This policy applies to the Astro Assistant mobile app (iOS and Android, package name co.msastro.assistant) and to the information pages on assistant.msastro.co.
This text replaces the privacy policy of the pre-registration website that was previously published at this address. That text only described the pre-registration form; it did not cover the app, the natal chart, the artificial intelligence or purchases.
Every technical detail written here was taken from the app's and the server's own code — there is not a single sentence written as "it is probably like this". If the code changes, this page changes too.
Short summary
If you are not going to read the long text, at least know this:
- What we collect: your name, email address and user ID coming from your Google or Apple account; your date, time and place of birth; the natal chart calculated from them; the questions you write and the answers you receive; your purchase records.
- What goes to the artificial intelligence: the placements derived from your natal chart (the signs and houses of your planets, your ascendant, your aspects) and the question text you wrote. Your date of birth, your time of birth and your place of birth are not sent as they are. Your name, your email address, your user ID and your payment details are not sent either.
- What we do not do: we do not sell your data, we do not use it for advertising. We did not put our own advertising, analytics or crash reporting tool in the app; there is no tracking, no cookies, we do not read the advertising ID. But Google's own SDK for signing in with Google is inside the app, and that SDK states in its own manifest that it collects data — we wrote plainly what that is in section 13.
- We do not use device location. The app does not ask you for location, camera, contacts, microphone or photo permission. The only device permission we ask for is the notification permission; and we ask for it not at first launch but after you have asked your first question. If you grant it, we receive a notification token from your device — what that is is written in section 2.4. If you do not want it, the app works just the same, and you can turn notifications off whenever you want.
- We do not see your card details. Payment stays entirely inside the App Store and Google Play.
- You can delete your account from the app. The moment you delete it your personal data is gone; the rows that remain as an accounting record are also permanently deleted after 30 days.
1. Data controller and contact
ASTRO LABS TEKNOLOJİ LİMİTED ŞİRKETİ
Maslak Mah. Ayazağa Cad. B2 Blok No: 842
Email: [email protected]
The data controller within the meaning of the Turkish Personal Data Protection Law No. 6698 (KVKK) and the controller within the meaning of the European Union General Data Protection Regulation (GDPR) is the company above. The address you should write to for every privacy-related question, request and application: [email protected]
2. What data we collect, and how
2.1. What you enter
| Data | How it reaches us | Required? |
|---|---|---|
| Date of birth | You type it while setting up the app | Yes — the app does not work without a chart |
| Time of birth | You type it | No — you can say "I don't know my time". The time field then stays empty and this choice is stored as a flag; your ascendant and house placements are not calculated |
| Place of birth: city name, country, latitude/longitude, IANA time zone and the UTC offset at the moment of birth | You type the name of the city and pick it from the list that appears; the coordinates and time zone belong to the city you picked | Yes |
| Your question texts (8–500 characters) | You write them | If you ask a question |
| The reason you select and the free-text note you write when reporting an answer | You write it | No |
| The like / dislike you give an answer | You tap it | No |
| Your name | Comes from Google/Apple; you can change it in Settings or clear it completely (at most 60 characters) | No |
2.2. What comes from Google or Apple
There is no sign-up with email + password in the app. There is only Continue with Google or Continue with Apple, and the sign-in is verified through Firebase Authentication. During this, the following reach us:
- Your email address. If you used "Hide My Email" on Apple, the address that arrives is the relay address ending in
@privaterelay.appleid.com; we store that too, so that support can reach you. - Your Firebase user ID and — if you signed in with Apple — your Apple user ID.
- Your name and the link to your profile photo (avatar URL). These are filled in only if they are empty in your account; a name you change in the app is not written back by the provider at your next sign-in.
We do not see, keep or reset your password. The security of your account depends on the security of the Google or Apple account you use.
