Celestium: Cosmic Compass — Privacy
Effective 2026-07-16 · Provided by WithJhinna (Texas, USA).
This service turns astrology/divination requests into readings for AI agents and, when you
explicitly ask, into a shareable web page. This policy describes exactly what we
collect, store, and can or cannot read — matched to how the service actually works.
What we collect — only what you send, only when you ask
- Reading inputs (birth date/time/place, questions): sent per request to
compute a reading. Not stored unless you opt into a shareable render.
- Shareable renders: only if you pass
render, we store that
chart + reading behind an unguessable link.
- Couples invites: if you send an invite to compare charts, we relay only
end-to-end-encrypted chart data between the two devices — we cannot read it, the key lives
solely in the invite link, and the encrypted blob expires automatically and can be revoked.
- Account identity: if you sign in, your email and chosen sign-in provider
(Apple/Google/email) are handled by our identity provider, Clerk.
- Billing: subscriptions are processed by Stripe; we do not store card data.
Shareable renders — how they’re protected
- Opt-in only — nothing is stored unless you request a render.
- Unguessable link — a 72-bit id; the page is not indexed by search engines.
- Auto-expiry — every render expires (default 90 days; you may set a shorter
time, or make it view-once).
- Revocable — you can delete any or all of your renders at any time.
- Encrypted at rest — the storage volume is encrypted. For an
encrypted render, we store only ciphertext and the key lives solely in your
link — we do not keep it, so we cannot read that render’s contents. For a standard render, the
content is readable by our service in order to display the page. We never sell it, and we do
not use it for advertising.
Honest limit: a standard (non-encrypted) render is readable by our service while
stored. An encrypted render protects the stored contents from us, a breach, or a legal demand —
but the link itself contains the key, so anyone you share the link with can read it.
Third parties
- Clerk — authentication / account identity.
- Stripe — subscription billing.
- Fly.io — hosting.
Retention
Renders auto-expire (default 90 days) and can be revoked sooner. Account identity is retained
until you delete your account, at which point all of your renders are deleted automatically.
Your rights
- Access / portability — signed in, request
GET /my/export for
your full render data (or contact us).
- Deletion — revoke a render (
DELETE /my/renders/:id), revoke all
(DELETE /my/renders), or delete your account (which cascades to all your renders).
- Erasure requests under GDPR/CCPA and similar laws — contact
dearjhinna@icloud.com.
We do not sell personal data and do not use it for advertising.
Contact
WithJhinna — dearjhinna@icloud.com.
Changes to this policy will be posted here with a new effective date.