Legal
Privacy policy
What we collect, why, who helps us run the service, and how you stay in control of your data.
Draft — to be reviewed by the owner
This page describes how What’s My Sky? handles your data as the app is built today (23 September 2026). It has not been approved yet, and the items in square brackets are placeholders the owner will complete.
In short
- We keep what the app needs to work for you: your account, your birth details, your settings, the readings written for you and your Ask the Sky conversations.
- Your birth details stay with us. The AI that writes readings receives the positions of your birth chart and today’s sky, computed from your birth details — not the details themselves (exactly what it receives).
- No advertising, no analytics trackers, and we never sell your data.
- You can download everything we hold about you, and delete your account and all of it, at any time in Settings.
What’s My Sky? presents astrology as an interpretive tradition alongside measured astronomy. Nothing in it is medical, psychological, financial or legal advice.
Who we are
What’s My Sky? (the website and the iOS and Android apps) is run by [owner name or company], [postal address], the controller of your personal data under the EU and UK General Data Protection Regulation (GDPR). Write to us at [owner contact email].
What we collect and why
Everything below is tied to your account unless it says otherwise, and is deleted with your account.
| Data | What exactly | Why | Kept |
|---|---|---|---|
| Account | Your email address, whether you have confirmed it, and the name you give (optional). Your password is stored only as a scrypt hash. If you sign in with Google or Apple: your identifier there, the name and email they share, the profile picture link Google shares, and the sign-in tokens they issue, encrypted. | To run your account and sign you in. | Until you delete your account. |
| Password resets | When you ask to reset your password: a one-time code tied to your account, stored only as a hash. Confirmation links carry no stored code. | To let you choose a new password from the link we email you. | Works for one hour; deleted when used, or at a later clean-up once expired. |
| Sessions | When you signed in, when the session expires, and the browser’s user-agent string (the kind of browser and device). Not your IP address. | To keep you signed in, and to show your sessions in your data export. | Until it expires: 30 days after you last used it. |
| Birth details | Your birth date; the time if you know it, with its accuracy and any ± margin; the birthplace’s name, region, country, coordinates, elevation and time zone; and the UTC instant and offset we worked out from them. | To compute your natal chart and your personal readings. | Until you change them or delete your account. |
| Settings | Zodiac frame, ayanamsa, house system, orbs and angle format; your current place (name, coordinates, time zone) if you set one; your notification choices (on or off, time and time zone). | To show the sky the way you asked, where you are. | Until you change them or delete your account. |
| Your readings | The personal readings written for you, the facts each was written from, and explanations you asked for. | So a reading stays the same when you come back to it. | Until you delete your account. |
| Ask the Sky | Your questions, the answers, the facts they cite and the steps shown while the answer was prepared. | So you can come back to a conversation. | Until you delete the conversation or your account. |
| Notifications | For each browser: the address its push service gave it and the encryption keys for that address. In the iOS or Android app: the device’s push token. The date of the last morning note. | To send the morning note you turned on, at most once a day. | Until you turn it off or remove the device, or the push service reports the address gone. |
| Generation records | For each AI-written text: the model, the number of tokens, the time taken and the outcome — no text, no birth details. | To control cost and quality. | Until you delete your account. |
| Abuse protection | Counters keyed by a keyed hash (HMAC-SHA-256) of your IP address or its network, your account identifier or, for sign-in attempts and emailed links, your email — never the values themselves. | To stop brute-force sign-in attempts, floods of email and overuse. | About two days. |
| Place searches | The text you type into a place search. It is not stored with your account; results are cached by query. | To find the place you mean. | Cached for up to a day. |
| Technical logs | Our functions record errors (by type) and counts — never birth details, reading text or questions. Our hosting platform records each function run’s duration. | To keep the service working. | One month. We do not switch on CDN access logs. |
- Account
- What exactly
- Your email address, whether you have confirmed it, and the name you give (optional). Your password is stored only as a scrypt hash. If you sign in with Google or Apple: your identifier there, the name and email they share, the profile picture link Google shares, and the sign-in tokens they issue, encrypted.
- Why
- To run your account and sign you in.
- Kept
- Until you delete your account.
- Password resets
- What exactly
- When you ask to reset your password: a one-time code tied to your account, stored only as a hash. Confirmation links carry no stored code.
- Why
- To let you choose a new password from the link we email you.
- Kept
- Works for one hour; deleted when used, or at a later clean-up once expired.
- Sessions
- What exactly
- When you signed in, when the session expires, and the browser’s user-agent string (the kind of browser and device). Not your IP address.
