Privacy Policy
Effective: August 30, 2026
Scope and platform boundaries
This policy applies to the Augurine website at augurine.com, the native Augurine app for iOS, and the shared account and server services used by both. One Augurine account can be used on both platforms. Website cookies and browser storage apply only to the website. StoreKit, Apple Push Notification service, widgets, and protected device storage apply only to the native iOS app. Subscription handling depends on where the purchase was made: Apple manages App Store billing, while Stripe processes purchases made on augurine.com.
1. Shared account and service data
The following categories can be stored or processed for the same account whether you use the website, the iOS app, or both:
- Account identity: email address, authentication provider, provider identity metadata, account timestamps, and a protected password hash when password sign-in is used. Google can provide a name and email when you choose Google sign-in. Apple can provide an email and provider identity when you choose Apple sign-in. The reviewed native Apple path does not persist the full name requested by Apple's authorization interface. Augurine does not receive the password for either provider account.
- Birth and chart data: birth date, optional birth time, time confidence or uncertainty, birth city, coordinates, timezone, house and tradition settings, calculated chart placements, and generated readings.
- Private content: journal ratings and text, emotion or domain tags, Witness Marks, chapter memories and questions, calibration responses, Predict questions, and related dates or astrological context that you choose to save.
- People and relationships: names or labels, birth details for people you add, relationship periods, permission records, compatibility inputs, and relationship readings. You are responsible for having a valid basis to provide another person's information.
- Professional client records: birth data, birth time provenance, chart settings, permission basis, and derived chart geometry for clients a practitioner adds to the private client workspace.
- Places and routes: place names, exact coordinates, timezones, residency periods, route stops, practical priorities, notes, calculation receipts, Place Dossier readings, private evidence, and sharing choices.
- Service records: feature preferences, completion state, notification preferences, generated content caches, calculation provenance, entitlement state, credit history, rate limit state, and bounded operational records used to deliver and protect the service.
- Billing linkage: billing provider, plan, subscription status, provider customer or transaction references, renewal or expiry state, and refund or dispute observations. Augurine does not store complete payment card numbers.
A professional client record belongs to the practitioner's account and is visible only to that practitioner in the workspace. The practitioner can export or permanently delete each client record. Practitioners are responsible for an appropriate basis for holding a client's data, including permission from a parent or guardian when the client is a minor and applicable law requires it.
2. Website-only data
- Browser storage: authentication cookies, cookie preference, account-scoped deletion recovery state, rectification drafts, saved tool locations, Replay guidance state, temporary Predict or Timing prefill, conversion handoff state, and user interface receipts.
- Website analytics and measurement: page or feature activity, browser and campaign context, a pseudonymous account identifier for signed-in product analytics, and consented conversion events. Google enhanced conversions can receive an email normalized and hashed by the Google tag. Meta conversion matching can receive a SHA-256 email digest, IP address, user agent, and Meta browser or click identifiers. Providers can also receive ordinary network data.
- Website diagnostics: errors, redacted logs, stack traces, route and release context, performance traces, and a one-way pseudonymous account correlation identifier in Sentry. When website PostHog collection is enabled, PostHog also captures unhandled browser exceptions and promise rejections after the application redaction pass. Website Sentry session replay is disabled.
- Website analytics storage: after PostHog is allowed to initialize, its browser SDK can keep pseudonymous device and session identifiers, attribution, consent or opt out state, and queued analytics or exception events in local storage and cookies. The reviewed SDK defaults include a browser cookie that can last for 365 days.
- Web push: if website push is offered and you enable it, the service stores the browser push endpoint, public encryption keys, account link, and use timestamps needed for delivery.
- Website payments: Stripe receives the payment and billing details required to process a purchase on augurine.com. Augurine stores Stripe customer and subscription references plus account entitlement state.
3. iOS-only data
- StoreKit billing: product identifiers, purchase and restoration results, transaction state, original transaction linkage, environment, and an account token used to reconcile App Store access with your Augurine account. Apple retains App Store purchase history.
- Remote notifications: when enabled, an APNs device token, random installation identifier, permission disposition, account binding, category preferences, notification records, and delivery attempts. Apple processes delivery through APNs.
- Local notifications: reminder identifiers, scheduled times, categories, routes, and delivered notification state held by iOS on the device.
- Protected local state: session credentials, account deletion recovery state, Apple sign-in mapping, notification consent state, password recovery ownership, and account-scoped experience state in Keychain. Protected, backup-excluded files can cache Today, Chart, Timing, Replay, calibration, Sky Record, and onboarding data for local use.
- Widgets: an App Group file can contain a Today headline, date, timezone, lunar context, chapter date, optional coordinates, and planetary hour. Separate protected owner state links the widget data to the correct account.
