Privacy Policy
Last updated: 4 August 2026
Who this covers
This policy covers the AstroPi iOS app and astropi.app.
The controller responsible for your data is:
Ahmet Eren Tosun (sole proprietorship)
Am Tierpark 25, 10315 Berlin, Germany
VAT ID: DE455588598
Email: destek@astropi.app
Full company details are on the Impressum page.
What we collect
- An account identifier. On first launch the app creates an anonymous account. You do not have to register, and we do not ask for your email to use the app.
- Sign in with Apple (optional). If you link an account, we receive your name and email address. If you choose Apple’s Hide My Email, we only ever see the relay address.
- Birth details. The name you give a profile, date of birth, time of birth if you know it, and birth place, stored as the city you picked together with its coordinates and time zone. These are the inputs the chart is calculated from.
- People you add. The birth details of anyone you add for a compatibility reading are kept on your device. They reach us only if you ask Pi to interpret that compatibility. See the AI section below. Add another person’s details only where that person has agreed to it.
- Photographs. The coffee cup or palm photos you take or choose for a reading.
- Purchases. Which subscription or credit pack you bought, whether it is active, and your star balance. Card numbers never reach us; Apple handles payment.
- How you use the app. Which days you open it, how often, and which of a handful of screens you looked at. We keep this per day, for the streaks and pattern summaries the app shows you.
- Your daily check-in. The energy level and mood you tap in the daily ritual, and your feedback on ritual tasks.
- Live Activity token. If you have Live Activities switched on in iOS, we receive a token while a reading is being produced so its progress can update on your Lock Screen. It is deleted with the reading. This is separate from the app’s own reminders, which are scheduled locally on your device and send us nothing.
- Device details. Platform, app version and build number, and when you last opened the app.
- Technical and security records. When the app talks to our backend, our infrastructure providers log the request in the ordinary way: your IP address, the time, which endpoint was called and whether it succeeded. Firebase also assigns your installation of the app an installation identifier, and Apple’s App Attest issues an App Check token that proves the request came from a genuine copy of AstroPi and not a script. We use these to keep the service running and to block abuse.
- Crash reports. If the app crashes, or hits an error it can recover from, Firebase Crashlytics sends us a report: what went wrong and where in the code, your device model and operating-system version, the app version and build number, and what the app was doing just before. Your account identifier is attached, so we can see whether the same person keeps hitting the same fault. Your birth details, photographs and readings are never part of a report. Crash reporting is switched off in development builds. It runs only in the version installed from the App Store.
We use no analytics SDK at all: no Google Analytics, no third-party attribution kit. Crashlytics is the only diagnostic tool in the app, and its purpose is fault diagnosis, not the observation of users.
We do not collect your device location. A birth place is entered by you; it is not read from the device.
Readings are produced by AI
Your readings are produced by a large language model, Google Gemini, and not by a person.
For a coffee or palm reading, the photograph itself is sent to Gemini so it can be interpreted. For astrology and tarot, what is sent is text: your birth details and the chart values calculated from them.
The same applies when you ask Pi about a reading. Your question, up to a dozen earlier turns of that conversation, and the relevant chart context are sent to Gemini, and the reply is stored on your account so it can be shown again. If the question is about compatibility, the chart context includes the name and birth details of the person you added.
Because of this: please do not photograph anything you would not want handled by an external AI service, and do not upload photographs of, or add birth details for, other people without their agreement.
What Google does with it. We use Google Cloud Vertex AI under Google Cloud’s enterprise terms, not the free consumer tier of the Gemini API. Under those terms Google does not use the data we transmit (your photographs, your birth details and your questions) to train or improve its models, and does not use it for any purpose of its own. Google processes it only to return the reading, and retains a short-lived copy for abuse monitoring and to meet its own legal obligations, after which it is deleted on Google’s schedule rather than ours. Google’s handling is described in the Google Cloud Service Specific Terms and the Cloud Data Processing Addendum.
What happens to your photographs
A photo is uploaded to our storage, sent to Gemini to produce the reading, and then deleted as soon as that reading finishes, whether it succeeded or failed. If a deletion does not go through, a scheduled cleanup job retries it.
The written reading stays in your history until you delete it or close your account. The image does not.
Who else processes your data
- Google Firebase: sign-in, database, file storage, abuse prevention and crash reporting (Crashlytics).
- Google Gemini: generates the readings, as described above.
- Google AdMob: the optional rewarded adverts. See the next section for exactly what it receives.
- RevenueCat: manages subscriptions and entitlements.
- Apple: payments, Sign in with Apple, Lock Screen Live Activities, and turning the birth city you type into coordinates.
