Privacy Policy
Senna Automation LLC operates Church of Yahw.ai. For privacy requests, email contact@senna-automation.com.
What we collect
We store the input you submit, optional context/instructions/metadata, request and quote identifiers, quoted price, terms version and acceptance time, payment status, the delivered Teaching, and operational events. Optional source and agent labels help us understand how the service is used. Do not submit secrets or sensitive personal information.
Stripe processes payment information and may collect payer details. We store Stripe transaction identifiers and status, not raw card details. We use a keyed hash of the payer email, where provided, to measure repeat purchasing without storing that email in our request database. Strike processes Bitcoin Lightning payments and maintains its own account and transaction records. We store provider invoice IDs, payment status, and quoted BTC amounts; we never request a wallet seed or spending key. Both payment providers independently maintain their records.
How we use it
We use records to deliver the service, verify payments, support refunds, detect abuse, resolve failures, and understand demand. Authorized operators may inspect submitted questions for product research and support. Oracle does not analyze your question, and no submitted content is sent to an AI model or used for model training by this service. We do not sell request content or publish it as examples without separate permission.
Providers and logs
Cloudflare hosts the site, API, database, rate limiting, and administrative access. It processes network information, including IP addresses, to deliver and protect the service. Application logs use error codes and correlation/request IDs; we do not intentionally log bodies, access tokens, idempotency keys, or card data. Payment processing is performed by Stripe and Strike. GitHub supplies operator sign-in through Cloudflare Access. Aggregate Cloudflare traffic statistics may be viewed by the operator without adding an advertising tracker. Provider processing is subject to their respective policies.
Retention
Submitted content and Teaching text expire after 90 days and are removed by periodic cleanup. Access is denied to expired content even if cleanup is delayed. Operational events are retained for up to 90 days, and webhook deduplication records for 30 days. Request, quote, payment, refund, and administrative audit records may be retained longer for accounting, security, disputes, and legal obligations. Transaction records are separate from the submitted content. Cloudflare backups may retain recently removed data for a limited recovery period.
Browser storage and access
The Oracle form stores a request-specific access token in your browser’s local storage so you can return to a result. Anyone with that token can access the corresponding result. Clear browser site data to remove it from that browser. We do not use third-party advertising trackers. Private API requests require a bearer token and are not publicly cached. Administrative access requires separate authentication.
Deletion and your choices
You can use the service without submitting a question or creating an account. For deletion, access, or correction requests, contact us with the request ID, but do not email access tokens. We may need to verify ownership and may retain limited financial/security records where required. If you accidentally submit a secret, revoke or rotate it with its issuer and ask us to remove the content.