Privacy Policy

Version: 1.2

Last Updated: 2026-09-18

Effective Date: 2026-09-18

STORMVIBE Ltd., a Bulgarian limited liability company (EOOD), EIK 208809995, VAT BG208809995 ("Company," "we," "us," or "our"), operates StarBind, including our website at https://starbind.me, our mobile applications for iOS and Android, and all related services (collectively, the "Service").

This Privacy Policy explains how we collect, use, share, and protect your personal information when you use the Service. It also describes your rights and choices regarding your data.

One-off report purchases at the StarBind Reports storefront (starbind.me/reports) are a separate, account-free product covered by the Reports Privacy Policy. This policy governs the StarBind app and your StarBind account.

This Privacy Policy is a notice, not a contract. It tells you what we process and on which legal basis (Section 3); most of that processing rests on the contract you enter under our Terms of Service, on our legitimate interests, or on legal obligations, not on your consent. Where processing does depend on your consent, such as marketing messages, we ask for it separately and you can withdraw it at any time. When you create an account we record which version of this notice was shown to you.


1. Data Controller

For the purposes of applicable data protection laws:

2. Information We Collect

2.1 Information You Provide

Data Type Purpose Required
Email address Account creation, authentication, communications Yes
Password Account security (stored as a salted hash, never in plaintext) For email/password sign-up
Date of birth Natal chart calculation, Sun sign determination, daily horoscope, age verification (16+) Yes
Time of birth Natal chart calculation (Ascendant, house placements) Optional
Place of birth Natal chart calculation (geographic coordinates for house system) Yes
Birth coordinates Derived from place of birth for astronomical calculations Derived
House system preference Natal chart house system selection Optional
Birth data for other people you add Calculate compatibility charts, and save people to your circle for quick chart access Optional
Username / nickname Display in profile and shared content Optional
Full birth name To calculate name-based numerology values (such as your Expression, Soul Urge, and Personality numbers), whether in the app or in a paid Numerology report. The name is processed transiently on our server to derive these numbers and is not stored, logged, or sent to any LLM provider; only the resulting integers are saved Optional
Chat messages and dream journal entries Free text you write to the AI guide or record in your dream journal, used to generate the responses and readings you request. Stored under your account until deleted (see Section 7) Optional
Referral code Credit attribution for invite rewards Optional
Terms acceptance and Privacy Policy version Record of the Terms version you accepted and the Privacy Policy version presented to you, with a timestamp (GDPR Art. 5(2) accountability). Your marketing choice is a separate record, kept as consent under Art. 7 Yes

Birth-place autocomplete: when you type a birth place, the text you type is first matched against our own server-side place database; only if there is no match is the text, with no name, email, or other identifier attached, sent to a third-party geocoding service (Photon, operated by Komoot GmbH in Germany) to find matching places and their coordinates.

Data about other people you add: Some features let you enter another person's birth details (date, time, place), to calculate a compatibility chart, or to save someone to your circle for quick access. You provide this data and are responsible for having the right to share it (see our Terms of Service). We use it only to compute the chart you requested and store it under your account; you can delete it at any time, and deleting your account removes it. Because we typically hold only a name and birth details for these people, with no way to contact them, we rely on the disproportionate-effort exception in GDPR Art. 14(5)(b) rather than notifying each person individually. If your birth details were entered by someone else and you want them removed, contact legal@starbind.me.