2.3. Data generated automatically
| Data | Where it comes from |
|---|---|
| Account identifier (a random UUID) | Generated when the account is opened; this is your public identifier used in support correspondence and in links. Along with your account details, your database row number is also returned to the app; both go only to your own device, and not to the artificial intelligence provider or any other third party |
| Interface language, country code, time zone offset, platform (ios/android) | Derived from your device's language and region settings. The country code comes from your device's local settings, not from a location service |
| Last seen time | Updated at every sign-in |
| The information that you opened and read an answer (read marker) | Marked when you open the answer for the first time |
| Your natal chart: planet positions, houses, aspects, element and modality distribution | Calculated on our server with Swiss Ephemeris from the birth details you gave |
| The category of your question and — if a period is mentioned in the question — the date range of that period | Produced by the artificial intelligence pipeline |
| The full prompt sent to the artificial intelligence, the model's raw answer and the record of the pipeline steps | Stored while the answer is being produced |
| Purchase records and question credit movements | Written when a purchase is verified and when a credit is spent |
| Your notification token (FCM registration token) and the token's platform | Only if you grant the notification permission; the token is produced by the operating system and the app sends it to our server. For details see section 2.4 |
| Which reminder notification was last sent to you and when | Written so that the same text is not sent over and over and so that the sending frequency can be adjusted |
| Your IP address | In two places: (1) for rate limiting (60 requests per minute), temporarily — this use is not stored in a table linked to your account; (2) if a web session is opened on assistant.msastro.co, the IP address, the browser identifier (user agent) and — if a sign-in happened in that session — the account number are kept as a session record in the sessions table on our server. The mobile app does not use this session mechanism; the app works with a token and does not open a web session. For the lifetime of session records see section 8 |
What we do not collect: phone number, address, ID number, card or IBAN details, contacts, photos, audio, health data, device advertising ID (IDFA/AAID), device fingerprint, crash/diagnostic telemetry, web browsing history.
We do not measure behaviour — no usage statistics such as screen views, taps or session duration are kept; there is no tool in the app that measures this. The only exception is the three fields we store for the product's own function and listed above: the like/dislike vote you give an answer, the information that you opened and read an answer, and your last seen time. In the store privacy forms these three are declared as "app interaction".
2.4. Notifications and the notification token
The app sends you two kinds of notification:
- The "your answer is ready" notification. It arrives when the answer to the question you asked has been produced, and tapping it opens that answer's screen directly. So that you can tell which question it is, the text of the notification contains a short excerpt from the question text you wrote yourself (at most 60 characters).
- The reminder notification. If you have not opened the app for a while, a short reminder picked from a ready-made list of texts arrives. None of your data appears in it. The moment you open the app the counter resets and the reminders become less frequent.
For this we take a notification token (Firebase Cloud Messaging registration token) from your device. This token is a string the operating system produces in order to deliver the notification to the right device; it is stored together with your account and with the platform information (ios/android).
- When we ask for the permission: not at first launch. We ask after you have sent your first question, while you are waiting for the answer — so that what the notification is good for is self-evident at that moment.
- If you do not grant the permission no token is created, nothing is sent to our server, and the rest of the app works just the same.
- Turning notifications off: you can turn off the Settings > Notifications switch inside the app; when you turn it off your token is deleted from the server and no notification is sent to you. If you prefer, you can also turn them off from your device's system settings (iOS: Settings > Astro Assistant > Notifications; Android: Settings > Apps > Astro Assistant > Notifications). You can turn them back on whenever you want.
- Where your token goes: in order to deliver the notification to your device, the token and the notification's title/text pass through Google's Firebase Cloud Messaging infrastructure, and on iOS additionally through Apple Push Notification service. For details see section 7.
- No marketing. There is no advertising, no third-party promotion and no profile derived specially for you inside these notifications; the reminder texts are fixed and come from the same pool for everyone.
