Last updated
21 July 2026
1. Controller
The controller responsible for data processing in connection with Zodiacally is Aleks Paramonov, Grandweg 162, 22529 Hamburg, Germany, support@zodiacally.com. No data protection officer has been appointed because this is currently not required for this offer.
2. What data we process
Depending on how you use Zodiacally, we may process the following data:
- birth data entered by you, such as date of birth, optional birth time, birth place, optional name, language, and partner birth data for compatibility readings
- calculated astrology data, such as planetary positions, houses, aspects, moon phase, timezone, latitude, and longitude
- AI reading output, archive entries, mood check-in values, and profile settings stored in browser session storage for guests or linked to a signed-in account when account synchronization is used
- support-chat messages, ticket status, language, current page path, an account identifier for signed-in users, or a one-way guest access-token hash; a reply email address is stored when needed for human support
- account identifiers and, when you use the Journal community feature, your one-to-five-star rating, comment text, article reference, language, and timestamps
- email addresses used for account authentication, requested reading delivery, newsletter registration, or human support, plus newsletter consent version, confirmation status, timestamps, and one-way token hashes
- payment-related metadata such as Stripe Checkout session ID, product type, currency, payment status, and request verification token; card details are processed by Stripe and are not stored by Zodiacally
- technical access data that may arise when operating the website or server, such as IP address, browser type, device data, timestamps, requested pages, error logs, and rate-limit metadata; support and analytics rate limits use pseudonymous hashes instead of storing the raw address in their event tables
- consent choices stored locally in your browser; after Analytics consent, random visitor and session identifiers, event name and time, page path without query parameters, coarse device class, referrer host, and bounded interaction metadata. These identifiers are pseudonymized again on the server before storage; names, email addresses, birth data, form values, full referrer URLs, and raw IP addresses are not stored in the analytics event table
3. Purposes and legal bases
We process personal data only for defined purposes. The relevant legal basis depends on the feature and jurisdiction.
- providing requested readings, reading emails, compatibility checks, support-chat answers and requested human support handoffs, location lookup, paid checkout access, account functions, and the requested publication or management of Journal comments and ratings: Article 6(1)(b) GDPR where processing is necessary to provide the requested service
- sending the newsletter after double opt-in and recording the related consent: Article 6(1)(a) GDPR; consent can be withdrawn at any time through the unsubscribe link
- payment verification, security, abuse prevention, debugging, rate limits, community moderation, and reliable operation: Article 6(1)(f) GDPR based on our legitimate interest in secure and stable operation
- optional Google Analytics, Google AdSense, personalized ads, advertising measurement, cookies, local storage, or consent records where legally required: Article 6(1)(a) GDPR and Section 25 TDDDG/ePrivacy consent rules
- legal retention, tax, compliance, or response to lawful requests: Article 6(1)(c) GDPR where applicable
4. Session storage, account storage, cookies, and consent
For guests, profile data, reading archives, and mood check-ins may be stored in browser session storage. The support chat stores only the current conversation ID and a random guest access token in session storage so the ticket can be restored after a page reload. The conversation itself is stored server-side in Supabase. Chat text is sent to the configured AI provider only when an AI answer or internal draft is requested.
If you sign in and use account synchronization, account profile and related account data are stored in Supabase so they remain available across devices. A support conversation is linked to the server-verified account ID and cannot be opened with a client-provided user ID.
Your consent choices are stored in browser local storage so the banner does not reappear on every page. You can change your choices at any time through the Privacy settings button.
Only after Analytics consent, a random visitor identifier is stored locally and a random session identifier is kept in session storage. Sessions rotate after inactivity and the visitor identifier is rotated no later than the analytics retention period. Withdrawing Analytics consent stops collection and removes these identifiers from browser storage.
Necessary storage is used for requested app functions, security, support-ticket continuity, and consent management. Optional Analytics and Ads only load after the related consent has been given.
5. Recipients and third-party services
Your data is not sold. It is shared only where needed to provide, secure, or finance the service. Depending on configuration, recipients may include:
- OpenAI: AI-powered interpretation of calculated chart data. Birth profile and calculated astrology data may be sent to OpenAI so the reading can be generated. OpenAI may also process limited support-chat text if it is configured as the support model provider.
- Alibaba Cloud Model Studio/Qwen or Moonshot AI/Kimi: a bounded conversation history, selected verified support articles, language, and limited page context may be processed if one of these providers is configured. The chatbot has no direct source-code, database, payment, or account access.
- Stripe: payment processing through Stripe Checkout. Stripe processes payment details and returns payment status information so Zodiacally can unlock the paid reading.
- Resend: delivery of account confirmation, requested reading, newsletter confirmation, newsletter emails, support-ticket alerts, customer confirmations, and human support replies, plus management of confirmed newsletter contacts.
