Draft: pending review by a qualified Swiss data-protection lawyer
Privacy Policy · My Cosmic Self
Version 0.1 · 2026-07-12
This policy explains what personal data My Cosmic Self collects, why, who we share it with, and the rights you have. We wrote it to satisfy both the Swiss Federal Act on Data Protection (FADP, Art. 19) and the EU/EEA General Data Protection Regulation (GDPR, Art. 13 and 14). We have tried to keep it in plain language.
You must be at least 16 years old to use My Cosmic Self. See the "Age requirement" section below.
1. Who is responsible for your data (controller)
The controller responsible for your personal data is:
Lars Hoernle & Luca Sator, joint operators
Affolternstrasse 81, 8050 Zurich, Switzerland
(The founders currently operate as two private individuals; a company will be formed later.)
Contact for any privacy question or request: luca.lars.saho@gmail.com
EU/EEA representative (appointed under GDPR Art. 27): [EU REPRESENTATIVE: name + address, pending appointment]
2. What data we collect, why, and our legal basis
We only collect what the app needs to work. Here is every category of personal data we process.
| Data category | What it includes | Why we process it | Legal basis |
|---|---|---|---|
| Account / login | Email address, password, and — if you choose it — Sign in with Google (optional) | To create and secure your account, sign you in, and send account and email-verification messages | Contract (GDPR Art. 6(1)(b)): needed to give you the service |
| Birth data & computed chart | Birth date, time and place, coordinates, timezone, and the natal chart we calculate from them | To build your personal astrology chart, which is the core of the app | Contract (Art. 6(1)(b)). Because birth/worldview data can be sensitive, we also treat it with extra care |
| Profile self-description | Display/first name, pronouns, intentions, "vibes", relationship status, language/locale | To personalise the app and your readings | Contract for the basic profile; your explicit consent (Art. 9(2)(a)) for pronouns and relationship status, which can reveal sensitive information |
| Journal & wellbeing ratings | Free-text journal entries; mood, energy, sleep and social ratings (1–10); tags | To let you keep a private reflective journal and track how you feel over time | Your explicit consent (Art. 9(2)(a)): this is sensitive (health/intimate) data |
| Daily feedback | Daily mood rating (1–5) and short notes | To show your daily check-ins over time | Your explicit consent (Art. 9(2)(a)): sensitive (mood) data |
| AI-companion chat | The full text of your conversations with the AI companion | To let you chat with the AI companion and get chart-aware reflections | Your explicit consent (Art. 9(2)(a)): chat can contain intimate, sensitive content |
| Third-party (synastry) data | Another person's first name, relationship type, and birth date/time/place, plus the compatibility chart we compute | To let you explore compatibility ("synastry") with someone you know | Your legitimate interest in a private compatibility reading (Art. 6(1)(f)), supported by our documented Art. 14(5)(b) assessment. See our separate Third-Party Data Notice |
| Place searches | The place-name text you type when searching for a birth location, and the returned coordinates | To find birth-place coordinates for the chart | Contract (Art. 6(1)(b)). The search is a stateless lookup and is not stored against your identity by the geocoding provider |
| Operational & log data | Onboarding/tour progress, cached transits and horoscopes, AI-usage counters, admin access logs, notifications, and technical logs generated when you use the app | To run, secure, debug and rate-limit the service | Legitimate interest (Art. 6(1)(f)) in operating a secure, reliable service |
| localStorage (in your browser) | Your login session token, recent city searches, language preference, onboarding-tour flag, a pending-consent flag, and a flag recording that you chose a language explicitly | To keep you signed in and remember your preferences on your device | Contract (session) and legitimate interest (Art. 6(1)(f)) for preferences |
Where we rely on your explicit consent (profile self-description in part, journal & wellbeing ratings, daily feedback, AI-companion chat, and any personalisation of your readings), you can withdraw that consent at any time. See "Your rights" below. Withdrawing consent does not affect processing that already happened, and it does not stop you using the parts of the app that run on other legal bases.
We do not currently run advertising, ad pixels, marketing emails, analytics tracking, or payments. If we ever introduce paid plans or any new use of your data, we will update this policy first and, where the law requires it, ask for your consent.
Free trial preview (no account): The birth details you enter in the landing-page free trial are processed only in memory to compute your preview (Sun, Moon, and Rising). They are never stored and never sent to any AI provider. The place search in that trial goes only to Open-Meteo (Switzerland) to look up coordinates.
3. Who we share your data with (recipients and processors)
We do not sell your data. We use a small number of service providers ("processors") who process data only on our instructions under a data-processing agreement. Each receives only what it needs:
- Supabase (database, authentication, email verification): stores all of the data above (account, birth data and chart, profile, journal and wellbeing ratings, daily feedback, chat history, third-party/synastry data, operational data). This is our main data store.
- Groq, Inc. (United States): our AI language-model provider. Groq generates text for three features and receives only what each needs:
- AI companion chat — your birth-chart summary, current transits, first name, pronouns, intentions, vibes, relationship status, and your last 20 chat turns;
- Daily reading (generated for every user) — your chart and current transits, plus your intentions and vibes;
- Compatibility reading — your first name, the other person's first name, and the chart-derived compatibility data for the two of you.