- Why
- To keep you signed in, and to show your sessions in your data export.
- Kept
- Until it expires: 30 days after you last used it.
- Birth details
- What exactly
- Your birth date; the time if you know it, with its accuracy and any ± margin; the birthplace’s name, region, country, coordinates, elevation and time zone; and the UTC instant and offset we worked out from them.
- Why
- To compute your natal chart and your personal readings.
- Kept
- Until you change them or delete your account.
- Settings
- What exactly
- Zodiac frame, ayanamsa, house system, orbs and angle format; your current place (name, coordinates, time zone) if you set one; your notification choices (on or off, time and time zone).
- Why
- To show the sky the way you asked, where you are.
- Kept
- Until you change them or delete your account.
- Your readings
- What exactly
- The personal readings written for you, the facts each was written from, and explanations you asked for.
- Why
- So a reading stays the same when you come back to it.
- Kept
- Until you delete your account.
- Ask the Sky
- What exactly
- Your questions, the answers, the facts they cite and the steps shown while the answer was prepared.
- Why
- So you can come back to a conversation.
- Kept
- Until you delete the conversation or your account.
- Notifications
- What exactly
- For each browser: the address its push service gave it and the encryption keys for that address. In the iOS or Android app: the device’s push token. The date of the last morning note.
- Why
- To send the morning note you turned on, at most once a day.
- Kept
- Until you turn it off or remove the device, or the push service reports the address gone.
- Generation records
- What exactly
- For each AI-written text: the model, the number of tokens, the time taken and the outcome — no text, no birth details.
- Why
- To control cost and quality.
- Kept
- Until you delete your account.
- Abuse protection
- What exactly
- Counters keyed by a keyed hash (HMAC-SHA-256) of your IP address or its network, your account identifier or, for sign-in attempts and emailed links, your email — never the values themselves.
- Why
- To stop brute-force sign-in attempts, floods of email and overuse.
- Kept
- About two days.
- Place searches
- What exactly
- The text you type into a place search. It is not stored with your account; results are cached by query.
- Why
- To find the place you mean.
- Kept
- Cached for up to a day.
- Technical logs
- What exactly
- Our functions record errors (by type) and counts — never birth details, reading text or questions. Our hosting platform records each function run’s duration.
- Why
- To keep the service working.
- Kept
- One month. We do not switch on CDN access logs.
If you turn on the morning note, your personal readings for the day are prepared in advance each morning, so they are ready when the note arrives.
What the AI receives
Readings and Ask the Sky answers are written by Claude Haiku 4.5, a language model made by Anthropic, from facts our own astronomy engine computes. The model computes nothing itself, and it never sees your account.
For your personal readings the model receives the positions of your birth chart and today’s sky, computed from your birth details — not the details themselves:
- your natal chart as measured positions: the Sun, the Moon and the planets in both zodiacs, and your rising sign, angles and houses only when your birth time allows them; the aspects between them; today’s sky measured against them; and how far precession has shifted the zodiac since your birth, as an angle (for example “0.57°”);
- for today’s readings, when the Sun, the Moon and the planets rise and set where you are, in local times, and any eclipse seen from there;
- the frames used: tropical or sidereal, the ayanamsa and the house system;
- whether your birth time is exact, approximate or unknown;
- your hemisphere — northern or southern — but not your latitude;
- for today’s readings only: your local date, and the abbreviation of your time zone that its times are shown in (such as “AEST”).
Never sent, for any reading or answer: your name, email address, account or reading identifiers, IP address, birth date, birth year, birth time or age; the names or coordinates of your birthplace or current place; or your time zone’s name (names such as “Australia/Hobart” name a city).
Ask the Sky sends a short note about you — your local date with its weekday and the part of the day, your zodiac frame, whether a birth profile and a location are on file, and how accurate your birth time is — then your question and the conversation’s earlier questions and answers exactly as typed, and the facts its tools compute to answer, in the same form as above. Anything you type yourself, such as a date or a place, is sent as you typed it. A question that suggests distress or thoughts of self-harm is not sent to the model: you get a reply with places to find help.
What the positions imply. A chart’s positions are derived from birth details, so they are not anonymous: someone with an ephemeris could, in principle, work back from them to a birth date — and, with the rising sign and houses, to an approximate time and latitude. Our prompts never state those details, and the model is instructed not to state or estimate them.
Public readings (the day’s sky, regions and signs) contain no personal data. Under Anthropic’s commercial terms for its API, what we send is not used to train its models and is kept only for a limited period for safety monitoring [owner: confirm against Anthropic’s current commercial terms and data processing addendum].
