Astrafel Privacy Policy
Effective from 9 October 2026.
Astrafel is an iPhone app with star portraits, birth charts and forecasts for cats and dogs. This policy explains what data the app uses, where it goes, how long it’s kept and how to delete it.
In short
- There’s no sign-up and no accounts. We don’t know your name, email or phone number.
- Your pet’s name, birth date, birth time and place, and profile photo stay only on your phone — and in your iCloud if you turn on sync. We can’t access them.
- A photo for a star portrait goes to Anthropic (the Claude model) only with your consent — cropped to your pet, with any faces of people blurred.
- Personal forecasts are written by Claude from the signs of the planets in your pet’s chart — only with your permission, and without the name, photo or place.
- Usage statistics go to PostHog only if you allow them, and without anything that identifies you.
- No ads, no tracking, no selling of data. The advertising identifier (IDFA) isn’t used; RevenueCat receives the identifier for vendor (IDFV) to keep track of purchases.
- You can delete your data in the app: Settings → “Delete my data”.
1. Who is responsible for your data
The data controller is Arvids Kapusta, Daugavpils, Latvia (“we”).
Email for privacy questions and support: bonis22311@gmail.com.
This policy and the terms of use are published at astrafel.app/privacy and astrafel.app/terms and are also available in the app.
2. What stays on your phone
- Your pet’s profile: name, species, birth date, birth time and place (if you added them), profile photo, answers to the personality questions.
- Star portraits and forecasts you’ve already received, and the app’s settings.
- The birth chart is calculated on your phone and isn’t stored.
Your pet’s profile isn’t sent to us or to our providers; what is sent for portraits and forecasts is described in section 3, and the codes for statistics (species, sign, personality answers — if you allow statistics) in section 7. If you turn on “iCloud sync” (it’s off by default), the profile and portraits are also kept in the private iCloud database of your Apple Account. Only you can access it; Apple stores it.
The photo check — whether there’s a cat or a dog in the photo and whether a person takes up a noticeable part of the frame — happens on your phone; faces of people in the frame are blurred there too (section 4). The birthplace search uses Apple’s map service: Apple processes what you type, and it isn’t sent to us.
3. What leaves your phone and who receives it
Our server
Our server runs on Supabase: the database and the server functions are in the EU (Frankfurt); requests to it pass through the Cloudflare network. The server stores:
- Service IDs. A random device ID and a random customer ID that groups up to 5 of your devices using the same Apple Account, plus the customer ID for RevenueCat. The server issues them; we don’t know your name or your Apple Account details.
- App integrity data (Apple App Attest). The public key the app uses to sign requests, the app version, and Apple’s estimate of how many times the app has been registered on this device in the last 30 days.
- A hash of the customer secret. The app creates the secret itself and keeps it in the Keychain and in the iCloud of your Apple Account — this is how Premium and the free portrait are recognized after a reinstall and on a second iPhone. The server keeps only the hash.
- Subscription status: whether it’s active, which plan, until when, whether it’s a test purchase, and the subscription key — the App Store transaction ID of the subscription. With it, Premium limits are counted per subscription, so moving a subscription to another customer with “Restore purchases” doesn’t reset them.
- Flags: whether the free portrait has been used and whether limits have been broken. For up to two days after the free portrait — its text ID and a hash (SHA-256) of the request, from which the photo can’t be restored: if the answer is lost on the way, repeating the same request within a day returns the same portrait.
- Personal forecasts. For a forecast — only with your permission (section 5) — the app sends a random pet ID (not the name), the species, the language, the signs of the planets (and whether each is retrograde or its sign is uncertain) and the ascendant in the chart, transits (which planet to which point of the chart, the type of aspect, its orb in whole degrees and the date it becomes exact), and personality trait codes. For a pet whose sign was matched by personality — only the sign, transits to it and trait codes, without a chart. The server doesn’t keep the signs, transits or trait codes: the forecast cache holds only the pet ID, a hash (SHA-256) of the request — to recognize a forecast that’s already been written — and the finished forecast text.
