Orthodox Study

The web edition

Privacy

DraftThis page was written alongside the code it describes. Shane reads and signs it before launch; until then, treat it as an accurate account of what the software does rather than as a settled legal document.

Reading is open and anonymous. Today's readings, the Reader, the Library and search ask for no account, keep no record of who read what, and set no cookie of ours. You meet this page only because of Study — the companion that answers questions from the Library — which needs an account and costs money to run.

What an account holds

Your email address. A sign-in code has to reach you, and a subscription has to have an owner. There is no password to lose and no profile to fill in.

A session. Signing in sets one cookie holding a random token so the site knows you on your next visit. Only a hash of that token is stored here, so the cookie in your browser is the only copy. A session lasts ninety days from your last visit.

A line for each answer. When the companion finishes an answer we record which model ran, how many tokens went in and out, what it cost us, and which kind of turn it was — a first question, a follow-up, a passage read alongside. That line is how your monthly usage is counted.

Your question and the answer are not recorded. Neither is written to a database, and neither appears in a log. What the companion was doing while it worked is logged without them.

A hashed trace of the address you connect from, kept only against a request for a sign-in code, so a flood of them can be slowed. It is one-way and mixed with the date, so the same address becomes a different value tomorrow.

What leaves your device

Your question, the last few turns of the conversation, and the passages the companion gathered from the Library are sent to an AI provider, reached through OpenRouter. There is no way to write an answer without sending them. What the provider does with what it receives is governed by its policy, not this one.

The passages you gather on the Study table stay in your browser, and so do your notes, the answers you keep and your past conversations — the questions you asked and the answers you were given, held across visits so you can reopen them. They are not uploaded, not synced between your devices, and not visible to us. Clearing your browser's storage for this site clears them, and so does Clear all under Past conversations.

Signing in, and paying

The six-digit sign-in code is delivered by Resend, which sees your address and the code. The sign-in form is guarded by Cloudflare Turnstile, which checks that a person and not a script is asking; it is the one third-party script the site loads, and only on the sign-in panel.

Payment is handled by Stripe. Card details are entered on Stripe's own pages and never reach this site — we hold only the customer and subscription identifiers Stripe gives back, and the record that a payment happened.

How long it is kept

A sign-in code expires ten minutes after it is sent, and once. A session ends ninety days after you last used it, or the moment you sign out — so a reader who comes back within that span keeps one, and a reader who stops is signed out. Usage lines are kept for the billing period they belong to and ninety days after it, then reduced to totals; that reduction is planned and not yet running, so today those lines stay until you delete the account.

Deleting your account

Delete account in the account menu does it. Your email address, your session, your grants and every usage line go in one operation, and any subscription is cancelled first. What survives is the list of billing events Stripe requires us to be able to reconcile, with your account identifier removed from them, so what is left names nobody. What this browser kept is separate: it lives on your device, never here. The conversation you are in goes with the account either way. Your study table, your notes, your kept answers and your other past conversations are cleared only if you tick the box on the confirmation; leaving it unticked leaves those past conversations in this browser, readable by anyone who uses the device afterwards.

What this site does not do

No analytics. No advertising. No mailing list. No profile built from what you read, no record of which passages you opened, and no third-party script beyond Turnstile on the sign-in panel and Stripe's own payment and billing pages. Nothing here follows you to another site.

The phone app is separate

The Orthodox Daily Readings app is local-first and account-less: it needs no network, and nothing about your reading leaves the phone. It keeps its own policy, unchanged by anything on this page —read it here.

Questions

Write to smccusker22@gmail.com.

Ask about this

Opens in Study with this context for you to review. Answers require sign-in and access.

In the margin · source text