Privacy Policy
Version 2.0 · Effective 6 September 2026
Replaces the version dated December 2024, which described infrastructure we no longer use.
1. Who we are and how to reach us
1.1 AstroDexa is operated by Dexa LLC ("AstroDexa", "we", "us"). Postal address: published here once company registration completes; until then write to support@astrodexa.com. Email: support@astrodexa.com.
1.2 We are the data controller for the processing described in this policy, except where section 13 says an astrologer is the controller and we act on their behalf.
1.3 We are in the process of appointing a representative in the European Union under Article 27 GDPR. This section will name them as soon as they are appointed. Until then, contact us directly at support@astrodexa.com.
1.4 Privacy contact: support@astrodexa.com. We answer privacy requests within one month. If a request is complex, we may extend that by up to two further months and will tell you why inside the first month.
1.5 We have not appointed a Data Protection Officer; our current processing does not require one. Privacy matters go to support@astrodexa.com.
2. Who this policy covers
2.1 This policy applies to everyone who uses AstroDexa, anywhere in the world. We apply the standard set by the EU General Data Protection Regulation to all users, not only to users in Europe.
2.2 Where a right or a procedure exists only because of EU or EEA law, we say so. We still apply the practical part of it — export, deletion, correction — to everyone.
2.3 This policy covers astrodexa.com, the AstroDexa web application, the astrologer directory, and the consultation marketplace.
3. What we collect, and where it comes from
3.1 Data you give us directly
| Category | Examples |
|---|---|
| Account data | Email address, display name, chosen language, account role (free, Elara, Astrologer) |
| Authentication data | One-time login codes, session tokens, the account identifier returned by Google or Apple if you sign in that way |
| Birth data — your own | Date, time and place of birth, and the chart settings you choose |
| Birth data — other people's | Date, time and place of birth for anyone you add: partners, family, clients, public figures |
| Chart and workspace data | Saved charts, workspace layout, chart settings, notes and journal entries |
| Booking data | Consultations you book or receive, times, the offering booked, messages exchanged about a booking |
| Astrologer profile data | Public profile text, photo, links, offerings, prices, and verification or accreditation evidence you send us |
| Payment metadata | Plan, amount, currency, country for tax, invoice reference, subscription status. We never see or store full card numbers |
| Support and correspondence | Emails and messages you send us |
3.2 Data we generate about you. Interpretive chart output produced by our calculation engine, account activity records needed to run the service (login events, plan changes, security logs), and error diagnostics.
3.3 Data we receive from others. Payment and subscription status from Lemon Squeezy and Stripe. Basic profile fields and a token from Google or Apple when you use those sign-in options. Identity and payout verification status from Stripe for astrologers who take payments.
3.4 Data about you entered by someone else. If an astrologer works with you, or a friend or relative casts a chart for you, your birth data may be in AstroDexa because they entered it. Section 8 explains that situation in full. The source of that data is the user who entered it.
3.5 Analytics data. We use Plausible, which is cookieless and collects no personal data or persistent identifiers. We also count, ourselves, what the astrologer directory showed and what was clicked in it. See section 15.
4. Why we use your data, and our legal basis
Under GDPR every use of personal data needs a lawful basis. This table is the complete list.
