Privacy Policy
Last Updated: August 31, 2026
1. Introduction
This Privacy Policy explains how Moonphase Apps GmbH processes personal data when you use astrobella.com, the AstroBella mobile application for iOS and Android, and the associated services. It applies to processing governed by the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and the German Telecommunications Digital Services Data Protection Act (TDDDG).
2. Controller
The controller responsible for processing your personal data is:
Moonphase Apps GmbH
Ferdinand-Koch-Straße 31
26133 Oldenburg
Germany
- Managing directors: Philipp Marx and Joshua van Vliet
- Commercial register: Amtsgericht Oldenburg, HRB 219941
- VAT ID: DE365749986
- Email: support@astrobella.com
3. Summary of Processing
| Data category | Purpose | Legal basis |
|---|---|---|
| Account data, including name, email address, username, optional gender and internal user ID | Account creation, authentication, account administration and provision of the app | Art. 6(1)(b) GDPR |
| Birth data, including date, time, place and coordinates of birth | Creation of astrological calculations and personalised service features | Art. 6(1)(b) GDPR |
| Friend feature data, including usernames, zodiac signs, birthdays and friend requests | Provision of friend functions | Art. 6(1)(b) GDPR |
| Device contacts | Local contact matching, only after permission and without upload to us | Art. 6(1)(a) GDPR |
| AI advisor messages and relevant astrological context | Provision of the AI chat advisor | Art. 6(1)(b) GDPR |
| Feedback, ratings and transit comments | Provision and operation of interactive app functions | Art. 6(1)(b) GDPR |
| Subscription and purchase information | Performance and administration of subscriptions and purchases | Art. 6(1)(b) GDPR, and Art. 6(1)(c) GDPR for statutory retention |
| Push token | Delivery of push notifications | Art. 6(1)(a) GDPR |
| Device, technical and crash data | Technical stability, error analysis and service security | Art. 6(1)(f) GDPR |
| Analytics, attribution and advertising identifiers | Measurement, attribution and analysis of app use | Art. 6(1)(a) GDPR |
| Website form data | Handling contact requests and applications | Art. 6(1)(b) GDPR, Art. 6(1)(f) GDPR, and, for applications, Section 26 BDSG |
| Website technical data and aggregate analytics | Hosting, security, operation and aggregate measurement of the website | Art. 6(1)(f) GDPR |
4. App Data
4.1 Account and birth data
We process your name and email address when you register with Apple Sign In, Google Sign In or email registration. We also process your username, optional gender and internal user ID. We process your date, time and place of birth to provide astrological calculations. The place of birth is resolved to coordinates through Google Places API. Account and birth data are transmitted to our servers for these purposes.
The provision of account and birth data is necessary to create an account and provide personalised astrological functions. If you do not provide this data, we cannot provide those functions.
Unless stated otherwise, we receive the personal data described in this policy directly from you. Where you use Apple Sign In or Google Sign In, we receive the registration data supplied through the relevant provider. Technical, device and crash data are generated through your use of the app or website. Friend data may be received from the relevant user or generated through the friend feature interaction.
4.2 Friend functions and local data
When you use friend functions, we process friend list data consisting of usernames, zodiac signs, birthdays and friend requests. Friends you add manually are stored only on your device. If you grant access to device contacts, contacts are read only locally and are not uploaded to us.
4.3 AI chat advisor
When you use the AI chat advisor, we process your chat messages and send them, together with your birth chart, transit data and moon data needed as context, to our servers. OpenAI processes this data in the United States on our behalf under a data processing agreement. OpenAI does not use this data to train its models.
4.4 Feedback, ratings, comments and tarot history
We process in app feedback, ratings and transit comments when you submit them. Tarot history remains only on your device and is not transmitted to us.
4.5 Subscriptions and purchases
In app subscriptions and purchases are handled through Apple App Store, Google Play and RevenueCat, Inc. We do not store card details. Website purchases for yearly horoscopes are processed through Stripe. Stripe processes email address, payment data and IP address transiently to determine the tax jurisdiction. We do not store the IP address for this purpose.
