Legal

Privacy Policy

Last updated: August 2026

What we process

The engine is stateless: request bodies (birth data, coordinates, questions) are computed in memory and are not written to disk or retained. We do not store birth charts, journals, or profiles. Request logs store only the key identifier prefix, endpoint path, HTTP status, latency, and timestamp for rate limiting, quota accounting, and abuse prevention.

Account data

Portal accounts store an email address, password hash (never plaintext), and role. Order records store the email and plan used at checkout. This data is used to operate the service, send service messages, and provide invoices.

Data protection

API keys are stored as SHA-256 hashes; plaintext keys are shown once at creation. Traffic is encrypted in transit (TLS 1.3). We do not sell personal data and do not use it for advertising or AI training.

Your rights

You may request access, correction, or deletion of your account and order data at any time by contacting us. Because the engine stores no birth data, there is no stored birth data to export or erase — a data subject request can be satisfied from account data alone.

Subprocessors

We use Cloudflare (edge hosting, D1 database, Analytics Engine), the payment provider active on your checkout, and our email provider. A current subprocessor register is available on request.

Cookies

The portal uses an authentication session cookie when you sign in. No third-party advertising cookies are set.