2.2 Information Collected Automatically

Data Type Purpose
IP address Security, abuse prevention, and rate limiting. We do not derive your location from your IP address, and IP addresses are not written to our usage or crash telemetry
Device information OS type, version, and device model (for compatibility and debugging)
Device identifier Stable per-install ID used to bind your account to the device that registered it
Device timezone Read once at signup to seed your profile timezone, which schedules notifications and daily content in your local time. Changed only explicitly in your account settings, never silently re-synced
Device attestation token Apple App Attest / Google Play Integrity attestation, used at signup and for in-app purchases to confirm requests originate from a genuine, unmodified app instance
App version Troubleshooting, feature availability
Usage data (app) Screens visited and feature-usage events in the app, recorded under a random per-session identifier that is never stored on your device and never linked to your account, for first-party analytics and product improvement. No third-party analytics service receives the app's telemetry; the app contains no analytics or advertising SDK. Website measurement is separate and is described in the next row and in Section 6
Website visit data (starbind.me and starbind.me/reports, never the app) Whatever you choose in the banner, our own server counts how many checkouts are started on the reports storefront (legitimate interest), with no identifier attached and nothing stored on your device; without Analytics consent that count carries no campaign channel. Your browser measures nothing until you accept a category. After you accept Analytics: arrivals and page views per page and campaign channel. After you accept Analytics or Advertising: the event data and the technical request data described in Section 6, processed by the vendors named there. The banner asks before anything else runs; no page you type birth details into carries a measurement tag at all - this site's Big Three page and its free chart tools, the reports Big Three page and the reports order form - and neither do the legal pages or the reports library pages
Crash and error reports Identifying and fixing technical issues. Reports contain the technical error and the screen it occurred on; they are not linked to your account
Report download access events When a sharable report download link is opened, we log a hashed IP (SHA-256 with a daily-rotating salt; we cannot recover the original IP), 2-letter country code, browser user-agent, HTTP Referer header (when sent), and timestamp. Used for fraud prevention and aggregated download analytics. We do not set tracking cookies or share these logs with third-party analytics providers.

2.3 Information from Third Parties

We may receive information from:

You can create an account either with an email address and password or with Sign in with Apple or Sign in with Google. We do not support Facebook or other social-login providers.

2.4 Information We Retain After Account Deletion

When you delete your account, we hard-delete all of the data above except for one record: a counter of how many StarBind accounts have been created from your physical device (via the device identifier in §2.2). We keep only the count, not your account or any of its contents, in a separate table that has no link back to you. We rely on this counter under GDPR Art. 6(1)(f) (legitimate interests) to limit account-creation abuse.

We also retain anonymized audit-log entries (event type, hashed email, timestamp) sufficient to demonstrate that deletion, consent, and other security-relevant events occurred (GDPR Art. 5(2) accountability). These anonymized entries are retained for 24 months from the date of the event, after which they are deleted.

3. How We Use Your Information

We use your personal information for the following purposes:

Purpose Legal Basis (GDPR)
Provide the Service: calculate natal charts, generate horoscopes, deliver readings Contract performance
Create and manage your account Contract performance
Process payments for premium features Contract performance
Generate AI-powered content: daily horoscopes and interpretive readings via LLM Contract performance / Legitimate interest
Send transactional communications: account verification, password resets, subscription updates, billing notifications Contract performance
Send marketing communications: emails or push notifications about new features, content, or promotions Consent, withdrawable at any time via your account settings or the unsubscribe link in any marketing email, without affecting the lawfulness of prior processing
Improve the Service: analyze usage patterns, fix bugs, develop new features Legitimate interest
Limit account-creation abuse: count of accounts created per device (see §2.4) Legitimate interest
Ensure security: detect fraud, prevent abuse, enforce our Terms Legitimate interest
Operate sharable report download links: count downloads, log referrer and hashed IP for fraud prevention and aggregated analytics Legitimate interest
Compute and store charts for other people you add: compatibility charts and people you save to your circle Legitimate interest
Count checkout starts on the reports storefront, counted by our own server when the checkout is created, with no identifier and no device storage (the campaign channel is attached only if you accepted Analytics; otherwise the count is untagged) Legitimate interest
Measure how the website is used (Analytics category): Google Analytics 4 plus our own arrival and page-view counts per page and campaign channel, the rest of our per-step funnel counters (report viewed, sample opened, cart add, store button) and per-tab link attribution, on starbind.me and the reports storefront only Consent, given in the cookie banner and withdrawable at any time via "Cookie settings" in the website footer
Measure whether an ad led to a purchase and build remarketing audiences (Advertising category): Google Ads, Meta and Reddit tags report product views, checkout starts and confirmed purchases, and each platform holds two audiences for 30 days: people who viewed a report and did not buy, and people who started checkout and did not buy Consent, given in the cookie banner and withdrawable at any time via "Cookie settings" in the website footer; a Global Privacy Control signal counts as a refusal of this category
Keep evidence of your cookie choice (receipt id, wording revision, language, the two category answers, the action and the time; nothing that identifies you) Legal obligation (GDPR Art. 7(1))
Comply with legal obligations: respond to lawful requests, meet regulatory requirements Legal obligation

3.2 Automated Decisions and Profiling

We will never use your birth data, account information, or content you submit to make decisions based solely on automated processing that produce legal or similarly significant effects on you (GDPR Article 22). The natal-chart calculations and automatically generated readings the Service provides are entertainment content; they have no legal or contractual consequences for you.

