Scope and roles
This policy applies to moira-astro.com, its public calculators, Urania Workspace, saved-chart tools, AI features, community publishing, donations, subscriptions, and practitioner-directory features. Independent practitioners and linked services may be separate controllers for information you give them directly.
When you enter another person’s birth information, you are responsible for having lawful authority to do so. Do not submit private or sensitive information that the calculation or feature does not need.
Information Moira collects
- Account and profile identifiers: name, email, Clerk user ID, role, preferences, and account status.
- Chart and birth-event data: names or labels, birth dates and times, locations, coordinates, time zones, saved charts, placements, settings, synastry and relationship records, returns, forecasting inputs, and derived chart packets.
- Private Hellenistic continuity records: user-titled condition dossiers, exact timeline snapshots, policy and provenance receipts, engine/resource identifiers, and user-authored reminders. Reminder records do not imply automatic email or predictive-alert delivery.
- Payments: Stripe customer, checkout, subscription, invoice, product, price, donation, refund and payment-status identifiers; payer name, email, amount, message, discounts and tax metadata. Moira does not receive full card numbers or CVV.
- Community publishing: articles, questions, comments, uploads, revisions, tags, drafts, recovery state, collaborators, bookmarks, reactions, reports, moderation records, and article-view hashes.
- First-party product reviews: public display name, 1–5 rating, plain-text review, current version and moderation state, policy acceptance, reports, editorial feature position, and content-free lifecycle/audit events. Only approved review content is public.
- Practitioner directory: application and public profile fields, biography, specialties, links, profile photo, birth placements selected for publication, practitioner-specific reviews, booking inquiries, directory status, and synastry caches.
- AI features: prompts, chart-derived context packets, model inputs and outputs, reading caches, model name, token counts, estimated cost, duration, success or failure, and related feature metadata.
- Communications: transactional email records and delivery status, support correspondence, deletion and privacy requests, safety reports, and copyright notices.
- Security and operations: IP address or salted IP hash, request and server logs, session/security signals, browser and device information, tier, tool-usage events, cron/webhook failures, and admin audit records.
Public, account-private, and browser-local data
| State | Examples | Control |
|---|---|---|
| Public after approval | Published articles/comments, author identity, selected practitioner profile and birth placements, and approved first-party product reviews | A product review is public only while its current version is approved. Editing withdraws it pending re-review; author deletion removes it. |
| Account-private | Saved charts, Hellenistic dossiers/timeline receipts/authored reminders, Workspace sessions, private relationship data, draft posts, inquiries, AI readings/caches, and pending, rejected, or removed product reviews | Available to the signed-in account and authorized operators/processors needed to run the service. Removed product reviews are read-only to the author. |
| Browser-local | Chart library identities, names, birth dates/times and locations; Workspace session/settings; saved-chart cache; onboarding state; astrocartography pins; Writer Studio recovery drafts | Stored in localStorage or similar site storage on that browser. Clear the site’s browser data to remove local copies. |
Clearing browser data can remove unsynced work and does not delete server records. Conversely, deleting a server account cannot remotely erase copies left in a browser, exported file, recipient’s device, search index, or third-party archive.
The Cookie & Browser Storage Policy identifies Moira’s authentication cookies, local and session storage, IndexedDB chart cache, purposes, persistence, and controls.
Purposes and legal bases
| Purpose | Typical data | Basis where applicable |
|---|---|---|
| Provide calculators, accounts, Workspace, saved content and requested AI features | Account, chart, birth-event, settings, prompts and output | Perform the service contract or take requested pre-contract steps |
| Secure, debug, meter, prevent abuse and improve reliability | Logs, usage events, IP or salted IP hash, success, duration and cost | Legitimate operational and security interests, balanced against user rights |
| Process subscriptions, donations, refunds, taxes and records | Billing and transaction metadata | Contract and legal/accounting obligations |
| Publish and moderate public content at your direction | Articles, comments, profiles, approved product reviews, reports, uploads and attribution | Contract, legitimate service/community interests, safety, and your publication direction |
| Send optional non-essential email | Email and preferences | Consent where required; withdraw through the provided control |
| Respond to rights, disputes and lawful requests | Account, correspondence, audit and relevant service records | Legal obligations and legitimate interests in establishing and defending rights |
Which legal basis applies depends on the feature, jurisdiction, and facts. Moira does not claim consent as the basis for every use.