Payment providers and app stores may process payment data under their own privacy terms and legal responsibilities. We retain transaction records where required by law.
4.6 Push notifications
We process a Firebase Cloud Messaging token to send push notifications only where you have consented. You may withdraw your consent at any time.
4.7 Technical data and crash reports
We process device model, operating system, app version, crash logs and, where applicable, the user ID through Firebase Crashlytics to identify and remedy technical errors. Our legitimate interest is the secure and reliable operation of the app. You may object to this processing on grounds relating to your particular situation.
5. Website Data
5.1 Website hosting and aggregate analytics
The website is hosted by Vercel Inc. We process technical data necessary to deliver, secure and operate the website. Vercel also provides cookie free aggregate analytics. The website does not set cookies. Our legitimate interests are the secure operation, maintenance and aggregate measurement of the website.
5.2 Contact and application forms
If you use a contact form, we process your name, email address and message to handle your inquiry. If you apply for a role, we also process the zodiac sign and experience level you provide. Form submissions are delivered through Brevo, formerly Sendinblue SAS, and may be processed through internal communication tools of our processors. Contact and application data are retained for up to 12 months.
We process contact requests where necessary to take steps before entering into a contract or to perform a contract. Otherwise, we process them on the basis of our legitimate interest in responding to communications. Applicant data are processed for the employment relationship under Section 26 BDSG.
6. Analytics and Attribution
We use the following app analytics and attribution providers only on the basis of consent: Firebase Analytics, provided by Google LLC, AppsFlyer Ltd., Singular Labs, Inc., and the Facebook SDK, provided by Meta Platforms. The related processing may include analytics, attribution, device and advertising identifier data.
On iOS, we access the Identifier for Advertisers only after App Tracking Transparency consent. On Android, we process the Google Advertising ID only with consent. You can withdraw analytics and attribution consent at any time through the relevant app consent settings. Withdrawal does not affect the lawfulness of processing before withdrawal.
Where consent is required under Section 25(1) TDDDG to store information on, or access information from, your terminal equipment, we obtain that consent separately. This applies in particular to consent based analytics, attribution and advertising identifier processing.
7. Legal Bases
We rely on the legal bases identified in the summary table and detailed sections. Contractual processing under Art. 6(1)(b) GDPR covers processing necessary to provide the app, personalised astrological features, friend functions, the AI chat advisor, feedback functions and purchases. Consent under Art. 6(1)(a) GDPR covers device contact access, push notifications, analytics, attribution and advertising identifiers.
We rely on Art. 6(1)(c) GDPR where we must retain transaction records to comply with statutory accounting and commercial retention obligations, including Section 147 of the German Fiscal Code and Section 257 of the German Commercial Code. We rely on Art. 6(1)(f) GDPR for crash analysis, website hosting, security, maintenance, aggregate website measurement and communications not connected to a contract. Our legitimate interests are the stable, secure and effective operation and improvement of our services, and the handling of communications. You may object to processing based on Art. 6(1)(f) GDPR as set out in Section 11.
Except for transaction data that we must retain by law, you are not legally required to provide personal data. However, you must provide the data necessary for an account, personalised astrological functions, purchases, a response to a particular request, or any other selected feature if you want to use that service. Consent based processing is optional and can be refused or withdrawn without affecting the core service, unless the relevant consent is necessary for the particular optional function.
8. Recipients and Processors
We disclose personal data to recipients where necessary to provide the services, process payments, fulfil legal obligations, secure our services or pursue the purposes stated in this policy. Where a provider processes personal data on our behalf, we use an appropriate data processing agreement where required by law.
