their services.
4. Your rights
You have the right to:
- Request a copy of the personal data we hold about you
- Correct inaccurate or incomplete information
- Request deletion of your account and associated data
- Withdraw your consent to future communications at any time
- Object to or restrict specific uses of your data
To exercise any of these rights, email us at hello@divinathor.com. We will respond within 30 days.
California residents (CCPA/CPRA): You have the right to know what personal information we collect, to request deletion, to correct inaccurate information, and to opt out of any sale or sharing of personal information. We do not sell or share personal information as those terms are defined under the CCPA.
European residents (GDPR): You have the additional rights of data portability and the right to lodge a complaint with your local supervisory authority. Our legal bases for processing are your consent (waitlist signup, notifications) and our legitimate interest in operating a secure service.
5. Data retention
We keep your account data while your waitlist entry is active or until you request deletion. Aggregate, anonymized analytics may be retained beyond that point. If you ask us to delete your account, we remove your personal data from our active systems within 30 days; residual copies in encrypted backups are purged on the normal backup rotation cycle.
6. Security
We use industry-standard measures to protect your data:
- TLS encryption for all data in transit
- Encryption at rest for database storage
- Google OAuth for authentication — we never see or store passwords
- Supabase Row-Level Security policies restricting access at the database level
- Audit logging for administrative actions
No system is perfectly secure. If you believe your account has been compromised, contact us immediately.
7. Cookies
We use only essential cookies required for the site to function:
- Authentication cookies issued by Supabase and Google
- Session cookies to keep you signed in across pages
- Anonymous measurement cookies set by Vercel Analytics and Speed Insights (no cross-site tracking)
We do not use third-party advertising cookies or cross-site tracking technologies. You can clear cookies at any time through your browser settings, though doing so will sign you out.
8. Children
Divinathor is not directed to, and does not knowingly collect personal information from, anyone under the age of 18. If you believe a minor has provided us with data, please contact us and we will delete it.
9. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify registered users by email and update the "Last updated" date above. Your continued use of the service after the effective date constitutes acceptance of the revised policy.
10. Contact
Questions, requests, or concerns about this policy or your data: