Legal

Privacy Policy

Last updated: April 13, 2026

1. Who We Are

Astria is a personalized AI astrology platform available at astriasky.com. The data controller is Astria, reachable at contact@astriasky.com.

2. What Data We Collect

  • Account data: name, email address, profile photo — provided at registration.
  • Birth data: date, time, and place of birth — required for natal chart calculation and astrological features.
  • Payment data: processed exclusively by a PCI DSS certified provider. We do not store any card numbers on our servers.
  • AI conversations: messages exchanged with Oracle AI, saved for continuity and personal context.
  • Palm images: photos uploaded for Palm Reading — processed temporarily and not retained after analysis.
  • Usage data: pages visited, features used — for service improvement purposes.

3. How We Use Your Data

  • Calculating and displaying your natal chart, transits, numerology, and other astrological features.
  • Personalizing Oracle AI responses with your astrological context.
  • Processing payments and managing subscriptions.
  • Sending account-related emails (confirmations, notifications).
  • Improving the platform based on aggregated, anonymized behavior.

We do not sell, rent, or share your personal data with third parties for marketing purposes.

4. Third-Party Services

  • Authentication: SOC 2 certified provider for account and session management.
  • Payments: PCI DSS Level 1 certified provider — we have no access to your card details.
  • Artificial intelligence: enterprise AI models accessed via secure API. Data is not used for model training.
  • Database: data stored securely on cloud infrastructure located in the European Union.
  • Email: specialized provider, GDPR compliant.

Each provider is contractually required to comply with GDPR and not use your data for any other purpose.

5. Legal Basis (GDPR)

  • Contract performance — to provide the service you signed up for.
  • Consent — for optional features (e.g. Palm Reading, uploaded images).
  • Legitimate interest — for anonymized usage analysis and platform improvement.
  • Legal obligation — where we are required by law to retain certain data.

6. Your Rights (GDPR)

If you are an EU/EEA resident, you have the following rights:

  • Access — request a copy of your personal data.
  • Rectification — correct inaccurate data.
  • Erasure — request deletion of your account and associated data.
  • Portability — receive your data in a structured format.
  • Objection — object to processing based on legitimate interest.
  • Withdrawal of consent — at any time, without affecting prior processing.

Contact: contact@astriasky.com. We respond within 30 days.

7. Data Retention

  • Account data is retained for as long as the account is active.
  • Upon account deletion, personal data is erased within 30 days, except financial data which we are legally required to retain (7 years, per fiscal regulations).
  • Oracle AI conversations can be deleted at any time from within the app.

8. Security

All communications are encrypted via HTTPS/TLS. Data is stored in secure databases with restricted access. Authentication follows SOC 2 security standards. We conduct regular security assessments.

9. Cookies

We use only essential technical cookies for authentication and application functionality. We do not use third-party tracking cookies, behavioral advertising, or third-party analytics.

10. Policy Changes

Any significant changes will be communicated via email or in-app notification at least 14 days before taking effect.

11. Contact

For any privacy-related questions: contact@astriasky.com

Privacy Policy — Astria