3. Why we process your data and what our legal basis is
| Data | Purpose | Legal basis |
|---|---|---|
| Name, email, provider identifiers, avatar, account identifier | Opening your account, recognising you, being able to give you support | Performance of a contract (KVKK art. 5/2-c · GDPR art. 6/1-b) |
| Date, time and place of birth, coordinates, time zone and the calculated chart | Drawing your natal chart — this is the service itself | Performance of a contract (KVKK art. 5/2-c · GDPR art. 6/1-b) |
| Your question texts and the answers produced | Answering your question, keeping the answer in your list | Performance of a contract (KVKK art. 5/2-c · GDPR art. 6/1-b) |
| Sending the question text and the chart block to OpenAI | Producing the answer | Your explicit consent (KVKK art. 5/1 and art. 9/1 · GDPR art. 6/1-a and art. 49/1-a) — see section 4 |
| Language, country code, time zone, platform | Showing the interface in the right language and with the right time | Performance of a contract and legitimate interest (KVKK art. 5/2-f · GDPR art. 6/1-f) |
| Purchase records, question credit movements | Verifying your payment, granting your credit once, preventing the same receipt from being used again, resolving refund disputes | Performance of a contract and legal obligation (KVKK art. 5/2-ç · GDPR art. 6/1-c) |
| Answer reports, likes, IP-based rate limiting, abuse detection | Catching harmful content, keeping the service up, preventing fraud | Legitimate interest (KVKK art. 5/2-f · GDPR art. 6/1-f) |
| Your notification token (FCM registration token) and its platform | Letting you know when the answer is ready for the question you asked | Performance of a contract (KVKK art. 5/2-c · GDPR art. 6/1-b) — it is the message telling you that the service you asked for has been delivered |
| Your notification token and your last-send record | Sending you a reminder notification if you have not opened the app for a while | Your explicit consent — the notification permission you gave on the device (KVKK art. 5/1 · GDPR art. 6/1-a). It ends the moment you turn it off in Settings; see section 2.4 |
| Last seen time | Seeing whether your account is active, matching support requests | Legitimate interest (KVKK art. 5/2-f · GDPR art. 6/1-f) |
We do not ask for special category (sensitive) data. There is no field in the app for health, religion, political opinion, sexual orientation or ethnic origin. Writing such a thing in your free-text question is your own choice; the text you write is processed in the same way as other question texts and is deleted after the same period. We recommend that you do not write such information in your question.
4. Artificial intelligence: what goes to OpenAI and what does not
Answers are produced with OpenAI's language model. The model is gpt-4o-mini, the endpoint https://api.openai.com/v1/chat/completions. No human astrologer reads your question and writes the answer.
What goes
When you ask a question, the pipeline makes four calls to OpenAI:
- Topic check — only your question text.
- Category determination — only your question text.
- Date extraction — your question text and today's date.
- Answer generation — the block derived from your natal chart and your question text.
The block that goes out in the fourth step looks like this. The line layout is fixed, but the marked lines are added only if their condition is met — that is, the block that goes out is not exactly the same for everyone:
NATAL CHART
Sun: Cancer, house 10
Moon: Pisces, house 6
Ascendant: Taurus [K1]
Midheaven: Aquarius [K1]
Mercury: Cancer, house 11, retrograde
Venus: Leo, house 12
... (the Mars, Jupiter, Saturn, Uranus, Neptune, Pluto, Chiron, North Node,
South Node, Lilith, Juno, Pars Fortuna lines continue in the same format)
ASPECTS (strongest first) [K2]
Sun trine Moon, orb 2.31, applying [K2]
ELEMENTS fire 2, earth 4, air 1, water 3
MODALITIES cardinal 3, fixed 5, mutable 2
NOTE: the birth time is unknown, so houses and the Ascendant are left out. Do not mention houses. [K3]
PERIOD IN QUESTION: 2026-10-01 to 2026-12-31 [K4]
QUESTION
<the question text written by the user>
The markers in square brackets do not appear in the prompt; they were added here to show which lines are conditional:
[K1]is written only if you gave your time of birth. If you said "I don't know my time", your ascendant, your midheaven and all house information appear nowhere in the prompt.[K2]is written only if there are calculated aspects in your chart; the ten strongest aspects are listed.[K3]is added only if your time of birth is unknown.[K4]is added only if a period is mentioned in your question (for example "the next three months").
