Legal
Privacy Policy
How Astrummo collects, uses, shares, protects, and deletes personal data across the Android application, website, and support services.
Last updated: 9 September 2026
Astrummo is designed as a privacy-conscious personal astrology service. We do not sell personal data, use it for third-party behavioural advertising, or allow advertising networks to build profiles from your activity in Astrummo.
1. Controller and contact details
The controller responsible for personal data processed through Astrummo is:
MB “Decentralizuotas”
Company code: 304897618
Perkūnkiemio g. 13-91, Vilnius, LT-12114, Lithuania
hello@astrummo.com
2. Scope and age requirement
This Policy applies when you visit astrummo.com, use the Astrummo Android application, register or manage a service-contact email, contact support, request account or data deletion, or otherwise use Astrummo (together, the Service). Third parties such as Google Play operate their own services under separate privacy notices.
Astrummo is intended exclusively for adults aged 18 or older. It is not directed to children or minors.
3. Personal data we process
| Category | Examples | Purpose |
|---|---|---|
| Account and authentication | Manus/OpenID identifier, name, email when supplied, login method, role, account timestamps, and last sign-in | Create and secure your account, maintain sessions, and prevent misuse |
| Birth and profile | Date and exact time of birth, place search, coordinates, timezone, Moon sign, ascendant, nakshatra, and other chart data | Calculate and display your chart and personalised features |
| Ask Astrummo and memory | Questions, relevant context, generated answers, topics, previous concerns, conversation summaries, unresolved questions, and preferences | Answer questions, preserve continuity, and personalise later responses |
| Optional life context | Information you choose to share about career, relationships, wellbeing, finances, recurring concerns, and previous insights | Personalise responses when memory is enabled and relevant |
| Compatibility | Partner birth and profile information entered by you | Generate the compatibility result you request |
| Interpretation usage and controls | Message and processing counts, estimated service cost, subscription state, rate-limit state, and aggregate monthly usage | Apply limits, prevent abuse, operate the Service, and manage costs |
| Subscriptions | Pseudonymous purchase identity, product and entitlement IDs, trial, renewal and expiry state, and cached entitlement | Start, verify, restore, and manage paid access |
| Notifications | Expo push token, platform, timezone, permission and preference state, minimised scheduling data, and delivery status | Send notifications you request at suitable times |
| Optional analytics and diagnostics | Pseudonymous events, app version, app/device context, crash and error data, and limited performance traces | Understand product use and improve reliability, only after opt-in |
| Website and support | Ordinary server logs, IP/network and browser data, pages requested, aggregate Umami analytics, correspondence, and support content | Operate and secure the website, measure aggregate use, and respond to requests |
| Service-contact email | Pseudonymous public contact ID, normalized email, pending/verified/deleted state, hash-only verification and status credentials with expiry, provider delivery metadata, service-consent timestamp, locale, abuse-control metadata, and lifecycle timestamps | Verify an address and send critical outage, security, subscription, and other essential-service notices requested by you |
| Privacy choices | Consent and preference status and update time | Honour and demonstrate your choices |
| Optional marketing or waitlist email | Email address and separate marketing or waitlist consent, confirmation, and unsubscribe records | Send only optional communications requested through a separate opt-in |
Some information is stored locally on your device, including profile data, conversation and memory caches, compatibility information, preferences, progress markers, notification settings, and cached subscription state. Relevant account, profile, memory, usage, and notification information is also stored server-side so the Service can operate across sessions.
Sensitive information
Astrummo is not a medical, therapy, legal, or financial service. Do not provide medical records, diagnoses, government identifiers, payment-card details, passwords, or information unnecessary for an astrology service. If you discuss highly personal matters, they may be included in the context needed to answer your request and, where personalisation memory is enabled, may contribute to future continuity. You can delete conversation memory or request full account deletion at any time.
4. How we obtain personal data
We receive information directly from you when you use an account, enter birth or compatibility data, ask questions, adjust privacy choices, enable notifications, subscribe, register or manage a service-contact email, contact support, or separately opt in to marketing or waitlist updates.
The production sign-in flow uses Manus OAuth. We also receive purchase and entitlement data from Google Play and RevenueCat, optional analytics from PostHog, optional diagnostics from Sentry, notification-delivery data from Expo, and place-search results from OpenStreetMap Nominatim.
5. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Accounts, chart calculation, Ask Astrummo, compatibility, subscription access, and requested features | Performance of a contract or pre-contract steps requested by you |
| Optional app analytics and diagnostics | Consent; these features are off by default and may be disabled |
| Aggregate, cookieless website analytics | Legitimate interests where the privacy-preserving implementation and local law allow; otherwise consent |
| Optional update emails | Consent; you may unsubscribe at any time |
| Requested service-contact email and essential notices | Performance of the requested service and our legitimate interests in security, service continuity, and communicating material operational information; marketing remains separate |
| Notifications you enable | Consent and/or performance of the requested feature |
| Security, fraud and abuse prevention, rate limits, and legal claims | Legitimate interests, balanced against your rights |
| Tax, accounting, consumer-protection, and other mandatory records | Legal obligation |
When we rely on consent, you may withdraw it at any time without affecting processing already carried out lawfully. We do not use calculated or generated interpretations to make legal or similarly significant decisions about you.
6. Astrology calculations and interpretive processing
Deterministic calculations
Core astronomical and Jyotish calculations are produced by Astrummo’s calculation engine using licensed Swiss Ephemeris components and rule-based logic. These calculations are produced independently of the interpretation layer.
Generated explanations
Ask Astrummo uses a tightly constrained interpretation layer supported by artificial intelligence to translate calculated astrology context into natural-language guidance. The server sends structured prompts, relevant chart facts, and relevant conversation or personalisation context through the Manus Forge gateway to a selected hosted language model. We minimise direct identifiers sent for generation and do not intentionally include payment-card or government-identification data.
Generated explanations can be incomplete, inaccurate, or unsuitable for a particular situation. They are for personal insight, reflection, and entertainment—not medical, psychological, legal, financial, or other professional advice.
7. Analytics, diagnostics, and website measurement
App analytics and diagnostics are off by default. If you opt in, Astrummo uses PostHog for selected analytics events and Sentry for crash, error, and limited performance diagnostics. Session replay, automatic capture, screenshots, profiling, failed-request capture, and default personally identifiable information are disabled in the inspected configuration. You may change or reset these choices in the app’s privacy settings.
The website includes platform-provided Umami analytics designed for aggregate, cookieless measurement. Ordinary requests may still expose network and browser metadata needed for delivery and security. Website fonts are delivered through Google Fonts, which receives ordinary request metadata when your browser requests a font file.
8. Notifications, place search, and payments
Notifications
If enabled, Astrummo processes an Expo push token, platform and timezone information, preferences, access state, and minimised chart data needed to plan the notification. You can disable notifications in the app or device settings.
Place-of-birth search
When you search for a place of birth, Astrummo sends the search text to OpenStreetMap Nominatim to obtain settlement and coordinate data. The timezone and historical offset are then calculated using the geo-tz database.
Subscriptions and payments
Android subscriptions are processed through Google Play Billing. RevenueCat validates purchases and maintains Astrummo entitlement status. Astrummo receives purchase and entitlement metadata but does not receive or store your full payment-card details. Price, currency, tax, trial eligibility, billing date, and renewal terms are those displayed by Google Play at checkout.
9. Service providers and recipients
We disclose only data reasonably necessary for each provider’s function. We do not sell or rent personal data.
| Recipient | Function |
|---|---|
| Manus / Manus OAuth / Manus Forge | Infrastructure, authentication, account/session storage, interpretation processing, prompts/context, and generated outputs |
| Google Play | Distribution, billing, subscription management, cancellation, and refund handling |
| RevenueCat | Purchase validation and entitlement management using pseudonymous metadata |
| PostHog | Optional, consented product analytics using selected pseudonymous events and app/device context |
| Sentry | Optional, consented crash/error and limited performance diagnostics with minimisation controls |
| Expo | Push-token registration and notification delivery when enabled |
| OpenStreetMap Nominatim | Place-search text and returned settlement/coordinate data |
| Resend | Delivery of separately managed service-contact verification and essential notices, plus distinct waitlist or optional marketing email where requested |
| Manus-hosted Umami | Aggregate website measurement |
| Google Fonts | Website typeface delivery |
| Advisers and authorities | Limited disclosure where necessary for compliance, security, legal advice, or legal claims |
10. International transfers
Some providers may process data outside Lithuania or the European Economic Area, including in the United States. Where the GDPR applies, transfers take place under a legally recognised mechanism such as an adequacy decision, the European Commission’s Standard Contractual Clauses, or another lawful safeguard. Contact us for information about safeguards relevant to a particular transfer.