Who helps us run the service
These providers process data on our behalf, only to run What’s My Sky?:
| Provider | What they do | What they receive |
|---|---|---|
| Amazon Web Services | Hosting: the content delivery network (CloudFront), the servers (Lambda), file storage (S3), secret storage and logs. | Every request to the site — including your IP address, as any web server receives it — and the data above while it is processed. |
| Database provider (Neon) | Stores the data described above. | The data described above, encrypted in transit. |
| Amazon Web Services (Simple Email Service) | Sends the only two emails we send: the link that confirms your email address, and a password-reset link when you ask for one. | Your email address and the message, which holds only that link: no birth details, no tracking images, no tracked links. |
| Anthropic | Writes readings and Ask the Sky answers (Claude Haiku 4.5). | Only what is listed under “What the AI receives”. |
| Open-Meteo (or Photon by komoot) | Place search. | The text typed into a place search and a language code, sent from our servers — not your IP address. |
| Browser push services (Google, Mozilla, Apple, Microsoft) | Deliver the morning note in your browser. | Your subscription’s address and an encrypted message they cannot read. |
| Apple Push Notification service, Firebase Cloud Messaging | Deliver the morning note in the iOS and Android apps (when available). | The app’s push token and the note. |
| Google Fonts | Fonts for the site’s share images. | Requests from our servers only, when an image is drawn; no personal data. |
- Amazon Web Services
- What they do
- Hosting: the content delivery network (CloudFront), the servers (Lambda), file storage (S3), secret storage and logs.
- What they receive
- Every request to the site — including your IP address, as any web server receives it — and the data above while it is processed.
- Database provider (Neon)
- What they do
- Stores the data described above.
- What they receive
- The data described above, encrypted in transit.
- Amazon Web Services (Simple Email Service)
- What they do
- Sends the only two emails we send: the link that confirms your email address, and a password-reset link when you ask for one.
- What they receive
- Your email address and the message, which holds only that link: no birth details, no tracking images, no tracked links.
- Anthropic
- What they do
- Writes readings and Ask the Sky answers (Claude Haiku 4.5).
- What they receive
- Only what is listed under “What the AI receives”.
- Open-Meteo (or Photon by komoot)
- What they do
- Place search.
- What they receive
- The text typed into a place search and a language code, sent from our servers — not your IP address.
- Browser push services (Google, Mozilla, Apple, Microsoft)
- What they do
- Deliver the morning note in your browser.
- What they receive
- Your subscription’s address and an encrypted message they cannot read.
- Apple Push Notification service, Firebase Cloud Messaging
- What they do
- Deliver the morning note in the iOS and Android apps (when available).
- What they receive
- The app’s push token and the note.
- Google Fonts
- What they do
- Fonts for the site’s share images.
- What they receive
- Requests from our servers only, when an image is drawn; no personal data.
If you choose “Continue with Google” or “Continue with Apple” on the website, that company tells us who you are, under its own privacy policy. The App Store and Google Play distribute the apps under theirs.
Cookies and storage on your device
We use no advertising or analytics cookies. Each item below exists only for a feature you use. The names starting with __Secure- are sent only over HTTPS, which the site always uses; a copy of the app running on a computer for development, over plain HTTP, uses the same names without that prefix.
| Name | Purpose | Lifetime |
|---|---|---|
__Secure-sky.session_token | Keeps you signed in. Scripts on the page cannot read it. | 30 days, renewed as you use the app |
sky.onboarding | Remembers whether your birth details are still missing, so the right page opens. | 30 days |
__Secure-sky.state | Protects a Google or Apple sign-in while it is in progress. | Five minutes |
__Secure-sky.device | Remembers that this browser has signed in to your account with its password, so that a flood of wrong passwords from elsewhere cannot lock you out here. It holds a random code and a signature, not your email address, and is sent only to the sign-in service. Scripts on the page cannot read it. | One year, renewed when you sign in |
wms_zodiac_frame | The zodiac frame you chose for horoscopes while signed out (with the same value in local storage). | One year |
wms_region | The region of the home page’s “sky over your region”. | Up to a year |
wms.pwa.engagement.v1 | Local storage: counts visits so the offer to install the app appears only after you have used the site a little, and remembers if you dismissed it. | Until you clear it |
| Offline copies | The service worker keeps public pages, public readings, star data and images so the site works offline. Personal pages and data are never kept, and the copies are cleared when you sign out. | Until replaced |
| App storage | In the iOS and Android apps: the site’s address (for the offline page) and, with notifications on, the device’s push token. | Until you delete the app |
__Secure-sky.session_token- Purpose
- Keeps you signed in. Scripts on the page cannot read it.