We never sell your personal data. We do not share your birth details, photographs or readings with anyone for advertising. The one exception to be clear about: if you consent to personalised adverts, Google may use your advertising identifier and ad-interaction data to select the adverts you see. Under some US state privacy laws that counts as “sharing for cross-context behavioural advertising.” Decline tracking and that does not happen.
Adverts and tracking
Adverts are optional and never shown to Pro subscribers. You only see one if you choose to watch a rewarded advert to unlock a feature.
Adverts are served by Google AdMob. Whether or not you consent to personalisation, AdMob receives: your IP address (from which it infers approximate location, at city level), the Identifier for Vendors (IDFV) and other device and app identifiers, your device model, operating-system version and language, and ad-interaction data: that an advert was requested, shown, watched to the end or dismissed. If you allow tracking, it additionally receives Apple’s Identifier for Advertisers (IDFA) and may combine that with data from other apps and sites to personalise adverts and measure them. It never receives your birth details, your photographs or your readings.
Before the first advert we ask for what your region requires: in the EEA, the UK and Switzerland, Google’s certified consent form, which also lists the ad-technology providers you are consenting to and lets you accept or reject them individually; on iOS everywhere, Apple’s App Tracking Transparency prompt. If you decline, adverts still work; they are simply not personalised.
You can change your mind at any time: in the EEA, the UK and Switzerland, Profile › Ad privacy settings reopens Google’s form; on any device, iOS Settings › Privacy & Security › Tracking controls the advertising identifier.
How Google handles this data is described in the Google Privacy Policy and in How Google uses information from sites or apps that use our services. You can also opt out of ad personalisation across Google at adssettings.google.com.
Why we are allowed to process it
These are our legal bases under the GDPR and UK GDPR:
- To perform our contract with you (Art. 6(1)(b)): producing readings, running your subscription and star balance, keeping your history, and settling refund questions with Apple.
- Your consent (Art. 6(1)(a)): personalised adverts, and using the camera or photo library. You can withdraw either at any time, in the app or in iOS Settings.
- Our legitimate interests (Art. 6(1)(f)): keeping the service secure, preventing abuse and fraud, fixing faults, and understanding in aggregate which features are used. We have weighed these against your interests; you may object at any time.
- Legal obligation (Art. 6(1)(c)): keeping invoice and tax records for as long as German law requires.
People you add for a compatibility reading. Their birth details normally never leave your device. When you ask Pi about that compatibility, we process them on the basis of our legitimate interest (Art. 6(1)(f)) in providing the feature you requested, on the understanding that you have their agreement. We do not build a profile of that person, do not contact them, and delete their details with the reading. Because we have no way to reach them ourselves, we rely on Art. 14(5)(b): telling each of them directly would be disproportionate, and we publish this notice instead. If someone has been added without wanting to be, they or you can email destek@astropi.app and we will erase every trace of them and object on their behalf.
A note on sensitive subjects. We do not ask for health, religious, political or sexual information and none of it is required to use AstroPi. But readings, and what you type into Pi, can touch such things. A question may concern an illness, a belief or a relationship. If you volunteer that kind of detail, you are explicitly consenting to us processing it to answer you (Art. 9(2)(a)), and you can withdraw that by deleting the reading or your account. Please do not disclose to Pi any information whose storage you would not wish to permit. We do not use palm or coffee-cup photographs to identify anyone, so they are not biometric data in the sense of Art. 9 GDPR; we still treat them as sensitive and delete them as soon as the reading is finished.
Where your data is processed
We are established in Germany. Our backend runs on Google Cloud in the United States (region us-central1), and the AI that writes your readings runs there too, with one exception: the model used for coffee-cup readings runs on Vertex AI’s global endpoint, so that request may be served from a Google data centre in any region. Google, RevenueCat and Apple may process data in further countries as part of their own services.
These transfers out of the EEA and the UK are covered by the European Commission’s Standard Contractual Clauses and the UK Addendum, which form part of our data processing agreements with Google (Cloud Data Processing Addendum), RevenueCat and Apple, together with the technical measures described under “How we protect your data”. Google and Apple are additionally certified under the EU–US Data Privacy Framework, so transfers to them rely on the European Commission’s adequacy decision of 10 July 2023. You can ask us for a copy of the safeguards at destek@astropi.app.
How long we keep things
- Photographs: minutes. Deleted the moment the reading finishes.
- Readings, Pi replies, birth profiles and your star balance: until you delete them or close your account. Closing your account removes them from the app at once and you will not be able to see them again; they are held in a separate archive for a further 1 year from the end of the calendar year of the deletion, for the sole purpose of defending a legal claim should one be brought (Art. 17(3)(e) GDPR). A scheduled job destroys the archive when that period runs out.
- Usage log, check-ins and ritual preferences: until you close your account, then the same 1-year archive.