| Provider or recipient | Country | Purpose | Transfer safeguard |
|---|---|---|---|
| Google LLC and Google Firebase | United States | Google Sign In, Google Places API, authentication, database, push notifications, remote configuration, crash reporting and app analytics | EU-US Data Privacy Framework, where certified |
| Apple | United States | Apple Sign In and Apple App Store purchases | EU-US Data Privacy Framework, where certified |
| Google Play | United States | In app purchases | EU-US Data Privacy Framework, where certified |
| RevenueCat, Inc. | United States | Subscription and purchase administration | Standard Contractual Clauses |
| OpenAI | United States | Processing of AI advisor requests on our behalf | Standard Contractual Clauses |
| Stripe | United States | Website payment processing and tax jurisdiction determination | EU-US Data Privacy Framework, where certified |
| Brevo, formerly Sendinblue SAS | France | Delivery of website contact and application form submissions | No transfer outside the European Economic Area identified for this processing |
| Vercel Inc. | United States | Website hosting and cookie free aggregate analytics | Standard Contractual Clauses |
| AppsFlyer Ltd. | Israel | App analytics and attribution | European Commission adequacy decision for Israel |
| Singular Labs, Inc. | United States | App analytics and attribution | Standard Contractual Clauses |
| Meta Platforms | United States | Facebook SDK analytics and attribution | Standard Contractual Clauses |
| Internal communication tools of our processors | European Economic Area or other applicable location | Handling website contact and application submissions | Appropriate processor agreement and, where applicable, a transfer safeguard described in Section 9 |
9. International Transfers
Personal data may be transferred to countries outside the European Economic Area, in particular the United States and Israel. For transfers to certified United States recipients, we rely on the European Commission adequacy decision for the EU-US Data Privacy Framework. For other United States transfers, we rely on the European Commission Standard Contractual Clauses. Transfers to Israel rely on the European Commission adequacy decision for Israel.
You may request information about the applicable safeguard or a copy of the relevant safeguard by contacting us. We may redact information where necessary to protect confidential information or the rights of others.
10. Retention
| Data | Retention period or criterion |
|---|---|
| Account and birth data | Until account deletion |
| Account related content and data used to provide app functions | Until no longer needed to provide the relevant function, subject to deletion requests and mandatory retention duties |
| Data stored only locally on your device, including manually added friends and tarot history | Until you delete it or uninstall the app |
| Push token | Until you withdraw consent, revoke the relevant permission or uninstall the app |
| Analytics and attribution data | 14 months |
| Crash data | 90 days |
| Website contact and application data | Up to 12 months |
| Transaction records | 10 years, where required under Section 147 of the German Fiscal Code and Section 257 of the German Commercial Code |
After the relevant period, we delete or anonymise personal data unless a longer retention period is required or permitted by law.
11. Your Rights
Subject to the statutory requirements, you have the following rights:
- Access (Art. 15 GDPR): You may request confirmation of processing and access to your personal data.
- Rectification (Art. 16 GDPR): You may request correction of inaccurate or incomplete data.
- Erasure (Art. 17 GDPR): You may request deletion of your data.
- Restriction (Art. 18 GDPR): You may request restriction of processing.
- Data portability (Art. 20 GDPR): You may receive data you have provided in a structured, commonly used and machine readable format, or request its transmission to another controller.
- Objection (Art. 21 GDPR): You may object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(e) or Art. 6(1)(f) GDPR, including profiling based on those provisions.
- Withdrawal of consent (Art. 7(3) GDPR): You may withdraw consent at any time with future effect.
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Art. 22 GDPR. The AI advisor is an entertainment feature and does not produce legal effects.
12. Complaint Right
You have the right to lodge a complaint with a data protection supervisory authority. Our competent supervisory authority is:
Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5
30159 Hannover
Germany
13. Account Deletion
You may delete your account through the app settings or by emailing support@astrobella.com. Deletion of your account does not delete data stored only locally on your device. You can remove local data by deleting it in the app where available or by uninstalling the app.
14. Children
AstroBella is not directed at children under 16 years of age. Where we rely on consent to process the personal data of a child under 16, consent must be given or authorised by the holder of parental responsibility.
15. Security
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, taking account of the state of the art, implementation costs, and the nature, scope, context and purposes of processing.
16. Changes
We may update this Privacy Policy where necessary to reflect changes in processing activities or applicable law. The version published in the app or on the website applies from the stated update date.
17. Contact
For privacy questions or to exercise your rights, contact:
Moonphase Apps GmbH
Ferdinand-Koch-Straße 31
26133 Oldenburg
Germany
- Email: support@astrobella.com