Astro Assistant

Home Türkçe

Privacy Policy

Last updated: 13 September 2026

This policy applies to the Astro Assistant mobile app (iOS and Android, package name co.msastro.assistant) and to the information pages on assistant.msastro.co.

This text replaces the privacy policy of the pre-registration website that was previously published at this address. That text only described the pre-registration form; it did not cover the app, the natal chart, the artificial intelligence or purchases.

Every technical detail written here was taken from the app's and the server's own code — there is not a single sentence written as "it is probably like this". If the code changes, this page changes too.


Short summary

If you are not going to read the long text, at least know this:

1. Data controller and contact

ASTRO LABS TEKNOLOJİ LİMİTED ŞİRKETİ
Maslak Mah. Ayazağa Cad. B2 Blok No: 842
Email: [email protected]

The data controller within the meaning of the Turkish Personal Data Protection Law No. 6698 (KVKK) and the controller within the meaning of the European Union General Data Protection Regulation (GDPR) is the company above. The address you should write to for every privacy-related question, request and application: [email protected]

2. What data we collect, and how

2.1. What you enter

DataHow it reaches usRequired?
Date of birthYou type it while setting up the appYes — the app does not work without a chart
Time of birthYou type itNo — you can say "I don't know my time". The time field then stays empty and this choice is stored as a flag; your ascendant and house placements are not calculated
Place of birth: city name, country, latitude/longitude, IANA time zone and the UTC offset at the moment of birthYou type the name of the city and pick it from the list that appears; the coordinates and time zone belong to the city you pickedYes
Your question texts (8–500 characters)You write themIf you ask a question
The reason you select and the free-text note you write when reporting an answerYou write itNo
The like / dislike you give an answerYou tap itNo
Your nameComes from Google/Apple; you can change it in Settings or clear it completely (at most 60 characters)No

2.2. What comes from Google or Apple

There is no sign-up with email + password in the app. There is only Continue with Google or Continue with Apple, and the sign-in is verified through Firebase Authentication. During this, the following reach us:

We do not see, keep or reset your password. The security of your account depends on the security of the Google or Apple account you use.

2.3. Data generated automatically

DataWhere it comes from
Account identifier (a random UUID)Generated when the account is opened; this is your public identifier used in support correspondence and in links. Along with your account details, your database row number is also returned to the app; both go only to your own device, and not to the artificial intelligence provider or any other third party
Interface language, country code, time zone offset, platform (ios/android)Derived from your device's language and region settings. The country code comes from your device's local settings, not from a location service
Last seen timeUpdated at every sign-in
The information that you opened and read an answer (read marker)Marked when you open the answer for the first time
Your natal chart: planet positions, houses, aspects, element and modality distributionCalculated on our server with Swiss Ephemeris from the birth details you gave
The category of your question and — if a period is mentioned in the question — the date range of that periodProduced by the artificial intelligence pipeline
The full prompt sent to the artificial intelligence, the model's raw answer and the record of the pipeline stepsStored while the answer is being produced
Purchase records and question credit movementsWritten when a purchase is verified and when a credit is spent
Your notification token (FCM registration token) and the token's platformOnly if you grant the notification permission; the token is produced by the operating system and the app sends it to our server. For details see section 2.4
Which reminder notification was last sent to you and whenWritten so that the same text is not sent over and over and so that the sending frequency can be adjusted
Your IP addressIn two places: (1) for rate limiting (60 requests per minute), temporarily — this use is not stored in a table linked to your account; (2) if a web session is opened on assistant.msastro.co, the IP address, the browser identifier (user agent) and — if a sign-in happened in that session — the account number are kept as a session record in the sessions table on our server. The mobile app does not use this session mechanism; the app works with a token and does not open a web session. For the lifetime of session records see section 8

What we do not collect: phone number, address, ID number, card or IBAN details, contacts, photos, audio, health data, device advertising ID (IDFA/AAID), device fingerprint, crash/diagnostic telemetry, web browsing history.

We do not measure behaviour — no usage statistics such as screen views, taps or session duration are kept; there is no tool in the app that measures this. The only exception is the three fields we store for the product's own function and listed above: the like/dislike vote you give an answer, the information that you opened and read an answer, and your last seen time. In the store privacy forms these three are declared as "app interaction".

2.4. Notifications and the notification token

The app sends you two kinds of notification:

For this we take a notification token (Firebase Cloud Messaging registration token) from your device. This token is a string the operating system produces in order to deliver the notification to the right device; it is stored together with your account and with the platform information (ios/android).

