Privacy Policy
1. Who We Are
STARCHAN is operated by STARCHAN LLC. We are the data controller for personal data collected through this website. For privacy-related questions, contact: privacy@starchan.ai.
2. Data We Collect
We collect the following categories of personal data:
- Account data: Email address, username, hashed password, account creation date
- Profile data (optional): Bio text, avatar image, astrologer badge preference
- Subscription data: Stripe customer ID, subscription tier, subscription status, billing period dates
- Forum data: Posts, threads, uploaded images, report submissions you make
- Astrology data (optional, sensitive): Birth date, birth time, and precise birth location (latitude/longitude and location label) — collected only if you use chart calculation features and only with your opt-in consent (see Section 11a)
- Technical data: IP address (for rate limiting and abuse prevention) and browser user-agent (in server logs). Each forum post and thread you create also records the IP address and browser user-agent it was made from — see Section 8 for how long we keep this
- Refund-abuse-prevention data (only if you request a refund): a one-way cryptographic hash of your payment method's Stripe fingerprint (for example a card, bank account, or Cash App identifier) and a separate one-way (salted) hash of the IP address from which the refund was requested — retained to enforce our money-back guarantee limits (see Section 8)
3. How We Use Your Data
We use personal data only to:
- Provide and maintain your account
- Process subscription payments via Stripe
- Display your posts and profile on the platform
- Calculate and save astrological charts (if you use chart features)
- Enforce community guidelines and moderate content
- Send notification digests (if you have opted in)
- Prevent abuse and enforce rate limiting
We collect only what we need for these purposes and do not repurpose your data for advertising, profiling, or any secondary use.
4. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA) and UK, where applicable, we process personal data under the following legal bases:
- Contract performance (Article 6(1)(b)): Account data, subscription data, and forum posts are processed to provide the service you signed up for.
- Legitimate interest (Article 6(1)(f)): Technical data (IP address, user-agent) is processed for security, rate limiting, and abuse prevention.
- Consent (Article 6(1)(a)): Birth chart data is collected only with your explicit, opt-in consent and used solely for chart calculation. You may withdraw consent and delete all saved charts at any time from your account settings.
5. Payment Processing — Stripe
We use Stripe, Inc. to process payments. Stripe may collect personal data, including via cookies and similar technologies, such as transactional data and identifying information about the devices that connect to its services. Stripe uses this information to operate and improve its services, including for fraud detection and prevention, authentication, and analytics related to the performance of its services.
STARCHAN never receives or stores your full payment card details. See Stripe's Privacy Policy. Stripe never receives your birth data.
6. Third Parties and Data Sharing
STARCHAN does not sell, rent, or share your personal data with third parties for advertising or marketing purposes, and we do not share data for cross-context behavioral (“targeted”) advertising or for profiling.
Birth data is never shared with any third party for any purpose. Your birth date, birth time, birth coordinates, birth location label, and computed chart data are stored encrypted at rest (see Section 11) and are not transmitted to advertising networks, analytics providers, data brokers, AI training datasets, or any other external service. This restriction is absolute and is not waived by the general service-provider terms below.
We do not load third-party advertising or behavioral tracking pixels — including Meta/Facebook Pixel, TikTok Pixel, Google Tag Manager with user-keyed events, Hotjar, Microsoft Clarity, or LinkedIn Insight Tag — on any page of the Service.
The only third parties that ever receive non-birth-data personal information from us are service providers strictly necessary to operate the Service, acting under contract and only for the purposes below:
- Stripe, Inc. — payment processing (see Section 5). Stripe never receives birth data.
- Our hosting and transactional email providers — to run the Service and send account emails (such as verification, password reset, and receipts). Email content never contains birth data.
- Law enforcement or other parties — only when required by applicable law or valid legal process.
We do not currently use any third-party or behavioral website analytics. If we adopt analytics in the future, we will use only a privacy-preserving, cookieless, aggregate-only solution that collects no personally identifiable information and performs no cross-site tracking, and we will update this policy before doing so.
7. Cookies, Tracking, and Browser Storage
STARCHAN stores authentication tokens in your browser's localStorage to keep you logged in. This storage is strictly necessary to provide the Service. It is not used for tracking or advertising and is not shared with third parties.