| What we do | Why | Legal basis |
|---|---|---|
| Create and run your account, log you in, keep your session | You asked us to provide the service | Contract, Art. 6(1)(b) |
| Calculate, store and display your charts, workspaces and journal | Core function of the product | Contract, Art. 6(1)(b) |
| Send login codes, receipts, booking confirmations, reminders and service notices | Operating the service you signed up for | Contract, Art. 6(1)(b) |
| Take payment, handle subscriptions, pay astrologers | Performing the purchase | Contract, Art. 6(1)(b); legal obligation for tax and accounting records, Art. 6(1)(c) |
| Run the booking marketplace: match, book, confirm, invoice | Performing the booking, and our own interest in operating a functioning marketplace | Contract, Art. 6(1)(b), and legitimate interests, Art. 6(1)(f) |
| Share your chart with an astrologer you book, so they can prepare your reading | Performing the consultation you booked | Contract, Art. 6(1)(b) |
| Share your journal or notes with an astrologer you book | Only if you tick the share box for that specific booking | Consent, Art. 6(1)(a), per booking, never remembered between bookings |
| Host client charts and portal records on an astrologer's behalf | The astrologer's relationship with their client | We act as processor for the astrologer — see section 13 |
| Improve the product using aggregated and de-identified data: which features are used, where errors occur, how fast pages load | We need to know what is broken and what is used in order to fix and improve it. Personal data is touched only in the step that produces the aggregate, and never analysed in identifiable form | Legitimate interests, Art. 6(1)(f), supported by a documented Legitimate Interest Assessment |
| Keep the service secure: abuse detection, rate limiting, fraud prevention, audit logs | Protecting accounts and the platform | Legitimate interests, Art. 6(1)(f) |
| Email you about features similar to what you already bought | Keeping existing customers informed | ePrivacy soft opt-in, with an unsubscribe link in every message and at the point we collect your address |
| Email marketing to people who have not bought anything | Not covered by the above | Consent, withdrawable at any time |
| Cookieless analytics, and counting what the directory showed | Understanding aggregate traffic, and whether our own listings and placements work | Plausible processes no personal data. The directory counting in section 15.3 stores no identifier that outlives the day it was made, and none we can attach to an account; both are disclosed here for transparency |
4.1 What "improve our products" means here, precisely. We never use your personal data to improve the product. Improvement work runs only on counts, timings, error reports and aggregated, de-identified statistics — data that can no longer be tied to you and is therefore no longer personal data. Your personal data is touched only in the automated step that produces those aggregates, and you can object to that step (section 12.6). We never read or use your journal, your notes, your chart interpretations or your chat history to build, tune or train anything — there is no setting that enables it, because we do not do it. All improvement work happens inside our organization; nothing leaves it (section 4.2). If any of this ever changes, it changes through a new version of this policy under section 19, never quietly.
4.2 We do not sell your data. We do not sell, rent or trade personal data, and we do not share it with advertisers, data brokers or ad networks. There are no advertising or tracking pixels on AstroDexa. The only parties who receive your data are the service providers listed in section 9, who process it on our instructions, and the recipients described in sections 8 and 13.
4.3 If we ever rely on legitimate interests, you can object under section 12. We will stop unless we can show compelling grounds that override your interests, or we need the data to establish or defend legal claims.
5. Sensitive data
5.1 Birth date, birth time and birth place are ordinary personal data. They are not, by themselves, special-category data under Article 9 GDPR.
5.2 But free text can become sensitive the moment it is written. A journal entry about an illness, a note about a relationship, a message that reveals a belief — these are special-category data, and so, potentially, is an interpretation our engine generates that reads as a statement about your health or your beliefs. No European regulator has yet issued guidance on astrology software specifically. We take the cautious position.
5.3 In practice that means: where you store free text or interpretive output in AstroDexa, we treat it as potentially special-category data, we ask for your explicit consent to store and process it on that footing, and we keep it out of any product-improvement or model-training use entirely (section 4.1).
5.4 Please do not put more sensitive detail into free-text fields than you need to.
6. Automated processing and interpretation
6.1 AstroDexa calculates charts and generates interpretive text automatically. That text is an astrological interpretation, not a decision about you. We do not use it to decide anything with legal or similarly significant effect — we do not use it to grant or refuse service, set prices, or assess anyone's suitability. Article 22 GDPR automated-decision-making rules are therefore not engaged.
6.2 We tell you this anyway, because interpretive output can read as a statement about your health, your character or your beliefs, and you should know it was produced by software.
7. Cookies and local storage — see section 14
8. Data about other people that you enter
8.1 AstroDexa lets you enter birth data for people other than yourself: partners, family, clients, public figures.
8.2 Your responsibility. When you enter someone else's data, you need your own lawful reason to do so.
- If you are a private individual casting a chart for a relative or friend out of personal interest, that is normally covered by the household exemption in Article 2(2)(c) GDPR, which applies to your own activity.