The remarketing audiences in Section 3.1 group website visitors by two actions (viewed a report, started checkout) for 30 days so the platform can show them a StarBind ad. That is the only profiling we do, it runs only with your consent to the Advertising category, it uses no account data, no birth data and no report content, and it has no legal or similar effect on you.

4. AI and LLM Data Processing

We use third-party large language model (LLM) providers to generate personalized astrological content such as daily horoscopes, readings and chat replies. We work with two LLM providers, each under its own data processing agreement, and may route any of the content below to either of them: OpenAI (OpenAI API) and Google (Vertex AI, which hosts Google's own models and third-party models on Google's infrastructure). Which provider serves a given feature is an operational choice we can change at any time; what data each kind of content carries does not change with the provider and is described here and in the table in Section 5:

5. Service Providers and Other Recipients

We do not sell your personal information. The recipients below operate the Service for us or, where the Role column says so, decide for themselves how they use what they receive. The four website-tag rows (Google Analytics, Google Ads, Meta, Reddit) receive data only after you accept the matching category in the website cookie banner (Section 6); they never receive anything from the app.

Recipient Role Purpose Data shared Region Transfer mechanism
Google LLC (Firebase Cloud Messaging + Vertex AI) Processor Push notification delivery; LLM provider for automatically generated horoscopes, readings and chat responses Push device tokens; notification body. For LLM processing, the data described in Section 4: astrological data without account identifiers, the yearly-reading transition date and age, free text you submit in chat or dream entries and the display nicknames a feature uses LLM processing: European Union (Vertex AI EU multi-region, pinned in our code). Push delivery: United States EU-US Data Privacy Framework (Google LLC self-certified) and EU Standard Contractual Clauses (Google Cloud Data Processing Addendum); no training on API data; retention as described in Section 4
OpenAI, L.L.C. (OpenAI API) Processor LLM provider for automatically generated horoscopes, readings and chat responses; automatically generated images, such as shareable cosmic artwork For readings, horoscopes and chat: the data described in Section 4: astrological data without account identifiers; for yearly readings only, the exact birthday-derived date on which your astrological year turns and your age at that point; free text you submit in chat or dream entries, plus the display nicknames a feature uses. For images: the prompt text describing the image to generate, which carries astrological themes plus the display nicknames you set for yourself or for people in your circle, where a feature uses them (for example, compatibility artwork) Global endpoint, no regional restriction (United States and other countries where OpenAI and its sub-processors operate) EU Standard Contractual Clauses (OpenAI Data Processing Addendum); no training on API data; retention as described in Section 4
Brevo (Sendinblue SA) Processor Transactional email: account verification, password reset, billing notifications Email address; subject line and body of the message European Union (France) EU processing; any onward transfer by Brevo's own sub-processors is governed by Brevo's data processing agreement and its Standard Contractual Clauses
Cloudflare, Inc. Processor Hosting for the starbind.me website (landing pages, learn reference, horoscopes, sky news, free chart tools, and the reports storefront), content delivery network, DNS, share-link Worker, object storage (R2: generated images, shareable report files, and app-update bundles), Turnstile anti-abuse checks, and the reverse proxy in front of our API (api.starbind.me) that filters abusive and automated traffic before it reaches our servers. Cloudflare Web Analytics is switched off IP address; standard web request data (URL, headers, user-agent); images and report files generated for you and stored in R2; the content of your requests to and responses from the app's API, in transit only (Cloudflare decrypts and re-encrypts each request at its edge to inspect it for abuse; it does not store request or response bodies, and it keeps only request metadata such as IP address, URL and timing) United States with EU edge network EU Standard Contractual Clauses
Microsoft Corporation (Microsoft Azure) Processor Primary server infrastructure for the API, database, and caching; application monitoring (server logs plus the usage and crash telemetry described in Section 2.2); storage of the website cookie-consent evidence described in Section 6.5 All data described in Section 2, at rest, including the consent evidence (receipt id, wording revision, language, two category answers, action, time; no IP address, user agent, page address, email, account or order) European Union (Azure EU regions, within the Microsoft EU Data Boundary) Customer data is stored and processed in EU regions. Microsoft may make limited transfers outside the EU Data Boundary in the circumstances set out in its Product Terms (for example security investigations, remote support, or service quality), under the safeguards in the Microsoft Products and Services Data Protection Addendum
