LEGAL

Privacy Policy

Last updated: 2 July 2026

StarMatch maps the heavens, but it is careful with what it learns about you. This Privacy Policy explains, in plain language, who controls your personal data, what we process, why, on what legal basis, and the rights you have under the General Data Protection Regulation (GDPR / RODO).

Who is the controller of your data

The controller of your personal data is NRMConsulting Maciej Miernicki, a Polish sole proprietorship (a sole proprietorship (jednoosobowa działalność gospodarcza) entered in the Polish Central Registration and Information on Business (CEIDG)) registered in CEIDG (Centralna Ewidencja i Informacja o Działalności Gospodarczej), operating the StarMatch service at starmatch.pl.

NIP: 5871727423 REGON: 387454735 Correspondence address: Wały Jagiellońskie 28/30 lok. 2, 80-853 Gdańsk General contact: kontakt@starmatch.pl Data-protection matters: privacy@starmatch.pl

No Data Protection Officer (Inspektor Ochrony Danych) has been appointed, because the law does not require one for an operation of this size and nature. For any question about your data, write to privacy@starmatch.pl.

What StarMatch is, in privacy terms

StarMatch is a mystical Greek-astrology web app (free to try, with two optional one-time paid unlocks): natal charts, compatibility (synastry), numerology, a "Matrix of Destiny", forecasts, and the "Astral Oracle" — an AI chatbot. It is provided for reflection and entertainment only and is not professional medical, psychological, financial, or legal advice.

Access may vary over time: at times the app is a closed beta behind a login with operator-created accounts, and at times it is open to the public with self-registration. On the pre-launch page, anyone may leave their email to join the launch waitlist and receive a welcome email, occasional updates, the launch announcement, and launch offers such as introductory pricing (sent through our EU email provider, Brevo — see the processors section below). The Service offers two optional one-time paid unlocks — the full-application unlock (every reading) and the Astral Oracle add-on (unlimited use of the AI) — processed by our payment provider Stripe (see the processors section below); a free tier remains (the essence of your birth chart, the public reference pages, and a limited daily number of Oracle questions), and StarMatch carries no advertising. It uses consent-gated product analytics (PostHog) that load nothing until you opt in via the cookie banner, and no advertising or cross-site tracking technologies of any kind.

What categories of data we process

Account data (stored on our server, in Google Firestore): your chosen username (a handle — not your real name), a salted password hash (never the plaintext password), an optional administrative label/note, and the dates and creator of the account. We do not collect an email address, phone number, or real name for the account itself.

Astrology profiles (stored only in your browser, in localStorage — not sent to any server on their own): a name, a relation (self / partner / friend / family / other), a birth date, an optional birth time, and a birthplace (place name, latitude, longitude, and IANA time zone). You may add profiles for other people. From these inputs the app computes and displays derived data — your chart placements (planets in signs and houses, aspects), compatibility scores, numerology, and Matrix of Destiny — which are themselves personal data.

Oracle chat data: when you consult the Astral Oracle, your browser sends the conversation and an assembled personalisation context to our server, which forwards it to Google Vertex AI. This context is rich — it can include the active profile's name, birth date, age and life-stage, birthplace, the full natal chart, today's transiting sky, a Matrix of Destiny summary, the names + relation + sun/moon signs + compatibility of other people you saved, your free-text "what you are seeking" note, the chat history, and your interface language. See the section "The Astral Oracle and AI processing" below for the complete list. Please do not enter special-category data (for example about your health, sexuality, or religious or philosophical beliefs) into the Oracle's free-text fields — see that same section.

Browser storage: in addition to the astrology profiles, your browser stores your chat history (capped at roughly 100 messages), your "seeking" text, and your Oracle-memory consent flag, plus the cookies described in our Cookie Policy.

Transient security data: when you log in, we briefly process your IP address in memory for anti-brute-force / anti-abuse throttling. This is used transiently for security and is not stored as a permanent log of your activity.

Birthplace lookups: when you type a birthplace, your browser sends the text query directly to the Open-Meteo geocoding service to resolve coordinates and time zone (no account, key, or cookie is involved).

