Privacy Policy
Last updated: July 26, 2026
AstroLina ("AstroLina", "we", "us") is a small, two-person project — a mother and her son. This policy explains what personal information we collect when you create an account or use AstroLina, why we collect it, and the choices you have. We try to collect as little as possible.
If you have any questions, email us at contact@astrolina.org.
Who we are
AstroLina is web-based astrocartography software, available at astrolina.org and at maps.astrolina.org. The core software is free and open source. You can use AstroLina without an account; creating a free account unlocks the Advanced toolkit, and a paid Pro tier unlocks the professional toolkit.
We are based in Canada. Where applicable, we act as the "data controller" for the information described below.
What we collect
We only collect what's needed to run your account and keep the service working.
- Your email address. Required to create an account. We use it to send your sign-in codes and, if you opt in, occasional product updates (see Marketing emails below).
- A display name (optional). Shown in your profile. You choose it and can change or skip it.
- Your saved birth charts (only when signed in). If you save charts to your account — a label you give each chart, plus the birth date, time, and birthplace you enter — we store them so they sync across your devices. You can delete a saved chart at any time, which removes it from our servers.
- Your journal entries (only when signed in; part of the Pro toolkit). If you use the locational journal, each entry you create — the spot you tag on the map (its coordinates and place name), your title and notes, a category, an event date, and which saved chart it belongs to — is stored so it syncs across your devices. You can delete any entry at any time, which removes it from our servers.
- Your saved reports (only when signed in; part of the Pro toolkit). If you save a report to your report library, we store that report so it syncs across your devices: the cover text you wrote (such as a title, a client's name, and your byline), the report's contents — the places it covers, its settings, and any notes you wrote — and any map images you added to it. You can delete a saved report at any time, which removes it (and any images only it used) from our servers. Reports you only draft but never save to the library stay in your browser.
- Your pinned places (only when signed in; part of the Pro toolkit). If you pin candidate cities to compare, we store that short list (each city's name and coordinates) so it syncs across your devices. Unpin a city and it's removed from our servers.
- Home locations on your charts (only when signed in, and only if you set one). A chart can carry the place its person lives now — a label and coordinates, used as the compass/bearing origin. It's stored with that chart and syncs like the rest of it; change or clear it (or delete the chart) and it's removed from our servers.
- Billing information (only if you buy Pro). Payments are processed by Stripe — your card number goes directly to Stripe and never touches our servers. We store what we need to run your plan: which plan you bought (subscription or lifetime), its status and renewal date, whether you've used a free trial, and a customer reference that links your account to Stripe's records. The billing address you enter at checkout goes to Stripe to process the payment and calculate any applicable sales tax.
- Your marketing preference. Whether you opted in to product/feature emails, plus the date and where that choice was made — a record we keep so we can honour your choice.
- Sign-in and security data. When you sign in we create a session so you stay logged in. We store only a hashed form of your one-time codes and session tokens — never the plaintext.
- Technical data for security. We briefly use your IP address (provided by our network, Cloudflare) to rate-limit requests and prevent abuse. We do not build advertising or tracking profiles.
- Waitlist email. If you ask to be notified about the paid "Pro" tier, we store that email for that purpose only.
We do not sell your personal information, and we do not use it for third-party advertising.
Your charts and maps
If you're not signed in, everything you do in AstroLina — birth details, charts, and the maps you create — is processed in your browser and stored only in your browser's local storage. None of it is saved on our servers. (Two things do pass through the network for anyone using the app: place lookups and the background map tiles — see Who we share it with below.)
When you're signed in, the birth charts you save — and, if you use the Pro toolkit, your journal entries, saved reports (including their images), and pinned places, plus a home location if you set one — are also stored on our servers (our database at Cloudflare) so they sync across your devices. The maps and lines AstroLina draws from your charts, and your other app settings, still live only in your browser. You can delete any of these at any time in the app — they're removed from our servers too — and deleting your account removes all of them.
