Security and data handling

Birth details are personal data, and your users trust you with them. This page says what the astrology API keeps, what it does not, and how your keys are protected. The legal version is our Privacy Policy.

Birth details you send

  • The API uses the dates, times and places in a request only to compute the answer. Neither our gateway nor the calculation service stores request bodies.
  • Our web server's access log keeps the address (URL) of each request for 30 days. Dates and coordinates you put in a URL appear there for that time, so send birth details in the body of a POST request.
  • No request data goes to an AI provider. Readings are written from fixed rules and a written library of text, so the same input always gives the same answer.
  • Our usage records count requests and errors per key, per endpoint, per day. They hold no birth details.

API keys

  • We store only a hash of each key, plus its first characters and its last 5 characters so you can recognize it. The full key is shown once, when you create it.
  • Test keys and live keys are separate. Test keys call the same API with a small allowance and are never billed.
  • Each key has its own per-minute rate limit. Revoke a key at any time from your account, and it stops working right away.
  • Owners and admins manage keys. Members can see a key's name and prefix, but cannot create or revoke keys.

How the service is built

  • Customers call only our API gateway. The calculation service runs on a private network and accepts calls only from the gateway.
  • The gateway forwards only the operations in the published API reference, with their own query fields, a size limit and a timeout.
  • Connections use HTTPS. Passwords and API keys are stored only as hashes. Only the people who run the service can reach the database.
  • The site and the API run with a major cloud hosting provider. Business customers who sign a data processing addendum (DPA) can get the full list of our providers.

Your account and your data

  • We keep your account, team, keys and usage records while your account is open. When you ask us to close it, we delete them within 30 days.
  • We use only the cookies needed to keep you signed in. There are no analytics or advertising cookies, and no third-party trackers.
  • To see, export or delete your data, email [email protected]. We reply within 30 days.
  • Business customers can ask for a data processing addendum (DPA) at the same address.

Found a security problem? Tell us through the contact page and we will usually reply within one business day. How keys work in practice is in authentication and rate limits.

Astrology API

Try it with a test key

Test keys call the real API with 1,000 requests a month and are never billed. Or try a request in the API reference first.

  1. 01

    A free test key, with 1,000 requests a month

  2. 02

    Try any endpoint in your browser first

  3. 03

    Every rule published, so you can check any answer