Privacy Policy for Horoscorpio
Version 1.6 · Effective 18 August 2026
This Policy covers Horoscorpio both as the anonymous, read-only mobile app and as the web application (horoscorpio.com) with member accounts. Part A applies to everyone; Part B discloses the additional information handled once you create an account or use the web / social features.
Terms
- Consumer: users of Horoscorpio who have downloaded the app or use the web application.
- Member: a Consumer who has created an account (web / cloud services).
- Horoscorpio: brand of the application developed by Kudomos (ABN 15 384 058 395).
- We, our, us: the development team of Horoscorpio.
Overview
Horoscorpio ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how Horoscorpio — as a mobile application and a web application with member accounts — collects, uses, and protects information when you use our planetary timing, aspect calculation, and planetology services.
Our guiding principle is unchanged: we collect as little as possible, we do not track you, we do not profile you for advertising, and we never sell your information. The web application adds member accounts, which necessarily involve some personal information (an email, a password, an age signal, and anything you choose to contribute). Everything we hold is disclosed below.
---
PART A — Applies to everyone (mobile and web)
Information Automatically Collected
- Server Communications: When the app requests astronomical data, our cloud server provides public planetary position and aspect data to your device. No tracking or personal-data collection occurs during this process.
- Transient network data: Like any web service, our infrastructure (and our providers) may briefly process your IP address and request timestamps for delivery, security, and abuse-prevention. We do not use this to build a profile of you.
- Referral links: If you arrived through a referral link that someone shared with you (a web address of the form
horoscorpio.com/r/CODE), your browser stores that code — and nothing else — in its own local storage for up to 90 days, and we count the opening of that link as a number only. The code identifies the person who shared the link, so that we can credit them if you later choose to become a paying member. It does not identify you, contains no information about you, is not a third-party cookie or tracking pixel, is never shared with an advertising network, and is read by exactly one request: the moment you create an account, if you create one. We keep no record of which link an individual visitor opened — only a per-day total per code. You can clear it at any time by clearing your browser's site data, and if you never register it is simply discarded.
Information NOT Collected
Horoscorpio does not collect: your real name — accounts are pseudonymous, identified only by an auto-generated handle (e.g. BlueCadaver), never your legal name; device hardware details; app-usage analytics or performance metrics; crash/diagnostic data; third-party analytics, advertising IDs, or tracking pixels; location data (unless you voluntarily enter a birth place for a natal feature); browsing history; or access to your photos, contacts, or files.
Data Sharing
Horoscorpio does not sell, trade, or rent your information. Disclosures are limited to the service providers listed in Part C and to legal requirements.
---
PART B — Applies to Members (web accounts & social features)
Creating an account or using the web social layer means we necessarily hold more than the anonymous app does. Specifically:
Information You Provide
- Account data: your email address (for login, verification, password reset, and service notices); a password, stored only as a salted PBKDF2 hash (never in plaintext, never recoverable by us); an auto-generated display handle; and your birth year (used only for age assurance — see "Children and Young People").
- Age-verification record (participation features only): if you complete the one-time age check required for Groups engagement actions and for lodging words, we store a single outcome — verified 16+, below the minimum, or the check did not complete — together with the date, the method, an opaque provider reference, and, where a check failed, a short provider reason code (for example "document expired"). We do not receive or store your identity document, your name as it appears on it, its number, or its images. Your date of birth is returned to our server so that the comparison against the minimum age can be made; it is held only in memory for the moment that takes and is never stored. We instruct the provider to delete what it collected once the outcome is returned. This record exists so we do not ask you to verify twice, and as evidence that the check took place.
- Referral attribution: if you registered after arriving through someone's referral link, we record the referral code against your account, once, at registration. Its only purpose is to credit the person who shared the link if your membership becomes a paid one; it is never used to profile you, to target you, or to tell that person anything about you. They are shown counts — how many members their link produced — and never your identity, email address, handle, or activity. This record is deleted with your account when you use Delete my data.
- Optional profile: social handles you connect (either self-typed or verified via that platform's official sign-in); a short greeting line; notification preferences.
- Contributed content ("canonisations"): the keyword(s) you lodge against a planet-pair and aspect, the orb at the time, method, and timestamp; journal submissions; and group ratings. These form the shared planetology corpus.
- Social / GEO activity: group participation, consent grants (Address / Challenge / Invite / Submit), blocks, and reports you make.
