Astrum Terrae — Privacy Policy

In force since 02 Aug 2026

§ 1. Scope and Controller

This Privacy Policy describes how personal data of persons using the Astrum Terrae website and application (together, the "Service") is processed — including visitors, account holders, users of the Service's features, persons making payments and persons contacting the Controller.

Data Controller: Paweł Tymcio, Obrońców Westerplatte 4, 78-400 Szczecinek, Poland. Contact for privacy matters: ptymcio@gmail.com. Site: https://sacred-site-atlas.emergent.host/. No Data Protection Officer has been appointed.

The Controller determines the purposes and means of processing described here. Certain providers — payment operators and app stores in particular — may act as separate controllers within their own privacy policies.

This Policy fulfils the information duty of Articles 12 and 13 GDPR. If the Controller obtains data from a source other than the data subject, information required by Article 14 GDPR will also be provided, unless a statutory exception applies.

§ 2. Definitions

Personal data — information relating to an identified or identifiable natural person. Account — an individual user profile enabling use of the Service. User — a person using the Service, whether or not they hold an Account. Location data — country, city, time zone or geographic coordinates. Technical data — device, OS, browser, IP address, log data and usage. Cookies and similar technologies — files, local storage, app IDs, pixels, SDKs and other technologies storing or accessing data on a device.

§ 3. Sources and scope of processed information

The Controller may obtain data (a) directly from the User during registration, purchase, saving settings, entering data into the generator or contacting the Controller; (b) automatically from the device and usage where necessary for operation and security, and — with consent — for analytics; (c) from payment operators, app stores, external sign-in providers or other providers when the User uses their services in connection with Astrum Terrae.

3.1 Account data: e-mail, display name (if available), password stored as a cryptographic hash (never in cleartext), account ID, creation date, security settings, login history and security-relevant events.

3.2 Purchase and payment data: chosen plan, transaction date/amount/currency/status, transaction identifiers issued by the operator, invoice data if requested or required by law, refund/chargeback/failure information. The Controller does not receive or store full card numbers, CVV codes or other full payment credentials — these go directly to the operator.

3.3 Location data: locations entered manually, device-shared locations after system permission, approximate location from IP if technically determined. Server-side handling: DURING SESSION ONLY.

3.4 Settings, content and results of symbolic features: chosen astronomical/symbolic systems, service settings, saved places, data entered into generators (words, intentions, descriptions). Generated content is NOT stored server-side.

3.5 Technical data, logs and analytics: IP, request time, session IDs, browser and OS info, app version, language, time zone, error/crash reports, usage events; cookie/SDK/app IDs only per User settings and law.

3.6 Contact and complaint data: name, email/phone/channel of contact, message content and attachments, case-handling records.

§ 4. Purposes, legal bases, obligation to provide data, retention

Account creation and operation, authentication, feature delivery — Art. 6(1)(b) GDPR (performance of contract), retained while the Account exists and thereafter as needed for limitation periods or legal obligations.

Paid access, subscription management, billing — Art. 6(1)(b) GDPR; tax and accounting records under Art. 6(1)(c) GDPR, retained per statutory periods (typically 5 years).

Astronomical and geographical computation — Art. 6(1)(b) GDPR; retained SESSION-ONLY unless the User saves places.

Message and complaint handling — Art. 6(1)(b), (c) or (f) GDPR as applicable, retained until case closure and thereafter as needed.

Security, fraud prevention, diagnostics — Art. 6(1)(f) GDPR (legitimate interest), typically 30–180 days, longer only on incident or dispute.

Non-essential analytics — Art. 6(1)(a) GDPR (consent) and Art. 399 Polish Electronic Communications Law.

Newsletter/marketing (if any) — consent under Art. 6(1)(a) GDPR + electronic marketing consent; retained until withdrawal; proof of consent kept as needed to demonstrate compliance.

Claims establishment/defence — Art. 6(1)(f) GDPR until limitation period expires or proceedings conclude.

Providing an e-mail and Account details is voluntary but required to create an Account. Providing details for a purchase is a condition of that contract. Sharing precise device location, consenting to analytics, saving optional preferences, and marketing consents are voluntary. Consent may be withdrawn at any time; withdrawal does not affect prior lawful processing. Consent to cookies, analytics or marketing may not be pre-ticked or hidden in Terms/Policy acceptance.

§ 5. Location data

Location data is used to compute planetary hours, local time, astronomical data and celestial positions for the chosen place. Precise device location is only requested after User action and system-level permission. Withdrawal of permission does not automatically delete previously saved places — those must be deletable separately. The Controller does not track continuous movement or build travel histories. Where architecture allows, precise location is processed on-device or session-only.