- Access tokens expire after 15 minutes
- Refresh tokens expire after 7 days
You can clear this data at any time by logging out. We also store your theme preference (light/dark mode) in localStorage.
We do not use advertising cookies, tracking cookies, or any cookies that would require a consent banner under ePrivacy Directive Article 5(3). Because we do not sell or share personal data or use targeted advertising, there is nothing to opt out of; however, we honor browser-based opt-out preference signals such as Global Privacy Control (GPC) as a valid opt-out request where applicable.
8. Data Retention
- Account data: Retained until you delete your account
- Posts and threads: Retained indefinitely; anonymized (author removed) upon account deletion, not deleted. The IP address and browser user-agent recorded with each post are retained for as long as the post exists — including after account deletion — so we can investigate abuse and meet child-safety evidence and reporting obligations (18 U.S.C. § 2258A). They are never displayed publicly
- Uploaded images: Retained until the associated post is deleted by a moderator
- Subscription data: Retained for the duration of your subscription plus 90 days for billing-dispute resolution
- Refund-abuse-prevention data: When a refund is issued under our money-back guarantee, we retain a one-way cryptographic hash of the payment method's Stripe fingerprint (card, bank account, or similar identifier), solely to enforce our one-refund-per-account-and-per-payment-method limit and to detect repeat-refund abuse. Because this fingerprint hash exists to prevent fraud, it is retained on an ongoing basis and is not erased when you delete your account or submit a deletion request. It contains no card or account number and cannot be reversed. Apart from the retained items disclosed elsewhere in this policy (anonymized posts and their recorded technical data, correspondence on legal hold, and billing records kept for dispute resolution), this fraud-prevention data is the only personal data that survives account deletion, and we keep only the minimum needed for this purpose. Separately, we retain a salted one-way hash of the IP address from which the refund was requested for up to 90 days as a short-term abuse tripwire; that IP hash is automatically deleted after 90 days and is removed if you delete your account.
- Server logs (IP, user-agent): Retained for 30 days and then deleted
- Saved charts and birth data: Retained only while you have active consent on file; deleted when you delete the chart, revoke consent, or close your account (see Section 11a)
9. Your Rights
Depending on where you live, you may have some or all of the following rights regarding your personal data:
- Access / know what personal data we hold about you
- Correct inaccurate data
- Delete your data ("right to be forgotten")
- Portability — receive a copy in a machine-readable format
- Restrict or object to certain processing
- Opt out of any sale, sharing, or targeted advertising (note: we do none of these)
- Withdraw consent for birth chart data at any time
- Appeal a denied request (see below)
These rights are subject to the narrow exceptions permitted by law. In particular, if you have used our money-back guarantee, we retain a one-way payment-method-fingerprint hash (and, for up to 90 days, a salted one-way hash of the refund-request IP) to prevent refund abuse (see Section 8); we retain the technical data recorded with anonymized posts (see Section 8); and we retain correspondence placed on legal hold. Where such an exception applies, we will tell you what we kept and why.
To exercise any of these rights, contact us at privacy@starchan.ai. We will respond within 45 days (and within one month for requests made under the GDPR), and we may extend that period once where permitted by law, with notice to you. You may also exercise several of these rights directly in your account settings (chart deletion, consent revocation, and account deletion).
Appeals. If we deny your request, we will explain why and tell you how to appeal. To appeal, reply to our decision or email privacy@starchan.ai with the word “Appeal.” If we deny your appeal, you may contact your state Attorney General.
California residents (CCPA/CPRA): You have the right to know, delete, and correct your personal information, to opt out of the sale or sharing of personal information, and to limit the use of sensitive personal information. STARCHAN does not sell or share personal information and does not use sensitive personal information for any purpose other than providing the Service you requested. We will not discriminate against you for exercising your rights.
Residents of any U.S. state with a comprehensive privacy law (including California, Virginia, Colorado, Connecticut, Texas, Oregon, Montana, Indiana, Kentucky, Rhode Island, and others as such laws take effect): You have the rights listed above, including the right to appeal, as provided by your state's privacy law. Your precise birth location is sensitive personal information under these laws, so we collect it only with your opt-in consent and use it solely to provide the Service (see Section 11a).