- Birth date / time / place: collected only if you use natal-chart features (a future addition). This is sensitive information, collected with explicit consent and treated with heightened care.
- Support and correspondence: if you contact a Horoscorpio role address or open an in-product support case, we process the sender and recipient addresses, subject, message, language, mail-authentication and delivery metadata, case history, and any files you choose to provide. Correspondence is free-form and may contain sensitive information, so please do not send passwords, recovery codes, payment-card details, or unnecessary private material.
How We Use Member Information
Solely to: run your account and authenticate you; verify your email and enable password reset; assure age and enforce the minimum age for accounts; build the planetology corpus from your consented contributions; form live groups and operate the GEO consent ladder; deliver notices you've opted into; handle support and rights requests; and maintain security, prevent abuse, and moderate the service. Support correspondence may be processed by deterministic rules and, when enabled, a locally operated language model to suggest a category, summary, translation, or reply draft. Model output is advisory: it does not establish identity or entitlement, send a reply, delete a case, change an account, or make a legal or similarly significant decision. Consequential actions require authorised human review.
The Matrix — proximity resonance and aura sharing
The Matrix is an optional Member feature that renders your quality-aura — a colour spectrum derived from keyword contributions you have already lodged — and, with your consent, composes it alongside the auras of other consenting Members. Its handling of information is as follows:
- Consent is specific, informed, and required. The Matrix does not operate unless you affirmatively consent at a purpose-specific prompt, presented the first time you open the feature, that discloses precisely what is shared. Consent may be withdrawn at any time from your account Settings; withdrawal removes you from the shared pool and ceases sharing, and does not require you to uninstall the application (consistent with GDPR Art. 7(3), which requires withdrawal to be as easy as the giving of consent).
- Only quality-keyword data is shared — never personal information. What another Member may perceive of you through the Matrix is your aura (the derived keyword spectrum), under an auto-generated, non-identifying tag. In Groups, the name other Members see is generated separately for each group and is discarded when that group ends: the same person appears under different names in different groups, so a Member cannot be followed or catalogued from one group to another, and your account handle is never shown to them. We do not disclose your name, email address, precise location, or contact details through the Matrix. Your legal identity and any connected social handles remain private unless and until you separately grant them through the GEO consent ladder.
- Proximity features (where and when enabled). Where the Matrix offers proximity discovery, your device may exchange a rotating, anonymised presence token over short-range radio (Bluetooth Low Energy) and/or near-field communication (NFC) in order to detect other consenting Members in your immediate vicinity. These tokens carry no personal information and are designed not to be linkable to you by third parties. You are discoverable only while signed in with the feature enabled, and only as an anonymous tag; you become identifiable to another Member solely through mutual, affirmative consent.
- Location. The core Matrix does not collect or store your location. Any future "ambient" discovery layer will use only coarse, approximate location to indicate general areas of compatible activity — never a precise position, and never a bearing toward an identifiable individual — and will be separately disclosed and consented before any release.
- No covert profiling. The Matrix reflects content you contributed and the live sky; it does not infer, score, or reveal anything about your private conduct.
The Planetology Caveats (specific to this service)
- Your profile is contributed, not surveilled. Planetary positions come from cached Astronomy Engine ephemeris calculations — astronomical geometry, not inferences drawn about your behaviour. Legacy NASA/JPL-derived reservoirs may be used only where expressly labelled for validation or backfill. Your "aura"/keyword profile is content you chose to lodge.
- Group matching is not covert profiling. Matches derive from the live sky plus your consented contributions — never from hidden scoring of your private conduct.
- Birth data is sensitive and is minimised, gated behind your account, encrypted in transit, and never shared for marketing.
Member Data Storage, Residency & Retention
- Residency: account and contribution data are stored in Cloudflare D1, Oceania (
OC) region. - Security: passwords are PBKDF2-hashed; the operator console sits behind Cloudflare Zero Trust Access; application secrets are kept in provider secret stores; and traffic is protected with TLS and HSTS. Payment is processed by Stripe: we never receive or store card numbers, only the subscription and billing records needed to provide and account for the service. Account records are generally pseudonymous, but support messages and optional features can contain identifying or sensitive material. Those records are separated by role and purpose, access-restricted, and excluded from model training.