The system message that goes alongside it is largely fixed: astrological style rules and the language the answer is to be written in. In addition, if your question has been classified into a topic heading, that heading (such as love, career, health) and a short guidance sentence belonging to that heading are appended to the end of the system message. Your name, your email address, your user ID and your birth details do not appear in the system message.
What does not go
- Your raw date of birth, your time of birth, the name of your place of birth and its coordinates do not go. What goes to the model is the sign–house–aspect placements calculated from them with Swiss Ephemeris. The date of birth, the time, the city name and the coordinates appear nowhere in the prompt.
- Your name, your email address and your avatar link do not go.
- Your user ID does not go — neither your database number nor your account identifier (UUID).
- Your purchase and payment details do not go.
So OpenAI sees a chart block and a question, without knowing who you are.
The answer produced comes back to us; we store the answer, the prompt that was sent and the model's raw response linked to your account (why, and for how long: section 8).
Your explicit consent
The app does not send anything you write to the model without taking your consent:
- Before you start your first question, a "Use of artificial intelligence" screen appears. The screen says exactly the same as what is written above: your chart block and your question text go to OpenAI, your date, time and place of birth do not go as they are.
- The moment you say "I accept", the date and time of your consent is recorded to your account.
- If there is no consent record, the question endpoint turns the request down; you cannot ask a question without giving your approval. This is not a checkbox, it is a rule enforced on the server.
- The consent lives in your account, not on the device; it stays the same even if you change your phone or delete and reinstall the app.
- If you say "Cancel" you carry on using the app — you see your chart, you change your settings — you just cannot ask questions.
Withdrawing your consent
Let us be honest: there is no "I withdraw my consent" button inside the app. The consent record you gave stays until your account is deleted.
There are two ways to withdraw your consent:
- Stop asking questions. The consent only operates when you ask a question; as long as you do not ask a question, nothing goes to OpenAI.
- Delete your account. Deletion takes the consent record and everything alongside it (section 9).
If neither of these suits you, write to [email protected]; we will remove the consent record by hand, and from that moment on you cannot ask questions but your account stays. Withdrawal takes effect for the future: it does not retroactively invalidate answers produced before the withdrawal.
5. Place of birth search and location
This is the most misunderstood part, so we write it plainly:
- The app never uses your device's location. It does not ask for location permission; there is no location permission text on the iOS side, and no location permission is declared on the Android side. There is no call in the code that reads location.
- You find your place of birth by typing it. The city name you type comes to our server, our server searches for it through Nominatim (OpenStreetMap) and returns a list to you.
- The only thing that goes to Nominatim is the text you typed. Who you are, your account and your identifier do not go. Our server makes this request with the identifier
AstroAssistant/1.0; this is a requirement of OpenStreetMap's terms of use. - The search endpoint does not even require a sign-in, and the search text is not linked to your account. So that the same search is not repeated, the query is kept in a cache on our server for 24 hours; the cache key is a digest of the query text and contains no user identifier.
- The latitude/longitude we store is not where you are, it is the birth city you selected, and it exists only to calculate your chart correctly.
6. Purchases and payment
Question credits are sold in three consumable packs (pack_3, pack_5, pack_10). There is no subscription.
- We do not see your card details. The payment stays inside the App Store or Google Play; only the store's "this purchase is genuine" answer reaches us.
- What we send to the store for verification: to Apple, only the transaction number; to Google, the app package name, the product code and the purchase token.
- What we keep in our database: the platform, the product code, the transaction number, the original transaction number, the purchase token, the number of question credits granted, the status, the verification time and the raw response returned by the store.
- What the raw response contains: the account and order information on the store side. It is kept because a chargeback or refund dispute is argued over this record; it is automatically emptied after 12 months (by a cleanup job that runs weekly), while the purchase row itself remains.
- Rejected purchase attempts are also recorded, for abuse tracking.
