Legal

Privacy Policy

Last updated July 29, 2026

AstroShadow (“we,” “us”) is a small, independently-run project. This policy describes, plainly and specifically, what happens to the data you enter when you generate a birth chart or a numerology profile, or when you keep a Journal — this is a factual description of how the app works today, not boilerplate.

1. What we collect

We only collect what you type directly into the birth chart and numerology forms:

For the birth chart and numerology tools, we don't ask for an account, an email address, a payment method, or anything beyond the birth details above — there's no login and no way for us to identify you across visits.

If you create a Journal account, we additionally collect:

2. Why we collect it

Birth chart and numerology data: solely to calculate and display your natal chart or numerology profile back to you, in your browser, in the same request.

Journal data: solely so you can keep a private record of what you notice, get suggested symbol matches for what you write, and see a weekly tally of which elements keep showing up. Your email is used only for authentication. Nothing you enter — in either case — is used for any other purpose: no marketing, no profiling, no resale, no sharing with third parties.

3. Where it's stored

For the birth chart and numerology tools, there is no server-side database.Your birth data is processed in memory for the duration of a single request to generate your chart or profile, and the result is sent back to your browser — nothing is written to a database, and we have no way to look up “your” data after the fact, because we never kept it.

Our server does log limited technical debug output while it talks to NASA JPL Horizons (see below) to look up the Nemesis asteroid position — which asteroid, and whether the lookup succeeded or failed — but not your birth date, time, name, city, or coordinates.

What is stored, and where: once your chart is generated, it's saved to your own browser's localStorage (not a cookie, not sent to us) under the key astroshadow:lastChart, so pages like Body Map can reference your most recent chart without asking again. This never leaves your device. Numerology results aren't stored anywhere at all, not even locally — they exist only in the page while it's open and disappear the moment you refresh or navigate away.

The Journal is the one exception.Your account email, journal entries, confirmed symbol tags, and mood are stored server-side in a Postgres database hosted by Supabase, in the EU region. Every one of those tables has Row Level Security enabled, and the database itself — not just our application code — enforces that your account can only ever read, write, or delete your own rows. No user, including us through the ordinary app, can query another user's journal entries.

Our server logs never include your journal entry text or mood. When something goes wrong saving, loading, or exporting an entry, we log a generic outcome (e.g. “failed to save journal entry”) and the database's own error message — never the content you wrote.

4. Third parties

We rely on five external services:

We don't use any other third-party service. No advertising networks, no data brokers.

5. Cookies & tracking

AstroShadow does not use advertising cookies, and does not sell or share data with ad networks.Journal accounts use one essential, strictly-necessary sign-in cookie to keep you logged in — this does not require consent under GDPR's ePrivacy exemption for functional cookies. The browser localStorage described above is separate from this and isn't used to track you either — it only stores your own most recent chart, on your own device, for your own convenience, and nothing is transmitted from it to us.

As of July 26, 2026, we use Vercel Web Analytics and Speed Insightsto see aggregate page-view counts and page-load performance, and to track four specific product events: a chart being generated, a Destiny Statement being revealed, a Journal signup, and a Journal entry being saved. Each of those four events sends only its bare event name — no birth data, no journal content, no email address, and no other identifying details are attached. We checked the library's own source directly: it sets no cookies and no persistent identifier on your device, and its script and data both travel through our own domain rather than a third-party one.

As of July 29, 2026, we also use Google Analytics (GA4) to collect anonymised page-view and session data — which pages are visited, in what order, and aggregate visit counts. Unlike Vercel Analytics above, Google Analytics uses cookies— but only after you click “Accept” on the cookie banner shown on your first visit. Until then, Google Analytics runs in Google's own Consent Mode, defaulted to denied: no cookie is set on your device, and no ID that could identify you or link separate visits together is used. A small number of cookie-less pings may still reach Google even while denied — this is Consent Mode's own documented behaviour, used only to model aggregate traffic statistically, not to track anyone individually. We don't configure Google Analytics to collect your name, email, birth details, or journal content in any case — only the pages you visit plus the standard technical signals (browser, rough device/location) Google's script attaches automatically. That data is processed by Google under Google's own privacy policy, not ours.

As of July 29, 2026, we also use Microsoft Clarity for session recording and heatmaps — an anonymised playback of mouse movement, scrolling, and clicks, so we can see where people get stuck or lose interest on a page. Clarity is gated more strictly than Google Analytics: its script isn't requested from Microsoft at all — not even in a cookie-less or denied state — until you click “Accept” on the same cookie banner, one decision covering both tools. We haven't configured Clarity to collect your name, email, birth details, or journal content, and by default it masks text and input content in its recordings rather than capturing it verbatim; for the full detail of what Microsoft itself does with that data, see Microsoft's own privacy statement.

Your choice is remembered in your browser's localStorage (not itself a cookie) under the key astroshadow:cookieConsent, so the banner only asks once, for both tools together. To withdraw consent after accepting, clear your browser's cookies and site data for AstroShadow (or use private/incognito browsing) — this removes the Google Analytics and Clarity cookies along with your stored choice, so both go back to denied and the banner reappears the next time you visit. If you click “Decline,” the same denied state is stored immediately for both and the banner won't ask again either.

7. Your rights

Under GDPR and similar laws, you have rights over your data. Here's how each applies, concretely — birth chart/numerology data first, then the Journal.

For the Journal, both of these are self-serve, built into the product, and available from the bottom of your Journal page:

8. Wellbeing disclaimer

AstroShadow's content — archetypes, shadow work, numerology, body-map correspondences — is offered for entertainment, self-reflection, and personal growth. It is notmedical, psychological, or professional advice of any kind, and it is not a substitute for therapy, counseling, or professional mental health care. If you're struggling or in crisis, please reach out to a licensed professional or a crisis line in your region.

9. Changes to this policy

We may update this policy as the product changes. If we add cookies, analytics, or any tracking technology, we'll update this page and add a consent mechanism before doing so, not after.

10. Contact

Questions about this policy or your data can be sent to [email protected].

See also our Terms of Service.