Cosmic Ephemeris Privacy Policy
This Privacy Policy explains how Cosmic Ephemeris ("we," "us," or "our"), an independent service based in Georgia, United States, collects, uses, discloses, retains, and protects personal information when you visit the website; create an account; use the dashboard, APIs, SDKs, saved searches, schedules, jobs, or webhooks; contact support; or manage a subscription.
1. Our role
Cosmic Ephemeris determines the purposes and means of processing account, authentication, security, usage, support, and billing-administration information. When a customer submits another person's birth or relationship information, the customer chooses the purpose and is responsible for its instructions, notices, permissions, and lawful basis. Unless a separate signed data-processing agreement says otherwise, the Service does not promise that Cosmic Ephemeris acts solely as a processor or service provider for that customer. No public data-processing agreement is currently offered.
2. Information we collect
Account and authentication information
We process your name, email address, password hash, account and plan status, Terms version and acceptance time, account timestamps, login timestamps, and any separately established mailbox-verification status. Passwords are one-way hashed. API keys, dashboard session identifiers, signing secrets, legacy verification tokens, and password-reset tokens are stored in one-way or encrypted forms appropriate to their function and are not intentionally logged in plaintext. For API-key administration, we store the label, project, environment, scopes, optional expiration and budget, display prefix, unit totals, and environment-policy settings.
Usage, device, and operational information
The application records the API endpoint, request time, response status, duration, billable status, and usage units. Web-server, application, security, and infrastructure logs may include IP address, requested path, browser user agent, referring origin, timestamp, generalized error information, and security signals. We do not intentionally put passwords, raw API keys, session cookies, signing secrets, complete calculation request bodies, or raw place-search queries in these logs.
Calculation and place inputs
Requests can include names, birth dates and times, selected or resolved timezones, latitude and longitude, place queries and country filters, transit or target dates, zodiac and ayanamsa choices, relationship/comparison inputs, chart-rendering options, event filters, and other documented calculation settings. Place search uses a self-hosted, pinned GeoNames-derived catalog; a query is processed to return candidates and is not intentionally persisted in the application database. Historical timezone resolution uses the selected place or explicit coordinates and local date/time with pinned IANA timezone data.
Synchronous routes process request values to return results and do not intentionally persist complete request bodies, calculated chart results, context bundles, SVG charts, or calculated period lists in the application database. Usage metadata is recorded separately. Numerology requests can additionally contain an optional name and birth date returned in the response; it is synchronous only.
Saved charts, saved searches, and schedules
Signed-in users may opt into saved chart profiles containing a label, birth date and time, timezone, coordinates, zodiac, ayanamsa, and house system. Saved event searches store a label and reusable criteria such as event types, bodies, aspects, Moon phases, zodiac, ayanamsa, display timezone, orb, and grouping choice. They do not store a requested UTC interval or calculated results by themselves.
If you enable a saved-search schedule, Cosmic Ephemeris also stores the selected API-key association, daily or weekly cadence, UTC run time, optional weekday, 24-, 72-, or 168-hour forward window, enabled status, next and last run times, last job reference, and bounded error status. At the selected time, the scheduler uses the saved criteria to create an event-calendar job. The resulting normalized job input and result are then retained under the batch-job rules below. Disabling or deleting a schedule stops future scheduled submissions but does not retroactively undo an already admitted job or usage unit.
Batch-job and import information
If you create a supported batch job, including one submitted by a saved-search schedule, Cosmic Ephemeris stores its normalized inputs, status, and results for up to 24 hours so you can poll or cancel it. A job contains at most ten items. Bounded NDJSON import discards the original bytes after parsing and stores no uploaded filename, remote URL, or compressed archive; only normalized job inputs and results are retained.
