Privacy Policy
Version: 1.2
Last Updated: 2026-09-18
Effective Date: 2026-09-18
STORMVIBE Ltd., a Bulgarian limited liability company (EOOD), EIK 208809995, VAT BG208809995 ("Company," "we," "us," or "our"), operates StarBind, including our website at https://starbind.me, our mobile applications for iOS and Android, and all related services (collectively, the "Service").
This Privacy Policy explains how we collect, use, share, and protect your personal information when you use the Service. It also describes your rights and choices regarding your data.
One-off report purchases at the StarBind Reports storefront (starbind.me/reports) are a separate, account-free product covered by the Reports Privacy Policy. This policy governs the StarBind app and your StarBind account.
This Privacy Policy is a notice, not a contract. It tells you what we process and on which legal basis (Section 3); most of that processing rests on the contract you enter under our Terms of Service, on our legitimate interests, or on legal obligations, not on your consent. Where processing does depend on your consent, such as marketing messages, we ask for it separately and you can withdraw it at any time. When you create an account we record which version of this notice was shown to you.
1. Data Controller
For the purposes of applicable data protection laws:
- Data Controller: STORMVIBE Ltd. (EIK 208809995, VAT BG208809995), 27E Srebarna Street, Bldg. 7, Entr. A, Apt. A2, Lozenets District, Sofia 1407, Bulgaria, legal@starbind.me
- EU/EEA Representative (GDPR Article 27): Not required. The Company is established in the European Union (Bulgaria) and acts as data controller from within the EU.
2. Information We Collect
2.1 Information You Provide
| Data Type | Purpose | Required |
|---|---|---|
| Email address | Account creation, authentication, communications | Yes |
| Password | Account security (stored as a salted hash, never in plaintext) | For email/password sign-up |
| Date of birth | Natal chart calculation, Sun sign determination, daily horoscope, age verification (16+) | Yes |
| Time of birth | Natal chart calculation (Ascendant, house placements) | Optional |
| Place of birth | Natal chart calculation (geographic coordinates for house system) | Yes |
| Birth coordinates | Derived from place of birth for astronomical calculations | Derived |
| House system preference | Natal chart house system selection | Optional |
| Birth data for other people you add | Calculate compatibility charts, and save people to your circle for quick chart access | Optional |
| Username / nickname | Display in profile and shared content | Optional |
| Full birth name | To calculate name-based numerology values (such as your Expression, Soul Urge, and Personality numbers), whether in the app or in a paid Numerology report. The name is processed transiently on our server to derive these numbers and is not stored, logged, or sent to any LLM provider; only the resulting integers are saved | Optional |
| Chat messages and dream journal entries | Free text you write to the AI guide or record in your dream journal, used to generate the responses and readings you request. Stored under your account until deleted (see Section 7) | Optional |
| Referral code | Credit attribution for invite rewards | Optional |
| Terms acceptance and Privacy Policy version | Record of the Terms version you accepted and the Privacy Policy version presented to you, with a timestamp (GDPR Art. 5(2) accountability). Your marketing choice is a separate record, kept as consent under Art. 7 | Yes |
Birth-place autocomplete: when you type a birth place, the text you type is first matched against our own server-side place database; only if there is no match is the text, with no name, email, or other identifier attached, sent to a third-party geocoding service (Photon, operated by Komoot GmbH in Germany) to find matching places and their coordinates.
Data about other people you add: Some features let you enter another person's birth details (date, time, place), to calculate a compatibility chart, or to save someone to your circle for quick access. You provide this data and are responsible for having the right to share it (see our Terms of Service). We use it only to compute the chart you requested and store it under your account; you can delete it at any time, and deleting your account removes it. Because we typically hold only a name and birth details for these people, with no way to contact them, we rely on the disproportionate-effort exception in GDPR Art. 14(5)(b) rather than notifying each person individually. If your birth details were entered by someone else and you want them removed, contact legal@starbind.me.
