Privacy Notice

How constellatedself handles your data

Who we are

constellatedself is operated by Quiet Reason (quietreason.ch), the data controller for the personal data described here. To exercise any of your rights or ask questions, contact us via the details on our website.

What data we collect and why

  • Account data — your name, email address, and a hashed password (bcrypt). Used to operate your account (legal basis: contract).
  • Signup waitlist — when registration is full, we store the name (if provided) and email address you submit so we can notify you when signups reopen (legal basis: consent).
  • Birth data — names, birth dates, times, and locations you save. Used solely to compute charts and generate readings you request (legal basis: contract). Only enter other people's birth details if you have their permission.
  • Readings — AI-generated readings (astrological, tarot, I Ching) and the prompts used to generate them are stored on our server so you can revisit them without regenerating. Prompts contain the birth data you supplied for that reading.
  • Interactive reading state — tarot deals and I Ching casts temporarily store your question, selected chart reference, and deal/cast outcome so the flow can survive a server restart. This state expires after 30 minutes and is erased with your account.
  • Terms acceptance — the version of the Terms of Use you accepted, when you accepted it, and the IP address used, kept as a record of the agreement (legal basis: legal obligation / legitimate interest).
  • Preferences and codes — display settings and any free-token or discount codes redeemed on your account.
  • Technical logs — server logs (which may include your IP address and email) kept for 7 days for security and debugging (legal basis: legitimate interest). AI usage logs record token counts and your email, never the content of prompts or readings.

Cookies

We use only strictly necessary cookies — no advertising, analytics, or tracking cookies of any kind, and no third-party cookies. Because these cookies are essential for the service to function, no consent banner is required.

CookiePurposeLifetime
stars_sessionKeeps you signed in (session token)30 days
pending_verification_emailShows your email on the “verify your email” page during signup1 hour

Third-party processors

We share the minimum data needed with these processors to provide the service:

  • Anthropic and Google (Gemini) — chart details (birth date, time, place, name as entered) are sent to generate AI readings you request. We have opted out of the use of this data for model training where such controls exist.
  • Resend — delivers transactional email for account verification and password resets; processes your email address.
  • OpenStreetMap Nominatim — the location text you type is sent for geocoding (converted to coordinates). Only the place name is sent, never your account details.
  • Stripe — processes one-time token-bundle payments. If you buy tokens, your email address and payment details are handled by Stripe; we never see or store your card number. Stripe also sends payment receipts to your email address.

Fonts and all other assets are served directly from our own server; no requests are made to CDNs or font services.

Data retention

  • Completed readings (including their prompts): kept until you move them to trash; readings in trash are permanently deleted after 30 days unless you restore or permanently delete them sooner.
  • Account and birth data: kept until you delete your account.
  • Signup waitlist entries: kept until signups reopen and the notification process is complete, or deleted sooner on request. An entry is removed automatically if that email creates an account.
  • Reading requests that failed or never completed: purged automatically after 30 days.
  • Temporary tarot-deal and I Ching-cast sessions: inaccessible after 30 minutes and deleted by the maintenance process (or immediately with account deletion).
  • Server and AI usage logs: rotated after 7 days. Because deletion actions themselves are logged for security and audit purposes, an email address may remain in these logs for up to 7 days after account deletion.
  • Local token-purchase, token-charge, and Stripe-customer mappings: erased with the account. Stripe retains its own payment records under its legal and regulatory obligations.
  • Password-reset and verification tokens: expire after 1–24 hours.
  • Terms-acceptance records: kept while the account exists and erased with the account.

Your rights

Under the GDPR and the Swiss FADP you have the right to access, rectify, export, and erase your personal data, to restrict or object to processing, and to lodge a complaint with a supervisory authority. You can delete individual saved charts in the app at any time, and delete your account yourself from the Settings page. Account access is disabled immediately; after a 30-day grace period during which you may restore it, application data and local billing mappings are permanently erased. Short-lived security and audit log entries then expire within the 7-day log-retention period described above. To exercise any other right, contact us and we will respond within 30 days.

Security

All traffic is encrypted (HTTPS). Passwords are stored only as bcrypt hashes. Session cookies are HttpOnly and Secure.

Last updated: July 2026

← Back