- Lifetime
- 30 days, renewed as you use the app
sky.onboarding- Purpose
- Remembers whether your birth details are still missing, so the right page opens.
- Lifetime
- 30 days
__Secure-sky.state- Purpose
- Protects a Google or Apple sign-in while it is in progress.
- Lifetime
- Five minutes
__Secure-sky.device- Purpose
- Remembers that this browser has signed in to your account with its password, so that a flood of wrong passwords from elsewhere cannot lock you out here. It holds a random code and a signature, not your email address, and is sent only to the sign-in service. Scripts on the page cannot read it.
- Lifetime
- One year, renewed when you sign in
wms_zodiac_frame- Purpose
- The zodiac frame you chose for horoscopes while signed out (with the same value in local storage).
- Lifetime
- One year
wms_region- Purpose
- The region of the home page’s “sky over your region”.
- Lifetime
- Up to a year
wms.pwa.engagement.v1- Purpose
- Local storage: counts visits so the offer to install the app appears only after you have used the site a little, and remembers if you dismissed it.
- Lifetime
- Until you clear it
- Offline copies
- Purpose
- The service worker keeps public pages, public readings, star data and images so the site works offline. Personal pages and data are never kept, and the copies are cleared when you sign out.
- Lifetime
- Until replaced
- App storage
- Purpose
- In the iOS and Android apps: the site’s address (for the offline page) and, with notifications on, the device’s push token.
- Lifetime
- Until you delete the app
The orrery’s “use my location” asks your browser or phone for your position only when you use it, and the position stays on your device. The link from onboarding to the orrery’s “your birth sky” carries your birth moment and your birthplace, rounded to about a kilometre, in the page address, so your browser’s history keeps them.
What we never do
- Sell or rent your personal data, or share it for advertising.
- Show ads, or use analytics or tracking tools that follow you across sites.
- Send marketing email, or track whether you open our emails or follow their links.
- Write your birth details, reading text or questions to our logs.
- Make decisions about you with legal or similarly significant effects: readings are written automatically, and that is all they are.
Legal bases
Under the GDPR we rely on:
- Our contract with you — to run your account, compute your chart and readings, keep your settings and conversations, and export or delete your data.
- Your consent — for notifications and for “use my location”. Withdraw it at any time by switching the notification off in Settings, or in your browser or phone settings.
- Our legitimate interests — protecting the service against abuse (the hashed rate-limit counters), keeping it working (error logs) and controlling the cost of AI generation. You can object; write to us.
- Legal obligations — when the law requires us to keep or disclose data.
Your rights and controls
- Access and portability: Settings → Your data → Download my data gives you a JSON file with your account, sign-in methods, sessions, birth details, settings, readings and Ask the Sky conversations (passwords and tokens are never included).
- Correction: change your birth details and settings in Settings; for anything else, write to us.
- Deletion: Settings → Account → Delete account deletes your account and everything linked to it at once. Copies in our database provider’s backups expire within [backup retention, days].
- Objection, restriction and consent: write to us, or turn the notification off.
- Complaints: you can complain to your data protection authority; we would welcome the chance to help first.
We answer requests within one month. California residents: we do not sell or share personal information.
Security
- Everything travels over HTTPS; passwords are stored only as scrypt hashes; Google and Apple sign-in tokens are encrypted at rest.
- The session cookie is HttpOnly, Secure and SameSite=Lax, and every change you make must come from our own site.
- Sign-in attempts and costly features are rate-limited. Wrong passwords slow down attempts from the network they come from, and never lock you out of a browser you have signed in with. Resetting your password signs out every device.
- Pages load scripts, styles and data only from our own site (a Content Security Policy); the AI service’s key never leaves our servers.
- Only the app’s servers hold the database credentials; secrets live in encrypted storage.
International transfers
Our hosting runs in the United States (AWS, us-east-1) and the content delivery network serves you from its nearest location. Anthropic processes AI requests in the United States. The database is hosted in [database region]. Transfers from the EU and UK rely on [the EU–US Data Privacy Framework or Standard Contractual Clauses, per provider].
Children
What’s My Sky? is not directed at children. You must be at least 16 years old to create an account. We do not knowingly collect data from anyone younger; if you believe a child has created an account, write to us and we will delete it.
Changes to this policy
When this policy changes we will update it here with a new date and, for significant changes, tell you in the app before they take effect.
Contact
[owner contact email] · [owner name or company] · [postal address]. If the law requires one, our representative in the EU or UK is [representative, if required].