Privacy Policy
For every Eadiefleet product · Last updated August 02, 2026
Eadiefleet Corporation is the controller of the personal information described here. We are a Canadian company and we handle personal information under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA); where the GDPR or another law gives you stronger rights, we honour those too.
The honest summary: we collect what a product needs to work and what the law needs us to keep. We do not sell personal information, we let no outside advertising network near you, and we do not use your content to train machine-learning models. Some of our communities do carry advertising, sold by the community and served by us — see Advertising below for exactly what that records.
What we collect
Because you gave it to us
- Account details — your email address, and a name if you set one. Most of our products sign you in with a short code sent to that address rather than a password, which is why the address has to be one you can actually read.
- What you create in a product — the messages, records, and files you put into it. What this amounts to varies: in Sidereal it includes your birth date, time, and place, and whatever you say to the Seer; in Community-IO it's your posts and profile.
- Billing details — for web purchases, your name, billing address, and the last four digits and brand of your card. The full card number goes to Stripe and never reaches our servers. For App Store purchases we receive only Apple's signed record of the transaction, which does not identify you to us.
- What you write to support — the message and the address it came from.
Because the software recorded it
- Session records — IP address and browser user-agent for each sign-in, so you can see where your account is signed in and we can spot abuse.
- Server logs — requests, errors, and timings, retained for 30 days.
- Analytics on this website and our product sites — self-hosted Plausible, which sets no cookies, records no personal identifiers, and does not follow you between sites. That is why this site asks you nothing about cookies.
- Analytics inside a community — a community is a different case and we won't pretend otherwise. Community-IO records a visit: IP address, browser, operating system, device type, the page you arrived on, the site that referred you, and an approximate location derived from the IP — usually a city. If you are signed in, that visit is linked to your account. This is how a community knows how many people read something and how its advertising is counted, and it is why a community asks for your consent to cookies where this site does not.
Sensitive information
Some of what our products hold is personal in the ordinary sense of the word — an astrological reading is a private thing. We treat it accordingly: it is encrypted at rest, only reachable by your own account, and never used for anything but showing it back to you.
Advertising
Some of our communities carry advertising. It is worth being precise about what that does and doesn't mean, because the word usually implies a great deal more than happens here.
The advertising is ours end to end. A community sells its own space to businesses it chose, and the banners are stored and served by us from the same servers as everything else. There is no ad network, no ad exchange, no bidding on you, and no third-party script in the page. Nobody outside Eadiefleet receives anything about you because an advert was shown.
What we record is a count. When an advert is displayed or clicked we store which banner, in which placement, as part of which run, and which visit it belonged to — so an advertiser can be told how many people saw their advert and how many followed it. Because it is tied to a visit, and a visit is linked to your account when you are signed in, that record is personal information and we treat it as such: it is yours to export and yours to have deleted, and it goes when your account goes.
We do not build advertising profiles, we do not target adverts using anything you have written or read, and we do not follow you to any other website. An advertiser is told how their advert performed. They are never told who you are.
Why we're allowed to hold it
- To perform our contract with you — running the product you signed up for and taking payment for it
- Our legitimate interests — keeping the service secure, preventing abuse, and understanding in aggregate how the products are used
- Legal obligation — keeping financial records for the period tax law requires
- Your consent — for anything optional, such as a product newsletter, which you can withdraw at any time
Who else touches your data
We keep this list short on purpose, and we keep it current. These are our processors, what they do, and where:
- Stripe — payment processing for web purchases (United States, Ireland)
- PayPal — payment processing for Community-IO Pro memberships. PayPal holds the payment details; we receive the record of the transaction (United States)
- Apple — payment processing for in-app purchases; Apple is an independent controller for those transactions under its own privacy policy
- Mailgun — transactional email, including sign-in codes (United States)
- Anthropic — used by Sidereal to generate readings. What you ask the Seer and the relevant parts of your chart are sent to the Claude API. Anthropic does not train its models on API traffic.
- OpenStreetMap Nominatim — used by Sidereal to turn a birthplace name into coordinates. Only the place name is sent, never your identity.