- Counters and usage statistics: how many requests, portraits and forecasts there were per minute and per day, how many times limits were hit, and how much the AI requests cost.
- Generated texts of portraits and forecasts — without device or customer IDs — and reports about them from “Report a problem” (only the reason code).
- An IP address pseudonym — see section 6.
The server doesn’t store photos, your pet’s name, or the birth date, time or place.
Anthropic (the Claude model)
Anthropic, the company that develops the Claude AI model, receives from our server:
- for a star portrait from a photo — the photo of your pet (only with your consent, section 4), the species, codes of the Sun sign, its element and personality traits, and the language of the answer; the Moon and ascendant signs aren’t sent for a portrait;
- for a personal forecast — the forecast data listed above (only with your consent, section 5), but without the device, customer or pet IDs;
- Claude’s finished texts — before they’re shown, another request to Claude checks them (moderation).
Anthropic doesn’t receive our service IDs.
RevenueCat
RevenueCat handles purchases: it receives subscription information from the App Store and the customer ID issued by our server. The RevenueCat library in the app also sends RevenueCat technical data: the identifier for vendor (IDFV — an ID Apple gives the app on this device; it isn’t the advertising identifier), the iPhone model, the system languages, the app and iOS versions, the App Store country (storefront) and the IP address. Apple processes the payment. Neither we nor RevenueCat receive your payment card details or the name and email of your Apple Account.
PostHog
Anonymous statistics — only if you allow them (section 7).
Apple
- App Attest — checks that the app is genuine; Apple tells our server how many times the app has been registered on the device.
- App Store — purchases and subscriptions.
- iCloud — sync (if turned on) and storage of the customer secret.
- Map service — the birthplace search.
Apple processes this data as an independent controller under its own privacy policy.
Cloudflare
The app downloads free forecasts by sign as files from Cloudflare R2 storage. The file address contains only the language, species, sign and month.
Support email
If you write to us, your email arrives in a Gmail mailbox (Google). We use the correspondence only to reply and will delete it if you ask.
4. Photos and Anthropic
A photo is sent only if you tapped “Allow” on the “AI photo analysis” screen. Before sending, the app:
- checks that there’s a cat or a dog in the photo; photos where a person takes up a noticeable part of the frame are rejected on your phone;
- crops the photo to your pet and blurs any faces of people in the frame;
- makes the photo smaller and removes metadata from the file (EXIF, location); the server removes it again.
The service doesn’t describe people. The zodiac sign never comes from the photo: Claude looks at the coat, expression and pose and writes the text of the portrait.
We don’t store the photo. Anthropic doesn’t use it for training and deletes it automatically within 30 days. It’s kept longer, up to 2 years, only if automated safety systems flag the request.
Our server holds the photo only in memory while the request is running. You can withdraw consent at any time: Settings → “AI photo analysis” → “Withdraw consent”. Without consent, you can get a portrait by the stars — from the sign and the personality answers, without a photo or AI.
5. Personal forecasts
Personal forecasts are written by Claude (Anthropic) from the planet positions in your pet’s chart — without the name, photo or place. They can be used to work out your pet’s birth date, and if you added the time, roughly the birth time as well.
Forecast data is sent only if you tapped “Allow” on the “AI personal forecasts” screen: it appears before the first personal forecast, separately from the consent for photo analysis. Only codes are sent, such as the signs of the planets and the ascendant in the chart (with whether a planet is retrograde or its sign is uncertain), the planets’ aspects to them on the forecast days, the species, the language and personality traits (section 3). Planet degrees and the birth date, time and place aren’t sent, but the birth date can be worked out from the signs of the planets and the dates of the transits. For a pet whose sign was matched by personality, the forecast is written from the sign and your personality answers, without a birth date.
