What we collect
Account data: your email address and a hashed password, plus a session cookie while you are signed in.
Birth data: the names, birth dates, times and places you enter for yourself and for other people, and the charts and written reports calculated from them. Birth data can reveal a great deal about a person; enter other people’s data only with their agreement.
Billing data: your plan, subscription status and Stripe customer reference. Card details go directly to Stripe and never reach our servers.
Technical data: standard server logs (IP address, browser, time of request) kept for security and troubleshooting. We do not run advertising trackers.
Why we process it
To provide the service you asked for: calculating charts, storing your profiles, generating reports and billing your plan (performance of a contract).
To keep the service secure and to fix problems (legitimate interest). To send password-reset and billing emails (contract). To answer your messages (legitimate interest or consent).
Who processes data for us
Vercel (hosting, USA and EU), Supabase (database, EU region), Stripe (payments and tax calculation), Resend (transactional email), Anthropic (the AI model that writes reports; it receives the calculated chart positions, not your email or account details), komoot Photon and OpenFreeMap (birthplace search and map tiles; they receive the place names you type and the map areas you view, not your account). Each provider acts under a data-processing agreement; transfers outside the EU rely on standard contractual clauses or an adequacy decision.
How long we keep it
Account and birth data stay until you delete a profile or your account. Reports are deleted with their chart. Server logs are kept for up to 30 days. Billing records are kept for as long as tax law requires. Deleting your account removes your profiles, charts and reports at once; Stripe keeps invoice records under its own retention rules.
Cookies and storage
One first-party cookie keeps you signed in for up to 30 days. Your theme preference is stored in your browser. There are no analytics or advertising cookies. The marketing pages set no cookies at all.
Your rights
You can access, correct, export or delete your data. Most of this you can do yourself in the app: edit or delete profiles, download chart data, and delete your account under Profiles & Settings. For anything else, email support@natalgps.com. If you live in the EU or UK you may also complain to your data-protection authority. We answer requests within one month.
Children
natalGPS is not directed at children under 16, and we do not knowingly create accounts for them. Birth data about children may be entered by a parent or guardian for their own use.
Changes
We update this policy when the service or our providers change and announce material changes in the app. Questions about privacy: support@natalgps.com.