3. Why we process your data and what our legal basis is

DataPurposeLegal basis
Name, email, provider identifiers, avatar, account identifierOpening your account, recognising you, being able to give you supportPerformance of a contract (KVKK art. 5/2-c · GDPR art. 6/1-b)
Date, time and place of birth, coordinates, time zone and the calculated chartDrawing your natal chart — this is the service itselfPerformance of a contract (KVKK art. 5/2-c · GDPR art. 6/1-b)
Your question texts and the answers producedAnswering your question, keeping the answer in your listPerformance of a contract (KVKK art. 5/2-c · GDPR art. 6/1-b)
Sending the question text and the chart block to OpenAIProducing the answerYour explicit consent (KVKK art. 5/1 and art. 9/1 · GDPR art. 6/1-a and art. 49/1-a) — see section 4
Language, country code, time zone, platformShowing the interface in the right language and with the right timePerformance of a contract and legitimate interest (KVKK art. 5/2-f · GDPR art. 6/1-f)
Purchase records, question credit movementsVerifying your payment, granting your credit once, preventing the same receipt from being used again, resolving refund disputesPerformance of a contract and legal obligation (KVKK art. 5/2-ç · GDPR art. 6/1-c)
Answer reports, likes, IP-based rate limiting, abuse detectionCatching harmful content, keeping the service up, preventing fraudLegitimate interest (KVKK art. 5/2-f · GDPR art. 6/1-f)
Your notification token (FCM registration token) and its platformLetting you know when the answer is ready for the question you askedPerformance of a contract (KVKK art. 5/2-c · GDPR art. 6/1-b) — it is the message telling you that the service you asked for has been delivered
Your notification token and your last-send recordSending you a reminder notification if you have not opened the app for a whileYour explicit consent — the notification permission you gave on the device (KVKK art. 5/1 · GDPR art. 6/1-a). It ends the moment you turn it off in Settings; see section 2.4
Last seen timeSeeing whether your account is active, matching support requestsLegitimate interest (KVKK art. 5/2-f · GDPR art. 6/1-f)

We do not ask for special category (sensitive) data. There is no field in the app for health, religion, political opinion, sexual orientation or ethnic origin. Writing such a thing in your free-text question is your own choice; the text you write is processed in the same way as other question texts and is deleted after the same period. We recommend that you do not write such information in your question.

4. Artificial intelligence: what goes to OpenAI and what does not

Answers are produced with OpenAI's language model. The model is gpt-4o-mini, the endpoint https://api.openai.com/v1/chat/completions. No human astrologer reads your question and writes the answer.

What goes

When you ask a question, the pipeline makes four calls to OpenAI:

  1. Topic check — only your question text.
  2. Category determination — only your question text.
  3. Date extraction — your question text and today's date.
  4. Answer generation — the block derived from your natal chart and your question text.

The block that goes out in the fourth step looks like this. The line layout is fixed, but the marked lines are added only if their condition is met — that is, the block that goes out is not exactly the same for everyone:

NATAL CHART
Sun: Cancer, house 10
Moon: Pisces, house 6
Ascendant: Taurus                              [K1]
Midheaven: Aquarius                            [K1]
Mercury: Cancer, house 11, retrograde
Venus: Leo, house 12
... (the Mars, Jupiter, Saturn, Uranus, Neptune, Pluto, Chiron, North Node,
     South Node, Lilith, Juno, Pars Fortuna lines continue in the same format)
ASPECTS (strongest first)                      [K2]
Sun trine Moon, orb 2.31, applying             [K2]
ELEMENTS fire 2, earth 4, air 1, water 3
MODALITIES cardinal 3, fixed 5, mutable 2
NOTE: the birth time is unknown, so houses and the Ascendant are left out. Do not mention houses.   [K3]
PERIOD IN QUESTION: 2026-10-01 to 2026-12-31   [K4]

QUESTION
<the question text written by the user>

The markers in square brackets do not appear in the prompt; they were added here to show which lines are conditional:

The system message that goes alongside it is largely fixed: astrological style rules and the language the answer is to be written in. In addition, if your question has been classified into a topic heading, that heading (such as love, career, health) and a short guidance sentence belonging to that heading are appended to the end of the system message. Your name, your email address, your user ID and your birth details do not appear in the system message.

What does not go

So OpenAI sees a chart block and a question, without knowing who you are.

The answer produced comes back to us; we store the answer, the prompt that was sent and the model's raw response linked to your account (why, and for how long: section 8).

Your explicit consent

The app does not send anything you write to the model without taking your consent:

Withdrawing your consent

Let us be honest: there is no "I withdraw my consent" button inside the app. The consent record you gave stays until your account is deleted.

There are two ways to withdraw your consent:

  1. Stop asking questions. The consent only operates when you ask a question; as long as you do not ask a question, nothing goes to OpenAI.
  2. Delete your account. Deletion takes the consent record and everything alongside it (section 9).

