Privacy Policy

Choreograph turns your own life data into art. That only works if you know exactly what it reads, where it goes, and how to make it stop.

Last updated 28 August 2026

Who we are

Choreograph (choreograph.cc) is operated by Ortomate Ltd, a company registered in New Zealand. Ortomate Ltd is the data controller for the personal information described in this policy. For anything in this document, write to privacy@choreograph.cc.

Choreograph is a small, personal art project. It is not an advertising business, it has no data-broker relationships, and it does not sell personal information to anyone, ever. What follows describes it as it actually works, not as a template.

The short version

  • You connect the services you want read. Nothing is collected from a service you have not connected.
  • Once a day, Choreograph assembles that day's data into a “data trail”, sends it to AI models to be interpreted, and produces a piece of art from it.
  • The art is published. The data trail is not. Your raw calendar entries, tasks, transcripts and health metrics are never shown on the public site.
  • Health and biometric data — sleep, heart rate, HRV, readiness, weight, body composition — is treated as sensitive. It is stored in a column that public pages cannot read.
  • We never sell your data, never use it for advertising, and never use it to train AI models.
  • You can disconnect any service at any time, and ask for everything to be deleted, at privacy@choreograph.cc.

What we collect

Choreograph collects two different things, and it is worth keeping them apart: the data you deliberately connect, and the small amount of ordinary information any website has.

1. Data from services you connect

Each of these is optional and separately connected. A service you have not connected is simply absent from the day, and the pipeline carries on without it.

OuraSleep duration, sleep efficiency and sleep score; average heart rate, lowest heart rate and average HRV; readiness score and body-temperature deviation; steps, distance, active and total calories, and activity score. Daily summaries only — no raw sensor streams.
FitbitDaily activity summary (steps, distance, calories) and sleep summary.
Apple HealthMetrics you choose to push from Health Auto Export, which may include weight and body composition, workouts, mindful minutes and State of Mind entries.
Google CalendarEvents in the calendars you nominate for the day in question: titles, times, locations and attendee names.
TodoistTasks created and completed on the day.
Limitless / FieldyLifelog transcripts of your day, from a device you wear and control. Used to find the day’s shape and the occasional overheard line.
GitHubCommit and repository activity authored by you. Organisations you place on a denylist are hard-redacted before anything leaves the collector.
LocationApproximate coordinates and the place, region and country name for the day, when you send them. Used to know where the day happened and to look up its weather.
WeatherConditions for the day at your location, retrieved from OpenWeatherMap. This is public data about a place, not about you.
About youA short profile you write yourself, so the artwork knows who it is about.

Some of this is health and biometric information, which is sensitive by law in most jurisdictions and is treated as sensitive here regardless of where you live. See Health and biometric data below.

2. Ordinary site information

  • Analytics. The site uses Plausible, a privacy-focused analytics service that sets no cookies, collects no personal data, and does not track visitors across sites. It records aggregate page views only.
  • Email address. If you have an account, we hold the address we send your daily and monthly letters to.
  • Server logs. Our hosting provider keeps short-lived request logs for security and debugging, in the normal way.
  • Cookies. The public gallery sets no tracking cookies. A signed session cookie is set only when someone logs into the private administrative area.

How we use it

There is one purpose, and everything else follows from it: to make a daily piece of art out of your own day, for you.

Concretely, each day the pipeline:

  • assembles the day's data trail from whichever services are connected;
  • sends it to AI models, which write a short interpretation of the day and a prompt describing an image;
  • generates the image, a short written piece, an audio companion, and — on a rotation — a video, a small browser game, or a 360° panorama;
  • stores a compact numeric digest of the day's signals so that monthly writing can say true things about longer arcs (“readiness under sixty for eleven days”) rather than guessing;
  • emails you when the piece is published, and once a month writes you a chapter about the month that just ended.

We do not use your data for advertising, profiling for third parties, credit or insurance decisions, resale, or training any AI model. See AI processing for how that last point is enforced with our providers.

What becomes public, and what never does

This is the most important section in the policy, so it is the most specific.

Published on the public site: the generated image, its title, the short written piece, the audio, and any video, game or panorama for that day, together with the date. Monthly chapters are published only when explicitly released.

Never published: your raw data trail. Calendar event titles and attendees, task lists, lifelog transcripts, commit messages, coordinates, and every health and biometric figure stay on the server. The numeric daily digest is held in a separate database column that public queries do not select, precisely so that a change to a public page cannot accidentally expose it. Lifelog transcripts are not retained at all — only the length of the day's transcript is recorded.

Also never published: the private half of a monthly chapter. Each chapter is written in two parts — a public memoir piece and a private, blunter reading addressed to you alone. The private part is excluded by name from every public query and reaches only you.

An honest caveat. The published artwork is an interpretation of your day, so by its nature it can carry traces of what happened in it — a mood, a place, an event, a phrase. If a day contained something you would not want reflected in a public piece, keep that day unpublished or ask us to remove it. Published pieces are indexed by search engines.

Health and biometric data

Sleep, heart rate, heart-rate variability, readiness, body temperature, weight and body composition are health information. They get specific handling:

  • They are collected only from services you have explicitly connected, and only for the purpose of making your own artwork.
  • They are never displayed on any public page, never included in the data sent to a browser, and never included in a published piece as a figure.
  • They are stored separately from the data the site publishes, so that publishing more of a page cannot start publishing them.
  • They are never sold, never shared for advertising, and never disclosed to anyone except the processors listed below, and only as needed to produce your art.
  • They are never used to make any decision about you, automated or otherwise, beyond what a picture ends up looking like.