- Retention: account data is kept while your account is active; contributed canon is retained as part of the cumulative corpus (de-identified from you at the aggregate layer). Support and correspondence records are kept according to documented case-category periods and then deleted or de-identified; quarantine and attachments have shorter, separately controlled periods. Legal, financial, security, and safety records may be retained only for the period reasonably required by law or to establish, exercise, or defend a claim. If we suspend or ban an account, we retain the minimum evidence needed to defend the decision, handle appeals, or meet legal obligations — then delete or de-identify it.
- Deletion (DELETE MY DATA): every member account has a Delete my data control in the profile. Using it permanently removes — in one operation — your account; the account-linked copies and attribution of keyword uploads; journal submissions; ratings; GEO activity; group presence; optional profile fields; subscription record; and your stored payment methods at Stripe. Two narrow categories of account-linked records survive deletion, both time-bounded and access-restricted: (a) financial processing records we must keep under tax and audit law (with no remaining operational account linkage), and (b) safety records — contribution attempts that were flagged or rejected by the safety gates, retained for safety review and, where legally required, disclosure to authorities. Separately, Contributions already irreversibly assimilated into the de-identified aggregate global planetology corpus survive without account attribution under the corpus licence in the Terms. Deletion does not unwind the aggregate weights, ranks, classifications, canonical progressions, or derived wordmaps already produced from them. Those corpus results cannot be used to restore the deleted account or re-identify its former member.
Your Member Rights
You may access, correct, export, or delete your account and associated personal data (GDPR Art. 17 / APP 13), object to or withdraw consent for a processing activity, and complain to the OAIC (Australia) or your EU/UK supervisory authority. Withdrawing consent stops future attribution and removes your linkable records, but does not retroactively remove already-aggregated, no-longer-linkable words from the corpus. Requests: [email protected].
---
PART C — Service Providers (all users)
We do not sell your information. We rely on:
- Stripe — payment processing for the web membership and the mobile app sold directly on horoscorpio.com as a one-time purchase. Stripe collects payment details and billing address directly; we receive subscription or purchase status, billing country (for tax), payment confirmation, and the limited billing records needed to provide and account for the service, but never full card details. Stripe calculates and adds applicable GST/VAT/sales tax at checkout and retains transaction records to meet its own financial-law obligations even after you delete your account with us. Governed by Stripe's own privacy policy.
- Stripe Identity — age verification for the two participation features (Groups engagement actions and lodging words), and only when you choose to start a check. You are taken to a page operated by Stripe, where you present an identity document directly to Stripe; the document never passes through Horoscorpio. Stripe returns to us one answer: whether you are 16 or over. We then instruct Stripe to redact the verification record, which permanently removes the collected personal data at Stripe. Stripe returns your date of birth to our server; it is compared to the minimum age in memory, reduced to a single yes-or-no, and discarded in the same request. It is never written to our database, our logs, or any backup, and no part of our service can retrieve it afterwards. We never receive your identity document. This is a separate operation from payment processing: starting a check does not create a payment, and paying does not create a check. Governed by Stripe's own privacy policy and its Identity terms.
- Regional pricing and language recommendation: the country of your network connection, as seen at our hosting provider's edge, selects the regional price/currency shown to you and a suggested interface language. This is a property of the connection (never GPS, never a device permission) and is not stored as any location history.
- Astronomy Engine sky cache — open-source astronomical ephemeris calculations generated ahead of time and served from Cloudflare storage. No personal data is sent to Astronomy Engine or NASA for the launch runtime path.
- NASA/JPL-derived legacy reservoirs — used only where expressly labelled for validation or backfill. No personal data is sent to NASA.
- Railway — hosts our legacy cloud server (the mobile beta API). May log standard access data.
- Cloudflare (web) — hosting, Email Routing, member and support data stores, security controls, and Zero Trust operator access. Database placement is configured for the Oceania (
OC) region where supported, although Cloudflare may process transient routing and security data through its global network. - Resend (web) — transactional email (verification, reset, notices). Servers in the United States — a cross-border disclosure under APP 8; verifying your email constitutes consent to this transfer.
When local support-triage assistance is enabled, the model runs on operator-controlled infrastructure without cloud-model processing. It receives only bounded, redacted case text and approved support material, has no email-sending or account-management authority, and its output is not used as a private training corpus.
Legal Requirements
We may disclose information only if required by law or to protect our rights, users' safety, and the integrity of the service.