Verifying your request. To protect your data, we verify rights requests against the account email we have on file. An authorized agent may submit a request on your behalf with your written permission, and we may ask the agent to provide proof of that authorization.
10. Children's Privacy
STARCHAN is intended for adults and is not directed to children. We do not knowingly collect personal data from children under the age of 13. If you believe a child under 13 has created an account or provided us with personal data, please contact us immediately and we will delete it promptly.
11. Security Measures
We implement reasonable and appropriate technical measures, including:
- bcrypt password hashing with individual salts
- HTTPS encryption for all data in transit
- Encryption at rest for all birth data. Each saved chart's birth date, birth time (UTC), birth latitude, birth longitude, birth location label, and computed chart payload (
chart_json) is individually encrypted using authenticated encryption (Fernet: AES-128-CBC for confidentiality plus HMAC-SHA-256 for integrity, with a fresh random initialization vector per encryption) before being written to the database. The encryption key is managed separately (via SOPS + age) and is never stored alongside the database. A database breach therefore exposes ciphertext only — not your birth data. - Short-lived JWT access tokens (15 minutes) with refresh-token rotation
- Rate limiting on authentication endpoints to mitigate brute-force attacks
- Content Security Policy headers to mitigate cross-site scripting
No system is 100% secure, and we cannot guarantee absolute security; however, we take reasonable and appropriate measures to protect your data.
11a. Birth-Data Consent & Revocation
What we collect: If you choose to save astrological charts, STARCHAN stores your birth date, birth time (when known), birth latitude and longitude (to street-level accuracy), birth timezone (IANA identifier), and any computed chart payload (chart_json) that your client generates. Birth time is stored as NULL when not known — we never substitute a fake noon value to disguise unknown-time charts.
How we secure it: Every birth-data column on every saved chart is individually encrypted at rest using Fernet (AES-128-CBC + HMAC-SHA-256) with a fresh random initialization vector per encryption (see Section 11). The encryption key is managed via SOPS + age and is never co-located with the database. A database breach exposes ciphertext only.
Why we collect it: Birth date, time, and location are mathematically required to compute any astrological chart — ascendant, house cusps, dasha boundaries, divisional charts, and transits all depend on them. We do not collect this data for any other purpose, and we do not derive secondary data products from it.
No third-party sharing — absolute: Your birth data is never transmitted to advertising networks, analytics providers, data brokers, AI training datasets, or any other external service. This restriction is not waived by our general data-sharing terms in Section 6. The pages on which birth data is collected, displayed, or stored never load Facebook Pixel, Google Tag Manager, TikTok Pixel, Hotjar, Microsoft Clarity, LinkedIn Insight Tag, or any equivalent tracking technology.
Consent at collection (just-in-time): Because your precise birth location is treated as sensitive data under U.S. state privacy laws, we collect it only with your explicit, opt-in consent, requested at the moment it first becomes relevant. You can register and use STARCHAN's forum without ever providing birth data. The first time you attempt to save an astrological chart, we ask you to grant a discrete, opt-in consent — “I consent to STARCHAN storing my precise birth location, encrypted at rest, never sold or shared with third parties.” — before any birth location is stored; until you grant it, chart saving is declined. You can review, grant, or revoke this consent at any time in Account → Privacy.
Revocation: You may revoke birth-data consent at any time from Account → Privacy. Revocation has the following effects, applied immediately and without further confirmation:
- All birth-data columns on every chart you own are set to NULL (birth date, birth time, timezone, latitude, longitude, location label, and computed chart payload).
- Each affected chart is tombstoned (
deleted_atset to the revocation timestamp) and disappears from your active chart list. Non-PII metadata such as the chart name and creation timestamp is preserved for our internal audit log. - Future attempts to save a new chart return a 403 error from our API until you grant consent again.
Revocation is destructive. Tombstoned charts cannot be recovered — granting consent again does not restore them.
Retention: Birth data is retained only while you have active consent on file. Revoking consent or deleting your account removes it under the rules above. We do not perform any background expiry of birth data — consent is the sole gating condition.
11b. Data Breach Notification
If we become aware of a security breach that compromises your personal data, we will notify affected users and any applicable regulators without undue delay and within the shortest deadline required by applicable law. We will describe, to the extent known, what happened, the categories of data involved, the steps we are taking, and what you can do to protect yourself.