- Purchase and invoice records: 10 years from the end of the year of each record; subscription renewals that arrive after you delete your account start their own period from their own date. German commercial and tax law requires this (§ 257 HGB, § 147 AO), so these records survive the deletion of your account. They are then used for nothing except accounting and answering the tax authority.
- Technical and security logs: up to 30 days in the ordinary course, and longer only for a specific record we need to investigate an incident or abuse, for as long as that investigation lasts.
- Crash reports: 90 days, then deleted by Google on its own schedule. Because a report carries your account identifier, it is not reached by deleting your account; it expires on its own within 90 days.
- Correspondence with our support address: up to 2 years after the matter is closed, so we can follow up on a recurring problem.
Deleting your account
Profile › Delete Account removes from our live systems, immediately: your birth profiles; every reading and any files still attached to them; your stored Pi replies; your star balance and credit history; your daily check-ins, usage log and ritual preferences; pending upload permissions; and the account itself. None of it remains in the app, it cannot be restored, and you will not be able to see it again.
Removal from your access is not the same as destruction. The records move to an archive that is unreachable from the app, on two separate clocks: purchase and invoice records for 10 years (German commercial and tax law requires it: § 257 HGB, § 147 AO), and everything else for 1 year (solely to defend a legal claim). Each runs from the end of the calendar year of the record it covers, and a scheduled job destroys the archive when they expire. The archive is not accessed in the ordinary course of business; it is opened only for a dispute, an audit or an abuse investigation.
Your rights over the archived records continue. For as long as data is retained, your rights of access and portability apply to it: the archive is invisible in the app, not beyond your reach in law. Write to destek@astropi.app for a copy. Because your account is gone, we may have to ask for your purchase date or Apple order ID so we can identify which record is yours.
Your subscription continues. Deleting your account does not cancel an App Store subscription. Cancellation is carried out by you, either in the app under Profile › Manage Subscription or in iOS Settings › Apple Account › Subscriptions. If you do not cancel before deleting, Apple continues to bill you, and those renewals are recorded in the archive as invoice records.
The meaning of “immediately”. The data is removed from the running service at once, but copies persist briefly in places we cannot reach into individually: database point-in-time recovery snapshots, file-storage soft-delete, and provider request logs. Those expire on their own schedule and are gone within 35 days. Nobody works with them in the meantime; they exist only so the service can be restored after a failure.
Three things stay longer, and we cannot remove them: Apple’s own record of your purchases; the billing records RevenueCat and Apple keep for their own accounting; and our invoice records, which German law requires us to keep for 10 years (see above). For Apple’s own records, please contact Apple.
Your rights
Wherever you live, you can ask us to give you access to your data, to correct it, to delete it, to restrict how we use it, to object to processing based on our legitimate interests, to receive a copy in a portable, machine-readable format or have it sent to another provider where technically feasible, and to withdraw any consent you gave. Withdrawal does not affect what we did while the consent was valid. You are not subject to any decision with legal effect made solely by automated means; a reading constitutes entertainment and not a decision concerning you.
Email destek@astropi.app. We reply within one month, and will say so if a complex request needs up to two months more. Exercising these rights is free and we will not treat you differently for it.
If you are unhappy you can complain to a supervisory authority. Ours is the Berliner Beauftragte für Datenschutz und Informationsfreiheit (Alt-Moabit 59–61, 10555 Berlin, datenschutz-berlin.de), but you may equally complain to the authority where you live or work: in the UK the ICO, and in Türkiye the KVKK Authority. We have not appointed a Data Protection Officer; we are not required to, because our processing is not on a scale that triggers Art. 37 GDPR.
Children
AstroPi is rated 17+ and is not directed at children. We do not knowingly collect data from anyone below the age limits in our Terms of Use: 16 in the EEA, the UK and Switzerland (or the lower age your country sets, never below 13), and 13 elsewhere. Below that age AstroPi may be used only with the consent of a parent or guardian, who must supervise its use.
If you believe a child has given us data, email destek@astropi.app and we will delete the account and its contents.
How we protect your data
Traffic between the app and our servers is encrypted with TLS, and data is encrypted at rest by our providers. Requests are authenticated with a Firebase identity token and attested with Apple’s App Attest, so a request that did not come from a genuine copy of AstroPi is rejected. Database rules restrict every document to the account that owns it, and photo uploads are limited to a single-use permission scoped to one reading. Access to production is limited to those who need it. No system is perfectly secure, but if a breach is likely to put your rights at risk we will notify the supervisory authority within 72 hours and tell you without undue delay, as Arts. 33–34 GDPR require.
Changes
If we change how we handle your data we will update this page and its date. Significant changes will be announced in the app.