Privacy policy
Effective date: 2026-09-04
Last updated: 2026-09-04
1. Introduction and controller
Senary Design ("Senary", "we", "us") operates the senary.design website and the Senary Design iOS application (together, the "Service"). Senary Design is the controller of the personal data described in this policy. For all matters concerning this policy, contact base@senary.design.
Nature of the service
Senary is a theoretical exploration combining your Human Design chart with your body signal data. It is not medical advice. It is not predictive of life events. We use planetary positions and your birth chart as a symbolic framework to surface patterns in your physical activity data. Treat insights as exploration, not prescription.
2. Definitions
In this policy:
(a) "Account" means a registered user account on the Service.
(b) "Research Data" means the records described in clause 3.4.
(c) "You" means the natural person whose personal data we process.
3. Data we process
3.1 Accounts. When you register an Account we process your name, your email address, your password in protected form or your Sign in with Apple identifier, and the charts you save, including any birth data (date, time, and place of birth) you enter for chart calculation. Birth data is stored with your Account so that your chart can be shown to you and restored if you reinstall the app. Payments for web subscriptions are processed by Stripe; we do not receive full card numbers.
3.2 Beta waitlist. When you join the beta waitlist we process the name, email address, and date of birth you submit.
3.3 How research data is kept. Research records are kept with no names, no email addresses, no Apple IDs, and no dates, times, or places of birth.
3.4 Research Data. No Research Data is collected from anyone under the age of 16, in any of the categories below. From the moment you create an Account, if you are 16 or over, we collect as Research Data: (a) your chart's planetary activations and (b) your questionnaire answers. If you additionally enable data sharing in the app, we also collect (c) a daily record, computed on your device, of which of your centres the sky defined that day and how your activity that day compared with your own recent baseline, and (d) the health measurements you allow the app to read (such as activity, sleep, and heart measurements, and any others you allow) as recorded by your device, including measurements recorded before you enabled sharing. These measurements are sent when your device has a connection, which may be a mobile data connection. We do not send them over a personal hotspot or when Low Data Mode is on, and the first send is limited so it cannot use a large part of a monthly allowance. These records are not linked to your name, email address, or Apple ID. Your date, time, and place of birth are not stored in the research records.
3.5 Technical logs. Our servers record standard access information, including IP address, timestamp, and request path, when you use the Service.
3.5A Fit diagnostics. When the app tries to work out your energy mode on your device and the attempt does not succeed, it sends us a short technical report for your Account: what triggered the attempt, the outcome, the engine version, how long it took, the stages reached and their timings, counts of the days and workouts read, the app build, the iOS version and the device model. It contains no health measurements and no birth data. We use it only to offer you a recalculation and to fix the app.
3.6 The app also processes data solely on your device, including Apple Health readings, your journal, your significant events and the dates and places of your photos if you connect Photos. Data processed solely on your device is not transmitted to us except as described in clauses 3.4 and 3.5A.
3.7 Product analytics. The iOS app records how it is used: which onboarding steps and screens were viewed, which settings were changed, and the app version and device platform, together with an identifier for your Account. These records are processed for us by Mixpanel, Inc. They never contain your name, email address, birth data, health measurements or questionnaire answers, and they are not used for advertising or shared with anyone else. The identifier is dropped when you sign out or delete your Account.
4. Purposes and legal bases
4.1 Account data is processed to provide the Service to you. Legal basis: performance of a contract.
4.2 Waitlist data is processed to administer the beta programme. Legal basis: your consent.
4.3 Research Data is processed for a single purpose: research into how daily body measurements relate to planetary positions. Chart activations, the daily records described in clause 3.4, and questionnaire answers are processed on the basis of the consent you give when you create an Account, where research participation is stated. Daily health measurements are processed only on your explicit consent, given when you enable data sharing in the app. You may withdraw at any time in Settings; collection stops immediately upon withdrawal, with the further effects described in clause 6.4.
4.4 Technical logs are processed to secure and operate the Service. Legal basis: our legitimate interest in the security and operation of the Service.
4.5 Product analytics (clause 3.7) are processed to understand where the app confuses people and to improve it. Legal basis: our legitimate interest in improving the Service, limited to the data listed in clause 3.7.
5. What we do not do
We do not use personal data for advertising. We do not sell personal data. We do not share personal data with data brokers or with any third party, except processors engaged to operate the Service, such as our hosting providers, acting on our instructions. Data you choose to send to a third party yourself, using a personal access token under section 8, is transmitted at your direction and is not sharing by us. We do not carry out automated decision-making that produces legal or similarly significant effects concerning you.
