Privacy Policy

Last updated: 30 July 2026

Who we are

Enneuma is made and run by one person: Givi Vakhtangishvili, an individual entrepreneur registered in Georgia and working from Tbilisi. No company stands between you and whoever handles what you write here — the person who decides how your data is used and the person answerable for it are the same. In the language of the law, that makes us the data controller. Write to hello@enneuma.com about anything to do with your data; we will give you our full registered address on request.

We are based in Georgia and follow the Law of Georgia on Personal Data Protection. Because we serve visitors in the European Union, we also apply the GDPR, and the rights described below are available to you wherever you live.

This policy

This page explains what we collect, why, who else sees it, how long we keep it, and what you can ask us to do. We name every company that handles your data rather than calling them "trusted partners", because you cannot judge a partner you cannot see.

What we collect

To create and deliver your reading: your email address, the answers you choose during the journey, and — only if you offer them — your date of birth and, optionally, the hour and place. Alongside the order we store its price, its payment status, and a payment reference from our payment provider.

The hour and place of birth are used to shape the writing and are then discarded: they are removed before your answers reach the system that composes the reading, and only the year, month and day travel further.

If you write to us through the contact page or the chat, we receive your message and whatever you include in it. If you sign the guestbook, we store the name, rating and words you submit, and publish them on the site once we have reviewed them.

To keep the forms and the chat from being abused we count requests. Your IP address is turned into an irreversible fingerprint the moment it arrives and only the fingerprint is stored, so the counter can tell two visitors apart without recording who either of them is. If we send you a confirmation code, the code itself is never stored.

Your answers, and why we ask your consent

The questions ask about your fears, your shame, what keeps you awake and what you long to hear. Answers like these can reveal something about your mental and emotional state, which the law treats as a special category of data deserving stronger protection. We therefore do not rely on your purchase alone: before your reading is ordered we ask you to tick a box giving explicit consent for these answers to be processed.

You may withdraw that consent at any time by writing to us. Withdrawing it does not undo a reading already written and sent, but we will delete the answers we hold. If you would rather not give it, the questionnaire cannot be processed — it is the whole of what we would be working from.

Why we are allowed to use it

Your answers and birth data: your explicit consent. Your email address and order: necessary to perform the contract of delivering the reading you bought. Counting requests to prevent abuse: our legitimate interest in keeping the site standing. Payment records: a legal obligation to keep accounting records. Guestbook entries: your consent, withdrawn by asking us to remove the entry.

How your reading is composed

Your reading is written by an artificial-intelligence model working from your answers and a framework we wrote. The models we use are provided by Anthropic and by Google. Your answers are sent to them to produce your text and for nothing else. Neither company uses this data to train their models. Anthropic keeps a copy for seven days and Google for up to fifty-five days, in both cases only to detect misuse of their services, after which it is deleted.

No decision with legal or comparable consequences for you is made automatically. The reading is a text written for you to read and weigh, not an assessment used to decide anything about you. If you would like a person to look at what was written, ask us and one will.

Payments

Payments happen on the secure page of our payment provider, Flitt. Your card details go directly to them; we never see or store them. We keep only the confirmation that the payment succeeded and its reference number.

Who else handles your data

These companies process data on our behalf, under our instructions and no one else's: Netlify hosts the site; Neon holds the database; n8n Cloud runs the automation that assembles and sends your reading; Anthropic and Google provide the AI models; Google Drive and Gmail hold our copy of completed readings; Doppio turns your reading into a PDF; our email provider delivers the message; Flitt takes the payment.

We do not sell your data, we do not share it for anyone else's purposes, and we show no advertising on this site. We run no trackers in your browser: no analytics script, no advertising pixel, no third-party cookie.

If we are advertising and you reached us by clicking one of our advertisements, we tell the advertising platform — currently Meta, which owns Facebook and Instagram — that a purchase happened, so that we can see which advertisements are worth paying for. That message is sent from our server, not from your browser. It contains the amount, the currency, the identifier the advertisement itself carried, and your email address converted into an irreversible string of characters, so the platform can recognise a customer it already knows without ever receiving your address from us. We never send your answers, your birth data or your reading. Orders from the European Economic Area and the United Kingdom are excluded from this entirely.

Where your data goes

Some of the companies above are based outside Georgia and outside the European Economic Area, chiefly in the United States. When your data travels there it is covered by the European Commission's Standard Contractual Clauses, the safeguard designed for exactly this, and it is encrypted on the way.

What stays in your browser

Your progress through the questions — including any birth data you entered — is kept in your own browser so you can pause and return, together with your light-or-dark theme choice and, while a chat is open, an identifier for that conversation. If you arrived by clicking one of our advertisements, the identifier that advertisement carried is held too, and only until you close the tab. None of this is sent anywhere by itself. The rest stays until you clear your browser data or start the journey again, so on a shared computer it is worth clearing.

We set one cookie, and only if you are an administrator signing in to moderate the guestbook. There is no cookie banner because we set no advertising or analytics cookies at all — the advertisement identifier described above is not a cookie, is not readable by anyone else, and is gone when you close the tab.

How long we keep it

Your order and answers are deleted twelve months after you place them. If you begin a questionnaire and never complete the purchase, what we hold is deleted after thirty days. Guestbook entries stay until you or we remove them. The fingerprints used for counting requests are deleted within about a day.

Two copies live outside that database and are worth naming. The automation service keeps a record of each run — including the answers it processed — for up to thirty days. And the email carrying your reading stays in your own inbox, and in ours, until deleted; the link inside it does not expire, so treat it as you would any private message.

Your rights

You may ask us to show you the data we hold about you, to correct it, to delete it, to stop or limit what we do with it, to send it to you in a portable form, or to object to a particular use. Where we rely on your consent you may withdraw it, and where we rely on our legitimate interest you may object to it.

Write to hello@enneuma.com or use the contact page and a person will answer, normally within a month. We ask nothing for it. If you are unhappy with how we respond you may complain to the Personal Data Protection Service of Georgia, or, if you live in the European Union, to the data protection authority of your country.

How we protect it

Every connection to the site is encrypted. Your reading sits behind a long random link that cannot be guessed and is kept out of search engines. Card details never reach us. Access to the database is limited to the people who need it, and the forms are protected against automated abuse.

Children

The site is not directed at children. To make a purchase you must be at least 18 years old, or have the consent of a parent or legal guardian.

Changes and questions

If this policy changes, the new version will appear here with a fresh date at the top. Questions about your data are always welcome — write to us through the contact page.