Product-analytics data (only if you opt in): if you consent to analytics, we process — through PostHog — an opaque, irreversible identifier derived from your account, your role, and product-usage events (counts, scores, enumerations, booleans, and your interface language). Analytics never receives your name, your birth data, your Oracle questions, or your free-text "what you are seeking" note — these are masked or scrubbed before any event leaves your browser. See "Analytics (PostHog)" below.

Waitlist (leads) data: if you join the launch waitlist on the pre-launch page, we process the email address you submit, a hash of that email (to avoid duplicates), a salted hash of your IP address (for abuse prevention — the raw IP is not stored), your interface language, any UTM campaign parameters in the link you arrived through, and a record of your consent (its version and timestamp). See "Launch waitlist (leads)" below.

Source of data: most data comes directly from you. Where personal data concerns third parties (for example the birth data of partners or friends you add), the source of that data is the StarMatch user who entered it.

Your responsibility when entering other people's data

StarMatch lets you add profiles for other people — partners, friends, or family — which means you may enter another person's birth data and name. When you do this, you are responsible for having a lawful reason to do so.

Please only add another person's details if they are aware and have no objection, enter the minimum needed (a birth date is enough for most features; a birth time and place refine the chart), and remove their profile when it is no longer needed. Because these profiles live in your browser's localStorage, you control and can delete them at any time. Do not enter the data of children or of anyone who has asked you not to.

Purposes of processing and legal bases

We process your data only for clearly defined purposes, each with a legal basis under Article 6 GDPR:

  • Providing the service — creating and maintaining your account, keeping you logged in, and generating charts, compatibility, numerology, the Matrix of Destiny, and forecasts. Basis: performance of a contract and steps taken at your request before a contract (Art. 6(1)(b)).
  • The Astral Oracle chat — sending your context to the AI to generate a reply. Basis: performance of the contract / the service you requested (Art. 6(1)(b)).
  • Optional long-term Oracle memory — only if you opt in, so the Oracle can remember you across consultations. Basis: your consent (Art. 6(1)(a)), withdrawable at any time.
  • Product analytics — understanding how the app is used, to improve it, only if you opt in via the cookie banner. Basis: your consent (Art. 6(1)(a)), withdrawable at any time through the "Manage cookies" control.
  • Launch waitlist — keeping your email so that, after you tick the consent box and confirm via the email we send, we can send you a welcome, occasional news and updates about StarMatch, the launch announcement, and launch information such as introductory pricing or promotional offers relating to StarMatch. Basis: your consent (Art. 6(1)(a) and Art. 7), withdrawable at any time.
  • Security and anti-abuse — transient IP-based login throttling, a salted hash of the IP at waitlist sign-up, integrity of the service, and establishing or defending legal claims. Basis: our legitimate interests (Art. 6(1)(f)); you may object under Art. 21.
  • Functional/preference cookies — remembering your theme, language, and cookie choices, set only when you actively choose them. Basis: our legitimate interest in delivering the preference you requested; the essential session cookie is strictly necessary to deliver the logged-in service.

Birth date, time, and place are needed to generate a chart: without them, the relevant features cannot work. Providing them is voluntary, but the service depends on them. Oracle long-term memory is entirely optional and the rest of the service works without it.

Special-category data: birth date/time/place and astrological or numerological outputs are not, by themselves, special-category data under Art. 9 GDPR. However, the free-text Oracle chat could lead you to volunteer sensitive information (for example about your health, sexuality, or religious or philosophical beliefs). Please do not enter special-category data into the Oracle. If you nevertheless do, we rely on your explicit consent (Art. 9(2)(a)) as the basis for processing it within that conversation, and the entertainment / no-medical-advice nature of the Oracle still applies.

The Astral Oracle and AI processing

The Astral Oracle is an AI system — a chatbot powered by a large language model from Anthropic (Claude, by default Claude Sonnet), served through Google Vertex AI. You are talking to software, not a human. Its replies are AI-generated, may be inaccurate, and are for reflection and entertainment only.

