Privacy Policy
Your data, explained plainly.
Effective date: [INSERT EFFECTIVE DATE] · Last updated: [INSERT LAST-UPDATED DATE]
1. Who we are
“Phase,” “we,” “us,” and “our” mean [LEGAL ENTITY NAME], trading as Phase, with its registered address at [POSTAL ADDRESS]. Phase is an astrology application that creates birth charts, readings, reports, compatibility results, and optional AI-assisted responses.
Privacy contact: [PRIVACY-EMAIL]. General support: [SUPPORT-EMAIL].
2. What this policy covers
This policy covers the Phase mobile app, its Firebase-backed services, and this legal website. It does not control third-party services or device features governed by their own notices, including Google, Apple, your mobile operating system, or the app store through which you obtained Phase.
Phase is designed for personal reflection and entertainment. It is not a medical, mental-health, legal, financial, investment, emergency, or other professional advisory service. Do not submit information that you do not want processed to provide a reading.
3. Data we handle
We handle the categories below only as needed to operate the features you use.
- Account and sign-in data
- Phase creates a Firebase user ID for each guest or registered account. If you choose a registered sign-in method, Firebase Authentication also handles the information returned by that method: email address and verification status; Google or Apple account identity information made available to the app, such as a display name or email address; or phone number for SMS verification. Passwords are submitted to Firebase Authentication for email/password sign-in; Phase does not store a readable copy of your password in the app.
- Profile and birth-chart data
- Profile name, relationship label, selected gender value, date of birth, birth time and whether it is known, birthplace text, latitude, longitude, time-zone information, profile identifier, creation time, and the astrology chart calculated from those inputs. A profile may describe you or another person. You are responsible for having permission to provide another person’s information.
- Reading, report, and compatibility data
- Generated astrology readings, daily domain readings, report text, report generation dates, compatibility scores and explanations, and related calculation inputs or tool results. Compatibility records can include the birth details and names of two people.
- Chat and AI-request data
- Questions you type, the conversation history selected for an AI consultation, generated responses, and the chart context required for the request. The chat context can include your name, birth date and time, birthplace, current age, current dasha information, natal house map, and divisional-chart summaries. Report and compatibility requests can include similar chart-derived context, names, and generated calculation results.
- Place-search data
- If you search for a birthplace, the text you enter is sent to the place-search service so it can return matching places and coordinates. The current app build does not request access to your device’s precise or background location; it uses the birthplace that you enter or select.
- Technical and security data
- When you use network services, our service providers and your device may process authentication tokens, IP address, device/browser or app information, request timestamps, and security or fraud-prevention signals needed to secure sign-in, send SMS verification, deliver requests, and troubleshoot service operation. This can include information handled by Firebase, Google, Apple, or your device platform under their own terms.
- Purchase data, if paid features are enabled
- If Phase later offers in-app purchases, the applicable app store processes the payment. We receive the information needed to grant and restore the purchase or entitlement, such as product ID, order/transaction status, purchase token or transaction identifier, country/storefront context, and fraud or refund status. We do not receive your full payment-card number.
4. Why we use data
- To create, display, save, and sync astrology profiles, charts, readings, reports, and compatibility results.
- To authenticate your account, verify email or phone sign-in, prevent misuse, and protect cloud data so it is available only to the relevant account.
- To send the context needed to generate an AI-assisted reading or report when you request one.
- To search a birthplace and calculate the correct chart time-zone and coordinates.
- To provide support, enforce the Terms, maintain security, resolve faults, comply with law, and—if enabled—validate purchases and manage entitlements.
We do not sell personal information or use your birth-chart, chat, or profile content for targeted advertising. [CONFIRM THIS REMAINS TRUE BEFORE PUBLICATION.]
6. Storage and sync
On your device
Phase stores profile data and the selected active profile locally. It also stores chat history, daily readings, saved reports, and saved compatibility results locally. On Android this is application storage; on iOS this is app storage. The local records remain until you delete the relevant profile or account, clear the app’s storage, or uninstall the app.
Automatic signed-in profile sync
When you are signed in, Phase mirrors profile and birth-chart data to the Phase Firestore database for that Firebase user ID. This supports use of your profiles across devices. The current code syncs profiles; it does not automatically sync chat histories, daily readings, saved reports, or saved compatibility results merely because you signed in.
Device and exported-file backups
Phase does not provide an in-app backup or restore feature, and its Android configuration disables Android system backup. Your operating system or cloud-device-backup provider may still handle files outside Phase according to its own settings. If you export or save a PDF, that file is stored in a location you choose or, on Android, may be saved in Downloads; it is outside the Phase in-app deletion flow.
7. Retention and deletion
We keep local and cloud data only for as long as needed to provide the feature, until you delete it, or as required for legitimate security, accounting, dispute, or legal purposes. [INSERT THE APPROVED RETENTION PERIOD FOR SERVER LOGS, AI REQUEST LOGS, AND PURCHASE RECORDS.]