- Native analytics: Augurine sends reviewed PostHog events for app launch, authentication outcome, onboarding, Premium gates, App Store purchase state, and notification choices or opens. These events use the Augurine account identifier after sign-in. Automatic screen capture, tap capture, session replay, surveys, and automatic error capture are disabled in the native analytics configuration. The PostHog SDK also maintains a persistent pseudonymous device identifier, identity state, and an offline file queue for reviewed events, and it receives ordinary device and network context. During local sign out, account change, or completed deletion, the app closes the SDK and removes its exact project directory before analytics can start again. A recreated directory uses iOS data protection and is excluded from backup. This local cleanup cannot recall an event already being uploaded, and another offline device cleans its own copy only after it observes the account end. Depending on the production PostHog GeoIP setting, an IP address can be used to derive coarse location.
- Apple diagnostics: depending on your device analytics settings and Apple's controls, Apple can make crash, hang, launch, disk, device model, operating system, and stack diagnostics available for the iOS app. Augurine does not send those diagnostic payloads to PostHog, where automatic error capture is disabled.
- Device motion: when motion effects are available, the app reads device attitude to add subtle visual depth to the night sky. The reviewed native source processes these readings on the device and does not store or transmit them.
- Transient network data: authenticated request and response data is handled in ephemeral URL sessions without a persistent URL cache or cookie store. The Cloudflare bot challenge uses a nonpersistent web view limited to the challenge lifetime.
4. How we use information
- Authenticate accounts and keep sessions separate
- Calculate charts, timing, place factors, and forecasts
- Provide saved readings, private records, exports available within individual features, and account recovery
- Reconcile Premium access with the correct billing provider
- Deliver email, web push, APNs, widget, or local notification features you enable
- Protect the service through abuse controls, diagnostics, and security review
- Measure product use and consented marketing conversions
If you are in the United Kingdom or the European Economic Area, we rely on these legal bases. Performing our contract with you covers running your account, calculating your charts and timing, and reconciling Premium access. Your consent covers marketing measurement cookies and sending your data to OpenAI for personalized interpretation, and you can withdraw either at any time. Our legitimate interest in a secure, working service covers abuse prevention, diagnostics, and security review. Where the law requires it, we rely on legal obligation.
5. Personal data and OpenAI
Some personalized interpretation and synthesis features use OpenAI through Augurine's shared server services. Depending on the feature, inputs can include birth details, computed placements, daily activation context, partner birth data, timing context, selected timezone, derived location factors, the life event and milestone labels you wrote and the dates you gave them, and portions of readings already generated for you that are reused as context. Astrocartography reading requests omit the selected place name and exact coordinates, though derived factors can still convey approximate location context; a relocation reading includes the place label you chose. Every OpenAI generation begins with an explicit action you take in the interface, such as a generate, compose, write, or tailor control. Opening or refreshing a page shows cached or deterministic content only.
Predict uses deterministic rules and does not send new Predict questions to OpenAI. Predict records created before July 2026 can retain narration generated by an earlier system. Place Dossier static readings and blind calibration also do not call OpenAI.
OpenAI states that API inputs and outputs are not used to train its models by default unless the customer opts in. Its default abuse monitoring logs can contain prompts and responses and can be retained for up to 30 days, or longer when law requires it. Stricter retention controls apply only to eligible accounts that OpenAI has approved and the account has enabled. This policy does not rely on a stricter retention setting. Database deletion does not by itself delete provider-held request data.
We keep your AI permission decisions, including grants, refusals, and withdrawals, together with a short-lived log of provider request identifiers used to trace and reconcile generations. Request identifiers are removed after 90 days. Both are deleted when your account is deleted.
6. Service providers and disclosures
Augurine does not sell or rent birth data, journal content, or other private account content. The following providers process data for the stated service purpose:
- Supabase: authentication, PostgreSQL hosting, and shared account services
- Vercel: website, server, edge hosting, and request logs
- PostHog: website and native product analytics, website exception capture after redaction, account linked events, a persistent pseudonymous native device identifier, and possible coarse location derived from IP address
- Sentry: website error, log, and performance monitoring after application redaction
- Google, Meta, and Ahrefs: website analytics, campaign measurement, or consented conversion reporting
- Cloudflare Turnstile: signup and sign-in abuse prevention using challenge and network context
- Resend: transactional and digest email delivery using recipient and message content
- OpenStreetMap Nominatim: place search and coordinate lookup, including selected coordinates for reverse lookup
- CartoCDN: website map tiles, which expose the requesting IP address and tile coordinates
- Render: hosting for the shared astrology calculation and place search service used by both the website and iOS app, including bounded process memory caches and operational request logs retained under Render's own logging policy
- Upstash Redis: rate limit counters and short-lived pseudonymous delivery coordination
- Google and Apple: optional identity provider services when you choose their sign-in method
- Stripe: payment processing for purchases made on augurine.com
- Apple: StoreKit purchase handling, App Store transaction history, subscription management, refund decisions, APNs delivery, and app diagnostics controlled by device settings for iOS
- OpenAI: the bounded interpretation and synthesis processing described above
Augurine does not sell personal information. Consented conversion measurement does send a hashed email address, IP address, and advertising identifiers to Meta, which some laws, including California's, treat as sharing for cross-context behavioural advertising. Declining non-essential cookies stops it, and you can change that choice at any time.