- Hosting and infrastructure providers, currently including the providers used for frontend and backend deployments, such as Vercel and Railway.
- OpenStreetMap/Nominatim or another geocoding provider: birth place text may be sent for latitude/longitude lookup if coordinates are not already provided.
- Google Analytics: usage measurement only after Analytics consent and only if a measurement ID is configured.
- Google AdSense: advertising display and ad measurement only after Ads consent. For users in the EEA, UK, and Switzerland, Google requires a Google-certified CMP with IAB TCF for AdSense ad serving.
- Supabase: account authentication, account-linked profile storage, server-side support tickets and messages, newsletter consent records and promotional entitlement status, plus account-linked Journal comments and ratings. Support tables are not directly readable through browser roles. Ratings, comments, article references, and timestamps are publicly visible under a generic community label; account IDs, profile names, and email addresses are not displayed in the Journal.
- Firebase Crashlytics is not currently loaded on the website. If crash reporting is introduced later, this policy will be updated before activation.
6. International transfers
Some providers may process data outside the European Economic Area, including in the United States or other countries. Where this happens, the transfer is intended to rely on an adequacy decision, standard contractual clauses, consent, or another valid transfer mechanism under GDPR, depending on the provider, selected processing region, and configuration.
7. Storage and deletion
The browser keeps support conversation credentials only for the current browser session. Support tickets and messages are stored server-side so the conversation can be processed, escalated, answered, and documented. Closed tickets are subject to periodic retention review; the technical retention target is configurable and currently defaults to 90 days, but automatic deletion is not enabled until operational and legal review is complete.
If a ticket is escalated, the transcript and reply address may also be retained in the support mailbox as long as needed to handle and document the request.
Account-linked profile data remains until you change or delete the account, subject to necessary backups and legal obligations. Consent choices remain in local storage until you delete them in the browser or change them through the Privacy settings button.
Unconfirmed newsletter registrations expire after 24 hours and are periodically deleted. Confirmed newsletter addresses remain until you unsubscribe. Unsubscribed records may be retained for a limited period as a suppression and consent record before deletion, subject to legal requirements.
An address entered only to send a requested reading is not added to the newsletter database. It is transmitted to Resend for that delivery.
Journal comments and ratings remain stored and publicly visible until you remove your review through the article form, your account is deleted, or removal is required for moderation or legal reasons.
Server-side cache entries and rate-limit data are kept only for limited periods needed for performance, cost control, security, and abuse prevention.
Legal retention obligations may require longer storage in individual cases.
8. Usage analytics and Google AdSense
Usage analytics is optional and starts only after consent through the Zodiacally consent banner. Zodiacally then records data-minimized first-party events in Supabase to understand visits, page and CTA use, session engagement, funnel progress, and exit pages. Browser identifiers are random and are stored only as one-way server-side HMAC values. Analytics events are automatically reviewed for deletion and are retained for no longer than the configured period, currently up to 395 days, unless shorter deletion or legal retention is required.
If a Google Analytics measurement ID is configured, Google Analytics 4 may additionally process page views, events, approximate location, device, and browser information after the same Analytics consent. Google Analytics 4 states that it does not log or store individual IP addresses. Google may nevertheless process data as an independent provider according to its own terms and privacy information.
If Ads are enabled, Google AdSense may process data for ad delivery, fraud prevention, frequency capping, ad measurement, and, where consented, personalization.
9. Data security
We take appropriate technical and organizational measures to protect personal data against loss, misuse, and unauthorized access. This includes data-minimizing processing, public/private key separation, server-side AI calls, access restrictions, and securing the technical infrastructure.
10. Your rights
Subject to the applicable legal requirements, you may request access, rectification, erasure, restriction of processing, data portability, and objection to processing. Where processing is based on consent, you may withdraw consent at any time with effect for the future.
You also have the right to lodge a complaint with a competent data protection supervisory authority. For Hamburg, this is the Hamburg Commissioner for Data Protection and Freedom of Information.
If you have questions about privacy or would like to exercise your rights, please use the contact address listed above.
11. Automated decision-making
Zodiacally may use automated calculations and AI-generated text to create astrology readings and answer first-line support questions. These outputs do not produce legal effects or similarly significant decisions about you within the meaning of Article 22 GDPR. The support assistant cannot inspect or alter account, payment, or database records.
12. Requirement to provide data
You are not legally required to provide birth data. Without birth data, Zodiacally cannot create a personalized chart-based reading. Without consent where consent is required, optional advertising or analytics functions may be unavailable or limited.
13. Changes to this privacy policy
We may update this privacy policy if features, third-party services, deployment providers, or legal requirements change. The version published on this page shall apply in each case.