Without permission, you see the general forecast by sign, and everything else in Premium stays; you can allow it later with “Allow personal forecasts” on the forecast screen. You can withdraw consent at any time: Settings → “AI personal forecasts” → “Withdraw consent”. After that, no new requests are sent, and forecasts you already have stay on your phone. Anthropic doesn’t use this data for training and deletes it automatically within 30 days. It’s kept longer, up to 2 years, only if automated safety systems flag the request. Our server keeps the finished forecast for up to 15 days (section 9).
Each personal forecast is labeled “Text created by Claude (Anthropic) from your pet’s chart”. The free version doesn’t request personal forecasts: the free forecast by sign arrives as a ready-made file (section 3, Cloudflare).
6. IP address and hosting logs
Every request on the internet comes from an IP address. Here’s how we handle it:
- Our server doesn’t store IP addresses in readable form. To protect against mass attacks, it replaces the IP with a pseudonym based on a key that changes every day and is deleted from the working database after 48 hours and from database backups within 7 days. After that, the pseudonym can’t be linked to the address.
- Our hosting (Supabase) keeps technical request logs with the IP address and an approximate location derived from it for up to 7 days, for security and operations.
- Our hosting (Supabase) also makes daily backups of the database. They’re kept for up to 7 days and used only to recover from a failure.
- Cloudflare — the network in front of our hosting and the delivery network for free forecasts — also processes requests with the IP address and keeps its technical data under its own retention rules.
- Our website astrafel.app, where this policy and the terms of use are published, is hosted on Cloudflare Pages. It has no cookies or analytics and loads nothing from other sites. Cloudflare receives the IP address with each page request and keeps technical logs under its own rules.
7. Anonymous statistics
On first launch, the app asks whether it may collect anonymous statistics. Only if you tap “Allow” are events sent to PostHog (servers in the EU). They contain:
- which screens are opened and which buttons are tapped — first-launch steps, chart planets opened, the share card, the review request, data deletion; how many times the app has been launched, how long the steps and the paywall took, and how long the app was in the background (in ranges, not exact times);
- about your pet: the species and sign; whether the birth date, time and place were entered (without the values themselves) and where the time zone came from — the birthplace or the phone; how the chart was calculated — whether the birth time is known, whether the Sun and the Moon are close to a sign boundary, and whether the houses had to be calculated in a special way (this happens for places beyond the polar circle); the result of the on-device photo check (accepted, no cat or dog, a person in the frame, unreadable, or skipped); if the Sun changed sign on the birth day, whether you said the pet was born before or after that moment (or don’t know);
- answers to the personality questions, including those in the quiz (codes of the question and the chosen option, no text); which quiz questions were answered, the sign the quiz matched, and whether the season of birth was taken into account;
- the paywall and purchases: views, the selected plan, the price and currency of a purchase, the outcome of purchases and of restoring purchases;
- decisions on the consent screens and changes to settings (iCloud sync, AI consents, statistics); the outcome of portrait and forecast requests (done, by sign, or why it failed — for example, no pet or a person in the photo, a limit, no network) and the response time as a range; reports about texts — only the reason code;
- general information: the app version, the interface language, whether Premium is active, and the number of pets;
- with each event: its time and an event ID. Nothing else is added: the app removes the device model, system version, time zone and other technical details the PostHog library would otherwise attach. PostHog also sees the request’s IP address (not stored, see below) and the library name and version in the request header.
How statistics work:
- Events are sent under a random statistics ID — this is the “Statistics ID” on the “Delete my data” screen. It isn’t linked to the device and customer IDs on our server or to RevenueCat.
- Statistics never include your pet’s name, photos, texts, birth dates or places.
- PostHog is set up by us not to store the IP address and not to derive a location from it; on top of that, the app asks PostHog in every event not to derive a location from the IP.
- Until you decide, events are kept only in your phone’s memory; if you decline, they’re erased.
- You can change your mind at any time: Settings → “Anonymous statistics”. Once statistics are off, nothing more is sent: events not yet sent wait on the phone and go only if you turn statistics back on.
