Last updated · February 14, 2026

Privacy Policy

Operator note · This policy is a working draft based on a standard astrology-app template. It reflects Lodestar’s actual stack and practices but has not yet been reviewed by counsel. If you process EU or California-resident personal data at scale, run this past a lawyer before relying on it.

Lodestar Astrology (“Lodestar,” “we,” “our”) cares about your privacy. This policy explains what we collect, why, how long we keep it, and the rights you have to control it. We never sell your personal data. Full stop.

1. What we collect

When you use Lodestar, we may collect:

  • Account data — your email, a hashed password (we never see the plaintext), display name, and language preference.
  • Birth chart data — your date of birth, time of birth, and birthplace (city / coordinates). Stored encrypted at rest under a per-row key.
  • Usage data — pages viewed, features used, and aggregated session timing, via PostHog analytics. Anonymous until you sign in; pseudonymous afterward.
  • Payment data — when you subscribe, Stripe processes your card. Stripe shares your billing email and country with us; we never see your card number.
  • Email-engagement data — opens, clicks, unsubscribes for the emails we send you (Resend).
  • Support correspondence — any contact form submission or email you send us.

2. Why we collect it

  • To run your chart and reading — birth data is the input to the deterministic Vedic + KP astrology engine.
  • To deliver the product — auth, billing, the weekly Cosmic Forecast email if you opt in.
  • To improve the product — anonymized analytics tells us which features help people most.
  • To respond to you — when you contact support or report a bug.

3. Legal bases (EU / UK / EEA users)

  • Contract performance — to provide the chart, reading, or paid subscription you signed up for.
  • Legitimate interest — for fraud prevention, product analytics, and operational logging.
  • Consent — for marketing emails and non-essential cookies. You can withdraw consent any time.
  • Legal obligation — for tax records, accounting, and lawful disclosure requests.

4. Sub-processors we share data with

To operate Lodestar, we share narrowly-scoped data with the following sub-processors. Each is contractually bound to handle your data securely and only to deliver the service.

Sub-processorPurposeData shared
MongoDB AtlasPrimary database hostingAll account & chart data (encrypted)
StripePayment processingEmail, country, billing data
ResendTransactional + weekly emailsEmail address, message content
PostHogProduct analyticsPseudonymous usage events
Google AnalyticsAggregated traffic & marketing-channel analyticsAnonymized IP, page visits, referrer
Anthropic / OpenAI / Google (via Emergent)Optional AI-augmented narrative generationAstrological facts only — never your raw birth details
CloudflareCDN & DDoS protectionRequest headers, IP for routing
SentryError tracking & performance monitoringStack traces + minimal request metadata; PII scrubbing on

5. How long we keep your data

  • Active accounts — for as long as your account exists.
  • Birth chart data — encrypted at rest; deleted on account deletion + a 30-day tombstone window for recovery.
  • Email engagement — 24 months, then aggregated.
  • Payment records — 7 years (tax & accounting law).
  • Support emails — 24 months.

6. Your rights

Whether or not you’re in a jurisdiction that grants formal data rights, Lodestar honors all of them:

  • Access — request a copy of the data we hold about you.
  • Correction — fix any inaccuracy.
  • Deletion — from your account page, or by emailing us.
  • Portability — receive your chart data in a machine-readable format.
  • Withdrawal of consent — for marketing emails and non-essential cookies.
  • Lodging a complaint — with your local data-protection authority.

To exercise any right, email support@lodestarastrology.com or use the deletion control in your account settings.

7. Cookies & similar tech

Lodestar uses a small number of cookies and localStorage entries:

  • Session cookie — keeps you signed in. Required to use the app.
  • Cookie consent — remembers your choice from the consent banner.
  • PostHog analytics cookies — only set if you accepted analytics in the banner.

You can decline analytics any time via the cookie banner (it reappears if you clear browser storage) or by setting your browser to refuse cookies.

8. International transfers

Our infrastructure spans the United States and the EU. When we transfer data internationally, we rely on Standard Contractual Clauses or equivalent safeguards as required by GDPR Article 46.

9. Children

Lodestar is not intended for users under 16. If you believe a child has provided us with personal data, contact us and we’ll delete it.

10. Changes to this policy

We’ll update this page when our practices change, and signal significant changes by email or in-app notice. The “last updated” date at the top is your tell.

11. Contact

Privacy questions go to support@lodestarastrology.com. For formal data-subject requests, please include the email address on your account.

Reflective guidance only — not medical, legal or financial advice. Health entries are check-up prompts, never diagnoses.