When you consult the Oracle, your browser sends to our server, and our server sends on to Google Vertex AI, a context assembled to personalise the reply. This context can include: your profile name, birth date, age and life-stage, birthplace, your full natal chart, today's transiting sky, a summary of your Matrix of Destiny, the names + relation + sun/moon signs + compatibility of other people you have saved, your free-text "what you are seeking" note, the chat history, and your interface language. Google processes this to generate the response and acts as our processor.

If you have opted in to Oracle memory, we additionally store, in our database, an AI-maintained rolling summary of who you are and your past themes, durable "facts", your "seeking" text, a consultation count and last-consulted date, and an append-only log of the raw seeker/Oracle turns. This is used to personalise future replies and as a private corpus for improving the Oracle. It is keyed to your username and is deleted when you withdraw consent or delete your account (self-service deletion and export of this memory is being added).

Analytics (PostHog)

To understand how StarMatch is used and to improve it, we use PostHog, a product-analytics tool. Analytics are strictly opt-in: nothing loads and no event is sent until you accept analytics in the cookie banner. The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time through the "Manage cookies" control — after which analytics stop loading.

What analytics receives: an opaque, irreversible identifier derived from your account (we cannot reverse it to your username), your role, and product-usage events — counts, scores, enumerations, booleans, and your interface language. What it never receives: your name, your birth data, your Oracle questions, or your free-text "what you are seeking" note. These are masked or scrubbed before any event leaves your browser.

Session replay (recording of your screen interactions) is switched off and is never enabled unless you separately opt in; if it ever is, the recording is fully masked so that the content above is not captured.

Where it runs: analytics data stays in the EU. Events are sent through a first-party proxy on our own domain (an "/ingest" path) to PostHog's EU-hosted infrastructure, so there is no transfer of analytics data outside the European Economic Area. PostHog acts as our processor under a data-processing agreement (DPA). The cookie set by analytics is described in our Cookie Policy.

Launch waitlist (leads)

Before public launch, the StarMatch landing page lets you leave your email address to be notified when the service opens. This is voluntary and requires you to actively tick a consent checkbox; we will not add you without it. The legal basis is your consent (Art. 6(1)(a) and Art. 7 GDPR), which you can withdraw at any time.

What we store, in Google Firestore (the collection "starmatch_leads"): the email address you submit, a hash of that email (to avoid duplicate entries), a salted hash of your IP address for abuse prevention (the raw IP is not stored), your interface language, any UTM campaign parameters from the link you arrived through, and a record of your consent (its version and timestamp).

What we do with it: when you sign up we email you a confirmation link, and only once you click it do we add you to the list and send you a welcome message, occasional news and updates about StarMatch, the announcement when the service opens, and launch information such as introductory pricing or promotional offers relating to StarMatch. To manage the waitlist and send these messages we use Brevo (Sendinblue SAS), an email service provider based in the EU (see the processors section below). Every message carries a one-click unsubscribe link, and you can withdraw your consent at any time.

How long we keep it: for as long as you stay subscribed. The one-click unsubscribe link in any message stops all further emails and removes you from Brevo; to also have your waitlist entry erased from our database, email privacy@starmatch.pl and we will remove it.

Profiling and automated decision-making

StarMatch profiles you in the everyday sense: it analyses your birth data to compute compatibility scores, forecasts, numerology, the Matrix of Destiny, and the Oracle's personalised replies. The logic is astrological and numerological computation applied to the birth details you provide — it is interpretive and entertainment-oriented, not scientific.

This profiling produces no legal or similarly significant effects, so the prohibition on solely automated individual decision-making in Article 22 GDPR does not apply. There is no automated decision that affects your rights, finances, or legal status. We disclose this profiling here so you understand its logic, significance, and consequences — which are limited to generating readings for your reflection and amusement.