If neither of these suits you, write to [email protected]; we will remove the consent record by hand, and from that moment on you cannot ask questions but your account stays. Withdrawal takes effect for the future: it does not retroactively invalidate answers produced before the withdrawal.

5. Place of birth search and location

This is the most misunderstood part, so we write it plainly:

6. Purchases and payment

Question credits are sold in three consumable packs (pack_3, pack_5, pack_10). There is no subscription.

Accounting and invoicing are not on our side but on Apple's and Google's side; the official record of the sale is their payment reports. The purchase row in our database is removed 30 days after you delete your account (section 8).

7. Who we share with, and transfers abroad

We do not sell your data, and we do not give it to advertising networks, data brokers or measurement partners. The parties we transfer data to, and what goes to each of them:

RecipientWhereWhat goesLegal basis
OpenAI (artificial intelligence provider)USAYour calculated chart block and your question textYour explicit consent (KVKK art. 9/1 · GDPR art. 49/1-a)
Google — Firebase Authentication and Sign in with GoogleUSAYour authentication information during sign-in (ID token)Performance of a contract
Apple — Sign in with Apple and App Store Server APIUSA / IrelandAuthentication for sign-in; for purchase verification, only the transaction numberPerformance of a contract
Google — Play Developer APIUSAApp package name, product code, purchase tokenPerformance of a contract
Google — Firebase Cloud Messaging (notifications)USAYour device's notification token together with the notification's title and text. In the "answer is ready" notification the text carries an excerpt of at most 60 characters from the question text; in reminder notifications none of your data appearsPerformance of a contract for the "answer is ready" notification, your explicit consent (the notification permission) for the reminders
Apple — Apple Push Notification serviceUSAThe same notification content, in order to deliver the notification to the iOS device; Google's infrastructure passes the token on to AppleThe same as above
OpenStreetMap / NominatimEuropeThe city name you typed for your place of birth — without identityPerformance of a contract
Our server and infrastructure providersDigitalOcean · Amsterdam, the Netherlands (EU)Technical access to data within the scope of hostingLegitimate interest
Authorised public institutions and organisationsTürkiyeOnly when legally required, and only as far as requestedLegal obligation

What you need to know about transfers abroad:

Access inside the company: only our authorised personnel can access questions and answers, through the admin panel, for support and abuse review. This access is limited to what the work requires.

8. How long we keep your data

The periods in this table are not estimates; they were read from the scheduled jobs on the server.

DataPeriodWhat happens afterwards
Name, email, provider identifiers, avatar linkUntil you delete your accountEmptied at the moment of deletion
Date, time and place of birth, coordinates, time zoneUntil you delete your accountPermanently deleted at the moment of deletion
Your calculated natal chartUntil you delete your accountPermanently deleted at the moment of deletion
Your question texts, the answers, the prompt that was sent, the model's raw response, the pipeline recordsUntil you delete your account — there is no automatic cleanupPermanently deleted at the moment of deletion
The questions you delete from the appThey come off your list, they stay in the databaseWhen you delete your account they are permanently deleted too
Your answer reports (the reason + your note)Until you delete your accountPermanently deleted at the moment of deletion
Your notification token (FCM registration token)Until you turn notifications off, the token becomes invalid, or you delete your accountDeleted immediately when you turn it off in Settings. If the provider treats the token as invalid (if you deleted the app, or the operating system refreshed the token) it is deleted at the first failed send. On account deletion it goes along with the other data
Purchase records and question credit movements30 more days after you delete your accountPermanently deleted at the end of the 30th day
The raw store response of a purchase12 monthsIts content is emptied automatically; the purchase row remains
The deleted account row itself (the random account identifier, language, country code, time zone, platform, remaining credit count, dates)30 daysA cleanup job that runs every night at 03:10 permanently deletes the row
Place of birth search query24 hours of cacheDrops automatically; it is not linked to your identity anyway
Your session token (mobile app)Until you sign out or delete your accountOn deletion all tokens are revoked and your device signs out immediately
Your IP address — rate limitingFor the duration of the rate limiting windowDrops automatically
Web session record (session identifier, IP address, browser identifier, account number if any)120 minutes after the last activity (the session lifetime setting on the server)The session becomes invalid and its record is cleared from the session table on the server
Server logs (storage/logs)No time limit — the file does not rotate or get deleted automaticallyCleared by hand; for details and content see the note below

About the server logs. The server writes to a single log file in error and warning situations. These lines may contain personal data: your account number, your question's database number, the purchase transaction number, the platform and product code, and also the city name you typed while searching for a place of birth (if an error occurs while the search is being sent to the external service). Your question text, the answers, your date of birth, your time of birth, your coordinates, your name and your email address are not written to the logs. There is no automatic rotation or deletion setting on the server for the log file; the file is cleared by hand. Like every other period written here, this one is not an estimate either — it was read from the server's log settings. If we define an automatic retention period, this line will be updated.