- Google (Sign in with Google, optional): if you choose to sign in with Google, Google authenticates you and acts as an independent controller for that sign-in itself, under Google's own privacy policy. We receive only your email address and a sign-in token; we do not send Google any of your app content.
- Cloudflare (hosting and content delivery): serves the app and therefore processes network traffic (for example IP address and request data) to deliver and protect the site.
- Open-Meteo (OpenMeteo GmbH, Switzerland; geocoding): receives the place-name text you search for and, for timezone lookup, the place coordinates, and returns location/timezone data. It does not receive your identity.
Important boundary: your journal entries, wellbeing ratings, and daily-feedback notes are stored only in Supabase and are NOT sent to Groq or any other AI provider. Only your AI-companion chat content (plus the chart/profile context listed above) is sent to Groq.
We may also disclose data if the law requires it (for example a valid legal order).
4. International data transfers
Your data is stored in Switzerland. Our database is hosted in the Supabase EU/Zurich region (AWS eu-central-2, Zurich), so your data at rest does not leave Switzerland and Supabase is not a third-country transfer.
The only transfer to a country outside Switzerland/the EEA is to our AI provider:
- United States: Groq, Inc. When you use the AI companion, request a daily reading, or run a compatibility reading, the relevant chart/profile context (and, for chat, your last 20 chat turns) is transferred to Groq in the United States. The USA is not on the Swiss or EU list of countries with "adequate" data protection, and Groq is not certified under the EU-US / Swiss-US Data Privacy Framework. We therefore rely on EU Standard Contractual Clauses and the Swiss counterpart (Swiss SCCs), backed by a Transfer Impact Assessment, as the legal safeguard for this transfer.
- Cloudflare operates a global edge network to deliver and protect the site; it is covered by a data-processing agreement with Standard Contractual Clauses / Data Privacy Framework safeguards.
- Open-Meteo is operated in Switzerland, so place-name lookups are not a transfer to a third country.
Under Swiss law (FADP Art. 19) we are required to name the countries your data is exported to and the safeguard used. The only such export is to the United States (Groq), protected by Swiss/EU Standard Contractual Clauses plus a Transfer Impact Assessment, as stated above. You can ask us for a copy of the relevant safeguards at luca.lars.saho@gmail.com.
5. How long we keep your data
- We keep your data for as long as your account exists.
- You can delete individual journal entries and clear your entire chat history yourself at any time inside the app.
- When you delete your account, we remove your account and all associated data from our systems. Deletion also propagates to our processors according to their contracts (for example, Groq deletes data within a maximum of 180 days after termination of service).
- Some short-lived technical logs and rate-limiting records are pruned automatically.
We are still finalising a full retention schedule and will update this section as we introduce automatic, time-based deletion.
6. Your rights
Depending on where you live, you have the right to:
- Access: get a copy of the data we hold about you;
- Rectification: correct data that is wrong or incomplete. Note: you can edit your own birth data in the app at most once every 30 days; if you need a correction sooner, email us at luca.lars.saho@gmail.com and we will make it for you;
- Erasure: have your data deleted (you can delete your account, delete individual journal entries, and clear your chat history yourself);
- Portability: receive your data in a portable format;
- Objection: object to processing based on our legitimate interests;
- Withdraw consent: where we rely on your explicit consent (journal, mood, daily feedback, chat, personalisation), withdraw it at any time.
To exercise any of these rights, contact luca.lars.saho@gmail.com. We will respond within the timeframes set by applicable law. Using these rights is free unless a request is clearly unfounded or excessive.
7. Complaints
If you think we have mishandled your data, you can contact us first at luca.lars.saho@gmail.com. You also have the right to complain to a supervisory authority:
- In Switzerland: the Federal Data Protection and Information Commissioner (FDPIC), Bern.
- In the EU/EEA: your national data protection authority, or the authority for the EU/EEA where our representative is located.
8. Age requirement
My Cosmic Self is intended for people aged 16 and over. We do not knowingly collect data from anyone under 16. If you believe someone under 16 has created an account, please contact luca.lars.saho@gmail.com and we will delete it.
9. Cookies and local storage
We do not use tracking or advertising cookies. We only store a small amount of information in your browser's localStorage to make the app work:
- your login session token (to keep you signed in);
- your language/locale preference, and a flag recording that you chose a language explicitly (so we don't override your choice);
- your recent city searches and onboarding-tour progress;
- a pending-consent flag (set while you finish accepting the legal terms).
Because these are strictly necessary or preference items and we do not track you across other sites, no cookie-consent banner is required. If this ever changes, we will add the appropriate controls.
10. Changes to this policy
We may update this policy as the app evolves or the law changes. When we make a material change, we will update the version and date at the top and, where appropriate, notify you in the app. Please check back from time to time.
Questions? Contact us at luca.lars.saho@gmail.com.