Oura specifically. Oura data is used solely to generate your own daily and monthly pieces on Choreograph. It is not sold, not shared with any third party other than the AI processors listed below, not used for advertising or marketing, and not used to train any model. You can revoke Choreograph's access at any time from your Oura account at cloud.ouraring.com; collection stops immediately, and stored Oura data is deleted on request under Your rights.

Other people in your day

Your day contains other people: the colleague in the meeting, the friend in the conversation, the family at dinner. Their names can appear in a calendar entry or a transcript that Choreograph reads.

Those details are used only to interpret your day and are never published as data. The site does not build profiles of anyone other than the account holder, and it will not create an account for someone from another person's data. Deliberate constraints in the pipeline also limit how often recognisable people appear in the artwork at all.

If you appear in someone else's Choreograph and would rather not, write to privacy@choreograph.cc and we will deal with it.

AI processing

Making the art requires sending the day's data trail to third-party AI models. There is no way around that, so here is exactly what happens.

The trail is sent over encrypted connections to the providers listed in the next section. Those providers act as our processors: they handle the data on our instructions, to return a result, and are contractually barred from using it for their own purposes. We select providers on terms that exclude training on submitted data, and we use zero-data-retention or short-retention settings where they are offered.

Model output is generated, not verified. A written piece may contain an interpretation of your day that is inaccurate, unflattering, or simply wrong. It is art, not a record.

Who processes your data

We use these providers to run the service. Several are outside New Zealand, principally in the United States and the European Union, so using Choreograph involves your information being transferred and stored overseas. We rely on contractual protections — including Standard Contractual Clauses where applicable — to keep it protected to a comparable standard.

VercelHosting and the daily scheduled pipeline.
SupabaseDatabase and file storage for posts, generated media and encrypted credentials.
OpenRouter, with Anthropic (Claude)The writing and art-direction models. Receives the day’s data trail.
Google (Gemini)Image generation. Receives the generated image prompt.
ElevenLabsAudio generation. Receives the generated audio brief.
fal.aiVideo, panorama and music generation, running models including ByteDance Seedance and Flux. Receives the generated prompts.
ResendSending your notification emails.
OpenWeatherMapWeather lookup for the day’s location.
PlausibleCookieless, aggregate site analytics. Receives no personal data.
UpstashRate limiting. Receives request metadata only.

Your data may also be disclosed where the law requires it — a court order, a lawful request from a regulator — or where it is necessary to establish or defend a legal claim. If Choreograph is ever transferred to another operator, your data would transfer with it and you would be told first.

How it is protected

  • All traffic to and from the site, and to every provider above, is encrypted in transit.
  • The access tokens and API keys for your connected services are encrypted at rest with AES-256-GCM under a master key held outside the database, so a copy of the database alone does not yield them.
  • Public pages read the database through a restricted role that can only see published content. The unrestricted role is used only in server-side code that never runs in a browser.
  • The administrative area is behind a password and a signed session cookie, and is excluded from search engines.

No system is perfectly secure. If we discover a breach affecting your personal information, we will notify you and the Office of the Privacy Commissioner as required by the Privacy Act 2020.

How long it is kept

  • The raw data trail is not retained. It is assembled in memory for the day's run and discarded when the run finishes. What persists is the artwork, the written interpretation, and the numeric daily digest.
  • Lifelog transcripts are not retained — only the character length of the day's transcript.
  • Published pieces and their digests are kept indefinitely, because the gallery is a cumulative body of work. They are deleted on request.
  • Connected-service credentials are kept until you disconnect the service or close your account, then deleted.
  • Operational logs and job records are kept for a short period for debugging and then rotate out.

Your rights

Under the New Zealand Privacy Act 2020 you have the right to access the personal information we hold about you and to ask for it to be corrected. We extend the following to everyone, wherever you live, rather than only to those who can claim them:

  • Access — a copy of what we hold about you.
  • Correction — fix anything inaccurate.
  • Deletion — remove your pieces, your digests, your credentials, your account, or all of it.
  • Portability — your data in a machine-readable form.
  • Withdrawal of consent — disconnect any service, or all of them, at any time. Disconnecting stops collection from that point; it does not by itself delete what was already used, so say so if you want that too.
  • Objection and restriction — tell us to stop a particular use.

Write to privacy@choreograph.cc. We will respond within 20 working days, which is the Privacy Act standard and comfortably inside the 30 days the GDPR expects. There is no charge.

If you are unhappy with how we have handled a privacy matter, you can complain to the New Zealand Office of the Privacy Commissioner. If you are in the UK or the EEA, you may also complain to your local supervisory authority.

Children

Choreograph is not for children. You must be at least 16 to use it, and we do not knowingly collect information from anyone younger. If you believe a child has given us data, write to privacy@choreograph.cc and we will delete it.

Changes to this policy

If this policy changes we will update the date at the top of the page. If a change materially affects how your data is handled — a new category of data, a new purpose, a new class of recipient — we will email account holders before it takes effect, and where consent is the basis for the change we will ask for it again rather than assume it.

For the rules that govern using the site itself, see the Terms of Service.

Questions about this document, or about anything on this site, go to privacy@choreograph.cc. The companion document is the Terms of Service.