Webhook information
You may store up to five HTTPS webhook labels and URLs. When an owned job reaches a terminal state, Cosmic Ephemeris can send the selected destination a signed event containing a delivery ID, job ID, state, item/completion/failure counts, completion time, and authenticated job-status path. Inputs and results are not included. The destination receives data at your direction and may apply its own privacy practices. Signing secrets are shown only on creation or rotation and are not returned in endpoint lists.
Support, email, workspace, and legal-request information
If you contact us, we process the email address, message, attachments, account details, and follow-up records you provide. Do not send credentials, payment-card data, or unnecessary third-party birth data. Legacy verification, reset, and workspace-invitation messages can be queued in encrypted application payloads until delivery is attempted. A workspace invitation includes the invited email, workspace name, bounded role, and one-time link. Successfully delivered queue records are deleted. We may retain records reasonably necessary to authenticate and answer privacy, security, legal, and billing requests.
Billing information
Stripe processes payment-card and billing details on its hosted pages. Cosmic Ephemeris does not intentionally receive or store complete card numbers. We retain Stripe customer, subscription, price, status, billing-period, and signed-event identifiers needed to administer and reconcile subscriptions. Stripe processes information under its own privacy notice and legal obligations.
3. Sources of information
We receive information directly from you or your organization, automatically from your browser or API client, from Stripe about subscription events, from Cloudflare about abuse checks, and from service providers involved in operating or securing the Service. Self-hosted public datasets used to calculate or resolve an answer are calculation sources, not sources of account information about you.
4. Why we use information
- to create, authenticate, and secure accounts, sessions, keys, workspaces, and webhooks;
- to perform requested calculations, place/timezone resolution, saved workflows, scheduled searches, jobs, exports, and deliveries;
- to measure usage, apply entitlements, prevent abuse, diagnose errors, and protect shared infrastructure;
- to administer subscriptions, payments, cancellation, taxes, and billing reconciliation;
- to communicate about support, security, account, legal, privacy, and material service matters;
- to improve reliability and documentation and to maintain auditable calculation behavior; and
- to comply with law and establish, exercise, or defend legal claims.
Where a law requires a legal basis, these uses may rely on performance of our contract with you, our legitimate interests in operating and securing the Service, compliance with legal obligations, protection of vital interests in an emergency, or consent where we specifically request it. You may withdraw consent for future processing where consent is the basis, without affecting earlier lawful processing.
5. Providers and disclosures
We use providers for defined operational functions:
- Amazon Web Services (AWS) for application, database, backup, networking, monitoring, and related infrastructure;
- Cloudflare Turnstile for bot and abuse prevention, which can process a verification token, IP address, device, and browser signals;
- Google Workspace for transactional and support email; and
- Stripe for hosted checkout, payment processing, subscription management, and billing events.
We may disclose information to professional advisers bound by appropriate duties, to authorities or other parties when reasonably necessary to comply with law or protect rights and safety, in a merger, financing, reorganization, or transfer subject to appropriate safeguards, or at your direction. We do not currently sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising, or knowingly exchange it for monetary consideration.
6. Cookies and browser storage
Cosmic Ephemeris uses a secure server-backed session cookie for signed-in dashboard access. Login uses an eight-hour cookie by default; "Keep me signed in for 30 days" uses a fixed 30-day cookie. Activity does not extend either expiry, and logout or password changes can revoke sessions. Cloudflare Turnstile may use browser or device signals necessary for abuse prevention. The current site does not intentionally deploy an advertising analytics tracker. We will update this Policy and add any required choices before introducing non-essential analytics or advertising cookies.
7. Retention and deletion
We retain account and saved-workflow records while the account or record exists, then delete or de-identify them subject to security, billing, legal, dispute, and backup needs. Account deletion removes the active user row and dependent API-key, environment-policy, saved-chart, saved-event-search, schedule, batch-job, webhook, session, verification, reset, and current-quota records. Historical usage rows are disassociated from the deleted user identifier. The designated owner must transfer ownership before self-service deletion. Stripe may retain transaction information under its own obligations.