- If you are an astrologer entering a client's data, that is professional use. The household exemption does not apply. You are the controller of that data and you need your own lawful basis, your own privacy notice to your client, and the Data Processing Agreement described in section 13.
8.3 Our responsibility. The household exemption covers the individual user's own activity. It does not exempt us as the provider of the tool. We remain responsible for how the platform handles that data.
8.4 Article 14 and why we cannot write to everyone. GDPR normally requires us to inform a person when we hold data about them that we got from someone else. We cannot realistically contact every person whose birth data a user has typed into a private chart — we usually hold nothing but a name and a birth moment, with no way to reach them. We rely on the "disproportionate effort" exemption in Article 14(5)(b), and this public policy is the transparency measure that goes with it. We document that assessment internally and review it.
8.5 If you are that person. If you believe your data is in AstroDexa because someone else entered it, write to support@astrodexa.com. We will locate it, tell you what we hold, and act on your rights under section 12 — subject to the controller split explained in section 13.2, which determines who has to make the decision about deleting a copy held inside an astrologer's client records.
8.6 Public figures. Charts of public figures held for research or editorial purposes rest on legitimate interests, using birth data that is already published. The same rights in section 12 apply.
9. Who else processes your data
We keep the primary database in the European Union. These are the service providers who process personal data for us. Each acts on our instructions under a data processing agreement, except where noted.
| Provider | What they do | Where | Transfer mechanism |
|---|---|---|---|
| Hetzner Online GmbH | Hosts the application and the primary database | Germany / Finland | No transfer — EU company, EU infrastructure |
| Cloudflare, Inc. | DNS, network security, traffic routing | United States (global edge network) | Standard Contractual Clauses, plus EU-US Data Privacy Framework certification |
| IDrive Inc. (IDrive e2) | Encrypted database backups | Frankfurt, Germany | Standard Contractual Clauses |
| Lemon Squeezy, LLC | Merchant of record for subscriptions and one-time purchases; billing, invoicing, VAT | United States | Standard Contractual Clauses. Lemon Squeezy is also a controller in its own right for the tax and transaction records it must keep as seller of record |
| Stripe, Inc. / Stripe Payments Europe | Payments and payouts for consultations; identity and payout verification for astrologers | United States and Ireland | Standard Contractual Clauses, plus Data Privacy Framework certification |
| Amazon Web Services (SES) | Sends transactional email | eu-central-1, Frankfurt | Standard Contractual Clauses built into the AWS terms |
| Google LLC | "Sign in with Google", if you use it | United States | Data Privacy Framework certification |
| Apple Inc. | "Sign in with Apple", if you use it. Apple's private relay means Apple may be the only party that sees your real address | United States | Apple's published transfer terms |
| Plausible Insights OÜ | Cookieless traffic analytics | Estonia; servers in Germany, Finland and Slovenia | No transfer — EU company, EU infrastructure |
9.1 We also disclose data where the law requires it — a valid court order, a regulatory demand, a tax authority — and to professional advisers under confidentiality where we need advice about a specific matter.
9.2 If we ever add or change a processor, we update this list before the change takes effect.
10. International transfers
10.1 Your account data, charts and journal live on servers in the European Union. Several of the providers in section 9 are US companies, and their parent companies are subject to US law even when the data sits on European hardware. That counts as an international transfer under Chapter V GDPR.
10.2 For each of them we rely on the European Commission's Standard Contractual Clauses. Where a provider is also certified under the EU-US Data Privacy Framework, we treat that as an additional safeguard rather than the only one, because the Framework's future is currently before the Court of Justice of the European Union on appeal. If the Framework falls, the Standard Contractual Clauses in our agreements remain in force.
