Our data pledge
Your birth time, birthplace and ancestral details are deeply personal. We treat them that way:
- ✓We never sell or broker your birth or family data, and we never share it with advertisers or data brokers.
- ✓Your data is used only to compute and improve your own readings.
- ✓You can export everything and permanently delete your account and data at any time, from your profile. The only thing we must keep afterwards is the billing and accounting record of what you paid, because tax law requires it.
- ✓GDPR and CCPA first: you stay in control of your information.
Last updated: July 14, 2026
Introduction
Horospire ("we", "us", or "our") is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your information when you use our website at horospire.com and our Horospire mobile applications (together, the "Service"). By using our Service, you agree to the collection and use of information in accordance with this policy.
Data Controller
Horospire is operated by the following entity, which acts as the data controller for the personal data collected through the Service:
MB Libranet
Company code: 306214658
Registered address: V. Nagevičiaus g. 3, LT-08237 Vilnius, Lithuania
Contact: [email protected]
Information We Collect
Account & Profile Information
When you create an account or use our Service, we may collect the following information:
- Name - Used to personalize your experience and identify your account.
- Email address - Used for account authentication, communication, and password recovery.
- Password - Stored only as a securely hashed value; we never store your password in plain text.
- Username and bio - Optional, used if you choose to make a public profile.
- Avatar image - Optional profile picture you upload.
- Date of birth (day, month, year) - Required for generating your ancestral horoscope analysis.
- Time of birth - Used to refine horoscope calculations where provided.
- Gender - Used in certain horoscope calculation parameters.
- Timezone and language preference - Used to localize times and content.
- Notification preferences - Your choices for weekly digest, billing, product-update and push notifications.
- Sign-in identifiers - If you sign in with Apple or Google, we store the unique identifier they provide (Apple user ID / Google user ID) to link your account.
Birth Chart & Family Tree Data
When you generate analyses or build family trees, we may store:
- Birth details - The date, time, gender and (where provided) birth place, including approximate latitude/longitude and timezone used to calculate the chart.
- Ancestor dates (optional) - Your parents' birth dates and, if you choose to provide them, your parents' death dates and your grandparents' birth and death dates. These deepen the ancestral analysis (for example the parent-line gift/challenge sections and the Eight Keys check for a birth falling within a few days of a parent's or grandparent's birth or death date).
- Birth context (optional) - Your birth method (natural, cesarean or induced) and whether you are the firstborn child, used for the corresponding notes in the reading.
- Family member details - Names, relationships and birth details you enter for relatives when building a family tree. You are responsible for having a lawful basis to enter another person's data.
Payment Data
- Stripe customer & subscription ID - Links your account to your Stripe payment profile (web purchases).
- Subscription status - Your current plan type, purchase date and expiration date.
- Billing and invoice records - For web purchases, Stripe collects your billing address (required for VAT) and issues the invoice/receipt. Stripe holds the invoice on our behalf as the payment processor; we hold the corresponding payment, refund and subscription-change records so that we can account for what you were charged.
- App-store purchase receipts - If you make a purchase through the iOS or Android app, we store the Apple or Google purchase receipt details (product ID, transaction/order ID, purchase date, any applicable expiry date and environment) to verify the purchase, prevent duplicate fulfillment and manage access.
Note: Full payment card details are collected and stored exclusively by Stripe, Apple or Google and never touch our servers. Billing and accounting records are kept for the period tax law requires, even after you delete your account - see Data Retention below.
Generated & Content Data
- Horoscope analysis results - The ancestral horoscope calculations generated based on your input data.
- Daily Tarot draws - For signed-in users, we store the local reading date, timezone used for the draw, selected card, upright or reversed orientation and technical deck/selection version against the account so the same result is returned across sessions and devices.
- Chat conversations - Messages exchanged between you and our AI astrologer assistant about your horoscope analysis.
- AI chat memory - A short written summary of your past conversations, generated from your chat history so the assistant can remember context between sessions. It is stored against your account and refreshed as you chat.