Komoot GmbH (Photon geocoder) Processor Birth-place autocomplete: turning the place name you type into coordinates for your chart, queried only as a fallback when our own server-side place cache has no match The place text you type (e.g. "Sofia"); no name, email, or other identifier is attached European Union (Germany) No third-country transfer required (EU→EU)
Apple Inc. (App Store) Merchant of record (independent controller for payment) In-app purchase processing, subscription management, receipt validation Payment confirmations, subscription state, transaction identifiers (we never receive card numbers) United States Apple Paid Apps Agreement
Google LLC (Google Play) Merchant of record (independent controller for payment) In-app purchase processing, subscription management, receipt validation Payment confirmations, subscription state, transaction identifiers (we never receive card numbers) United States Google Play Developer Distribution Agreement
Google Ireland Ltd (Google Tag Manager + Google Analytics 4; website only) Processor under the Google Ads Data Processing Terms Loads the tag container as soon as you accept either optional category and fires only the tags of the categories you accepted; the Google Analytics tag inside it runs under the Analytics category and measures how the website is used: pages viewed, reports viewed, sample opened, checkout started, app-store button clicked, purchase completed Event fields we send: page path, surface (site or reports), language, report SKU, name, price and currency, order value, currency, gift flag and an opaque order token. Technical request data the tag processes automatically: IP address, user agent, page URL and referrer, its own cookie identifiers (_ga, _ga_<id>), timestamps and your consent state. Never your email, name, birth data, promo code, payment or download identifiers. Google Analytics keeps event-level data for 2 months (our setting) Ireland (EU); Google may process in other countries where it or its sub-processors operate Google Ads Data Processing Terms, with the EU Standard Contractual Clauses they incorporate for restricted transfers and Google LLC's EU-US Data Privacy Framework certification
Google Ireland Ltd (Google Ads tag; website only, Advertising category) Independent controller under the Google Ads Controller-Controller Data Protection Terms Measures whether a Google ad led to a report view, a checkout start or a purchase, and holds the two 30-day remarketing audiences described in Section 3.1 The same event fields as the Analytics row. Technical request data the tag processes automatically: IP address, user agent, page URL and referrer, its cookie and click identifiers (_gcl_au, _gcl_aw, _gcl_gb, and the gclid/gbraid/wbraid value from the ad link if you accept Advertising in that visit), timestamps and your consent state Ireland (EU); Google may process in other countries where it or its sub-processors operate Google's controller terms, with the EU Standard Contractual Clauses they incorporate for restricted transfers and Google LLC's EU-US Data Privacy Framework certification
Meta Platforms Ireland Ltd (Meta Pixel; website only, Advertising category) Joint controller with us for the event data the pixel collects for ad delivery and optimisation, and our processor for matching and measurement, under the Meta Business Tools Terms Measures whether a Facebook or Instagram ad led to a report view, a checkout start or a purchase, and holds the two 30-day remarketing audiences described in Section 3.1 The same event fields as the Analytics row. Technical request data the pixel processes automatically: IP address, user agent, page URL and referrer, its cookie and click identifiers (_fbp, _fbc, and the fbclid value from the ad link if you accept Advertising in that visit), timestamps and your consent state Ireland (EU); Meta's onward transfers to Meta Platforms, Inc. (United States) Meta Business Tools Terms; transfers under the Global Data Transfer Addendum they incorporate (EU Standard Contractual Clauses) and Meta Platforms, Inc.'s EU-US Data Privacy Framework certification
Reddit Netherlands B.V. (Reddit Pixel; website only, Advertising category) Independent controller for event data under the Reddit Advertising Data Processing Agreement Measures whether a Reddit ad led to a report view, a checkout start or a purchase, and holds the two 30-day remarketing audiences described in Section 3.1 The same event fields as the Analytics row. Technical request data the pixel processes automatically: IP address, user agent, page URL and referrer, its cookie identifier (_rdt_uuid), timestamps and your consent state. The rdt_cid value an ad link carries is removed before any tag loads and is never passed on Netherlands (EU); onward transfer to Reddit, Inc. (United States) EU-US Data Privacy Framework (Reddit, Inc. self-certified), with the EU Standard Contractual Clauses in Reddit's agreement as the fallback
TikTok Technology Ltd Not enabled No TikTok tag runs on the website and no data goes to TikTok. If we enable it, we update this policy and the cookie banner first None n/a n/a
Law enforcement and regulators Independent recipient When legally required or to protect our rights, your rights, or the rights of others As required by applicable law Varies As permitted by applicable law