10.3 You can ask us for a copy of the safeguards in place for any specific provider: support@astrodexa.com.
11. How long we keep things
| Data | Retention |
|---|---|
| Account, charts, workspaces, journal | For as long as your account is open |
| After you delete your account | Deleted from live systems within 30 days, subject to the exceptions below |
| Backups | Deleted data ages out of our rolling backups within 30 days. During that window backups are access-restricted and used only to restore the service after a failure |
| Billing, invoice and tax records | Kept for the period tax law requires, typically 7 to 10 years depending on jurisdiction |
| Identity and payout verification data for astrologers | Held by Stripe under its own anti-money-laundering obligations, on Stripe's schedule, not ours. We cannot shorten it |
| Booking records and consultation history | Kept while the astrologer's account is open, then 12 months after account closure |
| Client records held for an astrologer | On the astrologer's instructions, and deleted when they instruct us or when their account closes plus 30 days |
| Security and access logs | 90 days |
| Support correspondence | 24 months |
| Analytics | Aggregate counts: no personal data, retained indefinitely in aggregate form |
| Individual directory-exposure records (section 15.3) | 90 days, then deleted |
11.1 About backups specifically. When you delete something, it goes from the live database immediately. Our backup system continuously ships changes offsite, and old snapshots are superseded and overwritten as they age. That means deleted data leaves the backups on the rotation cycle above rather than instantly. We do not go into backups to retrieve deleted data, and backups are only ever restored wholesale after a failure.
12. Your rights
You have these rights over data we hold as controller. They are free to exercise. Write to support@astrodexa.com, or use the tools in your account settings where they exist.
12.1 Access. Ask what we hold and get a copy.
12.2 Portability. Get the data you gave us in a machine-readable format (JSON or CSV), or ask us to send it to another provider where that is technically feasible.
12.3 Rectification. Correct anything wrong. Most account and chart data you can edit yourself.
12.4 Erasure. Delete your account and your data. Read section 12.8 for the limits.
12.5 Restriction. Ask us to keep data but stop using it, while a dispute about accuracy or lawfulness is resolved.
12.6 Objection. Object to any processing we base on legitimate interests. You can object to direct marketing at any time and we stop immediately, no balancing test.
12.7 Withdraw consent. Where we rely on consent, withdraw it at any time. That does not undo processing already carried out lawfully.
12.8 What erasure does not reach.
- Records we must keep by law. Invoices, tax records, and Stripe's identity-verification data for astrologers. We keep the minimum, and we stop using it for anything else.
- Data held for legal claims. If there is a live dispute, we may keep what we need to defend it.
- Copies inside an astrologer's client records. If an astrologer has you as a client, the record of your work with them is theirs, not ours. Section 13.2 explains who to ask and what we do.
- Backups. They age out on the rotation cycle in section 11.
12.9 Complaints. If you think we have handled your data badly, tell us first — we would rather fix it. You also have the right under Article 77 GDPR to complain to a data protection supervisory authority, normally in the country where you live, where you work, or where the problem happened. If you are in the EU or EEA, the authority in your own country will take your complaint. You can also go to court.
13. Astrologers, clients, and who controls what
AstroDexa is both an app and a marketplace, and the roles differ depending on which part you are using.
13.1 We are the controller for: your own account, your own charts and journal, the public astrologer directory, search and ranking on the platform, our own marketing, the booking and payment flow, platform security, and aggregate product analytics. For the booking flow, we and the astrologer each determine part of the purpose, so we act as joint controllers for that specific step; a summary of who does what is available on request at support@astrodexa.com.
13.2 The astrologer is the controller of the client records they keep inside AstroDexa: the charts they cast for you, the notes they take, their portal for you, their record of your sessions. We host and process that on their instructions. We are their processor.
What this means in practice:
- If you want a copy, a correction or a deletion of what your astrologer holds about you, ask that astrologer. They decide.
- If you ask us instead, we will forward your request to them and tell you we have done so. We will not delete a client record on the client's request without the astrologer's instruction, because it is not ours to delete.
- If the astrologer closes their account, their client records are deleted on the schedule in section 11.
- Every astrologer who uses AstroDexa professionally is offered a standard Data Processing Agreement under Article 28 GDPR, and using the client-portal features means accepting it.