Who receives your data (processors and recipients)

We do not sell your data and we do not share it for advertising. We use a small number of processors who act only on our instructions:

  • Google (Google Cloud) — hosting (Cloud Run), database storage (Firestore — accounts, the launch waitlist, and Oracle memory), and AI inference (Vertex AI, serving an Anthropic Claude model). Hosting and Firestore storage are in the EU region. Your Oracle chat content is sent to Google's Vertex AI to generate the reply. Google processes this data under a written data-processing agreement (Google's Cloud Data Processing Addendum).
  • PostHog — product analytics, used only if you opt in. It receives the masked usage data described in "Analytics (PostHog)", routed through a first-party proxy to PostHog's EU-hosted infrastructure. PostHog processes this data under a written data-processing agreement (DPA).
  • Brevo (Sendinblue SAS, France) — our email service provider, used only if you join the launch waitlist. It receives and stores your email address and the waitlist details (your interface language, any UTM parameters, and your consent record), sends the confirmation request and the welcome, update, and launch emails, and provides the one-click unsubscribe link. Brevo is EU-based and stores this data in the EU; it processes it under a written data-processing agreement (DPA). The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time by unsubscribing.
  • Open-Meteo (open-meteo.com) — receives the birthplace text you type, sent directly from your browser, to return coordinates and time zone. No account, key, or cookie is used.
  • Stripe — our payment provider, used only if you buy one of the optional one-time unlocks (the full-application unlock or the Astral Oracle add-on). Stripe processes your payment and billing details (for example email, card data, billing address and any tax/VAT identifier) on Stripe's hosted checkout; it acts as our processor and, for fraud-prevention and regulatory purposes, as an independent controller. We never receive your full card number. Stripe may transfer data to the United States under the EU–US Data Privacy Framework and Standard Contractual Clauses.

We may also disclose data where required by law or to establish, exercise, or defend legal claims.

Where your data is processed and international transfers

StarMatch is operated from Poland (EU). Account data and the Firestore database are hosted in the EU region, and the service is delivered worldwide.

Google Vertex AI — which powers the Astral Oracle — is pinned to the EU (the Vertex AI "eu" multi-region), so the Oracle's AI inference is performed within the EU/EEA, alongside the EU-hosted Firestore database. Google LLC is nonetheless a company headquartered in the United States; to the extent any limited processing reaches the US, transfers to Google LLC are covered by the European Commission's adequacy decision for the EU–US Data Privacy Framework (Art. 45 GDPR; Google LLC is DPF-certified), with Standard Contractual Clauses (Art. 46(2)(c) GDPR) in Google's data-processing agreement as a backstop. You can request more information about these safeguards, or a copy of the relevant clauses, by writing to privacy@starmatch.pl.

Product analytics (PostHog) is hosted in the EU and reached through a first-party proxy on our own domain, so analytics data is not transferred outside the European Economic Area.

How long we keep your data (retention)

  • Account data: kept for as long as your account exists; deleted when the account is removed.
  • Oracle long-term memory and consultation log: kept only while your consent stands; deleted when you withdraw consent or delete your account.
  • Launch waitlist (leads): kept for as long as you stay subscribed. Unsubscribing (the link in any message) stops all emails and removes you from Brevo; email privacy@starmatch.pl to also have your entry erased from our database.
  • Product analytics: kept according to PostHog's retention settings, and only for as long as your analytics consent stands — withdrawing consent stops further collection.
  • Transient security data (login IP throttling): held only momentarily in memory and not retained as a stored log.
  • Data in your browser (astrology profiles, chat history, "seeking" text, consent flag): stored in your browser's localStorage under your control — it stays until you delete it or clear your browser storage, and it is never sent to a server on its own.
  • Cookies: retained for the durations listed in our Cookie Policy (the session and role cookies about 7 days; the theme, language, and cookie-consent preferences about 180 days to 1 year).

Where no fixed period is set, we keep data only as long as necessary for the purpose for which it was collected, or as required to defend legal claims.

Your rights

Under the GDPR you have the right to:

  • access your data and obtain a copy (Art. 15);
  • rectify inaccurate or incomplete data (Art. 16);
  • erasure — to be forgotten (Art. 17);
  • restrict processing (Art. 18);
  • data portability — receive your data in a structured, machine-readable format (Art. 20);
  • object to processing based on our legitimate interests (Art. 21);
  • withdraw consent at any time, where processing is based on consent (Art. 7(3)).

Many of these you can exercise yourself directly in the app: edit or delete astrology profiles (they live in your browser), clear your Oracle chat history and "seeking" text, and turn Oracle memory on or off. Self-service deletion and export of Oracle memory is being added. For anything else — or to make a formal request — write to privacy@starmatch.pl. We will respond without undue delay and within the time limits set by the GDPR.