Processors act only on our written instructions, under confidentiality and data protection terms. Where a recipient is a joint or independent controller (Apple and Google for payments; Google Ads, Meta and Reddit for the advertising events you consent to), its own privacy notice governs what it does with the data after receipt, and we cannot recall data already sent. The consent banner software we use (CookieConsent by Orest Bida, self-hosted under the MIT licence) runs from our own servers and sends nothing to its author; it is not a recipient. We update this list before a new recipient receives your data.

For the joint processing described above, we and Meta have agreed how to divide our responsibilities under the Meta Controller Addendum. We provide the notice, obtain the required consent and are responsible for the correct, secure integration on our site. Meta is responsible for security of its own product and for enabling access, correction, deletion, restriction and portability rights for personal data it holds after the joint processing. Each party remains responsible for the lawfulness of its own processing. You may exercise your rights against either party: contact us at legal@starbind.me, or use the contacts and rights information in Meta's Privacy Policy. We forward requests requiring Meta's action.

6. Cookies and Tracking Technologies

6.1 The App and the Website Are Different

The app (iOS and Android) stores only what it needs to run: your sign-in token, your settings and cached content, in the app's own storage. It contains no analytics or advertising SDK, sets no tracking cookies and sends its first-party telemetry (Section 2.2) under a random per-session identifier. Nothing in this Section 6 beyond that paragraph applies to the app.

The website (starbind.me, including the reports storefront at starbind.me/reports) asks before it measures. On first visit a banner offers three choices of equal weight: Accept all, Reject all, or Manage (choose per category). Nothing optional is pre-ticked. No analytics or advertising tag loads until you accept its category, and the banner never shows on its own on the pages that carry no tags at all, whatever you chose elsewhere: this site's Big Three and free chart tools, the reports Big Three page, order form, library, download, redeem and deletion pages, and the legal pages. Every page you enter birth details on is one of them.

6.2 Categories

The tag container itself (Google Tag Manager) loads as soon as you accept either optional category, and fires only the tags of the categories you accepted. Loading it means your browser requests the container from Google, which sees your IP address, user agent and page address in that request.

What we deliberately send to a tag is limited to: page path (without query string), surface (site or reports), language, the SKU, name, price and currency of a report you view, a checkout start, which app-store button you clicked, and after a confirmed purchase the order value, currency, gift flag and an opaque order token. Never your email or a hash of it, your name, birth data, promo code, payment, access or download identifiers, or free text.

Every vendor tag, once loaded, also processes technical request data on its own: your IP address, user agent, the page URL and referrer, its cookie or click identifiers, timestamps and your consent state. Section 5 names the vendor, its role and its transfer basis for each tag.

Before any tag or even the banner runs, our own script removes the ad-click identifier and any unlisted query parameter from the page address. If you accept Advertising in that same visit, the Google or Meta identifier is written into that vendor's own cookie (_gcl_aw or _gcl_gb, _fbc) so the platform can attribute a later purchase to its ad; otherwise it is discarded when you leave the page. Reddit and TikTok click identifiers (rdt_cid, ttclid) are always discarded: neither platform publishes a cookie format or a browser interface that would let us hand one over without putting it back in the page address.