2.2 Information Collected Automatically
| Data Type | Purpose |
|---|---|
| IP address | Security, abuse prevention, and rate limiting. We do not derive your location from your IP address, and IP addresses are not written to our usage or crash telemetry |
| Device information | OS type, version, and device model (for compatibility and debugging) |
| Device identifier | Stable per-install ID used to bind your account to the device that registered it |
| Device timezone | Read once at signup to seed your profile timezone, which schedules notifications and daily content in your local time. Changed only explicitly in your account settings, never silently re-synced |
| Device attestation token | Apple App Attest / Google Play Integrity attestation, used at signup and for in-app purchases to confirm requests originate from a genuine, unmodified app instance |
| App version | Troubleshooting, feature availability |
| Usage data (app) | Screens visited and feature-usage events in the app, recorded under a random per-session identifier that is never stored on your device and never linked to your account, for first-party analytics and product improvement. No third-party analytics service receives the app's telemetry; the app contains no analytics or advertising SDK. Website measurement is separate and is described in the next row and in Section 6 |
| Website visit data (starbind.me and starbind.me/reports, never the app) | Whatever you choose in the banner, our own server counts how many checkouts are started on the reports storefront (legitimate interest), with no identifier attached and nothing stored on your device; without Analytics consent that count carries no campaign channel. Your browser measures nothing until you accept a category. After you accept Analytics: arrivals and page views per page and campaign channel. After you accept Analytics or Advertising: the event data and the technical request data described in Section 6, processed by the vendors named there. The banner asks before anything else runs; no page you type birth details into carries a measurement tag at all - this site's Big Three page and its free chart tools, the reports Big Three page and the reports order form - and neither do the legal pages or the reports library pages |
| Crash and error reports | Identifying and fixing technical issues. Reports contain the technical error and the screen it occurred on; they are not linked to your account |
| Report download access events | When a sharable report download link is opened, we log a hashed IP (SHA-256 with a daily-rotating salt; we cannot recover the original IP), 2-letter country code, browser user-agent, HTTP Referer header (when sent), and timestamp. Used for fraud prevention and aggregated download analytics. We do not set tracking cookies or share these logs with third-party analytics providers. |
2.3 Information from Third Parties
We may receive information from:
- App stores: Apple App Store and Google Play share purchase, subscription, and refund events for the products you buy from us.
- Push notification providers: Firebase Cloud Messaging issues a device token we use to deliver notifications you have opted into.
- Sign-in providers: if you choose Sign in with Apple or Sign in with Google, we receive a signed identity token containing your email address and a stable account identifier, used only to create and authenticate your account. We never receive your password for those accounts and do not post to them.
You can create an account either with an email address and password or with Sign in with Apple or Sign in with Google. We do not support Facebook or other social-login providers.
2.4 Information We Retain After Account Deletion
When you delete your account, we hard-delete all of the data above except for one record: a counter of how many StarBind accounts have been created from your physical device (via the device identifier in §2.2). We keep only the count, not your account or any of its contents, in a separate table that has no link back to you. We rely on this counter under GDPR Art. 6(1)(f) (legitimate interests) to limit account-creation abuse.
We also retain anonymized audit-log entries (event type, hashed email, timestamp) sufficient to demonstrate that deletion, consent, and other security-relevant events occurred (GDPR Art. 5(2) accountability). These anonymized entries are retained for 24 months from the date of the event, after which they are deleted.
3. How We Use Your Information
3.1 Purposes and Legal Bases
We use your personal information for the following purposes:
| Purpose | Legal Basis (GDPR) |
|---|---|
| Provide the Service: calculate natal charts, generate horoscopes, deliver readings | Contract performance |
| Create and manage your account | Contract performance |
| Process payments for premium features | Contract performance |
| Generate AI-powered content: daily horoscopes and interpretive readings via LLM | Contract performance / Legitimate interest |
| Send transactional communications: account verification, password resets, subscription updates, billing notifications | Contract performance |
| Send marketing communications: emails or push notifications about new features, content, or promotions | Consent, withdrawable at any time via your account settings or the unsubscribe link in any marketing email, without affecting the lawfulness of prior processing |
| Improve the Service: analyze usage patterns, fix bugs, develop new features | Legitimate interest |
| Limit account-creation abuse: count of accounts created per device (see §2.4) | Legitimate interest |
| Ensure security: detect fraud, prevent abuse, enforce our Terms | Legitimate interest |
| Operate sharable report download links: count downloads, log referrer and hashed IP for fraud prevention and aggregated analytics | Legitimate interest |
| Compute and store charts for other people you add: compatibility charts and people you save to your circle | Legitimate interest |
| Count checkout starts on the reports storefront, counted by our own server when the checkout is created, with no identifier and no device storage (the campaign channel is attached only if you accepted Analytics; otherwise the count is untagged) | Legitimate interest |
| Measure how the website is used (Analytics category): Google Analytics 4 plus our own arrival and page-view counts per page and campaign channel, the rest of our per-step funnel counters (report viewed, sample opened, cart add, store button) and per-tab link attribution, on starbind.me and the reports storefront only | Consent, given in the cookie banner and withdrawable at any time via "Cookie settings" in the website footer |
| Measure whether an ad led to a purchase and build remarketing audiences (Advertising category): Google Ads, Meta and Reddit tags report product views, checkout starts and confirmed purchases, and each platform holds two audiences for 30 days: people who viewed a report and did not buy, and people who started checkout and did not buy | Consent, given in the cookie banner and withdrawable at any time via "Cookie settings" in the website footer; a Global Privacy Control signal counts as a refusal of this category |
| Keep evidence of your cookie choice (receipt id, wording revision, language, the two category answers, the action and the time; nothing that identifies you) | Legal obligation (GDPR Art. 7(1)) |
| Comply with legal obligations: respond to lawful requests, meet regulatory requirements | Legal obligation |
3.2 Automated Decisions and Profiling
We will never use your birth data, account information, or content you submit to make decisions based solely on automated processing that produce legal or similarly significant effects on you (GDPR Article 22). The natal-chart calculations and automatically generated readings the Service provides are entertainment content; they have no legal or contractual consequences for you.