Accounting and invoicing are not on our side but on Apple's and Google's side; the official record of the sale is their payment reports. The purchase row in our database is removed 30 days after you delete your account (section 8).
7. Who we share with, and transfers abroad
We do not sell your data, and we do not give it to advertising networks, data brokers or measurement partners. The parties we transfer data to, and what goes to each of them:
| Recipient | Where | What goes | Legal basis |
|---|---|---|---|
| OpenAI (artificial intelligence provider) | USA | Your calculated chart block and your question text | Your explicit consent (KVKK art. 9/1 · GDPR art. 49/1-a) |
| Google — Firebase Authentication and Sign in with Google | USA | Your authentication information during sign-in (ID token) | Performance of a contract |
| Apple — Sign in with Apple and App Store Server API | USA / Ireland | Authentication for sign-in; for purchase verification, only the transaction number | Performance of a contract |
| Google — Play Developer API | USA | App package name, product code, purchase token | Performance of a contract |
| Google — Firebase Cloud Messaging (notifications) | USA | Your device's notification token together with the notification's title and text. In the "answer is ready" notification the text carries an excerpt of at most 60 characters from the question text; in reminder notifications none of your data appears | Performance of a contract for the "answer is ready" notification, your explicit consent (the notification permission) for the reminders |
| Apple — Apple Push Notification service | USA | The same notification content, in order to deliver the notification to the iOS device; Google's infrastructure passes the token on to Apple | The same as above |
| OpenStreetMap / Nominatim | Europe | The city name you typed for your place of birth — without identity | Performance of a contract |
| Our server and infrastructure providers | DigitalOcean · Amsterdam, the Netherlands (EU) | Technical access to data within the scope of hosting | Legitimate interest |
| Authorised public institutions and organisations | Türkiye | Only when legally required, and only as far as requested | Legal obligation |
What you need to know about transfers abroad:
- Our own servers are in the Netherlands (DigitalOcean, Amsterdam). Your birth data, your chart, your questions and your answers are kept on this server; it is within the borders of the European Union. In KVKK terms this is also a transfer abroad, while in GDPR terms it is inside the European Economic Area.
- OpenAI's, Google's and Apple's servers are largely in the United States of America. This means that the data leaves Türkiye and the European Union.
- The transfer to OpenAI is made only with your explicit consent. If you do not give your consent, no question is asked and nothing goes to OpenAI.
- The transfers made to Google and Apple for sign-in and purchase verification are technically necessary for the service to work; these companies are subject to their own privacy policies.
- The notification transfer only happens if you grant the notification permission. If you do not grant it, no token is created and nothing goes to Google or Apple. When you turn notifications off, your token is deleted from our server and the transfer stops.
- The data protection legislation of these countries may not be the same as that of Türkiye and the EU.
- The legal safeguard for the transfer: these transfers abroad are based on your explicit consent (KVKK art. 9 · GDPR art. 49/1-a). You give this consent in three separate places: by accepting this Privacy Policy when you sign up, on the artificial intelligence consent screen that appears before you ask your first question, and when the notification permission is requested. You can withdraw all three separately — [email protected] for the artificial intelligence consent, the app's Settings screen for notifications, and account deletion for all of it. The transfer to OpenAI is in any case made with your explicit consent; if you do not give your consent, the transfer never happens.
Access inside the company: only our authorised personnel can access questions and answers, through the admin panel, for support and abuse review. This access is limited to what the work requires.
8. How long we keep your data
The periods in this table are not estimates; they were read from the scheduled jobs on the server.