6.3 What Is Stored on Your Device

Name Set by Purpose Category Lifetime
sb_consent (cookie) StarBind Your cookie choice, the wording revision you answered and the receipt id of the evidence record Necessary 6 months
App sign-in token and settings (app storage) StarBind Keeps you signed in to the app Necessary Until you sign out or delete the app
sb_reports_session (cookie, HttpOnly) StarBind Reports library sign-in Necessary 90 days, renewed while you use the library
Report cart, promo code (sb:promo), checkout recovery (sb:success), order-form hand-off (browser storage) StarBind Operate the reports storefront; the tab-scoped items are cleared when the tab closes Necessary Cart: 7 days after the last change; the rest: the browser tab
Dismissed-note flag (localStorage) StarBind Remembers you dismissed an informational note Necessary Until you clear browser storage
starbind:sun-sign (session storage) StarBind Remembers the sign the free chart widget computed while you stay in the tab Necessary The browser tab
Cloudflare Turnstile Cloudflare Anti-bot check on forms; cookieless Necessary None
sb:attr (session storage) StarBind Which tagged link brought you to this tab, so each funnel step is counted once and an order can name its channel Analytics The browser tab
sb:mk:ga4:<order> (local storage) StarBind Stops a purchase being reported to Google Analytics twice Analytics 90-day validity; see deletion note below
_ga, _ga_<id> (cookies) Google Analytics 4 Distinguishes visitors and sessions Analytics 2 years
sb:mk:google_ads:<order>, sb:mk:meta:<order>, sb:mk:reddit:<order> (local storage) StarBind Stops a purchase being reported to that platform twice Advertising 90-day validity; see deletion note below
_gcl_au (cookie) Google Ads Conversion measurement Advertising 3 months
_gcl_aw, _gcl_gb (cookies) Google Ads Holds the Google ad-click identifier from the link you arrived on Advertising 3 months
_gcl_ls (local storage, when used by the Google tag) Google Ads Ad-click attribution state Advertising No browser-set expiry; cleared here on withdrawal
_fbp, _fbc (cookies) Meta Distinguishes browsers; holds the Meta ad-click identifier from the link you arrived on Advertising 3 months
_rdt_uuid (cookie) Reddit Distinguishes browsers for conversion measurement Advertising 3 months

Purchase markers sb:mk:* are valid for 90 days. Expired entries are removed on the next use with consent for their category; withdrawal clears that category's markers. No deletion code runs while the site is closed, so entries may remain until such a return visit or browser clearing.

The vendor lifetimes are the values each vendor documents; we re-verify every row in a clean browser, for each consent combination, before the tags are enabled and again whenever a tag changes. Payment for reports happens on Stripe's own checkout pages (checkout.stripe.com), where Stripe's cookie policy applies.

6.4 Your Choices and Withdrawal

"Cookie settings" in the website footer, available in the site footer (static legal pages link back to the site's preferences), reopens the preference sheet. Withdrawing a category takes effect at once: the vendors are told the category is now denied, the items listed for that category in Section 6.3 are deleted from your browser as far as this site can reach them, and if code for the withdrawn category had already loaded on the page, the page reloads so the withdrawn tags stop running. A cookie a vendor set on its own domain rather than ours is not something a script on this site can delete; it stays until your browser or that vendor drops it, and you can remove it yourself in your browser settings. Withdrawal is as easy as consent and needs no email or account.

Withdrawal stops future collection. It cannot recall data a vendor already received; what a platform keeps after receipt, including your membership of a remarketing audience until it lapses after 30 days, is governed by that platform's own terms and by the rights you can exercise with it directly. If we change the banner wording, the categories or the vendors, the banner asks you again.

You can also block or delete cookies in your browser. Deleting sb_consent means the banner asks again; deleting the other necessary items signs you out of the reports library or empties your cart.

Whenever you make, change or withdraw a choice in the banner, your browser sends our server one record: a random receipt id, the wording revision you answered, the language you saw it in, your Analytics and Advertising answers, the kind of action (first choice, change, withdrawal) and the server's time. The receipt id is stored in sb_consent so the stored preference and the evidence can be matched; a granted category is activated only after the record is saved. The record holds no IP address, user agent, page address, email, account or order, and it is deleted 13 months after it is written. Rejections and withdrawals apply immediately whether or not the record is saved.

6.6 Global Privacy Control (GPC)

If your browser sends a Global Privacy Control signal, the website treats the Advertising category as refused on every page, whatever the banner or an earlier choice says, and no advertising tag loads. You can still accept Analytics.