§ 6. Data on beliefs and other special-category data

Merely using content about astrology, symbolism or magical traditions does not indicate a User's religious, philosophical or worldview beliefs. However, specific inputs or activity history may reveal or allow inferences about such beliefs.

The Controller does not intend to profile Users based on beliefs, health, sexuality, political opinions or other Article 9 GDPR special categories.

Users should not enter health, sexuality, racial/ethnic origin, political views, religious/philosophical beliefs, union membership, genetic or biometric data into free-text fields, unless the Service expressly provides such a feature with separate notice and explicit consent under Art. 9(2)(a) GDPR. GENERATOR TEXT INPUTS ARE NOT STORED.

§ 7. Payments, app stores, external sign-in

Payments are handled by external operators, in particular Stripe and PayPal, and in the case of mobile apps by the relevant app store. The operator may receive data required for payment as a separate controller under its own privacy policy. The Controller mainly receives confirmations, status, IDs and basic transaction parameters.

External sign-in providers (Apple, Google, or other) transmit data shown on the authorisation screen: e-mail, name, external account identifier. Currently used operators / integrations: STRIPE / PAYPAL / GOOGLE SIGN-IN.

§ 8. Cookies, SDKs and similar technologies

The Service may use cookies and similar technologies. Technologies strictly necessary for transmitting a communication or providing a requested service may be used without consent per Art. 399(3) of the Polish Electronic Communications Law.

Analytics, personalisation or marketing technologies not strictly necessary may only run after prior informed voluntary consent.

On first visit the User can (a) accept all optional technologies, (b) refuse them just as easily, (c) select categories, (d) view the vendor list and durations. Refusal must not block ordinary access to features that do not require optional tech. Users can change or withdraw choices at any time via the 'Privacy / Cookies Settings' panel.

§ 9. Recipients and processors

Data may be shared only as necessary with: hosting/database/CDN/backup providers; authentication, email, ticketing, security, error-monitoring and (with consent) analytics vendors; payment operators, banks, app stores; accounting/legal/audit/IT services; public authorities, courts or law-enforcement bodies where legally required.

§ 10. Transfers outside the European Economic Area

Some technology providers may process data outside the EEA. Where such a transfer occurs, the Controller relies on Chapter V GDPR bases — adequacy decisions or EU Standard Contractual Clauses supplemented by additional safeguards where needed.

§ 11. Automated decision-making and profiling

The Controller does not take Article 22 GDPR decisions based solely on automated processing. Automatic astronomical calculations, sigil generation and content personalisation implement User-chosen features and are not used to evaluate creditworthiness, health, financial or employment situation. NO ANALYTICS/MARKETING PROFILING.

§ 12. Rights of data subjects

Under GDPR you may have the right to: access and receive a copy; rectification and completion; erasure (right to be forgotten); restriction of processing; data portability of automated processing based on consent or contract; object to processing under Art. 6(1)(e) or (f); withdraw consent at any time; not to be subject to solely automated decisions under Art. 22; lodge a complaint with the Polish DPA (UODO).

Rights are not absolute — data will not be deleted where retention is required by law or for claims.

Requests to: ptymcio@gmail.com. Reply within one month, extendable by two more months for complex/many requests.

§ 13. Account deletion

Users may request Account deletion by email to ptymcio@gmail.com. Deletion terminates access to data, settings, generated content and Account features (except data required to be kept by law or for claims). Deleting the Account does not automatically cancel recurring subscriptions with external operators — Users should cancel these directly. Backup rotation: MAX 30 DAYS.

§ 14. Security

Technical and organisational measures appropriate to the risk: transmission encryption, secure password storage, access controls, security event logging, updates and backups, vendor agreements and confidentiality, incident and breach response procedures. No transmission or storage method is completely secure, but the Controller does not exclude statutory liability by general disclaimer.

§ 15. Minors

The Service is not directed at children under 16 (recommended limit for information-society services). Data of minors below the age boundary will not be knowingly collected without proper legal basis and parental consent.

§ 16. Changes to the Policy

The Policy may be updated due to changes in law, features, providers or processing methods. The current version is published in the Service with an effective date. Registered users will be notified of material changes in advance via the app or e-mail.

§ 17. Contact

E-mail: ptymcio@gmail.com. Postal: Obrońców Westerplatte 4, 78-400 Szczecinek, Poland.

© Astrum TerraePrivacy PolicyTerms of ServiceContact