| Data | Period | What happens afterwards |
|---|---|---|
| Name, email, provider identifiers, avatar link | Until you delete your account | Emptied at the moment of deletion |
| Date, time and place of birth, coordinates, time zone | Until you delete your account | Permanently deleted at the moment of deletion |
| Your calculated natal chart | Until you delete your account | Permanently deleted at the moment of deletion |
| Your question texts, the answers, the prompt that was sent, the model's raw response, the pipeline records | Until you delete your account — there is no automatic cleanup | Permanently deleted at the moment of deletion |
| The questions you delete from the app | They come off your list, they stay in the database | When you delete your account they are permanently deleted too |
| Your answer reports (the reason + your note) | Until you delete your account | Permanently deleted at the moment of deletion |
| Your notification token (FCM registration token) | Until you turn notifications off, the token becomes invalid, or you delete your account | Deleted immediately when you turn it off in Settings. If the provider treats the token as invalid (if you deleted the app, or the operating system refreshed the token) it is deleted at the first failed send. On account deletion it goes along with the other data |
| Purchase records and question credit movements | 30 more days after you delete your account | Permanently deleted at the end of the 30th day |
| The raw store response of a purchase | 12 months | Its content is emptied automatically; the purchase row remains |
| The deleted account row itself (the random account identifier, language, country code, time zone, platform, remaining credit count, dates) | 30 days | A cleanup job that runs every night at 03:10 permanently deletes the row |
| Place of birth search query | 24 hours of cache | Drops automatically; it is not linked to your identity anyway |
| Your session token (mobile app) | Until you sign out or delete your account | On deletion all tokens are revoked and your device signs out immediately |
| Your IP address — rate limiting | For the duration of the rate limiting window | Drops automatically |
| Web session record (session identifier, IP address, browser identifier, account number if any) | 120 minutes after the last activity (the session lifetime setting on the server) | The session becomes invalid and its record is cleared from the session table on the server |
Server logs (storage/logs) | No time limit — the file does not rotate or get deleted automatically | Cleared by hand; for details and content see the note below |
About the server logs. The server writes to a single log file in error and warning situations. These lines may contain personal data: your account number, your question's database number, the purchase transaction number, the platform and product code, and also the city name you typed while searching for a place of birth (if an error occurs while the search is being sent to the external service). Your question text, the answers, your date of birth, your time of birth, your coordinates, your name and your email address are not written to the logs. There is no automatic rotation or deletion setting on the server for the log file; the file is cleared by hand. Like every other period written here, this one is not an estimate either — it was read from the server's log settings. If we define an automatic retention period, this line will be updated.
9. Deleting a question versus deleting your account
These two are not the same thing, and should not be confused:
When you delete a question, that question and its answer are removed from your list. The record carries on sitting in the database, and the question credit you spent does not come back. The app tells you exactly this ("This question and its answer will be removed from your list"); it does not say "will be permanently deleted" — because that is not what happens.
When you delete your account, real deletion happens. With the Settings > Delete my account step, after two confirmations, the following are deleted there and then, and permanently:
- All your questions and answers — including the ones you previously removed from your list
- The prompts sent to the artificial intelligence, the model's raw responses and the pipeline records
- Your answer reports
- Your notification token and your send records — no more notifications go to your device
- Your birth details: date, time, place, coordinates, time zone
- Your calculated natal chart
- All your session tokens — your device signs out immediately
At the same time your identity fields are emptied: Firebase identifier, Apple identifier, email, name, avatar link, verification and password fields.
What stays behind for 30 days: the account row itself (the random account identifier that no longer carries an identity, the language, country code, time zone, platform, remaining credit count and dates), together with the purchase and question credit records. These are kept for store refund disputes and for the accounting trail. When the 30 days are up, all of it is permanently deleted.
If you sign in again with the same Google or Apple account, a brand new and empty account is opened. Because the identity fields were emptied, the old row cannot be matched with you under any circumstances; your old chart, your questions and your remaining credits do not come back.
If you cannot access the app, you can also send a deletion request by email. Step-by-step explanation: Account Deletion.
10. How to exercise your rights
Your rights under KVKK art. 11
In respect of your personal data, you have the right to request the following:
- To learn whether your personal data is being processed,
- To request information about it if it has been processed,
- To learn the purpose of the processing and whether the data is used in line with that purpose,
- To know the third parties to whom the data is transferred, at home or abroad,
- To request that it be corrected if it has been processed incompletely or incorrectly,
- To request that it be erased or destroyed within the framework of the conditions in KVKK art. 7,
- To request that correction, erasure and destruction operations be notified to the third parties to whom the data was transferred,
- To object to a result arising to your detriment through analysis carried out exclusively by automated systems,
- To claim compensation for the damage if you suffer damage because of unlawful processing.
