Zum Inhalt springen

Privacy Policy

Gültig ab 2026-08-11

What Zodivai collects about you, why it collects it, who else can see it, and how you get it back or have it deleted at any time.

Dieses Dokument wird auf Englisch veröffentlicht. Maßgeblich ist die englische Fassung — eine Übersetzung dient allein der Bequemlichkeit, und bei Abweichungen gilt der englische Text.

Who we are

Zodivai is an astrology service that calculates natal charts and writes readings from them. This policy covers the website at zodivai.com and the Zodivai mobile apps.

For questions about this policy or anything in it, write to support@zodivai.com.

What we collect and why

Everything below is data you give us or that follows from using the service. We do not buy personal data, and we do not combine your account with data brokered from elsewhere.

Birth data deserves a specific mention. A birth date, time and place is unusually identifying, and for some people it is sensitive in ways a date of birth alone is not. It is stored because a chart cannot be calculated without it, it is never sold, and it is not shared with any third party except the hosting provider that runs our database.

Alle Kategorien personenbezogener Daten, die Zodivai speichert, wofür sie verwendet werden und ob sie im selbst herunterladbaren Datenexport enthalten sind.
DatenWorum es sich handeltWarum wir sie habenIm Export
AccountYour email address, display name, preferred language, subscription tier, analytics preference, the date you signed up, and whether a deletion is pending.To give you an account, sign you in, bill the right tier, and write to you in a language you read.Enthalten
Birth profilesFor you and for anyone whose chart you save: a name, birth date and time, the latitude and longitude of the birth place and its display name, how confident you are in the time, the time zone, and the relationship to you.A natal chart cannot be calculated without a moment and a place. This is the most personal data the service holds, and it is the reason the service exists.Enthalten
ChartsThe calculated result of a birth profile — planetary and body positions, house cusps and aspects.So a chart is computed once rather than on every visit.Enthalten
Interests and preferencesThe topics you follow, your experience level, relationship context and preferred zodiac system.To choose which readings you are shown and how they are written.Enthalten
Journal entriesWhatever you write, plus the mood and life area you tag it with.To show you your own journal. Nobody reads these to target you, and they are not used to train anything.Enthalten
SubscriptionsWhich plan you are on, its status and its renewal dates.To decide what you have access to.Enthalten
One-time purchasesReports and forecasts you have bought individually.To give you the thing you paid for, and to keep giving it to you.Enthalten
Transit alertsThe alerts you have set up and the conditions that trigger them.To notify you when a transit you asked about happens.Enthalten
Reading feedbackYour ratings and comments on individual readings.To find out which readings are any good.Enthalten
Content engagementWhich articles and readings you have opened, and when.To pick what to show you next, and to see which content is worth writing more of.Enthalten
Compatibility reportsReports generated between two saved profiles.To show you a report you asked for without recalculating it.Enthalten
DevicesFor each device you sign in on: a push notification token, the platform, app version, locale, and when it was registered and last seen. The export carries everything here except the token, which is a credential for the device rather than a record about you — a token in an exported file is a token in a file.To deliver push notifications and to show you which devices have access.Enthalten
BookmarksThe readings and articles you have saved.To show you your saved list.Enthalten
ReferralsInvitations you have sent or accepted: the invite code, which side of it you were on, and when it was sent, accepted and rewarded. The export does not name the other person — that account is theirs, not yours.To credit a referral to the person who made it.Enthalten
Sign-in credentialsA hashed password if you set one, registered passkeys, active sessions and refresh tokens, and the identifiers of any Google or Apple account you sign in with.To sign you in and to let you end a session you no longer recognise.Auf Anfrage
Security logsAdministrative and security-relevant actions taken on your account.To investigate abuse and to be able to answer what happened to an account.Auf Anfrage

Who else sees it

We do not sell personal data and we do not share it for anyone else's advertising. Data reaches the following processors because the service cannot run without them, and each is bound to use it only on our instructions.

We will also disclose data where we are legally required to, and to protect the rights or safety of a person — including ours.

Dienste Dritter, die personenbezogene Daten erhalten, und was jeder von ihnen erhält.
WerWofürWas sie erhalten
IONOSHosting for the application and its databaseEverything above. Servers are in Germany.
CloudflareContent delivery, DNS and protection against attackIP addresses and request metadata for every visit.
StripeCard payments and subscriptions on the webEmail address and a customer identifier. Card numbers go to Stripe directly and never reach us.
RevenueCatPurchases made inside the mobile appsA pseudonymous user identifier and purchase status.
Apple / GoogleIn-app purchases and, if you use them, sign-inPurchase records, and the account identifier and email you release when you choose to sign in with them.
ResendTransactional email — sign-in links, password resets, receiptsYour email address and the contents of those messages.
PostHogProduct analyticsUsage events and a pseudonymous identifier. Switched off entirely if you opt out.
SentryCrash and error reportingDiagnostic data about a failure, which can include the account identifier involved.

Where your data lives

The application and its database run on servers in Germany. Some of the processors above operate in the United States and elsewhere; where personal data reaches them, it is transferred under Standard Contractual Clauses or an equivalent mechanism.

How long we keep it

Your account and everything attached to it is kept for as long as the account exists.

When you ask us to delete the account, it is marked for deletion immediately, every active session is revoked, and you are signed out. The data itself is erased 30 days later. That window exists so that a deletion you did not intend — or one made by someone who got into your account — can be undone by simply signing in again, which cancels it.

After the 30 days the erasure is permanent and we cannot recover the account. Records we are independently required to keep, such as a record of a payment, survive it; security logs are retained separately as described above.

Your rights

You can ask for a copy of your data, correct it, delete it, object to how we use it, or ask us to restrict that use. Two of those you can do yourself, immediately, without asking anyone:

For anything not covered by those, write to support@zodivai.com and we will answer within 30 days. If you are in the EEA or the UK and you think we have handled your data badly, you can complain to your national data protection authority.

  • Export — Settings → Account → Export data hands you a JSON file of your account, charts, journal, purchases and more.
  • Deletion — Settings → Account → Delete account, or the page at zodivai.com/delete-account if you cannot sign in.
  • Analytics opt-out — Settings → Privacy. Turning it off stops product analytics for your account.

Cookies

We set a session cookie when you sign in. It is strictly necessary — without it you cannot stay signed in — and it is not used for advertising. Analytics, when you have not opted out, sets its own identifier. We do not run third-party advertising cookies.

Children

Zodivai is not directed to children under 16 and we do not knowingly collect their data. If you believe a child has given us personal data, write to us and we will delete it.

Security

Traffic is encrypted in transit. Passwords are stored hashed, never in a recoverable form, and passkeys are supported so you need not have one at all. Access to production data is limited to those who need it. No service can promise it will never be breached, and we do not.

Changes to this policy

If we change this policy materially we will say so in the app or by email before the change takes effect. The effective date at the top always reflects the current version.