Legal
Privacy
How Witness accounts, forms, private audiences, hosted services, and approved public messages are handled.
Last updated August 26, 2026
Privacy policy
Information submitted
Contact, wishlist, signup, membership-interest, and public candle forms send the fields shown on each form to this website’s service. The project uses them for the stated form purpose, including moderation, demand planning, project updates, and replies where requested.
Witness accounts and My Chapel
Witness is the website’s free member identity. A passwordless sign-in request uses an email address to send a short-lived one-time link. The website stores the verified address as application-encrypted ciphertext and a separate keyed, non-reversible lookup value. It also stores an opaque member ID, account and Witness status, optional display name and preferred Maiden, secure-session hashes, role and consent history, and links to records the verified member is entitled to reopen. Raw magic-link and session tokens are not stored.
My Chapel can show a verified member’s newsletter choices, audience and public-flame history, future-membership interests, safe receipt summaries, and relationship-memory choices. The authenticated member may open her own audience and safe internal receipt records; those controls do not provide access to arbitrary Stripe objects or another member’s records.
Newsletter choices
Creating an account, purchasing an audience, submitting a membership-interest form, or lighting a public flame does not subscribe anyone to marketing. Newsletter enrollment uses a separate unchecked choice and a confirmation link. The consent ledger records selected topics, source, policy version, requested and confirmation times, and later unsubscribe, bounce, complaint, or suppression state. Transactional account, payment, answer-ready, failure, and refund notices remain separate from marketing consent. Test records are excluded from ordinary newsletter exports.
Once-A-Day private audiences
Once-A-Day uses the email address, selected Maiden, one visitor message, required acknowledgements, optional memory choice, and human-verification result needed to offer a private audience. Stripe hosts Checkout, handles the purchaser email and payment-card data, and remains the payment system of record; this website does not collect or store card data or retain a plaintext copy of the purchaser email. The website keeps only a keyed, non-reversible email identity value for duplicate protection and reconciliation.
Cloudflare Workers AI processes the selected bounded Maiden context, visitor message, and generated response to produce the requested answer. The service does not give the model browsing, email, social, payment, file, or other external-action tools. Message and answer content is stored by this website only as application-encrypted ciphertext; this is not end-to-end encryption.
A Once-A-Day audience is private within this website’s service and is not posted to the Public Candle Wall. “Private” does not mean end-to-end encrypted or absolutely confidential. Do not submit passwords, financial details, health records, government identifiers, or other sensitive information.
When a visitor selects “Let this Maiden remember me,” the choice is limited to the selected Maiden’s relationship memory. It does not create memory for another Maiden, another visitor, or the public project. Visitors can use the audience controls to forget one audience door, one Maiden relationship, or all Website audience memory.
Audiences Kept
For a guest, the “Audiences Kept” list is a browser feature that keeps only audience-door information on that device, such as the selected Maiden and a private audience door. For a signed-in Witness, My Chapel may also list linked, dated audience records on the server so the member can reopen her own complete answer without the old device token. Neither list is a continuing chat transcript, and neither creates a follow-up or regenerate control.
Public candles
Only approved public candle fields may appear on the wall: public alias or “Anonymous,” optional recipient, intention, path, color, public message, duration, and lighting time. Email addresses, payment details, provider records, moderation notes, private audience messages, and private audience answers are not public candle content.
Payments
When configured, an official hosted payment provider handles checkout, receipts, fraud review, disputes, and payment records under its own privacy policy. The site does not collect or store payment-card data.
Media and analytics
YouTube media uses privacy-enhanced embeds where available, though playing a video still contacts YouTube. The site does not add advertising trackers or nonessential analytics by default. If optional analytics are configured later, this policy must be updated before collection begins.
Security, retention, and choices
Unpaid audience reservations ordinarily expire after about 45 minutes. Encrypted audience messages and answers are configured for a 30-day retention window unless the visitor deletes them sooner or a longer hold is required for a payment, refund, abuse, security, or legal review. Opted-in Maiden relationship memory remains until the visitor forgets that Maiden relationship or all Website audience memory. Stripe retains its own payment and receipt records under Stripe’s terms and applicable obligations.
A Witness can download a private JSON record export, forget one audience, withdraw one Maiden’s relationship memory, forget all Website audience memory, sign out everywhere, or delete the Website account. Account deletion removes the reusable sign-in identity, profile, sessions, newsletter subscription, interests, and stored private audience words. Opaque payment and refund evidence, consent evidence, approved public-flame records, fraud-prevention records, and an active 24-hour cooldown may remain where needed for reconciliation, security, or applicable obligations. Deleting an audience likewise does not erase a still-active cooldown or payment record.
Administrative access is protected and audited. Protected exports may include member email addresses and transaction identifiers for support and reconciliation, but default exports exclude private messages, Maiden answers, card data, prompts, tokens, and secrets. Use the contact form or email legal@themaidensofficial.com to ask a privacy question or request review of information you submitted; include the Stripe receipt reference when available.