Empire of Light
Version v2 · Effective 2026-08-15 · Empire of Light (Media Marketing Resource LLC)
This Covenant is part of your contract with us. It is incorporated by reference into the Terms and Conditions and is legally binding on us — not a statement of values we can quietly revise. Where this Covenant and any other policy of ours conflict, the reading more protective of you governs.
This is the human contract. The Privacy Policy and the Consumer Health Data Privacy Policy carry the legal detail; nothing in them takes away a promise made here.
Empire of Light meets you where you are. To do that, the system pays attention to how you learn: the way you express ideas, where your strengths already live, where your growth wants to go, and which way of teaching serves you best. Your wheel is built from that attention.
We pay attention to how you learn so the teaching can meet you. That is the whole purpose. Specifically, the system observes:
From these it maintains your wheel scores, your learning profile, and your teacher match.
Your inner work is never ranked, never scored against another person, never put on a board — ever. It is shared only if you choose to share it.
What you give to this community is a different thing. When you show up, share what you're learning, or help someone else through a hard stretch, we may make that visible and celebrate it. Your growth is private. Your generosity can be seen. We will never blur the two — and nothing you do or don't do in community will ever change what your wheel says, what you are taught, or what you can reach.
That last sentence is a technical guarantee, not a sentiment: no measure of community participation is an input to your scoring, your teaching selection, your pacing, or your access.
Your data summary is available in your account at any time — your scores, your profile, and what the system has learned about how you learn.
Every field we store about you is listed, in plain language, in our data covenant manifest, which you can read yourself at any time without logging in. That list is not decoration: the software physically refuses to store a field that is not declared on it. An attempt to write an undeclared field fails on the spot rather than saving. We cannot quietly start collecting something new.
Email us and we will send you your data, in a readable format, verified against your registered address. Our commitment is 30 days; in practice we aim for 48 hours. Nothing is export-exempt — every category we hold is classified as exportable, and our system rejects any category that is not.
Two honest details. We do not yet have a self-serve export button — a person at Empire of Light runs it for you. Building that button is on our roadmap, and until it exists we will not claim otherwise. And for a few internal categories — the raw statistical estimates the engine uses, and our own housekeeping — we send you the list of what is held rather than the raw values, because those numbers are genuinely meaningless outside the math that produces them. Everything that is about you in a readable sense comes back in full.
Ask and we will erase you — fully, not "deactivated." You can start the request yourself with the Request erasure button on your Personal Data & Rights page, or by email; either way a person completes it, and we write to you when it is done. This is a real deletion: your records are removed, not flagged as hidden. There is no soft-delete anywhere in that path. We will not substitute de-identification for deletion when you have asked us to delete.
A person does this, not a script running unattended — and we think that is the better way.
Most services hand deletion to an automated job. You click, something is queued, and nobody ever confirms it finished. We do it the other way round:
Our commitment is 30 days; we aim for 48 hours. The tradeoff is honest: the button on your rights page starts the request instantly, and a person still completes it. An unattended delete button would be faster still — a person checking is more thorough, and we would rather be slow and certain than instant and unconfirmed.
What remains afterward: anonymous, aggregated counts that never carried your identity in the first place — there is no record there to erase, because none was ever written. Payment records held by our payment processor are kept as long as tax and accounting law requires; that is their obligation and ours, and we cannot delete those early.
Not to advertisers, not to brokers, not to anyone. We do not sell or share it for advertising of any kind, and we do not use your assessment responses, your conversations with your teacher, or your community content to train anyone's AI models.
One honest exception, stated plainly: if Empire of Light or Media Marketing Resource LLC is ever acquired or merges, your information would transfer with the business — that is how acquisitions work, and we will not pretend otherwise. If that ever happens, this Covenant transfers with it and continues to bind whoever holds your data, we will notify you before the transfer takes effect, and you will have the chance to export and delete first. We have no such plans.
When the system notices something about how you learn, it shows up as better teaching — and where it serves you, we tell you what we noticed.
The system improves by learning from everyone's patterns together. That learning is de-identified: trends, not people. What makes the teaching better for the next thousand learners carries no one's name.
Your Wheel is our good-faith reading — built from cited wisdom, careful engineering, and attention to your actual practice, and refined continuously with the real people who walk it.
It is not a clinical assessment, a diagnosis, or a scientifically validated measurement of you, and we will never pretend otherwise. When the mirror is uncertain, it says less and asks more.
Your assessment responses and your conversations with your teacher are processed by Google Cloud's Vertex AI (model: Gemini 2.5 Flash), running inside our own Google Cloud project in the United States. That processing is keyless — there is no shared API key — and your content is not used to train Google's models.
We do not send your assessment responses, your conversations, or your community content to any other AI provider. (We use a separate service, OpenRouter, to generate marketing images and website copy. It never receives anything about you.)
