Legal
Privacy policy
Stars&Self is made by INTROVERX LLC. This policy covers the Stars&Self app for Android (com.starsandself.app) and this website. It says what we collect, why we collect it, who else sees it, how long we keep it and how to make it go away.
The short version: we do not sell your data, we do not run adverts, there is no advertising SDK anywhere in the app, and your birth details are never handed to a marketer. You can delete your account and everything in it from inside the app, and when you do, it is gone for good.
Contents
Who is responsible
INTROVERX LLC, a Wyoming limited liability company in the United States, is the controller of the personal data described here. You can reach us at support@starsandself.app about anything in this policy, and we answer to the same address you wrote from.
What we collect, and why
Your account
- Your email address, which signs you in, carries account email and lets us reply when you write to support.
- Your password, held only as a salted hash by our authentication provider. We cannot read it, and neither can anyone else. If you sign in with Google we never see a password at all: Google tells us your email address and name, and nothing more.
- Your name, if you give one. The app is happy without it.
- Your time zone and the hour you want your reading, so it lands in the morning where you actually are.
- Whether you opted in to marketing email, and the moment you did. Opting in is a separate, deliberate tick at sign-up. Leaving it alone means we only ever send you account email.
Your birth details
Your date of birth, your time of birth if you know it, and your place of birth, which we store as a place name plus its latitude and longitude. From those three things the app calculates your natal chart and keeps it, so it does not have to ask again. This is the whole point of the app: without a birth chart there is nothing to read. If you do not know your birth time you can say so, and the app works with what it has.
People you add
If you use compatibility, you enter a name and birth details for someone else. We treat that exactly like your own data: it is visible only to you, it is never used to build a profile of that person, and it disappears when you delete the entry or your account. Please only enter someone else's details if they are happy for you to. In law you are the one who decided to put them in.
How you use the app
- Your notification settings, and a push token that identifies your device to the notification service, so the reading you asked for can reach you.
- The thumbs up or down you leave on a reading. It tells us which writing lands and which does not.
- Whether you have an active subscription and when it runs out.
- Product analytics: screens opened, buttons tapped, app version, device model, operating system and language. These events are tied to your account id and email address, so that when something breaks we can tell whether it broke for you or for everybody.
Payments
Subscriptions and one-off reports are sold through Google Play. Google takes the money and holds the card. We never see your card number, your billing address or your full name from a purchase. Our subscription provider tells us that an account has a valid entitlement and when it expires, and that is all we get.
Support
When you write to support from inside the app, we receive your message, your email address and the version of the app you are running, which is usually the fastest way to work out what went wrong.
What we do not collect
No advertising identifiers. No advertising or attribution SDKs. No device location: the app never asks for the permission, and your birth place is a city you typed, not where you are standing. No contacts, no photo library, no microphone, no call or message logs, no background tracking, and no health records. The health topic inside the app is a horoscope theme, not a note about your health, and nothing in the app is derived from medical data. Images you share are drawn on your device and never uploaded to us.
Our legal bases
For people in the European Economic Area and the United Kingdom, the law wants us to name a basis for each use. Ours are:
- Performing our contract with you: your account, your chart, your daily readings, your reports, your saved people and your purchases. Without this data there is no service to give you.
- Your consent: marketing email, and push notifications where your device or your local law treats them as consent. You can withdraw either at any time, in the app or by asking us, without losing the rest of the service.
- Our legitimate interests: product analytics to see which parts of the app work, keeping the service secure and free of abuse, and answering your support messages. We use the least data that answers the question.
- Legal obligation: the records of a sale that tax and accounting rules require us to keep.
Who else sees it
A small number of companies process data on our behalf, under contract, only on our instructions, and each one only gets what its job needs.
- Supabase (database, sign-in and file storage, hosted in the European Union): your account, birth details, charts, saved people and generated reports.
- PostHog (product analytics, United States): usage events, your account id and email address, app version and device metadata.
- RevenueCat (subscription management, United States): your account id and the state of your purchases.
- Google (United States): Google Play for billing, Firebase Cloud Messaging for delivering notifications, and Google sign-in if you choose it.
- Expo (push delivery, United States): the push token for your device and the notification we ask it to deliver.
- Resend (transactional email, United States): the support messages you send us, so they reach our inbox.
- OpenStreetMap Foundation, Nominatim (place search, European Union): the text you type into the birth place field and your device's IP address, which is how it can offer you matching cities. Your name and account are not sent with it.
We also disclose data where the law genuinely requires it, and we will tell you when we are allowed to. If the app is ever sold or merged, your data moves with it, and you will be told before anything changes.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, in the sense those terms carry under United States state privacy laws. We never have.
Where your data lives
Your account, birth details, charts and reports are stored in the European Union, wherever in the world you are. Using the app from outside the EU means your data is transferred there and kept there. Some of the processors listed above are in the United States, so that data reaches them there too, and those transfers run on the European Commission's standard contractual clauses or on the EU-US Data Privacy Framework where the provider is certified under it. We are a United States company, so United States authorities can in principle compel disclosure under their own law; we disclose only what we are genuinely required to.
How long we keep it
- Account, chart, saved people and reports: until you delete them or delete your account. Account deletion removes them straight away. Encrypted backups roll off within 30 days.
- Support email: up to 24 months, so we can pick up a conversation you started last year.
- Analytics events: up to 12 months.
- Sales records: as long as tax and accounting law requires, typically seven years. These hold the fact of a purchase, not your chart.
Your rights
If you are in the European Economic Area or the United Kingdom you have the right to get a copy of your data, to correct it, to have it deleted, to restrict or object to what we do with it, to take it elsewhere in a portable form, and to withdraw any consent you gave. Withdrawing consent does not undo what was lawful before you withdrew it. You can also complain to your national data protection authority, and in the United Kingdom to the Information Commissioner's Office.
If you are in California, Colorado, Connecticut, Virginia, Utah, Texas or another state with a privacy law, you have the right to know what we hold, to get a copy, to correct it, to have it deleted, and to opt out of sale, sharing and targeted advertising. There is nothing to opt out of, because we do none of those. We will not treat you worse for asking about any of this.
Wherever you are, write to us and we will do the same thing for you.
How to use them
Most of it is already in the app. Profile holds your details, your notification settings and your marketing preference, and the Account section deletes everything (see deleting your account). For anything else, email support@starsandself.app. We reply within 30 days, usually much sooner, and we may ask you to write from the address on the account so that we are not handing your chart to a stranger.
Children
Stars&Self is for people aged 16 and over. It is not built for children, not marketed to them, and not rated for them. If you believe someone under 16 has an account, tell us at support@starsandself.app and we will delete it and everything in it.
How we protect it
- Everything travels over encrypted connections, and is encrypted at rest by our hosting provider.
- Passwords are salted and hashed. Nobody at Stars&Self can read yours.
- Row level security is switched on in the database, so a query made with your session can only ever return your own rows.
- Generated PDF reports live in a private bucket and are handed out through links that stop working after an hour.
- Deleting your account runs on the server against your own signed-in session, so nobody can delete an account that is not theirs.
No system is perfect. If you find a hole, please tell us at support@starsandself.app before you tell anyone else, and we will fix it.
Changes to this policy
The app will keep changing, and this page changes with it. When something material changes we will say so in the app or by email before it takes effect. The date at the top of this page is always the day it last moved.
Contact
INTROVERX LLC, a limited liability company registered in Wyoming, United States.
support@starsandself.app