Privacy Policy
Last updated: 22 August 2026. This policy covers every app Mystiva publishes.
The short version
You tell an app when and where you were born, because that is what an astrology app is for. We keep that, encrypted, so the app can do its work. We do not sell it, we do not use it for advertising, and every app can hand it all back to you or erase it from its own Settings, without writing to anyone first.
The rest of this page is the detail behind those four sentences. If the detail ever contradicts the summary, the detail is what governs.
Who is responsible
Mystiva is the studio that publishes these apps, and it is the data controller for the personal data described here. Reach the controller at [email protected] — the address is read by a person, and a data request sent there is answered within 30 days.
General support goes to [email protected]. Both reach the same person; the split exists so a data request is not lost in a queue of bug reports.
What we collect, and why
Your birth details
Date of birth, time of birth, and place of birth including its coordinates and time zone. Without them an astrological chart cannot be calculated at all, so this is the one category the apps cannot work without.
Stored encrypted at rest, in columns that are unreadable without a key held outside the database. Legal basis: performance of our agreement with you.
Your account
An e-mail address, and the sign-in codes sent to it. The address is stored encrypted. Legal basis: performance of our agreement with you.
What you write
Journal entries, notes, and messages you send to an app's chat. These are yours; we process them to show them back to you and, for chat, to answer. Legal basis: performance of our agreement with you.
Details about people you add
If you add someone else — a partner, a friend — to compare charts, you give us their birth details too. You are responsible for having their agreement to do that. We treat those details exactly as we treat yours, and deleting the connection deletes them.
Device and technical data
A device identifier the app generates for itself, the app version, the operating system, the language, and — if you turn on notifications — a push token from Apple or Google. IP addresses appear in server logs and in rate-limit counters. Legal basis: our legitimate interest in running a service that works and is not abused.
Your raw IP address is never written to the database — only a keyed hash of it, which is what lets you see and revoke your own sessions. Log lines pass a redaction filter before they are written: e-mail addresses, coordinates, birth dates and tokens are replaced, in ordinary messages and inside exception text alike. A test writes a log line containing an address and fails if the address survives.
Usage analytics
Which screens are opened and which steps are completed, so we can tell where the app confuses people. Analytics events are checked in the app itself against a list of forbidden property names and value shapes before they are sent: a birth date or an e-mail address in an analytics event is a bug that fails a test, not a policy choice. Legal basis: legitimate interest, or your consent where local law requires it.
Crash reports
When something breaks we receive the error and the line of code it happened on. The request body, the query string, the headers, the IP address and any structured log data are removed before the report leaves the device or the server. There is no session recording and no screen capture. Legal basis: legitimate interest in fixing faults.
What we never do
We do not sell personal data, and we do not share it with data brokers. We do not use it to target advertising, in our apps or anywhere else. We do not build profiles for anyone but you, and we do not make automated decisions that have legal or similarly significant effects on you.
We also never collect: precise device location, your contacts, your social accounts, advertising identifiers, or any special category of data under Article 9 GDPR — we do not ask about health, religion, sexuality, politics or ethnicity, and there is no field in which to answer.
Beliefs, health and other sensitive subjects
Astrology sits close to belief, and what you write in a journal may touch health, relationships or religion. We do not ask for any of it and we do not infer it: an app calculates positions from a date, a time and a place, and nothing in that calculation is a statement about you.
Anything sensitive in your data is there because you chose to write it. It is stored and deleted like the rest, and it is never used to categorise you.
Artificial intelligence
Some apps answer questions about your chart using a large language model run by a third-party provider. Three things go to that provider when you send a message:
- The parts of your chart the question needs — signs, aspects, orbs, house numbers. This part is assembled by code and carries no name, no birth date, no birth time, no coordinates, no e-mail and no account identifier; a test fails if any of them appears.
- Your message, word for word.
- A few earlier messages from the same conversation, word for word, so a follow-up question makes sense.
So anything you type yourself goes as you typed it. If you write your name, your e-mail address or a date into a question, that is what is sent — we do not collect it and do not store it separately, but we do not strike it out either.
Our provider is contractually barred from using what we send to train its models. You can use the rest of an app without using chat; where an app has an AI switch, turning it off stops these transfers.
Who else touches your data
Only these, and only to do a job for us. Each is bound by a data-processing agreement.
- Our hosting provider — servers in Germany, where the database lives.
- Our AI provider — the chat messages described above.
- Our analytics provider — usage events, EU-hosted.
- Our error-monitoring provider — crash reports, EU-hosted.
- Apple and Google — payment and subscription state; we never see your card.
We may also disclose data if the law requires it. If we are ever compelled to, we will tell you unless we are forbidden from doing so.
Where your data is
Stored in the European Union. The servers, the database, the analytics and the error monitoring are all EU-hosted, in Germany and Ireland.
Administered from the United States, where the controller named above lives. Running the service means being able to reach the servers, so data stored in the EU is accessible from the US. That access, and any processing by a provider outside the EU, runs on the European Commission's Standard Contractual Clauses.
Not yet appointed: a representative in the European Union under Article 27 GDPR. A controller established outside the EU that offers services to people in the EU generally has to name one, and this page will name theirs here.
How long we keep it
- Your account, birth details, charts, journal and chat — while the account exists. This is the product; there is nothing to show you without it.
- After you delete your account — erased, except as noted below. Immediately in effect, in practice within minutes, at most within 30 days.
- Sign-in codes — 15 minutes, then unusable. Long enough to read an e-mail, short enough to be worthless if leaked.
- Sign-in sessions — 30 days, rotated on every refresh, revoked at once on sign-out or if an old token is reused.
- Chat working memory — 24 hours in memory, then it expires on its own.
- Export files — 24 hours, or until you download them, whichever comes first. The link works once.
- Server logs — a short rolling window, then overwritten.
- Crash reports — at most 90 days, held by that provider.
- Backups — a deletion reaches them on the next backup cycle; the record described below covers the window in between.
One record outlives deletion on purpose: a one-line note that an account was deleted, when, and under which key it was recorded. It holds no personal data — the account is identified by an irreversible hash — and it exists so that restoring a database backup cannot quietly bring a deleted account back to life. It is kept in the database and in an append-only ledger beside it, because a backup old enough to resurrect an account is also old enough to take the proof of its deletion with it. Without that pair, a deletion is a promise nobody can check.
Your rights
If you are in the EU, the UK, or another place with comparable law, you have the right to see your data, correct it, take a copy of it elsewhere, have it erased, restrict or object to how we use it, and withdraw any consent you gave.
Two of those need no request. Every app can export everything it holds about you, and delete your account and its contents, from its own Settings. Export produces a machine-readable file. Deletion is real deletion, not a hidden flag.
The steps, and what survives a deletion, are on Delete your account — including how to ask if you have already uninstalled the app.
For anything else, write to [email protected]. We answer within 30 days. If we get it wrong you can complain to your national data protection authority; if you are in the EU that is the authority where you live.
Age
These apps are not for people under 16. We do not knowingly collect anything from a child under 16, and if we learn that we have, we delete it. If you believe a child has given us data, write to [email protected].
Security
Traffic is encrypted in transit. The fields that identify you — birth details, e-mail address — are encrypted in the database under a key that is not stored with it, and which our deployment pipeline never sees. Access to production is restricted to key-based authentication.
No system is perfect, and a policy that claims otherwise is lying. If we discover a breach that puts your rights at risk we will notify our supervisory authority within 72 hours and tell you without undue delay.
Changes
When this policy changes materially, the app asks you to read and accept the new version before you continue. That is a mechanism in the software, not a line in a document: a changed policy version re-opens the consent screen for every existing account.