7. Data Retention

We keep each category of personal data only for as long as it is needed to provide the Service to you. Where a fixed period isn't meaningful, we delete data after a defined period of inactivity. Specifically:

Data Retention Period
Your account and the content you create or save in it (other than chat conversations) Until you delete it. Inactive accounts are deleted 24 months after the last sign-in.
Chat conversations (the messages you send and the responses you receive) Deleted 12 months after the conversation's last message
Usage and crash telemetry (session-scoped, never linked to your account) Up to 24 months
Anonymized audit-log entries (post-deletion accountability records, see §2.4) 24 months from the date of the event
Payment records As required by Bulgarian tax and accounting law (10 years, Accountancy Act art. 12)
Server logs Up to 90 days
Report download access logs 90 days
Website cookie-consent evidence (receipt id, wording revision, language, two category answers, action, time; see §6.5) 13 months from the record's date
Website purchase once-markers (sb:mk:*, on your device only) 90-day validity; expired entries cleared on next consented use, or on category withdrawal (Section 6.3)
Data held by the website tag vendors Google Analytics event data: 2 months (our setting). Remarketing audiences at Google Ads, Meta and Reddit: 30 days. Other vendor-side data: per that vendor's terms (Section 5)

Account deletion removes your data from our live systems immediately (see Section 11.1). Copies in our encrypted database backups age out within 7 days. Anything we must keep by law is retained for the periods in the table above.

8. Data Security

We implement industry-standard technical and organizational measures to protect your personal data, including:

Despite these measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.

9. Access by StarBind Staff

We strictly separate the data our staff can routinely view from content you create inside the Service.

Operational metadata: Authorised staff can view your account email, account status, subscription tier and free-credit balances, transaction history (records of purchases, spends, and refunds, without the prompt or response text of any individual feature), device identifier, the IP addresses recorded on security audit events (consent records, password changes, failed device-attestation attempts), and audit-log events. We use this access to provide support, process billing and refunds, prevent fraud, and enforce our Terms.

User-generated content: Conversations you have through the Service, dream journal entries you write, custom names and birth data you save for other people in your circle, and image-generation prompts you submit are not routinely accessible to staff. Staff review such content only when:

Each instance in which staff access user-generated content is logged in our audit log and is auditable.

10. International Data Transfers

Your data is primarily processed and stored on servers located in the European Union. Some recipients listed in Section 5 process specific, limited data in the United States under the safeguards described there. The website tag vendors contract with us through their EU entities (Google Ireland Ltd, Meta Platforms Ireland Ltd, Reddit Netherlands B.V.); their onward transfers to the United States rest on the safeguards named per row in Section 5, and they receive data only after your consent. If you access the Service from outside the EU, your information may be transferred to and processed in a country with different data protection laws.

For EU/EEA/UK users: Where we transfer personal data outside the EU/EEA/UK, we rely on:

You may request a copy of the applicable safeguards by contacting us.

11. Your Rights

11.1 For All Users

Regardless of your location, you may:

11.2 For EU/EEA/UK Users (GDPR)

Under the General Data Protection Regulation, you have the following additional rights:

To exercise these rights, contact us at legal@starbind.me. We respond without undue delay and at the latest within one month of receiving your request. For complex or numerous requests we may take up to two further months; if so, we tell you within the first month and explain why (GDPR Art. 12(3)).

If you believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local supervisory authority. Our lead supervisory authority is the Bulgarian Commission for Personal Data Protection (Комисия за защита на личните данни / КЗЛД), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria: https://www.cpdp.bg.

11.3 For California Residents (CCPA/CPRA)

Under the California Consumer Privacy Act and California Privacy Rights Act, you have the right to:

To submit a request, contact us at legal@starbind.me. We will verify your identity before processing your request.

11.4 For Residents of Other US States

If you reside in Colorado, Connecticut, Virginia, Utah, or other states with consumer privacy laws, you may have similar rights to access, delete, correct, and opt out of certain data processing. Contact us at legal@starbind.me to exercise your rights.

12. Children's Privacy

The Service is not directed to children under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at legal@starbind.me, and we will promptly delete such information.

13. Changes to This Privacy Policy

We update this Privacy Policy when our processing changes and publish the current version with its effective date. Where applicable law requires consent for new processing, we request that consent before the processing begins. Where applicable law requires direct notice of a change, we provide it through an appropriate channel.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

For EU/EEA data protection inquiries: contact us at the address above. The Company is established in the European Union (Bulgaria) and an Article 27 representative is not required.


This Privacy Policy was last updated on 2026-09-18.

← Back to StarBind · Cookie settings