Privacy Policy

Last updated: Oct 1, 2026

This policy explains what API for Astrology ("we") collects when you use this website and the Astrology API, and what we do with it. In short: we keep only what we need to run your account. We do not store the birth details you send to the API. We never sell data.

1. What we collect

  • Your account: name, work email, password (stored only as a hash), company name, and your mobile number if you choose to give one. We use the number only to reach you about your account, and you can change or remove it on your profile page.
  • Your team: the people in your company and their roles. When you invite someone, we store their email address until the invitation is accepted, canceled or expires after 7 days.
  • Sign-in sessions: the IP address and browser of each sign-in, to keep you signed in and to spot misuse.
  • API keys: a hash of each key, its first characters and its last 5 characters, so you can recognize it. We never store the full key.
  • Usage records: how many requests and errors each key made, per endpoint, per day. These records contain no birth details.
  • Forms: what you send through the contact form (name, email, company, note) and the email address you give a notify-me form.
  • Abuse limits: IP addresses, held for up to 1 hour, to limit sign-up, sign-in and form attempts.

2. Birth details you send to the API

The API uses the dates, times and places in a request only to compute the answer. We do not store request bodies. Our web server's access log keeps the address (URL) of each request for 30 days. So any dates and coordinates you put in a URL appear there for that time. To keep them out, send birth details in the body of a POST request.

If you send your users' details through the API, you decide how they are used. We use them only to answer your request. You are responsible for telling your users and for getting any consent the law requires. Business customers can ask for a data processing addendum (DPA) at the privacy email below.

3. Why we use it

  • To run your account, your keys and the API, and to count usage against your plan (our contract with you).
  • To keep the service safe and stop abuse (the law calls this a legitimate interest).
  • To reply to your messages, and to send the launch news you asked for (your request and consent). You can unsubscribe at any time.

4. Who we share it with

We never sell or rent your data. We share it only with the providers that run the service for us:

  • Our cloud hosting provider: the servers, the database and sending email.
  • Dodo Payments: payments. Dodo Payments sells our paid plans as the merchant of record, so it handles your card, billing details and taxes. We never see your full card number.

Business customers who sign a data processing addendum (DPA) can get the full list of our providers.

We also share data when the law requires it.

5. How long we keep it

  • Account, team, keys and usage records: while your account is open. When you ask us to close it, we delete them within 30 days.
  • Sign-in sessions: until they end (7 days after your last use).
  • Contact-form messages: as long as we need to reply and follow up, and no more than 24 months.
  • Notify-me emails: until we send the launch news for that service, then we delete them within 90 days.
  • Web server access logs: 30 days.

6. Your rights

You can ask to see, correct, export or delete your data, or object to how we use it. Email [email protected] and we will reply within 30 days. These rights apply wherever you live. They include your rights under the GDPR (EU and UK), the CCPA (California) and India's Digital Personal Data Protection Act. You can also complain to your local data protection authority.

7. Cookies

We use only the cookies needed to keep you signed in. We use no analytics or advertising cookies, and no third-party trackers. If you paste an API key into the docs to try a request, your browser keeps it in that tab only. It is gone when you close the tab.

8. Security

Connections use HTTPS. Passwords and API keys are stored only as hashes. Only the people who run the service can reach the database. Our security page explains how birth details and keys are handled, in plain words.

No service can promise perfect security. If a breach affects your data, we will tell you as the law requires.

9. Children

The service is not for anyone under 18, and we do not knowingly collect their data.

10. Changes to this policy

The date at the top shows when this policy last changed. For an important change, we email account owners before it applies.

11. Contact

Privacy questions: [email protected]. Anything else: the contact form.