The remarketing audiences in Section 3.1 group website visitors by two actions (viewed a report, started checkout) for 30 days so the platform can show them a StarBind ad. That is the only profiling we do, it runs only with your consent to the Advertising category, it uses no account data, no birth data and no report content, and it has no legal or similar effect on you.
4. AI and LLM Data Processing
We use third-party large language model (LLM) providers to generate personalized astrological content such as daily horoscopes, readings and chat replies. We work with two LLM providers, each under its own data processing agreement, and may route any of the content below to either of them: OpenAI (OpenAI API) and Google (Vertex AI, which hosts Google's own models and third-party models on Google's infrastructure). Which provider serves a given feature is an operational choice we can change at any time; what data each kind of content carries does not change with the provider and is described here and in the table in Section 5:
- What we send: the astrological data a feature needs (planetary positions, aspects, sign placements), plus any free text you choose to submit to an AI feature (such as chat messages or dream descriptions) and the display nicknames you set for yourself or for people in your circle, where a feature uses them (for example, compatibility readings). These requests carry no account identifiers: we do not send your email, user ID, birth date, birth location or full birth name, with one exception limited to yearly readings: to place the day your astrological year turns (your solar return) and the annual "profection" that changes on your birthday, the yearly request includes that exact birthday-derived transition date and your age at that point. This is necessary for an accurate yearly reading and is not sent for any other app feature. Stripping account identifiers does not make the request anonymous: the text you write, a nickname, or the yearly date can still be personal data, and we treat every request as such under the provider's data processing agreement.
- Purchased astrology reports are a separate product. What a report request carries, and how a draft is checked before delivery, is described in the Reports Privacy Policy, which is presented at purchase, not here.
- Where processing happens: Google Vertex AI requests are pinned to Google's EU multi-region in our code. OpenAI requests use OpenAI's global endpoint, without a regional processing restriction, and may be processed in the United States and in other countries where OpenAI and its sub-processors operate. Any transfer outside the EU is covered by the Standard Contractual Clauses in each provider's data processing addendum.
- Data retention by LLM providers: each provider processes your data to produce the response and may hold it briefly in a cache; at Google, the default cache is disabled for our project, so prompts sent there are not cached. Beyond that, how long it keeps the request depends on the service and the controls in use: where a provider's zero-retention controls are enabled for our account, inputs and outputs are not stored for abuse monitoring; otherwise the provider may keep them for a limited period (at OpenAI, up to 30 days) for security and abuse monitoring, subject to its own legal and security exceptions, as set out in its data processing agreement. Until we have confirmed zero-retention controls for a provider, you should assume its default retention applies.
- No training: our agreements with both providers prohibit them from using your data to train their models.