Syncing is your choice. Your account screen has a "Sync my charts & data to my account" switch, on by default. Turn it off and the app stops syncing your content — charts, journal entries, saved reports, and pinned places — entirely: nothing you create from then on leaves that device's browser, and nothing is downloaded, until you turn it back on (at which point the app syncs what you did in the meantime). The switch is per device, and it governs your content, not the connection itself: while it's off the app still checks your session and plan so you stay signed in, account actions you take (billing, email preferences, display name) still reach us, and place lookups still work as described below. While sync is off, anything already saved to your account stays on our servers — the app just stops reading and writing it. Changes and deletions you make while sync is off reach our servers when you turn it back on; to remove everything from our servers at once, delete your account.
Share links. AstroLina can create a link that opens a chart exactly as you see it. The birth
details (the chart's name, date, time, and birthplace, including its coordinates) are encoded in
the link itself, after the #. That last part matters: everything after a # is a fragment,
and browsers never send fragments to the server. So the birth details in a share link stay in the
browsers at either end — they never reach our servers, they are never written to our logs or our
hosting provider's, and we keep no copy of them in any database.
What we can't do is take a link back. Anyone who has it can open it, opening it saves the chart into their own browser, and neither we nor you can revoke or expire it once it has been shared. Please share these links only with people you trust to see those details, and only with the permission of the person they describe.
Images and reports you export. AstroLina can render the map, a chart, or a report to an image or PDF you can download, copy, or share. These are created in your browser — we never receive or store them. If you copy or share one, anything you chose to include in it (such as a name, date, or place) goes wherever you send it, so share with that in mind. (Separately, reports you save to your report library while signed in on the Pro toolkit do sync to your account — see What we collect above.)
Cookies and local storage
- Essential session cookie. When you're signed in we set one secure, HttpOnly cookie
(
__Host-astro_sess) so the service knows you're logged in. It contains a random token, not your personal details. We don't use advertising or analytics cookies. - Local storage. The app keeps your settings, a cached copy of your sign-in state, and your local charts and journal entries in your browser's local storage so the app works, even offline.
- Offline cache. AstroLina can be installed as an app. When it is, your browser caches the app's own files so it loads offline — this cache holds the software, not your personal data.
How we use your information
- To run your account and sign you in (passwordless email codes).
- To process payments and run your Pro plan — checkout, renewals, trials, plan changes, and billing management, handled with Stripe (see Who we share it with below).
- To send transactional email — your sign-in codes. These are always sent; they're necessary to use the account.
- To send marketing email — only if you opted in. You can opt out at any time.
- To look up places (geocoding) — when you search for a place or tag a spot on the map, we turn the place name into coordinates, or the other way around (see Who we share it with below).
- To keep the service secure and reliable — rate-limiting and abuse prevention.
Legal bases (for users in the EU/UK)
- Running your account, signing you in, and providing the features you use (such as place lookup and syncing): performance of a contract.
- Processing your Pro payments and managing your plan: performance of a contract; keeping transaction records afterwards: our legal obligations (tax and accounting law).
- Security, rate-limiting, and abuse prevention: our legitimate interests in keeping the service safe.
- Marketing emails: your consent, which you can withdraw at any time.
Marketing emails and your choices
Product and feature emails are opt-in — the box is unchecked by default, and creating an account never requires it. You can change your mind whenever you like:
- Click unsubscribe in any marketing email, or
- Toggle email preferences on your account screen in the app.
Withdrawing consent doesn't affect your account, and you'll still receive necessary sign-in emails.
Who we share it with
We use a small number of trusted service providers ("processors") to run AstroLina:
- Cloudflare — hosting, our database, sending transactional (sign-in) email, and the "human check" (Turnstile) that protects our sign-up form from bots. (The Pro waitlist doesn't need one — you join it from inside your account.)
- Stripe — our payment processor, only if you buy Pro. Checkout happens on Stripe's secure pages: your card and billing details go to Stripe directly, and Stripe shares with us only what we need to run your plan (what you bought and its status — never your full card number). Stripe also uses payment data for its own purposes, such as fraud prevention and legal compliance, as described in Stripe's privacy policy.
- Cloudflare also sends any opt-in marketing emails, from a separate sending domain
(
news.astrolina.org) so product updates and sign-in codes keep their own reputations. Used only if you opt in. - Photon (komoot) — powers place and address search. When you type into a search box, the text you typed is relayed through our servers to Photon to find matching places; for the Pro address search, a rough map location (rounded to about 1 km) rides along so nearby results sort first. Photon receives the search text and that rounded bias point — not your IP address or identity.