There is a limit on correction inside the app, and we are not hiding it. You can change your birth details (date, time, place) from inside the app only once; once you have used this right, the app hides the correction step. The limit exists to stop the chart from being recalculated over and over. This does not take away your right to correction: if you have used your one-off change and your information is still wrong, write to [email protected] and we will make the correction. The same route applies if something is wrong in another field that cannot be changed in the app.
Your rights under GDPR
If you are in the European Union you also have the following rights: access (art. 15), rectification (art. 16), erasure (art. 17), restriction of processing (art. 18), data portability (art. 20), objection (art. 21) and rights relating to automated decision-making and profiling (art. 22). For processing based on consent, you can withdraw your consent at any time (art. 7/3) — how to do it is written in section 4.
How to apply
Write to [email protected]. If you want to make a written application, you can also send it to our company address.
- It does not matter what you write in the subject line, but write your request clearly: "I want a copy of my data", "delete my account", "correct my name" and so on.
- Identity verification: your request must come from the email address linked to your account. This is the only way to prevent someone else's account from being interfered with. If you used "Hide My Email" on Apple, write from that relay address.
- Time: we conclude your request within 30 days at the latest. It is free of charge; if a fee is required in the exceptional cases determined by the Personal Data Protection Board, we will tell you in advance.
Your right to complain
If we reject your application, if you find the answer we gave insufficient, or if we do not answer in time:
- Türkiye: you can file a complaint with the Personal Data Protection Board within 30 days from the date you learn of the answer, and in any case within 60 days from the date of your application (kvkk.gov.tr).
- European Union: you can file a complaint with the data protection supervisory authority of the country you are in.
11. Children
Astro Assistant is not an app aimed at children, and it is not marketed to children.
Instead of writing a condition here that we cannot enforce, we write the truth: there is no age verification inside the app. We ask for your date of birth, but we use it for the chart calculation, not as an age gate. The range the server accepts is between 1 January 1900 and today; dates outside this range (a future date, or a date before 1900) are turned down. No date within the range is refused on the basis of age.
The checks that actually work are these:
- The Google or Apple account you use to open an account is subject to those platforms' own age rules.
- Purchases are made through an Apple ID or a Google Play account; if you do not want your child to make purchases, you can use Apple's Ask to Buy and Google's Family Link tools.
- You can see the current age rating in the stores on the app's store page.
If you are not of age, you should only use the app with the knowledge and permission of your parent or guardian. If you notice that a child has opened an account without your knowledge, write to [email protected]; we will delete the account and its data.
12. Security
The measures we take:
- On your device: your session token does not sit in plain text in the app's own files; it is held in secure storage protected with Keychain on iOS and Keystore on Android. On Android, backing up app data is turned off.
- In transit: all traffic between the app and the server goes over HTTPS. On the iOS side, plain-text HTTP connections are turned off by an app setting. All the calls our server makes to the outside are HTTPS too (OpenAI, Apple, Google, OpenStreetMap).
- No passwords: because there is no email + password sign-in in the app, there is no user password on our side to be leaked. Admin panel passwords are stored hashed.
- Keys on the server: the OpenAI key, the store verification keys and the Firebase credentials are kept only on the server side; they do not go inside the app package.
- Abuse limits: there is a limit of 60 requests per minute on the API; a separate and narrower limit applies to answer reporting.
- Access limit: only authorised personnel access the data, to the extent the work requires.
- The only device permission the app asks for is the notification permission. Location, camera, contacts, microphone and photo permissions are not requested; storage and display-over-other-apps permissions have been explicitly stripped out of the package, even where they come from libraries.
