ORA · LAST UPDATED SEPTEMBER 29, 2026
Privacy Policy
Your inner world deserves care. Here is what Ora processes, why, and the choices you have.
Who operates Ora
Ora: Inner World is operated by Jiayi Sun. This policy covers the Ora website, iPhone app, paired Apple Watch app and widgets. For privacy requests, contact yaoyaohuayuan.us@gmail.com. You can read this policy without creating an account.
Accounts and sign-in
Ora stores an account identifier, username, creation time, settings and the contact details you provide. Password-based accounts store a one-way password hash, not a readable password. Recovery codes are stored as hashes. Session credentials are held in the iPhone Keychain or an HttpOnly browser cookie and expire after 30 days. When you use Sign in with Apple, Ora verifies Apple’s signed identity, stores the app-specific identifier and an encrypted refresh credential, and may receive an Apple private relay email. Ora does not request your full name from Apple. Signing in does not itself grant Premium.
Email and phone verification
One-time verification codes confirm control of an email address or phone number. Verified contacts are stored separately from legacy, unverified profile details; an unverified address alone does not recover an account. Codes expire after five minutes, allow a limited number of attempts, and are stored as hashes with expiry and attempt information. Security cleanup removes old challenges when subsequent requests run; this is not a promise of immediate deletion at expiry. Tencent Cloud delivers supported text-message codes. Email-code delivery is being prepared using Resend and is available only once configured. The delivery provider receives the destination address or phone number and verification message. A channel that is unavailable cannot send a real code.
Local records and optional cloud sync
Guest conversations, saved cards, mood and breathing activities, sound creations and preferences are stored on your device. Signing in does not automatically upload them. Guest data is copied into an account only when you choose to import it. If you enable cloud sync, Ora stores the current account’s conversations, saved moments, activity records, sound creations and preferences in its cloud database so you can use them across supported App and Web sessions. Switching cloud sync off deletes its current cloud snapshot while keeping local records.
Rara and DeepSeek processing
Only after you allow AI data sharing and request a response, Ora sends DeepSeek up to 30 recent messages, the original question, selected earlier conversation excerpts, relevant card readings, current activity and feeling context, your language and relevant enabled memories. This information is used to generate an AI response. Cloud sync and AI sharing are separate: using Rara sends this context even if cloud sync is off. Ora does not deliberately include your account identifier, email, phone number or IP address in the AI prompt. However, text you write can identify you. DeepSeek processes the information under its applicable terms and privacy policy; we do not promise zero retention or that information already sent can be recalled. Do not include passwords, payment details, recovery codes or information you do not want the provider to receive.
Optional Rara memory
Memory requires a separate opt-in. It can store up to 50 explicitly shared facts, such as your preferences or goals, with supporting quotations and timestamps. Review individual memories or use Forget all in Settings to delete them. Switching memory off stops new collection and use; it does not itself delete existing memories.
Subscriptions and Apple
Apple processes your payment; Ora does not store your payment-card details. To verify access, Ora stores transaction and original transaction identifiers, product, environment, expiry, renewal and refund or revocation status associated with your Ora account. Your account identifier is also sent to Apple as the appAccountToken. Server notifications update subscription status. Limited transaction records, including the account token and ownership information, remain after account deletion to prevent reassignment and handle subscriptions or disputes. Deleting an Ora account does not cancel billing through Apple.
Watch, widgets and device permissions
The paired iPhone and Watch exchange an account or guest-space identifier, selected deck, language, quote theme, favorites, playback state and controls. Card, mood and breathing records are first saved locally and transferred to the corresponding Ora space on iPhone. They are uploaded only if that account has enabled cloud sync. Premium access is verified through Apple; designated internal owner and review accounts can also verify access through a limited server token. Quote widgets display public daily content rather than private chat messages. Ora does not read heart rate or Apple Health data. Motion data is used locally for card reflections and the sound bowl. Notifications support local reminders. Ora does not request contacts, photos or device location, or record microphone audio. Sound creations contain instrument settings and note sequences, not microphone recordings.
Security and diagnostic information
Servers receive network information such as IP addresses. Ora uses hashed IP and account-related keys, request counts and time windows for security and rate limits. Application error records contain request identifiers, error codes, upstream response status and retry information, without conversation text or explicit account identifiers. Hosting infrastructure may process additional request metadata to maintain and protect the service. There are no advertising or third-party behavioral tracking SDKs in the current implementation. Ora does not sell personal data or use it for targeted advertising.
Service providers and international processing
Ora uses Sites hosting with Cloudflare Workers and database services, DeepSeek for requested AI responses, Apple for supported sign-in and purchases, Tencent Cloud for supported verification texts, and Resend when verification email delivery is enabled. Support messages currently go to a Gmail mailbox, which receives your email address, message and any attachments you send. We may ask for device and app versions, an error message and reproduction steps. Service providers may process data outside your country. Network transmission is encrypted. Provider-specific retention, infrastructure logs and backups are subject to applicable service arrangements and policies; this policy does not promise a particular storage country or a fixed deletion period for all provider records.
Your choices, rights and retention
You can withdraw AI sharing in Settings to stop new AI requests on that device. You can switch off cloud sync, review and delete memories, and delete your account. Account data, synced content and memories are generally kept to provide your chosen features until you remove them or delete the account. Security information is retained for abuse prevention and service operation; limited transaction records are retained as described above. Depending on your location, you may have rights to access, correct, delete or obtain your data, object to or restrict certain processing, withdraw consent, or complain to a relevant privacy authority. Contact support for a request you cannot complete in the app. We may need to verify your identity. Necessary account and service processing supports the features you request; optional AI sharing, cloud sync and memory follow your separate choices.
Account deletion
Open Ora → Space → Settings → Delete account. Complete the identity verification and confirmation appropriate to your sign-in method. The account deletion guide page explains the separate password, Apple and verification-code paths. Deletion removes the account profile, sessions, linked verified contacts, memories and cloud-synced content, and clears current-device account content. Offline devices may retain local copies. Limited transaction, security and provider records described above may remain. Cancel Apple subscriptions separately.
Updates and contact
We update this policy and its date when practices change and seek additional permission when required. For privacy, access, correction or deletion assistance, email yaoyaohuayuan.us@gmail.com. DeepSeek’s policy is available at https://cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html and Apple’s at https://www.apple.com/legal/privacy/.
Questions? yaoyaohuayuan.us@gmail.com