We can also disclose information when required by law, to protect users or the service, or as part of a transaction where the recipient assumes the obligations stated in this policy.
7. Website cookies and analytics controls
Essential website cookies keep you signed in and record your cookie choice. Google storage and Meta browser measurement require acceptance through the website cookie banner. PostHog initializes for signed-out visitors only after acceptance. For signed-in website users, PostHog can initialize under the service operations basis unless website PostHog collection has been rejected. The Reject choice opts the website out of PostHog collection and optional Google and Meta measurement. The selected state is mirrored between browser storage and a cookie the server can read, with any disagreement resolved toward rejection. Use Cookie preferences in the website footer to reopen the choice and change it without clearing unrelated site data. Ahrefs web analytics is loaded without a cookie consent dependency.
The website cookie choice does not control native iOS analytics, App Store transaction data, APNs, iOS notifications, widgets, or device-local storage.
8. Storage and security
Account data is stored in Supabase PostgreSQL with user-scoped row-level security. Network connections use TLS. Witness Mark note text is stored in a dedicated ciphertext column. The website is served over HTTPS and applies telemetry redaction before Sentry submission.
Shared website and iOS place search can use a server cache for Nominatim responses with a requested 30 day revalidation period. The shared calculation service also keeps bounded process memory caches for repeated calculations and place searches. Those caches have no account identifier and remain until capacity eviction or process restart rather than a fixed time expiry. Hosting systems can separately retain request URLs, typed place queries, network context, status, timing, and minimized operational logs.
On iOS, credentials and small account capabilities use non-synchronizing Keychain storage. Rebuildable account and widget files use iOS data protection and are excluded from device backup by the app. WidgetKit and the notification system can retain a rendered timeline or delivered notification until iOS processes a reload or removal request. No storage or transmission method can guarantee absolute security.
9. Your choices and rights
- Review or correct account and birth details in Settings
- Change a website cookie choice through Cookie preferences in the website footer
- Manage iOS notification permission through Augurine and iOS Settings
- Delete individual records from the controls provided by the applicable feature
- Contact Augurine about an access or portability request by emailing support@augurine.com
- Delete the shared Augurine account from iOS Settings or from website account deletion
- Exercise any further access, correction, objection, restriction, portability, or complaint right provided by applicable law
Augurine does not currently offer a complete account export through a self service control. Access and portability requests require identity verification and can require manual processing. Existing exports available within individual features do not represent every account or provider record.
We may need to verify the request against the account. Do not send a password, authentication token, payment card number, Apple credential, or deletion recovery receipt. Billing cancellation is separate from privacy choices and follows the purchase origin.
10. Retention and account deletion
Account content is generally retained while the account is active or while needed to deliver a requested service. The account deletion workflow prepares a recoverable job, performs required provider cleanup, removes account-linked server records, then removes authentication. The iOS device or browser that performs or later observes the completed deletion clears the enumerated local state it owns. An offline or different device or browser cannot be purged remotely and can retain local residue until client cleanup runs, the user removes it, or the operating system or browser evicts it. If a required provider result cannot be confirmed, deletion can pause for retry or support review while the account remains recoverable.
An active Stripe subscription linked to the account is cancelled before deletion proceeds. Deleting the Augurine account does not cancel an App Store subscription. Apple continues to manage that subscription until you cancel it through Apple. Local App Store entitlement observations are erased, while Apple retains its own purchase history under Apple's policies.
After completion, a random no-identity deletion status receipt is retained for no more than 30 days so a lost connection can recover the result. Bounded rate limit or notification coordination data can remain until its short expiry. A random notification installation identifier can remain device-local after the deleted account's consent mapping is removed. Coarse experiment deletion totals and a run-specific pseudonymous enrollment fingerprint can remain without response text, event details, or a user identifier.
Website PostHog storage can persist according to the browser and reviewed SDK defaults, including a cookie that can last for 365 days. The shared Nominatim cache requests revalidation after 30 days. Bounded Rust process memory caches have no fixed time expiry and leave only through capacity eviction or process restart. Because those shared caches are not keyed by an Augurine account, account deletion cannot reliably locate one person's entries.
Stripe, Apple, OpenAI, PostHog, Sentry, Vercel, Render, Nominatim, CartoCDN, email providers, conversion providers, and the support mailbox can retain provider held records under their terms or applicable legal duties. Protected backups and records needed for security, fraud review, accounting, or legal duties can also remain after active account data is removed.
11. Children's privacy
Augurine is intended for people who are at least 16 years old, or the higher minimum age required by their jurisdiction. We do not knowingly collect personal information from a person below the applicable minimum age. Contact us if you believe such information has been provided.
12. Changes to this policy
We can update this policy as the service, providers, or legal requirements change. The revision date on this page will be updated. Material changes will receive any further notice or consent required by applicable law.
13. Contact
Augurine is operated by Ruminwright Studios Ltd, which is the controller responsible for the personal data described in this policy.
For privacy questions or data requests, email support@augurine.com. General support and platform-specific instructions are available at the Support page.