- Account journal entries and saved guidance - Journal entries or AI life-guidance questions and answers that you save to an account feature.
- 30-Day Challenge browser notes - Optional challenge notes are stored only in your browser's local storage. They are not collected by Horospire, do not sync to your account, and are not sent when you complete a day. Horospire cannot retrieve or delete them for you.
- Gift readings and messages - If you send a gift reading, the recipient's name and email address and the optional personal message you provide.
- PDF reports - Generated reports based on your horoscope analysis.
Usage Data
- Daily usage counters - We track daily counts of feature usage (chat messages, rewrites, PDF downloads, email sends, analyses, voice narration plays) to enforce fair-use limits. These counters are associated with your user account and reset daily.
- Activity logs - For security and audit purposes we log certain account actions, together with the IP address and (where available) user agent from which they were performed.
Technical & Security Data
- Session cookies - Essential cookies required for the Service to function, including authentication and CSRF protection.
- Login tracking - To help you and us spot suspicious activity, we record your last and previous successful login (timestamp, IP address and user agent) and recent failed login attempts (timestamp and IP address).
- IP address - Stored with analyses and activity logs and used for security, abuse prevention and approximate (country/city-level) geolocation. We send IP addresses to a third-party lookup service (ip-api.com) to detect datacenter/VPN traffic and determine approximate location.
- Push notification tokens - If you enable push notifications in our mobile app, we store the device push token needed to deliver them.
- Usage timestamps - When analyses were created or accessed.
Visitor Data (before you sign up)
Even if you do not have an account, we may record limited information about your visit to understand interest and improve the Service:
- Guest activity - Page views recorded with your session identifier, IP address, user agent, approximate country and the page visited. This server-side tracking is not recorded if your browser sends a "Do Not Track" (DNT) or Global Privacy Control (Sec-GPC) signal, and bot traffic is excluded.
- Guest leads - If you enter your email to view a free reading or receive a follow-up, we store that email together with your session identifier and IP address.
- Guest daily Tarot draw - If you draw without signing in, the card, orientation, reading date and timezone are kept only in an encrypted functional cookie in your browser until the next local day; we do not create an anonymous daily-draw database record.
How We Use Your Information
We use the information we collect for the following purposes:
- To generate and display your ancestral horoscope analysis.
- To provide chat functionality about your horoscope results.
- To generate downloadable PDF reports of your analysis.
- To maintain and manage your user account.
- To save your analysis history so you can return to previous results.
- To process payments and manage your subscription via Stripe.
- To enforce fair-use limits and prevent abuse of the Service.
- To improve and maintain the Service.
The lawful basis for each purpose under Article 6 of the GDPR (consent, contract performance, legitimate interests, and explicit consent for special-category data) is set out on our GDPR Information page.
Third-Party Services
OpenAI API
Our AI features (AI chat, AI rewrites, Life Guidance, Hermetic insight and voice narration) use the OpenAI API to generate conversational responses, interpretations and audio narration about your horoscope analysis. When you use these features, your horoscope calculation results (planetary positions, zodiac signs and derived details such as your approximate age) and your chat messages are sent to OpenAI's servers for processing; voice narration sends only the reading text being narrated. We do not send your name, email address, or other directly identifying account information to OpenAI - only the data necessary for generating astrological interpretations (data minimization principle). OpenAI's use of this data is governed by their own Privacy Policy. We recommend reviewing their policy to understand how they handle data.
Stripe (Payment Processing)
We use Stripe to process payments made on this website. When you make a purchase, your payment information (card details and billing address) is collected and processed directly by Stripe on its own hosted checkout page. We do not store your full card details on our servers; we store your Stripe customer and subscription identifiers, your plan and its dates, and our own record of the payments and refunds on your account. The lawful basis is performance of your purchase contract (Art. 6(1)(b) GDPR) and, for the resulting invoices and accounting records, compliance with our legal obligations (Art. 6(1)(c) GDPR).