Service providers and disclosures
Moira gives providers only the information reasonably needed for their role. These providers operate under their own terms and may retain billing, fraud, security, or legal records independently. Account deletion does not mean every processor record disappears automatically.
| Provider | Purpose | Data involved | Policy |
|---|---|---|---|
| Clerk | Authentication, account identity, and sessions | Account and authentication data | Provider policy |
| Stripe | Subscriptions, donations, tax and payment processing | Contact, transaction, billing and fraud-prevention data | Provider policy |
| Resend | Transactional and verification email delivery | Email address, message metadata, delivery status and message content | Provider policy |
| Anthropic | AI interpretation when you invoke an AI feature | Chart-derived prompt content, instructions and output | Provider policy |
| Hetzner | Application, database and backup hosting | Stored service data and server/network logs | Provider policy |
| Cloudflare | DNS, traffic delivery, availability and security | Network, device, request and security data | Provider policy |
Moira may also disclose information when reasonably necessary to comply with law, protect rights or safety, investigate abuse, complete a business transfer subject to appropriate protections, or act with your direction. Moira does not sell personal data or share it for cross-context behavioral advertising.
AI processing
When you invoke an AI feature, Moira constructs a prompt from relevant chart data, feature instructions, and any text you provide, and sends it to Anthropic’s API. The response may be cached so it can be shown again, measured, moderated, or regenerated. Avoid including information that is not needed for the reading.
Anthropic’s commercial/API data practices can change. Moira relies on the provider terms and privacy materials then in force rather than promising independently that provider data is never retained or used. Review Anthropic’s Commercial Terms and Privacy Policy.
Retention and deletion
Retention depends on the record and operational or legal need. The Data Retention Policy lists the current schedule, including product reviews pending or rejected for 180 days after their last update, administrator-removed reviews for 90 days after removal, resolved review reports and content-free review lifecycle events for 365 days, 7-day AI dashboard caches, 90-day operational logs, up to 7 years for billing records, and rolling backups up to 30 days.
A verified deletion request is normally completed within 30 days after verification. Some data is deleted, some public material may be anonymized, and limited records may remain for legal, accounting, security, dispute, or backup purposes.
Your rights and choices
Depending on where you live, you may request access, correction, deletion, restriction, objection, or portability; withdraw consent for an optional use; or complain to a competent privacy or data-protection regulator. Rights may have exceptions. Moira will explain a material denial where required.
Email hello@moira-astro.com or use the verified deletion flow. Moira may verify your identity and authority before acting. Authorized-agent requests require reasonable proof of authority.
To appeal a decision about a privacy request, email hello@moira-astro.com with the subject “Privacy Appeal” and identify the earlier request and decision. Moira will respond within the period required by applicable law. You may also complain to the privacy or data-protection regulator responsible in your jurisdiction.
Moira does not intentionally use third-party advertising pixels, analytics cookies, or third parties to collect cross-site activity for targeted advertising. Because no common Do Not Track standard creates a uniform signal, the service does not separately respond to browser DNT; applicable legally recognized opt-out signals will be evaluated as required.
International processing and security
Moira is operated from the United States and uses providers and infrastructure that may process data in the United States, Germany, the European Economic Area, or other provider locations. Transfer protections depend on applicable law and the provider’s then-current contractual and organizational safeguards; this policy does not claim a particular transfer mechanism where it has not been established.
Moira uses reasonable technical and organizational safeguards appropriate to a small online service, but no storage or transmission is guaranteed secure. Protect your login, use a trusted device, and notify Moira promptly of suspected account misuse.
Children and changes
Moira is intended for users aged 16 and older and is not directed to children under 13. If a parent or guardian believes a child submitted personal information, contact hello@moira-astro.com so Moira can investigate and remove it where appropriate.
Material policy changes will be communicated in a manner proportionate to the change, such as an in-product notice or email when appropriate, and will receive a new version and effective date. Moira will seek consent when the law requires it; silence or continued use alone is not treated as consent where that would be invalid.