- OVHcloud — the company we rent our physical servers from, and whose object storage in Beauharnois, Québec holds a mirrored copy of uploaded files. We run and administer the machines ourselves; OVHcloud provides the metal, the network, and the building it stands in (Canada, EU-owned)
- Bunny.net — the content network that serves images and video to members. A request for a photo reaches Bunny's edge before it reaches us, so Bunny sees the file being requested and the IP address asking for it (EU-owned, edge locations worldwide)
- Amazon Web Services — used by two products for two different jobs. Community-IO sends uploaded images and video to Rekognition to be scanned for unlawful and prohibited content, and video to MediaConvert to be transcoded; what comes back from moderation is a list of labels, and the labels are what we keep. Merlin ID sends the face captured during a verification to Rekognition for liveness, age estimation and face matching, and an identity document to Textract to be read. Moderation and verification run in the United States; transcoding stays in Canada
Two ways of paying us appear on that list only by their absence. An Interac e-Transfer is handled by your own bank, and we see that it arrived and what it was for, never your banking details. Bitcoin goes through a BTCPay server we run ourselves rather than a crypto payment company, so it introduces no third party to your information at all.
We run our own servers and databases rather than renting a managed platform, so your content sits with us and not inside somebody else's product. That does not mean the machines are in a cupboard: they are bare metal we rent from OVHcloud and administer ourselves, which is a different relationship from handing your data to a platform — nobody there operates the software, reads the database, or decides what happens to what is on it. We name them anyway, because they hold the hardware and a copy of the files, and a list of who can physically reach your data that leaves out the landlord is not a complete list.
We do not sell personal information, and we have never received a government request for user data; if we do, we'll tell you unless we're legally prevented from doing so.
Where your data lives
Our servers are in Canada, and so is the mirrored copy of uploaded files. Two things reach further. Image and video moderation runs in the United States. And images served through Bunny.net are cached at edge locations around the world, which is the point of a content network — a member in Australia is served from nearer Australia, and a copy of that image sits there until it expires.
Where a processor is outside Canada your information crosses a border and becomes subject to the laws there, and where required those transfers rest on Standard Contractual Clauses. We have deliberately kept the American surface small: the companies holding your files are European-owned, which is why the US CLOUD Act reaches less of this than it would at a hyperscaler.
How long we keep it
- While your account is open — for as long as you want it
- After you close your account — content is deleted within 30 days, apart from backups
- Backups — rotate out within 90 days, after which deleted content is gone from them too
- Server logs — 30 days
- Invoices and payment records — 7 years, because tax law says so
- A Merlin ID verification — under 24 hours. A screening carries an expiry from the moment it is created, and a sweep runs every hour destroying everything past it, taking the face capture and any identity document with it and leaving only a log entry recording that the deletion happened. Merlin ID is deliberately not a store of verification material; the customer who asked for the check has that window to collect the result
Most people whose face passes through Merlin ID have no account with us and never will — they are verifying themselves for some other business that uses it. We hold their information only as that business's processor, for the hours described above, and we do not build a profile across the businesses somebody has verified with.
Your rights
You can ask us to:
- Show you what we hold — most products have a one-click export in settings
- Correct anything wrong
- Delete your account and its contents
- Hand it over in a portable format
- Stop a particular use, or withdraw a consent you gave
Write to support@eadiefleet.com and we'll answer within 30 days. There's no charge. If you're unhappy with how we've handled a request you can complain to the Office of the Privacy Commissioner of Canada, or to your local supervisory authority if you're in the EU or UK.
Children
Our products aren't intended for children under 13, and we don't knowingly collect their information. If you believe a child has given us personal information, write to us and we'll remove it.
If something goes wrong
If personal information is exposed in a way that creates a real risk of significant harm, we will notify affected people and the Privacy Commissioner as the law requires, and we will tell you what happened rather than what our lawyers wish had happened. Our security page sets out the practices meant to keep that from happening in the first place.
Changes to this policy
We'll email account holders before any material change and always show the last-updated date at the top of this page.
Reaching us
Eadiefleet Corporation
PO Box 36015, Talbot Village PO
London, Ontario, Canada N6P 0C4
support@eadiefleet.com