11. Retention
| Data | Retention approach |
|---|---|
| Account, birth/profile, and chart data | While the account is active, unless you delete the category or request full deletion |
| Conversation summaries and personalisation memory | While memory is used or the account remains active; selectable memory may be deleted |
| Interpretation usage and anti-abuse records | As reasonably necessary to apply limits, operate the Service, investigate abuse, and manage costs |
| Subscription and entitlement records | As needed for paid access and applicable accounting, tax, refund, fraud, and dispute requirements |
| Notification data | Until disabled or deleted, subject to short-lived technical, delivery, and security records |
| Analytics and diagnostics | Only after opt-in and according to provider settings; opting out stops future collection |
| Support correspondence | As necessary to resolve the request and related security, contractual, or legal issues |
| Unconfirmed update email | Deleted after 48 hours if double opt-in is not completed |
| Confirmed update email | Until you unsubscribe, withdraw consent, or the communication purpose ends |
| Service-contact verification credential | 24 hours; a new request, resend, or email change rotates the active verification credential |
| Pending service-contact record | Until verified, replaced, removed, or no longer reasonably necessary for verification, security, and abuse prevention |
| Verified service-contact record | Until you remove the service email or the essential-contact purpose ends, subject to narrowly limited lawful retention |
| Service-contact abuse and idempotency metadata | For short operational windows reasonably necessary to enforce cooldowns, daily limits, replay protection, security, and dispute handling |
| Local app data | Until deleted in Astrummo, app data is cleared, or the app is uninstalled; uninstalling does not delete server data |
We periodically review whether information remains necessary. Limited records may be kept longer where required by law, subject to a legal hold, needed for a dispute, or necessary to protect the Service.
12. Your choices and rights
Depending on applicable law, you may have rights to information, access, correction, deletion, restriction, objection, portability, and complaint. You may withdraw consent at any time. We generally respond to GDPR requests within one month, subject to lawful extensions and identity verification.
- Change or reset app analytics and diagnostics preferences.
- Disable notifications in Astrummo or device settings.
- Manage essential service contact and optional marketing independently using a private status credential supplied after verification.
- Remove the service-contact email without deleting an Astrummo account or changing the separate waitlist.
- Delete conversation memory or birth/profile data selectively.
- Request full account and associated-data deletion inside the app.
- Use our public Delete My Data page outside the app.
- Email hello@astrummo.com for a privacy request.
You may complain to the Lithuanian State Data Protection Inspectorate or the supervisory authority in your habitual EU/EEA residence, place of work, or place of the alleged infringement.
13. Account and data deletion
Full deletion is designed to remove Astrummo-controlled records associated with your authenticated and pseudonymous identifiers, including the account record, birth/profile memory, long-term life memory, conversation summaries, per-user interpretation usage, notification profiles and deliveries, development-trial records where applicable, and associated interpretation-content reports. Astrummo-owned local storage, authentication state, notification data, analytics identity, RevenueCat identity, and diagnostics state are also cleared.
Deletion may not remove data controlled independently by Google Play, RevenueCat, or another provider. You must cancel Google Play subscriptions separately. Cancelling a subscription does not delete your account, and deleting your account does not cancel a subscription. Narrowly limited records may be retained where lawfully required.
The service-contact subsystem is separate from the waitlist and from any app account. A holder of the private status credential may remove the service-contact email and independently enable or withdraw marketing consent at Service-contact preferences. The page never displays the stored email address.
14. Automated processing, security, and adults only
Astrummo automatically calculates astrology factors and may generate personalised explanations, categories, reminders, and recommendations. These outputs do not determine eligibility for employment, credit, insurance, housing, education, healthcare, public benefits, or another legal or similarly significant decision.
We use reasonable technical and organisational measures such as authenticated sessions, pseudonymous identifiers, minimisation, opt-in analytics and diagnostics, redaction controls, access restrictions, and deletion tools. No system can guarantee absolute security.
We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided personal data, contact us so we can investigate and delete it where appropriate.
15. Changes and contact
We may update this Policy to reflect changes in the Service, providers, law, or data practices. We will update the date above and provide additional notice where a change materially affects your rights or our use of personal data. Where required, we will request fresh consent.
Questions, requests, and complaints may be sent to hello@astrummo.com or MB “Decentralizuotas”, Perkūnkiemio g. 13-91, Vilnius, LT-12114, Lithuania.