Welcome-credit abuse prevention
We keep the wallet and account-linked grant records while the account is active to track its balance and previous promotional grants. Successful account deletion removes that wallet, its remaining coins, and its account-linked grant records. Those coins do not transfer to a new account. Promotional amounts and eligibility are described with the applicable offer; general coin rules are explained in the Terms of Service.
We use secret-keyed fingerprints of verified sign-in identities, email addresses, and phone numbers to recognize previous welcome-credit claims across account deletion and re-registration. These fingerprints are pseudonymous personal data, not anonymous data. They are used only for welcome-credit eligibility and abuse prevention, are accessible only to the backend, and are not used for advertising.
While a credited account is active, we retain its claim record to prevent repeated grants. After successful account deletion, we remove the old account ID from its identity fingerprints and retain only a restriction marker and expiry time for 15 days. A matching new registration during that period does not receive welcome coins. After expiry, a new registration can qualify again; an active or previously denied account is not automatically refilled. The backend stops applying the restriction at expiry. Scheduled cleanup runs every 15 minutes and deletes expired markers; physical removal may take longer if cleanup is unavailable, and failures require operational follow-up. Deletion retries and deletion of an account that received no grant do not restart the restriction.
The retained restriction records contain no raw email address, phone number, provider identity, birth details, chats, or old account ID. We also retain a project-wide daily promotional coin total, containing no user identifiers, for up to two UTC calendar days plus scheduled-cleanup delay. Welcome-credit retention does not extend retention of ordinary account data.
- Delete a profile
- In the app, delete the relevant profile. The app removes that profile’s local chat history, saved reports, saved compatibility results, and local profile record, and requests deletion of the corresponding synced Firestore profile. It does not remove an exported PDF.
- Delete your account
- Use the in-app Delete account control or the public account deletion page for an account that can sign in with email, Google, Apple, or phone. A recent sign-in is required. The server deletes synced profiles, the coin wallet and account-linked starter/welcome-grant records, spending history, user-linked AI usage and request records, and the Firebase Authentication account. The in-app flow also clears that device’s local profile-related caches, including chats, readings, reports, and compatibility results; if you delete through the website while Phase is still installed, clear the app’s storage or remove the app to erase that device’s local data. A minimal protected welcome-credit restriction record is retained for 15 days as described above. Purchase receipts are reduced to a purchase-token hash and a deletion marker, without account or order details, to prevent duplicate purchase credits. A temporary deletion coordination record is kept for 24 hours after completion, then removed by a scheduled cleanup; removal may take longer if that service is unavailable. Failed cleanup is queued for automatic retries. Do not treat deletion as complete if a cloud deletion error is shown—retry while online to confirm completion.
- Ask for help
- If you cannot access the app, use the account deletion page to sign in and request deletion. For a guest account that has no recoverable sign-in, deletion must be requested in the app so Phase can verify the account without accepting an unsafe typed identifier. For another privacy request, email [PRIVACY-EMAIL] from the account email or provide enough information for us to verify your request.
Deletion from Phase does not delete copies you saved outside Phase, such as PDFs in Downloads, screenshots, or operating-system backups. It may also not remove data that a service provider must retain under its own legal obligations; we will explain any such exception when required.
8. Your choices and privacy rights
You can use Phase with a Firebase-authenticated guest account without creating a registered sign-in. Firebase-backed cloud sync and AI features require a Firebase-authenticated guest or registered account. You can choose not to use AI features or place search. You can edit or delete profiles and remove selected local history in the app.
Depending on where you live, you may have rights to ask for access, correction, deletion, restriction, objection, portability, or information about our processing. Contact us at [PRIVACY-EMAIL]. We will respond under applicable law and may need to verify your identity. You may also have the right to complain to the relevant data-protection authority.
9. Security
We use authenticated Firebase services and HTTPS/TLS network connections for supported cloud interactions. Access to cloud profile records is intended to be limited to the authenticated account that owns them. No method of transmission or storage is completely secure, so please use a unique password where available and avoid entering unnecessary sensitive information into chat prompts.
[Before release, verify Firestore security rules, Cloud Function authentication/authorization, production logging, encryption settings, staff access, incident response, and backup configuration. Update this section if those controls differ.]
10. Children
Phase is not directed to children under [INSERT MINIMUM AGE, FOR EXAMPLE 13 OR THE HIGHER AGE REQUIRED WHERE OFFERED]. Do not use Phase or submit another person’s data if you are below that age without the consent required by applicable law. If you believe a child has provided personal information without valid consent, contact us at [PRIVACY-EMAIL].
11. Changes and contact
We may update this policy when the app, its service providers, or applicable law changes. We will publish the updated version here and revise the “Last updated” date. For material changes, we will provide additional notice where required.
Questions or requests: [PRIVACY-EMAIL]
Mail: [LEGAL ENTITY NAME], [POSTAL ADDRESS]