If we ever change which model or provider processes your data, we update this promise and the Privacy Policy in the same change. The current, code-verified list of everyone who processes your data is in the Privacy Policy, Section 5.
This is the part most services do not explain, so we will.
Your conversations and your scoring are kept apart — in the code, not just in policy.
The Wheel is not one system. It is several, and each one is a separate service with its own key to the storeroom. Those keys are deliberately incomplete:
That is the shape of it: the closer a service gets to judging you, the less of you it is allowed to see. The only unrestricted key belongs to you.
Some things are never used to score you, ever: what your teacher remembers from your conversations, your practice history, and anything you say in a moment of crisis. Those are recorded so the teaching can be continuous and humane — not so you can be measured by them.
A few more protections, plainly:
None of this is a promise about intentions. It is how the software is built, and it is checked automatically every time we ship.
The usual bargain online is that personalization costs you privacy: the more a service knows about you, the better it serves you. We built the Wheel to refuse that trade. Here is the idea, in plain language.
The teaching material is written and curated before you ever arrive. It is a large library of passages drawn from named wisdom traditions — every one checked, tagged with the book it came from, and marked with how it may be used. Nobody generates a theory about you and then writes teaching from it.
When you speak, your words are used as a lookup key, not as a subject of study. The system asks the library a question — which of these already-written passages actually meets this moment? — and a small handful come forward. Those passages, not you, shape what you receive. Personalization here means which pre-authored material surfaces for you, not what a machine has concluded about you.
That is also why the teaching can name its sources. It is drawing on cited material rather than inventing, and it is instructed never to quote something it was not given and never to invent a source.
When a response is composed, the model receives a deliberately thin slice: what you just said, a short rolling window of the immediately preceding exchange, and the selected library passages.
It does not receive your name, your email, your account identifier, your scores, or any internal measure of your ability. Those live in compartments the conversational side of the system is structurally forbidden to read — not by policy, but in running code that raises an error rather than handing them over. It also does not receive your full history. The window is short and it moves; older exchanges fall out of it. There is no growing transcript of your life being shipped anywhere.
We would rather tell you this than let you discover it.
Your words do leave, to compose your reply and to score your responses. They go to Google's Vertex AI, inside our own cloud project, without a shared key, and they are not used to train anyone's models. What protects you is not that your sentences never travel — it is that your identity never travels with them, and the window is short. Anyone who tells you their AI teaching happens without your words reaching a model is either running something very limited or not telling you the whole story.
And personalization here is a selection mechanism, not a redaction mechanism. We are not claiming to scrub your sentences. We are claiming that the system is built so the sentence and the person are kept apart, and so the judgment about you never travels with the words.
Because the alternative — one system that knows everything about you and decides everything for you — is exactly the shape that makes people careful about what they say. And a person being careful with a teacher learns less. The compartments exist so you can be honest, which is the only condition under which any of this works at all.
Automated safety screening runs on messages you send your teacher. If it detects language suggesting you may be in crisis, teaching stops and you are offered real crisis resources immediately — automatically, never waiting on a human.
When that happens, a person is alerted — and the alert deliberately contains none of your words. It carries the system's decision and nothing you said. A human then follows up; our commitment is within 24 hours. We are a small team and we will not tell you we are here 24/7, because we are not.
Crisis exchanges are never scored. No measurement of you is produced from them — that is enforced in the code, not merely intended. They are never used to match you to a teacher and never enter our analytics. The only record kept is a safety-event entry noting that a flag occurred and what the system did, containing no text you wrote, and you can see it in your data view and have it erased.
The boundary we hold: Empire of Light is education for human growth. It is not therapy, medical care, or crisis services, and your teachers here — human and AI — are not a substitute for licensed professionals. If you are working with a therapist or clinician, this work can sit alongside that; it does not replace it.
If you are in crisis in the U.S., call or text 988 (Suicide & Crisis Lifeline). Outside the U.S., see the international directory linked from our Legal Hub.
Honesty in your responses (the wheel can only be true if you are), care in community spaces, and patience with the gates — the timing is part of the teaching.
Covenant version v2, effective 2026-08-15. Supersedes v1 (2026-06-10). Consent is captured at account creation with a version stamp stored per learner; existing learners are re-prompted on material change. Age gate: 18+.
Changes in v2: Promise 1 scoped to inner work with an explicit community firewall · Promise 5 states the acquisition exception honestly and binds any acquirer · Promise 9 added, naming the actual AI processor after a code-level trace · safety section now states the 24-hour human-review capacity · anti-bundling and no-quiet-change commitments added · the whole document made contractually binding via incorporation into the Terms.
Questions? Reach us at email us. Empire of Light is a registered fictitious business name of Media Marketing Resource LLC, Citrus Heights, California.