- OpenStreetMap's Nominatim service — powers the reverse lookup. When a spot you tag on the map can't be named by the app's built-in offline atlas, we ask Nominatim what's there. These requests go through our servers, so Nominatim receives only the spot's coordinates rounded to about 110 m — not your IP address or identity.
- OpenFreeMap — serves the map tiles (the background map imagery, plus the map's fonts and sprites). Your browser fetches these directly, so — as with any online map — OpenFreeMap receives your IP address and the map areas you view. It never receives your birth details or account information.
These providers process data on our behalf under their own security and privacy commitments. We share your information only as needed to provide the service, or where required by law.
International transfers
We're based in Canada, and our providers operate globally. Where personal data is transferred across borders, we rely on our providers' safeguards (such as standard contractual clauses) where required.
How long we keep it
- Account information — for as long as your account exists. Delete your account and we delete it.
- Saved charts, journal entries, saved reports, and pinned places — for as long as your account exists, or until you delete them in the app (deletion markers, which make deletes reach your other devices, are cleared from our servers within about 30 days).
- Home locations on charts — until you clear or change them, or delete the chart or your account.
- Billing records — deleting your account removes your billing details from our database and we ask Stripe to close your customer record, but records of completed transactions are kept (by Stripe, and in our accounting) for as long as tax and accounting rules require — typically several years.
- Unverified sign-ups — if you request a sign-in code but never finish signing in, the email address you entered is deleted automatically after 30 days. Email us if you'd like it gone sooner.
- Sign-in codes — expire within about 10 minutes.
- Sessions — expire after about 30 days, or when you sign out.
- Security/rate-limit data — kept only briefly: counters expire with their time window and a daily cleanup purges them (the same cleanup that enforces the other windows above).
Deleting your account removes your data from our servers. Copies in your own browser (local storage) stay on your device until you clear them there.
How we protect it
- In transit. Everything travels over HTTPS. AstroLina is served only over TLS, and so is every call between your browser and our servers.
- At rest. Your account data lives in a Cloudflare D1 database, encrypted at rest by Cloudflare and reachable only by our own server code — never directly from a browser.
- Secrets are never stored in the clear. Your one-time sign-in codes and your session tokens are stored only as hashes; we could not read them back if we wanted to. Your card number never touches our servers at all (see Who we share it with).
- Access. Only the two of us can reach the production data, through accounts protected by two-factor authentication. Our internal admin dashboard sits behind single sign-on and shows account and billing status — your email, plan, and usage counts. It cannot open the content of your charts, journal entries, or reports, and it doesn't show locations. Its only write actions are granting or changing plans and sending the marketing emails described above (only ever to people who opted in), and each is logged.
- Least data. The best protection is not holding something in the first place: signed out, nothing you do leaves your browser, and even signed in you can turn syncing off entirely.
No system is perfect. If we ever discover a breach affecting your personal information, we will notify the relevant regulator and any affected account holders as required by law, and tell you plainly what happened.
Your rights
Depending on where you live (for example, under Canada's PIPEDA, the EU/UK GDPR, Quebec's Law 25, or similar laws), you may have the right to access, correct, delete, or export your information, to object to or restrict certain processing, and to withdraw consent. To exercise any of these, email contact@astrolina.org. We'll respond within 30 days. You may also lodge a complaint with your local data protection authority.
Most of these you can do yourself in the app: your charts, journal entries, saved reports and pinned places can each be deleted in place, and deleting your account removes all of them at once. For a copy of everything we hold on you, email us and we'll put it together by hand — we're two people, so there's no self-serve export button, but the request is a normal one and we'll honour it within the same 30 days.
Children
AstroLina isn't directed to children, and we don't knowingly collect information from anyone under 16. If you believe a child has given us information, email us and we'll remove it.
Changes to this policy
We may update this policy from time to time. We'll change the "Last updated" date above and, for significant changes, let account holders know.
Contact
Questions or requests? Email contact@astrolina.org.
Mailing address: AstroLina, 1 Lomond Dr, Toronto, ON M8X 2Z3, Canada
Person in charge of personal information: Salvatore Grosso, co-founder — contact@astrolina.org. (Quebec's Law 25 asks that we name someone; on a two-person project it's the same address either way.)