Privacy Policy
Plain-language summary. The Off-Leash Oracle is a free, for-fun daily message service. We only collect what we need to deliver the reading you asked for — your email address if you subscribe by email, or a push-notification token if you enable notifications on a device. We do not sell or rent your information, we do not use advertising or analytics cookies, and you can unsubscribe at any time in one step. The full detail is below.
1. Who we are
The Off-Leash Oracle™ ("the Oracle," "we," "us," "our") is a website and daily-message service operated by Joy, Thee & Me LLC, a Texas limited liability company, at offleashoracle.com. Joy, Thee & Me LLC is the data controller responsible for the personal information described in this policy.
This policy explains what information we collect from visitors and subscribers, why we collect it, how we protect it, and the choices and rights you have. It is written to be read alongside our Terms of Use.
2. Information we collect
We practice data minimization: we collect only what is necessary to run the service you request. We do not require you to create an account.
a) Information you give us when you subscribe
- Email subscription: if you sign up for the daily reading by email, we collect the email address you submit. Email subscriptions use double opt-in — we send a confirmation email, and you are only added once you confirm.
- Push-notification subscription: if you choose "Notify me on this device," your browser generates a push registration token (via Firebase Cloud Messaging) that we store so we can deliver the daily notification to that device. This token identifies a browser/device, not your name or email.
- Text-message (SMS) subscription: SMS delivery is not currently offered. If we enable it in the future, we would collect the mobile phone number you submit, and this policy will be updated first with the applicable SMS terms and consents.
b) Information collected automatically for security & abuse prevention
- Technical request data: when you submit a subscription form or load the site, our servers process your IP address and request timestamps to apply rate limiting and prevent abuse.
- Anti-bot signals: our subscription forms use Google reCAPTCHA v3 and an invisible "honeypot" field to block automated sign-ups. reCAPTCHA collects device and usage information and is governed by Google's Privacy Policy (see §5 and §7).
c) Information stored locally on your device
- We store a small flag in your browser's localStorage (for example,
oraclePush) to remember whether you have enabled notifications on that device. This stays on your device and is not transmitted to us as personal information.
What we do not collect: we do not ask for your name, we do not run advertising or web-analytics trackers (no Google Analytics, no ad pixels), and we do not build behavioral profiles.
3. How we use your information
| Purpose | Data used |
|---|---|
| Send the daily Off-Leash Oracle reading you subscribed to | Email address / push token |
| Send a one-time confirmation ("double opt-in") and transactional messages (e.g., unsubscribe confirmations) | Email address |
| Prevent spam, bots, and abuse; secure the service | IP address, timestamps, reCAPTCHA signals, honeypot |
| Comply with law and respond to your privacy requests | As applicable to the request |
We do not use your information for advertising, for cross-context behavioral tracking, or to make automated decisions that produce legal or similarly significant effects about you.
4. Legal bases for processing (GDPR / UK GDPR)
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases:
- Consent (Art. 6(1)(a)) — for sending you the daily reading by email or push. You may withdraw consent at any time by unsubscribing (§9); withdrawal does not affect processing already carried out.
- Legitimate interests (Art. 6(1)(f)) — for security, rate limiting, and abuse prevention, balanced against your rights.
- Legal obligation (Art. 6(1)(c)) — where we must retain or disclose information to comply with law.
6. We do not sell or "share" your personal information
We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA) and similar U.S. state laws. We have not done so in the preceding 12 months. Because we do not sell or share, there is no "Do Not Sell or Share My Personal Information" action required — but you may still exercise the rights in §9.
8. Data retention
- Active subscribers: we keep your email address or push token for as long as you remain subscribed, so we can deliver the daily reading.
- Unsubscribes: when you unsubscribe, we deactivate delivery promptly. We may retain a minimal suppression record (e.g., a hashed or flagged entry) so that we do not accidentally re-contact you, consistent with anti-spam law.
- Security logs: IP/rate-limit and anti-abuse data are retained only for a short period necessary for security, then discarded or aggregated.
9. Your choices & privacy rights
Unsubscribing (available to everyone)
- Email: click the unsubscribe link in any email we send, or email us (§14).
- Push notifications: use "🔕 Turn off notifications" on the site, or revoke notification permission in your browser/device settings.
Legal rights
Depending on where you live (e.g., under GDPR/UK GDPR, the CCPA/CPRA, or other U.S. state laws), you may have the right to:
- Access / know what personal information we hold about you;
- Correct inaccurate information;
- Delete your information;
- Port a copy of your information;
- Withdraw consent and opt out of further messages;
- Not be discriminated against for exercising these rights;
- Lodge a complaint with your data protection authority (EEA/UK) or your state Attorney General.
To make a request, email hello@joytheeandme.com. We may need to verify your identity before acting on a request. You may use an authorized agent where the law allows. We will respond within the timeframe required by applicable law.
10. International data transfers
We are based in the United States, and our service providers (including Google) process data on infrastructure that may be located in the United States and other countries. Where we transfer personal information out of the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum) offered by those providers.
11. Children's privacy
The Off-Leash Oracle is intended for a general adult audience and is not directed to children under 13 (or under 16 in the EEA/UK). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us (§14) and we will delete it.
12. Security
We use reputable, security-hardened infrastructure (Google Firebase/Cloud), transport encryption (HTTPS/TLS), server-side abuse protection, and the principle of least privilege for administrative access. No method of transmission or storage is 100% secure, but we take reasonable and appropriate measures to protect your information and to limit what we collect in the first place.
13. Changes to this policy
We may update this policy as the service evolves or as the law changes. When we do, we will increment the version number and update the Effective Date and Last Updated fields at the top, and record the change in the Version History table below. Prior versions are preserved in our public source-control history so the exact policy in effect on any given date can be reconstructed. Material changes will be accompanied by additional notice where required by law.
14. Contact us
15. Version history
| Version | Effective date | Summary of changes |
|---|---|---|
| v1.0 | July 4, 2026 | Initial publication. Establishes privacy governance for email and web-push subscriptions: data minimization, double opt-in, processor disclosures (Firebase/Google, reCAPTCHA), GDPR legal bases, CCPA "no sale/share" statement, retention, rights, and version control. |
This document is version-controlled in the project source repository. The authoritative, timestamped change record — mapping each version to its effective date and commit — is maintained in CHANGE-CONTROL.md (Legal Document Register).