Legal
Privacy Policy
Last updated: March 2026
Arctara ("we," "our," or "us") is operated by Michelle Jennifer Pereira Costa,
Albert-Schweitzer-Str. 5, 35781 Weilburg, Germany.
Contact: [email protected]
This Privacy Policy explains how we collect, use, store, and protect your personal
data when you use the Arctara mobile application and website (arctara.app).
By using Arctara, you agree to this policy.
1. Data We Collect
Information you provide directly:
- Email address — for account creation and login
- Password — stored encrypted, never readable by us
- Username and optional profile photo
- Birth date, birth time, and birth location — for astrological calculations
- Cabinet data — your personal collection of crystals, herbs, and tools
- Grimoire entries — spells, rituals, and notes you write
Automatically collected information:
- Device type, operating system, and app version
- App usage data — features used, session duration, performance
- Location — only for birth chart calculations, stored locally on your device
2. How We Use Your Data
- To provide accurate astrological and astronomical calculations
- To save and sync your grimoire, cabinet, and spell history
- To authenticate your account securely
- To improve app functionality and fix errors
- To send important service updates (not marketing, unless you opt in)
We will never sell your personal data to third parties.
3. Third-Party Services
- Supabase — secure cloud storage and authentication (privacy policy)
- Expo — app delivery and updates (privacy policy)
- Swiss Ephemeris — astronomical calculations, runs entirely offline
- Free Astrology API — birth chart calculations. Your birth date, birth time, and birth location are transmitted to this service to generate astrological data. No data is stored by this service beyond the duration of the calculation.
- Cloudflare — infrastructure, content delivery, and DDoS protection for the arctara.app website. Cloudflare may process IP addresses and traffic data as part of this service (privacy policy)
4. Data Storage and Security
- Your data is stored on Supabase servers using industry-standard encryption
- Passwords are hashed and never stored in plain text
- Some preferences are stored locally on your device
- We use HTTPS for all data transmission
5. Your Rights (GDPR)
As a user, you have the right to:
- Access — request a copy of your personal data (Art. 15 GDPR)
- Rectification — correct inaccurate data (Art. 16 GDPR)
- Deletion — request deletion of your account and all data (Art. 17 GDPR)
- Restriction — limit how we process your data (Art. 18 GDPR)
- Portability — receive your data in a portable format (Art. 20 GDPR)
- Objection — object to processing (Art. 21 GDPR)
- Withdraw consent — at any time, without affecting prior processing
6. Data Deletion
To request deletion of your account and all associated personal data,
email us at [email protected]
with the subject line "Data Deletion Request".
We will permanently delete your data within 30 days of receiving your request.
Backup copies are deleted within 90 days.
7. Data Retention
- Active accounts — data retained while your account is active
- Deleted accounts — data permanently deleted within 30 days
- Backup copies — deleted within 90 days
8. Children's Privacy
Arctara is not intended for users under 13 years of age.
We do not knowingly collect personal information from children under 13.
If you believe a child has provided us with personal data, contact us immediately
at [email protected].
9. Cookies and Tracking
The Arctara mobile app does not use cookies or third-party advertising trackers.
The arctara.app website does not use tracking cookies or analytics tools that
identify individual users.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The current version is always
available at arctara.app/privacy.
Significant changes will be communicated via email or in-app notification.
11. Contact and Complaints
For any questions or requests regarding your personal data:
Email: [email protected]
Website: arctara.app
You also have the right to lodge a complaint with the supervisory authority
in Hessen, Germany:
Hessischer Beauftragter für Datenschutz und Informationsfreiheit
.
Governed by the laws of the Federal Republic of Germany.
Place of jurisdiction: Weilburg, Germany.