13.2a Sharing for a consultation. When you book a consultation, your chart is shared with that astrologer — they cannot prepare a reading without it. Anything beyond the chart is shared only if you choose it at booking time: journal entries and notes go to the astrologer only when you tick the share box for that specific booking, and that choice is never remembered for the next one. Access is temporary: it ends one hour after the consultation ends (for a written reading, one hour after delivery), and you can revoke it earlier. After that, the shared chart and any shared notes disappear from the astrologer's view. The notes the astrologer wrote themselves about your session are their own client records, held by them as controller under section 13.2. Outside a booking you have made, no astrologer sees your data.
13.3 Astrologer payout data. Identity documents, bank details and beneficial-ownership information for payouts go to Stripe. Stripe holds that under its own regulatory obligations. Neither we nor the astrologer can make Stripe delete it early.
14. Cookies and local storage
14.1 We use browser storage only for things the service cannot work without: your login session, security tokens, and your interface preferences such as language, theme and workspace layout. Under the ePrivacy rules these are "strictly necessary" and do not require a consent banner. We disclose them here because being exempt from asking is not the same as being exempt from telling.
14.2 The law treats localStorage and similar browser storage the same as cookies. Our session token may be held in either, depending on your browser.
14.3 We run no advertising cookies, no tracking pixels, no social-media widgets, no cross-site identifiers, and no third-party marketing scripts.
14.4 If we ever add storage that is not strictly necessary, we will ask for your consent first, and this section will say so before it happens.
15. Analytics
15.1 We use Plausible Analytics to count page views and see which parts of the site are used. Plausible sets no cookies, stores nothing on your device, assigns no persistent identifier, and does not follow you across sites. It produces aggregate counts, and no profile of you.
15.2 For that reason we do not ask for consent to it. Plausible is an Estonian company running on European infrastructure, so no data leaves the EU for this purpose.
15.3 Separately from Plausible, we count what the astrologer directory showed and what was clicked in it: which profile appeared, on which listing, in which position, whether the placement was a paid Boost, and whether it was clicked. We keep the individual records for 90 days and the daily totals indefinitely. No IP address, browser identifier, account identifier, referrer or page address is stored with them. Records made on the same day are tied together by a hash of your address and browser taken under a random key that exists only in our server's memory and is replaced every night; once it is replaced, that day's records cannot be recomputed, matched to the next day's, or matched to you. Nothing is written to your device for this, and so no consent is asked for it either.
16. Age
16.1 AstroDexa is for people aged 16 and over. You cannot register an account if you are under 16.
16.2 The minimum age for a child to consent to online services differs across Europe, from 13 to 16. We use 16 everywhere rather than applying different rules by country.
16.3 We do not knowingly collect data from anyone under 16. If we learn that an account belongs to someone under 16, we close it and delete the data. If you believe a child has an account, tell us at support@astrodexa.com.
17. Security
17.1 Data is encrypted in transit (TLS) and backups are encrypted at rest. Access to production systems is limited to the people who need it, with individual accounts and multi-factor authentication.
17.2 We do not store passwords, because AstroDexa has none — you sign in with a one-time code sent to your email, or through Google or Apple. That removes password-reuse risk, and it makes access to your email the key to your account. Keep it secure, and tell us at once if you think someone else has access.
17.3 No system is perfectly secure. We test, patch and monitor, and we will not pretend to a guarantee nobody can give.
18. If something goes wrong
18.1 If personal data is breached, we notify the competent supervisory authority within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to anyone.
18.2 If a breach is likely to put your rights at high risk, we tell you directly and without undue delay, in plain language: what happened, what data was involved, what it could mean for you, and what we are doing about it.
19. Changes to this policy
19.1 If we change this policy in a way that materially affects you — a new purpose, a new legal basis, a new category of recipient — we will email registered users at least 30 days before it takes effect, and post a notice in the app.
19.2 Minor corrections take effect on posting, with the effective date updated.
19.3 We keep previous versions available on request at support@astrodexa.com, and the version this one replaces stays archived on the site.
20. Version
Version: 2.0. Effective: 6 September 2026. Replaces: the AstroDexa Privacy Policy dated December 2024.