- Events are kept for no longer than 1 year.
Regardless of this choice, our server always counts the requests it receives — these are the counters and statistics from section 3. Without them, we couldn’t limit abuse or keep track of AI costs. They’re stored under the service device and customer IDs, without names, photos or texts.
8. Why we use data and on what legal basis
For users in the EEA, the UK and Switzerland, the legal bases under the GDPR and UK GDPR are:
- Running the app and the subscription — portraits, forecasts, purchases, Premium on all your devices (service IDs, forecast cache, subscription status, purchase information at RevenueCat): performance of our contract with you (Art. 6(1)(b)).
- Abuse prevention and security — App Attest integrity checks, limits, violation flags, the IP pseudonym, hosting logs: our legitimate interest (Art. 6(1)(f)) in keeping the service available and not letting attacks use up the AI budget.
- Server statistics and text quality — usage counters, AI costs, reports about texts: our legitimate interest in understanding load and costs and fixing bad texts.
- Sending photos to Anthropic: your consent (Art. 6(1)(a)).
- Sending chart data to Anthropic for personal forecasts: your consent (Art. 6(1)(a)).
- Anonymous statistics in PostHog: your consent (Art. 6(1)(a)).
- Replying to emails: our legitimate interest in answering your question.
You can withdraw consent at any time; this doesn’t affect the lawfulness of processing before you withdrew it. You can object to processing based on legitimate interest (section 11).
9. How long data is kept
On our server:
- service IDs, App Attest data, the customer secret hash, subscription status (including the subscription key) and flags — until you delete your data (section 10);
- the cache of personal forecasts — 8 days for daily and 15 days for weekly forecasts;
- random pet IDs — 90 days after the last forecast;
- usage statistics per device — 90 days; AI costs per customer — 30 days;
- limit counters — 2 days; records of exceeded limits — 90 days; a reduced limit after repeated violations lasts 30 days;
- generated texts and reports about them — 30 days;
- the IP pseudonym and records that use it — up to 48 hours;
- database backups — up to 7 days: data deleted from the database disappears from them when they expire;
- after you delete your data — the RevenueCat customer ID in the queue for deletion at RevenueCat (only the ID and dates): until we delete the data at RevenueCat (within 30 days) and for 30 days after that.
At our providers:
- Anthropic — up to 30 days; requests flagged by safety systems — up to 2 years;
- hosting logs (Supabase) — up to 7 days; Cloudflare’s technical data — under Cloudflare’s rules;
- the hosting of our website astrafel.app (Cloudflare Pages) — technical logs under Cloudflare’s rules (section 6);
- PostHog — no longer than 1 year;
- RevenueCat — until you delete your data; after that, we erase it at RevenueCat within 30 days;
- Apple — under Apple’s rules.
10. Deleting your data
Settings → “Delete my data”. The screen shows in advance what is deleted right away and what later.
Deleted right away:
- on our server — the customer as a whole with all devices (including other iPhones using the same Apple Account), pets, the forecast cache, statistics, subscription status, and the counters and flags of the device’s and customer’s limits;
- pet profiles and portraits in your iCloud;
- profiles, portraits and forecasts on this phone;
- the PostHog statistics ID is reset, and so is your decision about statistics: nothing new is sent until you allow statistics again, and new events aren’t linked to the old ones. If statistics were on, events already waiting on the phone (including the deletion itself) are still sent under the old ID; if they were off, unsent events are erased.
The app also erases the customer secret on this phone — in the Keychain and in iCloud. If it remains in the Keychain of another of your iPhones, it’s no longer linked to the deleted data: on its next request, that iPhone registers again as a new customer. To delete its data too, tap “Delete my data” on that iPhone as well.