---
Children and Young People
- A child in a country that sets a minimum age — accounts are not available. Registration is refused at the point of signup, so no account, contribution, GEO or payment record is created. The countries and the age each one sets are listed at horoscorpio.com/legal/age-minimums; the ages differ, because the instruments differ (GDPR Article 8 across the European Economic Area, at 13 to 16 depending on the member state; the Australian social-media minimum-age framework; the UK Age Appropriate Design Code and Online Safety Act; US state minimum-age laws and COPPA).
- A child in a country that sets no minimum age — an account may be held, and a parent or guardian may set one up and manage it, though nothing requires it. No minimum-age law reaches the account, so the member-to-member features are open to it on the same terms as any other member's, and we hold the same categories of information for it as for any other member. Where an account is instead placed in Younger Astronomer mode — because the member is under the minimum age that applies to them, or because they or their parent chose it — every member-to-member surface on that account is closed until they reach that age: the four engagement actions, the Matrix, social links, and any contact with another member. For an account in that mode we therefore hold no social handle, no greeting, no engagement record and no group-consent record; the personal information is the account itself (email, birth year, handle) and the words lodged into the corpus.
- At or above the minimum age that applies to you, or in a country that sets none — full features. We ask for your birth year only, never your full date of birth — the year is the least we need to apply the minimum age. It is recorded once at registration and cannot be changed afterwards; attempts to change it are logged.
- How the year is read. A year alone cannot tell us whether your birthday has passed, so we round down: you are treated as having reached the minimum age from the January after you actually reach it. Second use of your chart date, disclosed: if you have cast a birth chart, the birth date you entered for it may also be read to recognise your actual birthday and restore those months. It is used for this only where it agrees with your registered birth year, and only in your favour — a date that disagrees changes nothing, and no chart date can ever lower your age tier or move you below the minimum. Circumventing the age gate breaches our Terms.
- Two layers, deliberately. The birth year is a declaration you make at signup, and it governs access to the service as a whole. A verified age — an identity-document check operated by Stripe Identity — is additionally required for the two features that put you in contact with other people or in the shared corpus: the four Groups engagement actions, and lodging a word. The instrument itself (aspect timer, natal charts, planets, calendar, Solar HARP, Seven Force) and reading the Groups page need no document. A payment method is not age assurance and we do not treat it as such: card issuers disclose no age, minors hold payment cards, and the cardholder need not be the account holder. Where a check returns an age below the minimum, the two participation features are closed permanently on that account and we retain only that outcome — never the document or the date of birth.
Aggregate, De-identified Statistics
We may compile and share de-identified, aggregate statistics about how members use the service — for example, how many members contribute in a given language pool, or move between pools — with research, cultural, and institutional partners. These statistics never identify you and never include your words, email, handle, location, or account; they are released only in groups large enough that no individual can be recognised.
Language pools are not countries. A language pool is a community of members who chose that language — it is not a country, territory, or nationality, and we record no member location, so these statistics cannot be produced by country or territory. A pool's statistics say nothing about any state or its citizens; members of one language community span many jurisdictions and writing systems. Where our paid service is not offered for sale in a market, there is no membership there for any statistic to describe, and no statistic may be represented as describing such a market. We do not permit recipients to use pool statistics as a proxy for nationality, citizenship, residency, or territorial claims — nor for profiling individuals, or for political, law-enforcement, immigration, insurance, employment, or credit purposes. We do not sell your personal information.
Data-Breach Notification
If an eligible data breach occurs, we act under our internal Data Breach Response Plan and comply with the Notifiable Data Breaches scheme (AU Privacy Act) and, where applicable, GDPR Arts. 33–34 — notifying the OAIC / supervisory authority and affected individuals as required.
International Users
By using Horoscorpio, you consent to the processing of data as described under Australian legal frameworks, with the additional EU/UK protections noted where GDPR applies.
Changes to This Policy
We may update this Policy from time to time. Significant changes will be notified through app updates or in-app/website notices, with an updated effective date.
Contact Us
Email: [email protected] — Kudomos (ABN 15 384 058 395), Brisbane, Queensland, Australia.
Compliance
This Privacy Policy is intended to comply with: the Australian Privacy Act 1988 (Australian Privacy Principles) and Australian Consumer Law; GDPR / UK GDPR where applicable; CCPA where applicable; and children's-privacy expectations under COPPA and the UK Age Appropriate Design Code.