Consent and its withdrawal

Some processing depends on your consent — the Oracle's optional long-term memory, product analytics, and joining the launch waitlist. Each consent is separate and entirely voluntary; the rest of StarMatch works without any of them, and none is ever bundled into account creation.

You can withdraw each consent at any time, as easily as you gave it — by turning off the "let the Oracle remember me" setting (which stops further memory-based processing and triggers deletion of the stored memory), by using the "Manage cookies" control to turn off analytics (after which analytics stop loading), or by emailing privacy@starmatch.pl to be removed from the waitlist. You can also write to privacy@starmatch.pl for any of these. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.

Right to lodge a complaint

If you believe we process your data unlawfully, you have the right to lodge a complaint with a supervisory authority. In Poland this is:

Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa.

If you live in another EU/EEA country, you may also complain to the supervisory authority of your country of habitual residence or place of the alleged infringement.

Children and minimum age

StarMatch is intended for users aged 16 and over. This reflects the digital-consent age under Article 8 GDPR as applied in Poland. The service is not directed to children under 16, and under-16s may not use it. If we learn that an account belongs to someone under 16, we may remove it. If you are a parent or guardian and believe a child has provided us with data, contact privacy@starmatch.pl.

How we protect your data (security)

We apply technical and organisational measures appropriate to the risk:

  • passwords are stored only as salted scrypt hashes, never as plaintext;
  • sessions are kept with a signed, HMAC-protected session token (an httpOnly cookie in production);
  • all traffic is served over TLS/HTTPS;
  • access to the server-side store and administrative functions is restricted by role;
  • our hosting and database run on Google Cloud, which provides encryption in transit and at rest and resilient infrastructure.

No online service can be guaranteed perfectly secure, and we do not claim that it is; but we work to keep your data safe and to keep these measures current.

Cookies

StarMatch uses a small set of first-party cookies — an essential session cookie, a role hint, theme and language preferences, and a cookie-consent cookie (sm_consent, kept about 180 days) that records your cookie choices. The essential and preference cookies do not require consent; product analytics require your consent, which is why StarMatch shows a cookie-consent banner. We use no advertising or cross-site tracking cookies. The details (names, purposes, durations, and how to manage or withdraw consent) are in our Cookie Policy, which forms part of this Privacy Policy.

International users (UK and California)

United Kingdom: if you are in the UK, your data is processed under the UK GDPR and the Data Protection Act 2018, overseen by the Information Commissioner's Office (ICO, ico.org.uk), where you also have the right to complain. Your rights mirror those under the EU GDPR. Given the small, low-risk, occasional nature of any UK use, we currently rely on the limited exemption from the duty to appoint a UK representative; if this changes, we will appoint one and update this section.

California (CCPA/CPRA): the California Consumer Privacy Act applies only to businesses meeting specific thresholds (large annual revenue, large-scale buying/selling/sharing of personal information, or deriving most revenue from selling/sharing it). StarMatch — a small, free app that does not sell or share personal information — meets none of these, so the CCPA does not legally apply to us. As a matter of good practice, we confirm: we do not sell or share your personal information, and we do not use it for cross-context behavioural advertising. If you are a California resident, you may still ask us to know, access, delete, or correct your information by writing to privacy@starmatch.pl, and we will not discriminate against you for exercising any such request.

Changes to this Policy

We may update this Privacy Policy — for example to reflect new features or changes in the law. When we make a material change, we will update the "last updated" date and, where appropriate, notify you within the app. The current version always governs; please review it from time to time.

Effective date

This Privacy Policy is effective from 2026-06-23.

Your data & privacy rights

Export or delete the data StarMatch holds about you. These tools act on your account only.

Export my data

Download everything we hold for you — your account, the Oracle's memory and consultation log, and the profiles and chats stored in this browser — as one JSON file.

Erase the Oracle's memory

Permanently delete the long-term memory and consultation log the Oracle keeps for you on the server. Your account stays.

Clear this browser

Remove the birth profiles and Oracle chat stored in this browser. Affects only this device.