Kept for a while and deleted later:
- at Anthropic — up to 30 days, flagged requests up to 2 years; this can’t be deleted sooner;
- generated texts without device or customer IDs, and reports about them — up to 30 days;
- hosting logs (Supabase) — up to 7 days; Cloudflare’s technical data — under Cloudflare’s rules;
- database backups (Supabase) — up to 7 days; they’re used only to recover from a failure;
- the IP pseudonym and records that use it — no longer than 48 hours;
- limit counters tied to a hash of the subscription key — up to 2 days, records of exceeded limits — up to 90 days; the button doesn’t delete them, otherwise deleting data would reset the subscription’s limits; they’re no longer linked to the device or the customer;
- anonymous PostHog events — until the end of their retention period (section 9). To have them deleted sooner, copy the “Statistics ID” from the “Delete my data” screen before deleting and send it to bonis22311@gmail.com: we’ll ask PostHog to delete them, and if that’s technically impossible, they’ll be deleted when the retention period ends;
- data at RevenueCat — we delete it manually within 30 days; until then and for 30 days after, our server keeps only the RevenueCat customer ID in the deletion queue.
Deleting your data doesn’t cancel or lose your subscription: you cancel it in your Apple Account settings, and to get Premium back after deleting data, tap “Restore purchases”.
If you deleted the app without tapping “Delete my data”, the data on the server stays under service IDs. Install the app again: if the customer secret is still in the Keychain or in iCloud, the app will recognize the customer, and “Delete my data” will delete everything described above from the server.
11. Your rights
You have the right to know what data we hold about you and get a copy, to correct it, to delete it, to restrict processing, to object to processing based on legitimate interest, to receive the data in a machine-readable format, to withdraw consent, and to complain to the data protection authority in your country.
You can do a lot directly in the app: delete your data, withdraw consent for photo analysis and for personal forecasts, turn off statistics and iCloud sync, edit or delete your pet’s profile. For anything else, write to bonis22311@gmail.com — we’ll reply within one month.
We don’t know who you are: there’s no account, and the server holds only random IDs. So we may not be able to find your data from an email. For statistics events, include the “Statistics ID” from the “Delete my data” screen; if you ask us to delete them, we’ll ask PostHog to do so, and if that’s technically impossible, they’ll be deleted when the retention period ends. If we can’t identify you, we won’t be able to give access to, copy or correct the data (Article 11 GDPR); you can always delete the data on the server with the button in the app.
12. Children
Astrafel is rated 4+: its content is suitable for any age. But the app isn’t made for children and isn’t directed at children under 13. We don’t knowingly collect children’s data: the app doesn’t ask for a name, age or email, and photos where a person takes up a noticeable part of the frame are rejected. If you believe a child has sent us data, write to us and we’ll help delete it.
13. Transfers outside the EU
Our server’s database and functions (Supabase, Frankfurt) and PostHog are in the EU. Anthropic and RevenueCat are US companies; Cloudflare processes requests in many countries; emails to support are kept in Gmail by Google, a US company. When data from the EEA, the UK or Switzerland goes to a country without an adequacy decision, the transfer relies on the European Commission’s Standard Contractual Clauses (with the UK Addendum for the UK) in our data processing agreements with the providers, or on the provider’s participation in the EU–U.S. Data Privacy Framework.
We share data only with providers that are contractually bound to protect it at least as well as described here and to use it only to run Astrafel. Apple processes data as an independent controller under its own policy.
14. How data is protected
- All requests use HTTPS. Requests to the server are signed with this device’s App Attest key, so they can’t be forged from another device.
- The database can’t be accessed directly from the internet: only the server’s functions work with it.
- Only what’s needed is sent to the server: no names, no coordinates, no birth date as such and no free text.
15. Changes to this policy
We publish each new version here and in the app, with a new date at the top. We’ll announce significant changes — for example, a new recipient of data or a new purpose — in the update notes in the App Store. If new processing requires consent, we’ll ask for it before it starts.
16. Contact
Arvids Kapusta, Daugavpils, Latvia.
Email: bonis22311@gmail.com.