Euphia
Privacy Policy
Euphia is a personal astrology app for iOS and Android. Its astrology content is for entertainment and self-reflection. This Privacy Policy explains what data we process, why, and how you stay in control. You use Euphia anonymously by default — no name, email, or phone number is required to use the app.
1. Data controller
The party responsible for processing your personal data (the controller under GDPR; the veri sorumlusu under KVKK):
- Name: Seyfettin Yıldırım
- Address: Gaziantep, Türkiye (full postal address available on request)
- Contact: euphiaapp@gmail.com
2. In short
- Anonymous by default: your identity is an app-generated anonymous ID.
- On-device calculation: your natal chart is calculated on your device (Swiss Ephemeris).
- AI is optional: AI interpretations run only when you grant a separate, explicit consent. If you decline, the app still works using non-personalised templates.
- No tracking: we do not use the advertising ID (IDFA), and we do not do cross-app or ATT tracking.
- You stay in control: withdraw consent anytime, export your data, and delete your account.
3. What we process, why, and the legal basis
| Data | Purpose | Legal basis (GDPR / KVKK) |
|---|---|---|
| Birth date, time, and place | Calculate your natal chart (on your device); power AI interpretations if you enable AI | Consent for AI use; legitimate interest / contract for on-device calculation |
| Free text you write (Time Machine notes / reflections) | Sent to AI to personalise a reading only if you grant the separate AI-text consent; may include sensitive details | Explicit consent (special-category data / KVKK açık rıza). Not sent to AI without it. |
| App-generated device anchor (a hashed ID derived from an iOS Keychain UUID / Android ID) | Restore your data and subscription after reinstall on the same device | Legitimate interest / contract. This is not the advertising ID (IDFA); no cross-app tracking. |
| Push notification token | Deliver notifications you turned on (e.g. anniversaries) | Consent |
| Usage analytics + crash reports (Firebase) | Improve the app, diagnose crashes | Consent (analytics can be turned off in-app) |
| Subscription status (Euphia Pro) | Manage your subscription and entitlements | Contract / legitimate interest |
| Minimal server logs (IP address, AI usage counts, rate / abuse limits) | Security, abuse prevention, cost control | Legitimate interest |
4. On-device calculation and AI consent
Your natal chart is calculated on your device. AI interpretations are optional and gated behind an explicit in-app consent. If you decline, the app keeps working using non-personalised templates.
Free text you write (for example Time Machine notes) may contain sensitive details. It is forwarded to the AI provider only when you give a separate explicit consent. Without that consent, your text stays on your device and is not sent to AI.
Euphia does not use your data for automated decisions that produce legal or similarly significant effects (GDPR Art. 22). AI interpretations are for information and self-reflection only.
5. Sub-processors
We rely on a small number of trusted service providers (sub-processors) to run the service. For the current list of who receives data, for what purpose, and where, see the Sub-processors page.
6. International transfers
The AI providers (Anthropic, Groq), Firebase, and RevenueCat may process personal data outside the EEA / Türkiye (e.g. the United States). The safeguards are the providers' Data Processing Agreements (DPAs) and Standard Contractual Clauses (SCCs).
KVKK note: cross-border transfer rules changed with the 2024 KVKK amendments. A lawyer should confirm the correct transfer mechanism (explicit consent, adequacy, or an undertaking).
7. Retention
Personal data is kept while your account / the app is in use and is deleted when you delete your account (server-side cascade + local wipe). Concretely:
- Account and content data: until you delete your account; on deletion it is removed from live systems without undue delay and purged from backups within 30 days.
- Abuse / rate-limit logs: up to 90 days.
- Analytics and crash data: follow the provider's default retention (typically up to 14 months for analytics; up to 90 days for crash reports).
8. Your rights
Under GDPR Art. 15–22 and KVKK Art. 11 you have the right to:
- Access your data and obtain a copy;
- Rectification of inaccurate or incomplete data;
- Erasure — via Delete account in the app;
- Portability / export — via Export my data in the app;
- Restriction of, and objection to, processing;
- Withdraw consent — via the in-app AI and analytics toggles, which stops future processing.
To exercise these rights outside the app, contact euphiaapp@gmail.com. You also have the right to complain to a supervisory authority — in Türkiye the Personal Data Protection Authority (KVKK); for EU users, your local data protection authority.
9. Children
Euphia is not directed to children under 13, and we do not knowingly collect their personal data. If we learn that a child has provided us data, we delete it. This minimum age is kept consistent with the app store age rating.
10. Security
We apply reasonable technical and organisational measures to protect your data: encryption in transit (HTTPS/TLS), encryption at rest on our servers (via our backend provider), access controls (each user can access only their own data), and data minimisation. Data stored on your device is protected by your device's operating-system security. No method is 100% secure, but we aim to minimise risk.
11. Changes
This policy is versioned with an effective date. Material changes are surfaced in-app and may require re-consent (the app tracks a consent version).
12. Contact
For privacy questions or requests: euphiaapp@gmail.com.
This document is a technically accurate draft based on Euphia's actual data flows, and is not legal advice. It should be reviewed by a qualified lawyer before publication — particularly for KVKK (Türkiye), the controller identity, and the cross-border transfer mechanism.