PRIVACY POLICY
Your birth data belongs to you — we are only its temporary custodian.
Astralis is a self-knowledge tool built on BaZi, astrology and psychology. To function, it collects the following:
1. Chart-casting data: birth date (Gregorian), birth time (to the hour and minute), and birth place (country and city). These are required inputs for the BaZi four pillars, natal chart and rising sign. If any is missing, readings automatically degrade to “inference” confidence and are clearly labelled as such.
2. Account information: the email or phone number used to register, your display name, and an encrypted login credential. Email/phone is used only for identity verification and important notices (security alerts, policy updates) — never for marketing.
3. AI conversation content: the questions you type and the answers generated. Conversation context is used only for the current session's reasoning, is not stored as a long-term record, and never enters any model's training data.
4. Device and usage data: anonymous statistics such as browser type, access time and page dwell — used only for product improvement and anomaly diagnosis, never linked to your chart profiles.
We use your information only for these explicit purposes:
1. Chart calculation and reading generation: birth data is used to compute the BaZi four pillars, Ten Gods, Grand/Annual Cycles, the natal chart's Sun/Moon/Rising, houses and aspects, and psychology-dimension mappings.
2. Personalised experience: providing more relevant reading examples, knowledge-base recommendations and AI conversation context based on your existing charts. Source labels and confidence display for unlocked profiles also depend on chart data.
3. Account management and service notices: account info is used for login verification, password recovery, unlock-status sync and necessary security notices.
We explicitly do not use your birth data, conversation content or chart readings to train any machine-learning model — our own or a third party's. Astralis's AI readings are based on a fixed knowledge base and a pretrained model, never on user private data.
Demo environment note: in the current public demo, chart data and account info are stored encrypted in browser localStorage — the data lives on your device and is not uploaded to a remote server. Clearing browser data or switching devices will therefore lose your chart profiles. Please back up important charts (screenshots or exported text) yourself.
Production commitment: after launch, all data will be transmitted over HTTPS and stored with field-level encryption plus transport-layer encryption. Keys are held by an independent key-management service, physically isolated from the application servers. Sensitive fields such as birth time are stored with irreversible hashing combined with reversible encryption, decrypted on demand only when you actively view them.
Retention: after account deletion, your chart profiles and conversation history are permanently removed within 30 days. Anonymous statistics and system logs retain no personally identifiable data for more than 90 days.
We do not sell your personal information, and we do not share it with any unauthorised party. Specifically:
1. We never sell or exchange birth data, chart data or conversation content to third parties, whether for payment or not.
2. We never share personally identifiable information with advertisers for cross-site tracking or targeted ad delivery.
3. In limited necessary cases, minimum data may be shared with contractually bound providers: cloud-storage providers (only encrypted data blocks, unreadable by them), and AI inference compute providers (only the anonymised chart parameters needed for that inference, never identity information). All such providers sign strict confidentiality and data-protection agreements.
4. Legal obligations: only when we receive a valid legal instrument from a court with jurisdiction do we disclose, within the minimum scope permitted by law, and we notify you in advance wherever the law permits.
We protect your information with layered measures:
1. Transport security: all client–server communication uses TLS 1.2 or higher; known-insecure cipher suites are disabled.
2. Storage security: sensitive fields are encrypted at the database layer; keys and data are stored separately; backups are also encrypted and integrity-checked regularly.
3. Access control: production follows least-privilege — only authorised engineers access specific resources on a need basis via work orders, and all access is audited.
4. Vulnerability response: we track security disclosures continuously and maintain a response process. If you find a security issue, contact us via the details at the end — we thank valid reports.
5. Demo note: in localStorage demo mode, data protection relies only on the browser's same-origin policy and device security. Do not log in or generate sensitive charts on public devices.
You hold full control over your information at Astralis:
1. Access: view all chart profiles under “My Charts”. Astralis does not currently offer a data-export feature — please take your own screenshots of anything you want to keep.
2. Correct: fix birth data in the chart editor; change your display name, bound email or phone in settings.
3. Delete: delete individual chart profiles, or clear all charts and conversation records in one action. Deletion takes effect immediately and is irreversible.
4. Delete your account: email us from your registered address at any time to request account deletion (contact details in Section 10). We delete your account and chart data within 15 working days of verifying your identity. Transaction records and operation logs are retained for the periods described above for audit and anti-fraud purposes; they contain no chart content or conversation content.
5. Revoke consent: disable AI conversations, turn off personalised recommendations, or sign out to stop session-level data processing at any time.
Astralis uses cookies and browser local storage to keep you signed in, remember your preferences (default casting system, confidence display toggles) and support local chart saving in demo mode.
We group storage into three types: essential (login state, security tokens — the product cannot function without these), preference (interface and display settings — can be disabled), and statistical (anonymous access analytics — can be disabled without affecting function).
You can clear cookies and local storage in browser settings at any time. Note that in demo mode this also clears local charts. Once the production version supports cloud sync, local clearing will no longer affect data uploaded to your account.
Astralis is aimed at users capable of independent self-reflection. Users under 18 should use the service with a guardian's supervision and consent.
If you are a minor, please have a guardian read and agree to this policy before registering or generating a chart. If you are a guardian and find an unauthorised minor account, contact us via the details at the end and we will help resolve it.
We do not knowingly collect personal information from children under 14; if we find any, we delete it proactively. Metaphysical and astrological readings are inherently subjective and metaphorical — minors should treat them as a tool for self-exploration, not a basis for decisions. Major life choices should be discussed with a guardian or professional.
This policy may change as the product, regulations or security practices evolve. Material changes (wider use of information, new sharing scenarios, adjusted retention periods) are announced on-site and by registered email at least 30 days before they take effect.
Continuing to use the service after a change takes effect counts as acceptance of the new policy. If you disagree, you may close your account and delete data before the effective date; we never retroactively process data you have already deleted.
Archives of previous versions are available on request via the contact details below, so you can compare differences.
For questions, suggestions or security reports about this policy, reach us via:
1. On-site feedback: in Settings → Feedback after signing in; we reply within 3 business days.
2. Email: privacy@astralis.example (placeholder — the production address will be published on-site).
3. Data Protection Officer: for major personal-data requests, contact the DPO at the same email with the subject line “DPO channel”.
We commit to answering every piece of feedback with candour, transparency and a readiness to be questioned — that is Astralis's own methodology.
Birth data encrypted · used only to cast charts · never shared with third parties
Back to home