Privacy Policy
Who is responsible
Asteriva is operated by Mert Kuzey Tokşen (referred to as “we”). Asteriva is a brand name, currently operated by an individual; if a company is incorporated later, this section will be updated. For any privacy matter, contact support@asteriva.app.
What data we process
We only process data that the app needs to work. There are no hidden categories: the lists below are derived directly from our database schemas.
Account and sign-in data
- Email address and a password hash (Argon2id). We never store your password itself and cannot read it.
- Sign-in sessions per device (token identifiers, creation/expiry times), so that you can sign out everywhere and so that stolen tokens can be invalidated.
Profile and birth data
- Display name.
- Birth date and birth time (including a marker for ambiguous daylight-saving times), if you provide a birth time.
- Birth place selected from a places catalogue, with its coordinates and time zone. These are needed to compute your chart correctly.
- App language and, once computed, your Sun, Moon and rising signs.
Derived astrology data
- A stored copy of your computed birth chart (a “snapshot”), so the chart does not need to be recomputed on every request.
- The daily content selection state for your account (which reading was selected for which day).
AI data — only if AI is enabled and you consent
The AI chat feature is off by default and currently not active. If it becomes active and you explicitly enable it:
- Your questions are processed to generate a reply. Message processing uses OpenAI as a provider; requests are sent to OpenAI only when you use the feature.
- Your chat history is stored on your device, not on our servers.
- Our servers keep: usage quota counters, technical de-duplication records for requests, and any reports you submit about AI answers (the reported content is stored so we can review it).
What we do not process
- No advertising identifiers, no analytics SDKs, no third-party trackers in the app or on this website.
- Premium subscriptions are not active. A subscription data structure exists in our systems but is unused; no purchase or payment data is processed today. This policy will be updated before any payment feature launches.
Why we process it (purposes and legal bases)
- Providing the service (account, chart computation, daily readings): performance of our agreement with you.
- Security (sessions, rate limiting, abuse prevention): our legitimate interest in keeping the service safe.
- AI chat, when available: your explicit consent, which you can withdraw at any time in the app.
- Support: answering messages you send us.
Where data is stored
- Application server: OVHcloud (virtual server, EU region).
- Database: MongoDB Atlas (EU region).
- DNS and email routing for our domain: Cloudflare. Support email you send is routed through Cloudflare Email Routing to our mailbox.
- OpenAI receives AI chat messages only when the AI feature is active and you use it. It is not used otherwise.
International transfers
Our servers and database are hosted in the EU. Cloudflare operates a global network for DNS and email routing. If the AI feature is active, AI messages are processed by OpenAI, which may process data in the United States; this only happens with your consent, when you use AI.
How long we keep data
- Account, profile and derived data: for as long as your account exists.
- When you delete your account, the associated server-side data listed above is deleted from active systems. Operational backups expire on a rolling basis.
- Support emails are kept as long as needed to handle your request.
Your rights
Depending on your jurisdiction (including GDPR and the Turkish KVKK), you have the right to access, correct, delete and export your data, to object to certain processing and to withdraw consent.
- Correction: birth data and name can be edited directly in the app (changes to birth data are limited to once every 30 days).
- Deletion: use Settings → Delete account in the app, or email support@asteriva.app from your registered address (see the Delete account page).
Security
Passwords are hashed with Argon2id. All traffic uses TLS. The database is reachable only through our API — neither the app nor this website connects to it directly. Sessions can be revoked per device.
Children
Asteriva is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.
Changes and contact
We will update this page when our processing changes, and adjust the date above. Questions: support@asteriva.app.