Stripe acts as our processor for carrying out the payment, but it also acts as an independent controller of the payment data for its own purposes - fraud prevention and meeting the financial-services and anti-money-laundering obligations it is subject to as a regulated payment institution. Those purposes are governed by Stripe's own Privacy Policy, not by this one.
Apple & Google (Sign-In and App Purchases)
If you sign in with Apple or Google, those providers share a unique account identifier (and, depending on your choices, your name and email) so we can create or link your account. If you subscribe through the iOS or Android app, Apple or Google process the payment and provide us with a purchase receipt that we verify and store. Their handling of your data is governed by Apple's and Google's privacy policies.
Push Notifications (Apple APNs & Google FCM)
If you enable push notifications in our mobile app, we deliver them through Apple Push Notification service (APNs) and Google Firebase Cloud Messaging (FCM), which receive your device push token and the notification content.
Email Delivery
We use a third-party email delivery provider to send transactional and (where you have opted in) marketing emails, which involves sharing your email address with that provider for the purpose of delivery.
Cloudflare & IP Geolocation
Our site is served through Cloudflare, which acts as a content-delivery network and security layer and processes connection metadata (including IP addresses) to protect and accelerate the Service. We also send IP addresses to ip-api.com to determine approximate location and to detect datacenter/VPN traffic for abuse prevention. For maps and place lookups on the website use OpenStreetMap's Nominatim service. In the iOS app, place search uses Apple's MapKit and Local Search. The selected place name, coordinates and timezone are then sent to Horospire to calculate the chart.
Website Analytics & Tracking
These services apply to the horospire.com website only and are not embedded in the current iOS app. Where you accept website cookies via our consent banner, we use the following services, which may set cookies and collect usage data:
- Google Analytics 4 (GA4) - Collects usage data such as pages visited, session duration and general geographic region. Governed by Google's Privacy Policy.
- Microsoft Clarity - Provides heatmaps and session recordings (how visitors move, click and scroll through pages) to help us improve usability. Governed by Microsoft's Privacy Statement.
- Pinterest tag - A conversion-tracking pixel that records certain actions (such as viewing a reading or registering) to measure and improve our Pinterest marketing. Governed by Pinterest's Privacy Policy.
- Meta Pixel - A conversion-tracking pixel that records certain actions (such as calculating a chart, registering or purchasing) to measure and improve our advertising on Instagram and Facebook. Governed by Meta's Privacy Policy.
- TikTok Pixel - A conversion-tracking pixel that records the same kinds of actions to measure and improve our advertising on TikTok. Governed by TikTok's Privacy Policy.
These services only load if you accept cookies via our consent banner. If you decline, they are not activated. We do not sell your personal data or share it with data brokers.
Data Storage and Security
Your account data is stored on our server infrastructure. We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include hashed (not plain-text) password storage, encryption of certain sensitive fields, CSRF protection, optional two-factor authentication, and secure session management.
International Data Transfers
Some of the third-party processors we rely on - including OpenAI, Stripe, Apple, Google, Microsoft (Clarity), Pinterest, Meta and TikTok - are based in the United States, so using the corresponding features may involve transferring personal data outside the European Economic Area. Where this happens, we rely on the safeguards offered by those providers, such as the EU-US Data Privacy Framework and/or Standard Contractual Clauses.
Cookies
We use the following types of cookies:
Essential Cookies (always active)
- Session cookie - Maintains your authenticated session while using the Service.
- CSRF token cookie - Protects against cross-site request forgery attacks.
- hs_tarot_draw_v1 - Encrypted functional cookie that returns the same daily Tarot card to a guest browser and prevents an accidental redraw. It expires at the next local day.
Analytics & Tracking Cookies (only with your consent)
These are only set after you accept cookies via our consent banner:
- _ga / _ga_* - Google Analytics cookies used to distinguish visitors and track sessions.
- Microsoft Clarity (_clck, _clsk and related) - Used for heatmaps and session recordings of how visitors interact with pages.
