Legal · Privacy
Privacy Policy
What diosa collects, who processes it, how long it lives, and how to delete it — in plain language.
By the diosa astrologers · Computed on Swiss Ephemeris · Updated 2026-08-29
diosa is an astrology app built on a simple promise: your birth data is treated like health data — encrypted, never sold, yours to delete. This policy explains exactly what that means in practice. It covers www.mydiosa.com and the app behind it.
1. What we collect
Birth data you enter. To cast a chart, diosa needs a birth date, a birth time (optional — an untimed chart is cast as noon with a stated caveat), a birth place, and an optional label or name. This is the minimum a chart requires; we ask for nothing else.
Account data. If you create an account, our authentication provider (Clerk) stores your email address and the sign-in identifiers tied to it. If you sign in with Google, Clerk stores your Google account’s email address, name, and profile picture (the same fields any “Sign in with Google” button receives; diosa never sees your Google password). You can manage or delete your account from the app’s account screen.
Usage analytics. We use Google Analytics 4 to understand which pages are visited. GA4 is configured with IP anonymization and does not receive your birth data, chart contents, or readings.
Minimal technical logs. Our hosting and API layer keep short-lived operational logs (request metadata, error traces) to keep the service working and secure.
2. What stays on your device
diosa is local-first: the chart you cast during a session lives in your browser’s storage on your device, and the readings you see are cached there so they never silently rewrite themselves. You can clear it anytime by signing out and clearing site data. This device data is never sold and never used for advertising.
3. Where your data is stored
When you save a chart to your account, it is stored in a Supabase (PostgreSQL) database with encryption at rest and in transit. Your birth data is stored to compute and re-display your charts — not to profile you, not to train models on you, and never sold or rented to anyone.
4. Who processes data with us
We keep the list short and each processor scoped to its job:
- Clerk — account creation and sign-in, including the “Sign in with Google” option. Stores your email and sign-in identifiers on our behalf.
- Supabase — database and storage for saved charts and cached readings, encrypted at rest.
- Google Analytics 4 — aggregate, anonymized page analytics. No birth data, chart contents, or readings are ever sent to it.
- Map-based place search (OpenStreetMap Nominatim) — when you type a birthplace, the place name you typed is sent to a public geocoding service to resolve its coordinates. Coordinates are used to cast the chart; your typed place is not shared with advertisers.
- Vercel / Fly.io — hosting and the chart-calculation service (Swiss Ephemeris) that computes planetary positions from your birth data.
5. Why we process (legal bases)
For EEA/UK visitors: we process your birth data and account data to provide the service you asked for (contract); we process analytics and operational logs under our legitimate interest in keeping the service fast and secure; any optional communications would rely on your consent, withdrawable at any time. You may also object to processing based on legitimate interest.
6. Your rights
You can access, export, correct, and delete your data:
- Delete a chart — from your account’s chart list, at any time; deletion removes it from the service.
- Delete your account — from the account screen; this deletes your saved charts and account record. Residual encrypted backups age out on our providers’ standard schedules (typically within 30 days).
- Access / portability — your charts are visible and re-downloadable in the app, and you can request a copy of your data at any time via the contact route below.
EEA/UK users have the right to lodge a complaint with their supervisory authority; California users have the right to know, delete, and opt out of any “sale” or “sharing” of personal information — diosa does not sell or share personal information as those terms are defined, and has done so in the last 12 months.
7. How long we keep things
Session charts and reading caches live on your device until you clear them. Saved charts live in the database until you delete them or close your account. Operational logs are kept for up to 90 days. Aggregate analytics are retained per Google Analytics’ standard settings.
8. Children
diosa is not directed at children under 13, and we do not knowingly collect birth data from them. If you believe a child under 13 has given us their data, contact us and we will delete it.
9. Security
Data is encrypted in transit (TLS) and at rest (Supabase encryption). Access inside diosa is limited to what operating the service requires, and database access is gated by row-level security so charts are readable only by their owner.
10. Changes to this policy
If we change this policy, we update the date above and, for material changes, announce it in the service before it takes effect. The date at the top is the version you can rely on.
11. Contact
Privacy questions, data requests, and deletion requests: email privacy@mydiosa.com and we will respond within 30 days.
FAQ
Does diosa sell my birth data?
No. Birth data is stored to compute and display your charts, never sold, rented, or used for advertising.
What does 'Sign in with Google' share?
Only your Google account's email, name, and profile picture — the standard set any Google sign-in button receives. diosa never sees your Google password.
How do I delete my data?
Delete individual charts from your account's chart list, or delete your whole account from the account screen. You can also email privacy@mydiosa.com for a full export or deletion.
Does Google Analytics see my chart?
No. GA4 receives anonymized page analytics only — never birth data, chart contents, or readings.