Legal
Privacy policy
Draft — takes effect at launch · pending legal review
The summary below is the policy as we'd explain it across a table. The detail follows it. If the two ever seem to conflict, tell us — the summary is what we intend.
The short version
We collect what the product needs to work: your email, the birth data you enter, your charts, and basic product analytics. Birth data is sensitive and we treat it that way — encrypted at rest, never sold, never given to advertisers or data brokers, never used to train AI models. You can export everything we hold about you, or delete your account and have it all removed. Payments are handled by Stripe; we never see your card number.
What we collect
Account data. Email address and sign-in method (email, Google, or Apple).
Birth data.The birth dates, times, and places you enter — your own, and those of people you create charts with. By entering someone else's birth data you confirm you have the right to do so (see the Terms). Birth data exists to compute charts; it has no other use here.
Charts and content. The charts you create, the places you save, and the generated interpretations attached to them.
Payment data. Handled entirely by Stripe. We store your subscription status and tier, not your card details.
Product analytics. Which features get used, where flows break, and errors — via PostHog and Sentry. No advertising pixels, no cross-site tracking.
Where it lives, who touches it
Data is stored with Supabase (PostgreSQL, encrypted at rest). The services that process data on our behalf: Supabase (database and authentication), Stripe (payments and tax), Vercel (hosting), Resend (transactional email and, if you opt in, the newsletter), PostHog (product analytics), Sentry (error tracking), and Anthropic (generating chart interpretations for paid charts — the request contains the minimum chart data needed and, per Anthropic's API terms, is not used to train models). We don't sell personal data to anyone, full stop.
Your rights
From your account settings you can export a complete archive of your data, or delete your account. Deletion is soft for 30 days (in case you change your mind), then permanent. If someone else entered your birth data and you want it removed, write to us and we'll handle it — you don't need an account to make that request.
Newsletter
The newsletter is opt-in with a confirmation step, monthly, and every issue carries a one-click unsubscribe. Signing up for the product does not subscribe you to marketing email.
Contact
Privacy questions and data requests: [email protected].