AstroAPI Privacy Policy
This Privacy Policy explains the information AstroAPI processes when you visit the website, create an account, manage an API key, submit a calculation request, contact support, or—once billing is enabled—manage a subscription. It also describes current data limitations that are still being formalized before paid billing launches.
Information we process
Account and authentication data
We process your name, email address, password hash, email-verification status, account plan, account timestamps, and login timestamps. Passwords are transformed using a one-way password hash; AstroAPI does not store the plaintext password. API keys, dashboard session identifiers, email-verification tokens, and password-reset tokens are also stored only as one-way hashes where the application needs to recognize them later.
Usage and operational data
The application records the API endpoint, request time, response status, response duration, whether a request was billable, and the number of usage units. Web-server and security logs may also contain an IP address, requested URL, browser user agent, referring origin, timestamp, and error information. We do not intentionally place passwords, raw API keys, or calculation request bodies in those logs.
Calculation inputs
Calculation requests can contain a birth date, birth time, timezone, latitude, longitude, requested transit date or time, zodiac choice, ayanamsa, and other documented calculation parameters. The calculation service processes those values to return a result. The current application database does not intentionally persist request bodies or calculated chart results. Usage metadata described above is recorded separately.
Support and email data
If you contact support, we process the address, message, and related account details you provide. Verification, reset, password-change, and account-deletion emails are queued in encrypted application payloads until delivery is attempted. Successfully delivered queue records are deleted.
Billing data
Paid billing is currently disabled. When it is enabled, Stripe will process payment-card and billing details on its hosted pages. AstroAPI is designed to retain Stripe customer, subscription, price, status, billing-period, and signed-event identifiers rather than complete card numbers. Stripe's own privacy notice and retention duties apply to information it processes.
Why we process information
Information is used to create and secure accounts, verify email ownership, authenticate requests, perform requested calculations, enforce plan and abuse limits, report usage, deliver operational messages, provide support, investigate errors and security events, maintain the Service, comply with law, and establish or defend legal claims. When paid billing is enabled, information will also be used to administer subscriptions and reconcile verified billing events.
Providers and disclosures
AstroAPI uses providers that process information for defined service functions:
- Amazon Web Services (AWS) for application, database, backup, networking, and related infrastructure.
- Cloudflare Turnstile for bot and abuse checks. A verification token and network information, including IP address, can be sent to Cloudflare.
- Google Workspace for transactional email delivery and support email.
- Stripe for hosted checkout, payment processing, subscription management, and billing events when paid billing is enabled.
We may also disclose information when required by law, to protect users or the Service, in a business transfer subject to appropriate safeguards, or at your direction. AstroAPI does not currently sell personal information or use it for cross-context behavioral advertising.
Cookies and browser storage
AstroAPI uses a secure account-session cookie for signed-in dashboard access. Cloudflare Turnstile may use browser or device signals needed for abuse prevention. The current site does not intentionally deploy an advertising analytics tracker. If analytics, advertising, or additional non-essential cookies are introduced, this notice and any required consent controls must be updated before deployment.
Retention and deletion
Account records are retained while the account exists. Session, verification, and reset records expire or are revoked according to their security purpose. Deleting an account removes the user row and dependent API-key, session, verification, reset, and current quota records. Historical usage rows are retained without the deleted user identifier. The designated owner account must transfer ownership before it can use self-service deletion. Infrastructure backups expire according to the configured backup schedule, and Stripe may retain transaction records under its own legal obligations.
Permanently failed email-queue records are removed by a bounded cleanup job after seven days. Fixed deletion periods for historical usage rows, Stripe event records, and web-server logs are still being approved. Until that schedule is published, those records are limited to operational, security, billing, and legal purposes and should not be retained indefinitely. You may ask about the current schedule at the address below.
Your choices and rights
You can review basic account and usage information in the dashboard, revoke an API key, and use the account-deletion control. You may also ask to access, correct, or delete personal information, or object to or restrict processing where applicable law provides that right. We may need to verify the request and may retain information when law or security requires it. Authorized agents should identify their authority when making a request.
Third-party birth data
Customers control the purposes for which they submit another person's birth information. Customers are responsible for giving their own users an appropriate privacy notice, obtaining any required permission or other lawful basis, minimizing data, and complying with deletion requests. Contact AstroAPI before using the Service for regulated data or if a data-processing agreement is required; no public DPA is currently offered.
International processing and children
AstroAPI and its providers may process information in the United States and other locations where those providers operate. The Service is intended for developers who can form a binding contract and is not directed to children. Do not create a child account or submit children's personal information unless your use is lawful and appropriate safeguards are in place.
Security
AstroAPI uses measures including encrypted transport, one-way credential hashing, restricted service boundaries, request limits, and controlled access. No internet service is completely secure. If you believe an account or API key is compromised, revoke the key where possible and contact us.
Changes to this Policy
The effective date above identifies this version. Material changes will be posted here and, when reasonably practicable, communicated through account email or the dashboard before they apply.
Contact
Privacy questions or rights requests may be sent to support@astroapi.io. The formal legal operator identity and postal privacy-contact address have not yet been approved for publication and must be completed before paid billing is enabled.