No system is one hundred per cent secure; we are not guaranteeing that to you. If you notice a security vulnerability, write to [email protected]. If we determine that your personal data has been unlawfully obtained by others, we will notify the relevant authority and — where necessary — you, in accordance with KVKK art. 12/5 and GDPR art. 33–34.
13. Cookies and tracking
- There are no cookies in the app. There is no web browser inside it; the legal pages open in the system browser and the app records nothing.
- We have no advertising or analytics tool of our own. As a first party, we put no advertising network, no measurement/attribution partner, no crash reporting and no product analytics SDK in the app. In the package dependencies and in the iOS build lock file there is not a single match for Crashlytics, Sentry, Bugsnag, Firebase Analytics, AppsFlyer, Adjust, Amplitude, Mixpanel, Segment, Branch, OneSignal or AdMob. Firebase Cloud Messaging is used to deliver notifications; this is not a measurement tool, it is message delivery infrastructure. In the app's own Apple privacy manifest (
PrivacyInfo.xcprivacy) tracking is "no", and the purpose of every data type declared is app functionality only; there is not a single type declared for advertising or analytics purposes. The notification token used to deliver the notification to your device also appears in that manifest as device ID / app functionality. - But there are third-party SDKs inside the app; we are not hiding which ones. Google's own GoogleSignIn SDK (version 9.2.0) and its dependencies (AppAuth, GTMAppAuth, GTMSessionFetcher, GoogleUtilities, AppCheckCore) are inside the app for signing in with Google. Sign in with Apple is done with Apple's own framework, and purchases with StoreKit and Play Billing. Authentication runs through Firebase Authentication's JavaScript SDK. The native components of Firebase Cloud Messaging are in the app so that notifications can be received; these are for message delivery. Firebase's analytics package is not in the app.
- What Google's SDK says in its own manifest: the Apple privacy manifest (
PrivacyInfo.xcprivacy) of the GoogleSignIn SDK declares that it collects the following data types: name, email address, phone number, user ID, device ID, coarse location, "other data types" and "other usage data". As a purpose of use, besides app functionality, analytics also appears for some types; tracking, however, is declared as "no". This collection happens on Google's side and under Google's own privacy policy. This data does not come to us, it is not written to our database and it is not used for any analytics purpose on our side; the only things that reach us as a result of the sign-in are the name, email and user ID we listed in section 2.2. For Google's own processing you should look at Google's privacy policy. - On the server side we keep an error log (the "server logs" row in section 8); this is not an analytics product but an operational record, and it is not sent outside.
- There is no tracking. We do not read your device's advertising ID, we do not produce a device fingerprint, and we do not combine your data with other companies' data. Your notification token is used only to send you notifications; it is not used for advertising, it is not given to data brokers and it is not matched with other companies' data. In our iOS privacy manifest, tracking is declared as "no".
- These information pages (Privacy, Terms of Use, Support, Account Deletion) write no cookies and load no external fonts, images or scripts.
- If we use an advertising or analytics tool on the site in the future, we will update this section in advance.
14. Automated decisions and profiling
Your natal chart is calculated automatically and the answers are produced automatically. You are using it knowing this; this is what the app does.
That said, we do not take any automated decision that produces legal effects concerning you or that similarly significantly affects you. The answers are for entertainment; they are not an assessment, a score, a credit decision, a hiring decision or anything of the sort. Answers produced by artificial intelligence can be wrong; when you get a disturbing or irrelevant answer, use the "Report this answer" link underneath the answer — reports reach a human.
15. Changes to this policy
We may update this policy. The current text takes effect from the date it is published on this page, and the "Last updated" date at the bottom of the page changes.
If we make a substantial change — especially if the places the data goes or the purposes of the processing change — we will tell you inside the app. If the scope widens in a processing that is based on explicit consent, we will take your consent again; we do not use old consent for a new purpose.
16. Contact
ASTRO LABS TEKNOLOJİ LİMİTED ŞİRKETİ
Maslak Mah. Ayazağa Cad. B2 Blok No: 842
Email: [email protected]
Related pages: Terms of Use · Support · Account Deletion