- Batch-job normalized inputs and results expire 24 hours after submission and are removed by bounded cleanup.
- Job-webhook delivery records expire after about 25 hours.
- Permanently failed email-queue records are removed by bounded cleanup after seven days; successfully delivered queue records are deleted.
- Automated RDS backups are currently configured for fourteen-day retention. Deleted active data may remain in a backup until that backup expires or is overwritten.
Historical usage rows, Stripe event records, web-server and application logs, support correspondence, separately retained snapshots, and legal or incident records are retained for periods reasonably necessary for billing reconciliation, security investigation, service operation, legal compliance, limitation periods, and dispute handling. Exact periods can vary by record and legal requirement. We review the schedule and will update this Policy when a fixed public period is adopted. We do not use backup copies as active records and restore them only for recovery, continuity, security, or legal needs.
8. Your choices and privacy rights
You can review basic account and usage information, revoke keys, manage webhook endpoints, enable or disable schedules, export or delete saved profiles and searches, cancel a subscription, and request account deletion. Depending on where you live, you may have rights to know or access, correct, delete, or obtain a portable copy of personal information; object to or restrict certain processing; withdraw consent; or opt out of sale, targeted advertising, sharing, or certain profiling. We do not currently conduct the sale, targeted-advertising sharing, or solely automated high-impact profiling described above.
Send a request to support@cosmicephemeris.com with the subject "Privacy request." We may verify your identity and authority, ask an authorized agent for proof, deny or limit a request where law permits, and retain data where legally required. We will not discriminate against you for exercising an applicable right. If applicable law gives you an appeal right, reply with the subject "Privacy appeal" and explain why you believe the decision should be reconsidered. You may also complain to an appropriate regulator.
Because Cosmic Ephemeris does not currently sell personal information or use it for targeted or cross-context behavioral advertising, a browser Global Privacy Control or "Do Not Track" signal does not change current processing. We will reassess signal handling before introducing a use for which an opt-out signal is legally required.
9. Customer responsibility for third-party data
Customers decide why they submit another person's birth, relationship, or contact information. Customers must provide an appropriate privacy notice, obtain any required consent or other lawful basis, minimize data, secure their applications, and handle end-user requests. Do not use Cosmic Ephemeris for children's data or regulated/highly sensitive data without first confirming the use is lawful and covered by an appropriate written agreement.
10. International processing
Cosmic Ephemeris and its providers may process information in the United States and other countries where providers operate. Those locations may have different privacy laws. Where applicable law requires a transfer mechanism or additional contractual safeguard, the customer must contact us before submitting affected data; the public Service does not currently promise a particular data-residency region or public transfer addendum.
11. Children
The Service is not directed to anyone under 18, and people under 18 may not create an account. We do not knowingly collect personal information directly from children. Do not submit a child's personal information through the Service. If you believe a child provided information, contact us so we can investigate and take appropriate action.
12. Security
We use administrative, technical, and organizational measures designed to protect information, including encrypted transport, one-way credential hashing, limited credential disclosure, request and abuse controls, restricted service boundaries, backups, and controlled access. No method is completely secure, and we cannot guarantee absolute security. Revoke exposed credentials and contact us promptly. We will provide security-incident notice when required by applicable law.
13. Third-party sites and services
The website and Service may link to or interact with Stripe, webhook destinations, package registries, documentation sources, or other third parties. Their privacy practices apply to information they collect independently. This Policy does not control those third parties.
14. Changes to this Policy
The date above identifies this version. We may update the Policy prospectively as the Service or law changes. Material changes will be posted here and, when reasonably practicable, communicated through the account email or dashboard before they apply. We will request consent where applicable law requires it.
15. Contact
Privacy questions, rights requests, and appeals may be sent to support@cosmicephemeris.com. Cosmic Ephemeris is operated as an independent service based in Georgia, United States. Do not email credentials, payment-card details, or unnecessary birth data.