9. Deleting a question versus deleting your account

These two are not the same thing, and should not be confused:

When you delete a question, that question and its answer are removed from your list. The record carries on sitting in the database, and the question credit you spent does not come back. The app tells you exactly this ("This question and its answer will be removed from your list"); it does not say "will be permanently deleted" — because that is not what happens.

When you delete your account, real deletion happens. With the Settings > Delete my account step, after two confirmations, the following are deleted there and then, and permanently:

At the same time your identity fields are emptied: Firebase identifier, Apple identifier, email, name, avatar link, verification and password fields.

What stays behind for 30 days: the account row itself (the random account identifier that no longer carries an identity, the language, country code, time zone, platform, remaining credit count and dates), together with the purchase and question credit records. These are kept for store refund disputes and for the accounting trail. When the 30 days are up, all of it is permanently deleted.

If you sign in again with the same Google or Apple account, a brand new and empty account is opened. Because the identity fields were emptied, the old row cannot be matched with you under any circumstances; your old chart, your questions and your remaining credits do not come back.

If you cannot access the app, you can also send a deletion request by email. Step-by-step explanation: Account Deletion.

10. How to exercise your rights

Your rights under KVKK art. 11

In respect of your personal data, you have the right to request the following:

There is a limit on correction inside the app, and we are not hiding it. You can change your birth details (date, time, place) from inside the app only once; once you have used this right, the app hides the correction step. The limit exists to stop the chart from being recalculated over and over. This does not take away your right to correction: if you have used your one-off change and your information is still wrong, write to [email protected] and we will make the correction. The same route applies if something is wrong in another field that cannot be changed in the app.

Your rights under GDPR

If you are in the European Union you also have the following rights: access (art. 15), rectification (art. 16), erasure (art. 17), restriction of processing (art. 18), data portability (art. 20), objection (art. 21) and rights relating to automated decision-making and profiling (art. 22). For processing based on consent, you can withdraw your consent at any time (art. 7/3) — how to do it is written in section 4.

How to apply

Write to [email protected]. If you want to make a written application, you can also send it to our company address.

Your right to complain

If we reject your application, if you find the answer we gave insufficient, or if we do not answer in time:

11. Children

Astro Assistant is not an app aimed at children, and it is not marketed to children.

Instead of writing a condition here that we cannot enforce, we write the truth: there is no age verification inside the app. We ask for your date of birth, but we use it for the chart calculation, not as an age gate. The range the server accepts is between 1 January 1900 and today; dates outside this range (a future date, or a date before 1900) are turned down. No date within the range is refused on the basis of age.

The checks that actually work are these:

If you are not of age, you should only use the app with the knowledge and permission of your parent or guardian. If you notice that a child has opened an account without your knowledge, write to [email protected]; we will delete the account and its data.

12. Security

The measures we take:

No system is one hundred per cent secure; we are not guaranteeing that to you. If you notice a security vulnerability, write to [email protected]. If we determine that your personal data has been unlawfully obtained by others, we will notify the relevant authority and — where necessary — you, in accordance with KVKK art. 12/5 and GDPR art. 33–34.

13. Cookies and tracking

14. Automated decisions and profiling

Your natal chart is calculated automatically and the answers are produced automatically. You are using it knowing this; this is what the app does.

That said, we do not take any automated decision that produces legal effects concerning you or that similarly significantly affects you. The answers are for entertainment; they are not an assessment, a score, a credit decision, a hiring decision or anything of the sort. Answers produced by artificial intelligence can be wrong; when you get a disturbing or irrelevant answer, use the "Report this answer" link underneath the answer — reports reach a human.

15. Changes to this policy

We may update this policy. The current text takes effect from the date it is published on this page, and the "Last updated" date at the bottom of the page changes.

If we make a substantial change — especially if the places the data goes or the purposes of the processing change — we will tell you inside the app. If the scope widens in a processing that is based on explicit consent, we will take your consent again; we do not use old consent for a new purpose.

16. Contact

ASTRO LABS TEKNOLOJİ LİMİTED ŞİRKETİ
Maslak Mah. Ayazağa Cad. B2 Blok No: 842
Email: [email protected]

Related pages: Terms of Use · Support · Account Deletion

Last updated: 13 September 2026
ASTRO LABS TEKNOLOJİ LİMİTED ŞİRKETİ · Maslak Mah. Ayazağa Cad. B2 Blok No: 842 · [email protected] Privacy Policy · Terms of Use · Support · Account Deletion · Türkçe