- Pinterest (_pinterest_ct_* / _pin_unauth and related) - Used by the Pinterest conversion-tracking tag to measure marketing.
Our consent banner lets you accept or decline these analytics and tracking cookies; if you decline, they are not loaded. We do not use other advertising cookies. You can change your choice at any time by clearing your browser's local storage and site cookies, then refreshing the page.
Data Retention
Your account data and horoscope analyses are retained for as long as your account is active. You may delete individual analyses from your dashboard at any time. If you wish to delete your entire account and all associated data, you can do so from your profile settings or by contacting us; step-by-step instructions live on our Account Deletion page. Beyond this, we automatically prune certain operational and security data on a rolling basis:
- Guest activity (visitor page-view tracking) - deleted after about 30 days.
- Guest leads (email/IP captured before sign-up) - deleted after about 90 days.
- Push-notification device tokens that have been inactive for about 90 days - removed.
- Account activity logs - retained for about 365 days; security-relevant entries for up to about 1095 days (3 years).
- Expired login sessions - cleared automatically once they pass the session lifetime.
Daily Tarot draws linked to an account are retained while the account remains active and are deleted when the account is permanently erased. A guest daily-draw cookie expires at the next local day and is not stored as an anonymous draw record on our servers.
Deleted accounts (the legal claims and fraud hold)
When you delete your account it is closed and locked immediately: sign-in stops working on every device and your email address is released for reuse. The account's data is then retained in that locked state for up to 180 days before it is permanently erased. We keep it for this limited period so that we can establish, exercise or defend legal claims, and investigate fraud or abuse connected to the account, if the need arises (Art. 17(3)(e) GDPR; fraud prevention is also a legitimate interest under Art. 6(1)(f)). If a legal claim, chargeback or abuse investigation involving the account is still open when that period runs out, we keep that account's data until the matter is resolved and erase it then. During the hold the data is accessible only to authorised staff, is not used for marketing or any other purpose, and no emails or notifications are sent to you. When the period ends, or sooner if we conclude no review is needed, the data is permanently erased as described on our Account Deletion page.
Billing and accounting records (the exception to deletion)
We are a Lithuanian company and Lithuanian accounting and tax law requires us to keep the accounting record of every sale - the invoice and the payment/refund history behind it - for 10 years. We must keep those records even if you ask us to delete your account, and even if you ask us to erase your data: the law obliges us to retain them (Art. 6(1)(c) and Art. 17(3)(b) GDPR), so a deletion request does not remove them. For web purchases the invoice itself is held by Stripe on our behalf; we hold the corresponding payment, refund and subscription records.
The billing exception is narrow. It covers the financial record of your transactions: not your birth data, not your readings, not your chat history, not your family tree. Those are covered only by the time-limited deleted-accounts hold described above; once that hold ends they are deleted or stripped of the data that identifies you, while the payment records that must remain are unlinked from your deleted account wherever the accounting record does not depend on the link.
Your Rights
You have the right to:
- Access your personal data stored by us.
- Rectify any inaccurate personal data (you can edit your profile directly).
- Request deletion of your personal data (you can delete your account from your profile settings, which scrubs your personal data and removes related records following the limited retention period described under Data Retention). The one exception is the billing and accounting record of your purchases, which the law requires us to keep - see Data Retention.
- Object to, or request restriction of, the processing of your personal data.
- Withdraw your consent (including by declining or clearing analytics cookies, or deleting your account).
- Request portability of your personal data - you can download a copy of your data as a file from your profile settings.
For more details on exercising your rights under GDPR, please visit our GDPR Information page.
Children's Privacy
The Service is not intended for children under 16, and you must be at least 16 years old to use it. We do not knowingly collect personal data from anyone under 16. If we become aware that we have collected personal data from a child under 16, we will delete it promptly. If you believe a child has provided us with personal data, please contact us.
Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this page periodically for any changes.
Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact MB Libranet (company code 306214658, V. Nagevičiaus g. 3, LT-08237 Vilnius, Lithuania) at [email protected] or visit our Contact page.