We comply with all applicable U.S. state breach-notification laws (several of which require notice within 30 days of discovery) and, where it applies to us, the FTC Health Breach Notification Rule (which can require notice to affected individuals and the FTC within 60 days). Because birth date, birth time, and precise location can be treated as health-adjacent or sensitive data, we apply these protections to that data regardless of which specific statute is triggered.
[ATTORNEY: confirm] — Confirm whether the FTC Health Breach Notification Rule applies to this service and finalize the exact notification deadlines and recipient regulators for the states where we have users.
12. International Users
STARCHAN is operated in the United States and is intended for users located in the United States. We do not target or direct the Service to residents of the European Economic Area, the United Kingdom, or other jurisdictions outside the United States. If you access the Service from outside the United States, you do so on your own initiative and are responsible for compliance with local law, and you understand that your data will be processed in the United States.
[ATTORNEY: confirm] — If you intend to knowingly serve EU/EEA or UK users, GDPR likely applies regardless of company size and may require an Article 27 EU representative and a data-processing review. The cheapest pre-revenue path is to keep the “US-only” posture above (and consider a geo-block at signup). Confirm this scoping decision before marketing to or accepting EU users.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated “Last Updated” date. For material changes, we will make reasonable efforts to notify registered users by email or by a notice on the platform. Continued use of the Service after changes are posted constitutes your acceptance of the updated policy.
14. Contact and Privacy Requests
For privacy-related questions or requests: privacy@starchan.ai
For general inquiries: hello@starchan.ai
For abuse reports: abuse@starchan.ai
15. Inbound Communications
When you email one of our addresses — hello@starchan.ai, support@starchan.ai, privacy@starchan.ai, dmca@starchan.ai, or abuse@starchan.ai — we store the message and any attachments in order to read it, route it to the right person, and respond. The content of those emails is personal data and we treat it as such.
Encrypted at rest: The sender address and name, subject line, message body, and any AI-generated routing summary are individually encrypted at rest using the same authenticated encryption we use for birth data (Fernet: AES-128-CBC + HMAC-SHA-256, with a fresh random initialization vector per encryption; see Section 11). The encryption key is managed separately and is never stored alongside the database. Attachments are stored outside any web-served directory and are never publicly accessible.
Automated triage: To help one person manage incoming mail, an automated classifier reviews each message the moment it arrives and labels it (for example: urgent, routine support, thank-you, or likely spam/abuse) so that important and time-sensitive mail is surfaced and abusive mail is filtered out of the default view. This classification is performed by an AI service acting solely as a data processor for routing purposes. We do not use inbound email — or the results of this triage — for advertising, profiling, ad targeting, or sale to any third party, and we do not share it with advertising networks, analytics providers, or data brokers. The same no-tracking restrictions described in Section 11a apply to the systems that handle your correspondence.
Retention: Inbound mail is kept only as long as needed and is then automatically deleted on a documented schedule based on its type: routine support and general inquiries are retained for about 90 days after they are handled; thank-you/feedback mail for about 180 days; messages filtered as spam for about 30 days; and mail we filter as abusive or harassing is kept for about 90 days as evidence of a pattern. Correspondence connected to a legal matter, a copyright (DMCA) notice, a privacy request, a child-safety or intimate-imagery report, a credible threat, or an open dispute is placed on legal hold and retained for as long as the matter is active or the law requires, rather than being auto-deleted. A scheduled process performs the deletions and is built so that anything on legal hold is never purged.
Your rights cover this mail too: Emails you have sent us are included in the access and deletion rights described in Section 9. If you ask us to delete your data, we will erase your stored correspondence except where a specific message must be retained for an active legal claim, a legal obligation, or an open dispute — in which case we will tell you what was kept and why. We locate your messages using an irreversible hash of your email address, so we can find and act on your data without decrypting unrelated correspondence. To make a request, contact privacy@starchan.ai.
For DMCA copyright notices and data-subject (privacy) requests, our system sends an automated acknowledgement confirming receipt; all substantive responses are written and reviewed by a person.
[ATTORNEY: confirm] — Confirm the inbound-email retention periods (90/180/30 days) against applicable state-law disclosure requirements, and confirm that the AI-triage processor disclosure and data-processing terms are adequate for your processor agreement.