6. Retention
6.1 Account data is retained until you delete your Account. You can delete your Account in the app at any time: Settings, Account and privacy, Account, Delete account. Deleting your Account removes your sign-in, name, birth data, charts, questionnaire answers, energy mode, personal access tokens and settings from our systems immediately, ends every session, and revokes your Sign in with Apple session where Apple allows us to.
6.2 Waitlist data is retained until the beta programme concludes or you request removal, whichever occurs first.
6.3 Research Data is retained for the duration of the research programme, subject to your choices in clause 6.4.
6.4 You can end research participation in three ways. (a) If you turn off data sharing in the app, collection stops. (b) If you delete your Account, in the app or by writing to base@senary.design, we delete it. Research Data you have already contributed stays in the research programme, with no Account pointing at it, so it can no longer be traced to you through the Service. (c) If you ask us to erase your Research Data, by writing to the same address, we delete the research records themselves entirely within 30 days. You can ask for (c) after (b): for 24 months after an Account deletion we keep, in the deletion record described in clause 6.7, the encrypted research identifier that lets us find and erase those records on your request, and nothing else that identifies you.
6.5 Deleting health data in Apple Health, deleting the app, or replacing your device does not remove Research Data you have already shared. Those changes happen on your device and we cannot see them. If you want that data erased, write to base@senary.design and clause 6.4(c) applies.
6.6 Technical logs are retained on a short rotation and then deleted.
6.7 Deletion record. When an Account is deleted we keep, for 24 months, a record that the deletion happened and what it reached: a one-way hash of the email address, the versions of the documents you agreed to and when, the encrypted research identifier described in clause 6.4, and the date. It holds no name, email address, birth data, chart, health measurement or journal text. We keep it because the law requires us to be able to show that consent was given and that a deletion request was honoured, and so that a later upload from a device, a restored backup or a replayed message cannot bring a deleted Account back to life. Analytics records at Mixpanel, billing records at Stripe and backups are cleared on their own schedules, as set out in clause 6.8.
6.8 Processors and backups. Deleting your Account drops the analytics identifier so no further events are attributed to you; event records already held by Mixpanel expire on its retention schedule. Billing records at Stripe are kept as tax law requires. Database backups are kept on a fixed rotation and are not edited individually; a restore replays every recorded deletion.
7. Your rights
7.1 Subject to applicable law, you have the right to request access to, rectification of, or erasure of your personal data, the right to restriction of processing, the right to data portability, and the right to withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
7.2 You may exercise these rights through the controls described in clause 6.4 or by writing to base@senary.design.
7.3 You have the right to lodge a complaint with a supervisory authority.
8. Personal access tokens
8.1 You can generate a personal access token in the app. A token lets an AI assistant or other tool of your choice make API requests that read your own data. Any agentic AI assistant, meaning one able to call an API on your behalf, can be used in this way. It reads your own records only. If you have enabled data sharing, it can also read your health measurements, so that the assistant can examine how they correspond with planetary movements. A token is shown to you once at creation, can be revoked by you in Settings at any time, and is available from the age of 16.
8.2 Looking after your token is your responsibility. Revoke it if you believe it has been compromised, and replace it with a new one from time to time. We store only a one-way fingerprint of your token, never the token itself. That is why a token can be shown to you only once and why we cannot recover it for you.
8.3 We cannot tell whether a request is coming from your own assistant or from someone who has obtained your token. We therefore take no responsibility for what happens to data passed to a third party through a token. Share a token only with a service you trust, revoke it in Settings as soon as you no longer need it or if you suspect someone else has seen it, and replace it often. Revoking takes effect on the very next request. A third party that receives your data handles it under its own terms, not under this policy, and because we cannot recall data a service has already received, address any deletion or withdrawal request to that service as well as to us.
9. Security
We take reasonable technical and organisational measures to protect the personal data we process. If an incident affects your personal data, we will notify you and any authority the law requires us to notify.
10. International transfers
The Service is hosted on cloud infrastructure located in Australia. Product analytics (clause 3.7) are processed by Mixpanel, Inc. in the United States. Where personal data is processed outside your jurisdiction, we rely on safeguards recognised under applicable law.
11. Children
The Service is not directed to children. You must be at least 13 to create an Account, and research participation is available from the age of 16, so no Research Data is collected from anyone younger. If you believe a child under 13 has given us personal data, contact base@senary.design and we will delete it.
12. Changes to this policy
We may amend this policy. The current version, with its effective date, is published at senary.design/privacy. Amendments take effect on the stated effective date.
See also our terms of service.