5. Service Providers and Other Recipients
We do not sell your personal information. The recipients below operate the Service for us or, where the Role column says so, decide for themselves how they use what they receive. The four website-tag rows (Google Analytics, Google Ads, Meta, Reddit) receive data only after you accept the matching category in the website cookie banner (Section 6); they never receive anything from the app.
| Recipient | Role | Purpose | Data shared | Region | Transfer mechanism |
|---|---|---|---|---|---|
| Google LLC (Firebase Cloud Messaging + Vertex AI) | Processor | Push notification delivery; LLM provider for automatically generated horoscopes, readings and chat responses | Push device tokens; notification body. For LLM processing, the data described in Section 4: astrological data without account identifiers, the yearly-reading transition date and age, free text you submit in chat or dream entries and the display nicknames a feature uses | LLM processing: European Union (Vertex AI EU multi-region, pinned in our code). Push delivery: United States | EU-US Data Privacy Framework (Google LLC self-certified) and EU Standard Contractual Clauses (Google Cloud Data Processing Addendum); no training on API data; retention as described in Section 4 |
| OpenAI, L.L.C. (OpenAI API) | Processor | LLM provider for automatically generated horoscopes, readings and chat responses; automatically generated images, such as shareable cosmic artwork | For readings, horoscopes and chat: the data described in Section 4: astrological data without account identifiers; for yearly readings only, the exact birthday-derived date on which your astrological year turns and your age at that point; free text you submit in chat or dream entries, plus the display nicknames a feature uses. For images: the prompt text describing the image to generate, which carries astrological themes plus the display nicknames you set for yourself or for people in your circle, where a feature uses them (for example, compatibility artwork) | Global endpoint, no regional restriction (United States and other countries where OpenAI and its sub-processors operate) | EU Standard Contractual Clauses (OpenAI Data Processing Addendum); no training on API data; retention as described in Section 4 |
| Brevo (Sendinblue SA) | Processor | Transactional email: account verification, password reset, billing notifications | Email address; subject line and body of the message | European Union (France) | EU processing; any onward transfer by Brevo's own sub-processors is governed by Brevo's data processing agreement and its Standard Contractual Clauses |
| Cloudflare, Inc. | Processor | Hosting for the starbind.me website (landing pages, learn reference, horoscopes, sky news, free chart tools, and the reports storefront), content delivery network, DNS, share-link Worker, object storage (R2: generated images, shareable report files, and app-update bundles), Turnstile anti-abuse checks, and the reverse proxy in front of our API (api.starbind.me) that filters abusive and automated traffic before it reaches our servers. Cloudflare Web Analytics is switched off |
IP address; standard web request data (URL, headers, user-agent); images and report files generated for you and stored in R2; the content of your requests to and responses from the app's API, in transit only (Cloudflare decrypts and re-encrypts each request at its edge to inspect it for abuse; it does not store request or response bodies, and it keeps only request metadata such as IP address, URL and timing) | United States with EU edge network | EU Standard Contractual Clauses |
| Microsoft Corporation (Microsoft Azure) | Processor | Primary server infrastructure for the API, database, and caching; application monitoring (server logs plus the usage and crash telemetry described in Section 2.2); storage of the website cookie-consent evidence described in Section 6.5 | All data described in Section 2, at rest, including the consent evidence (receipt id, wording revision, language, two category answers, action, time; no IP address, user agent, page address, email, account or order) | European Union (Azure EU regions, within the Microsoft EU Data Boundary) | Customer data is stored and processed in EU regions. Microsoft may make limited transfers outside the EU Data Boundary in the circumstances set out in its Product Terms (for example security investigations, remote support, or service quality), under the safeguards in the Microsoft Products and Services Data Protection Addendum |
| Komoot GmbH (Photon geocoder) | Processor | Birth-place autocomplete: turning the place name you type into coordinates for your chart, queried only as a fallback when our own server-side place cache has no match | The place text you type (e.g. "Sofia"); no name, email, or other identifier is attached | European Union (Germany) | No third-country transfer required (EU→EU) |
| Apple Inc. (App Store) | Merchant of record (independent controller for payment) | In-app purchase processing, subscription management, receipt validation | Payment confirmations, subscription state, transaction identifiers (we never receive card numbers) | United States | Apple Paid Apps Agreement |
| Google LLC (Google Play) | Merchant of record (independent controller for payment) | In-app purchase processing, subscription management, receipt validation | Payment confirmations, subscription state, transaction identifiers (we never receive card numbers) | United States | Google Play Developer Distribution Agreement |
| Google Ireland Ltd (Google Tag Manager + Google Analytics 4; website only) | Processor under the Google Ads Data Processing Terms | Loads the tag container as soon as you accept either optional category and fires only the tags of the categories you accepted; the Google Analytics tag inside it runs under the Analytics category and measures how the website is used: pages viewed, reports viewed, sample opened, checkout started, app-store button clicked, purchase completed | Event fields we send: page path, surface (site or reports), language, report SKU, name, price and currency, order value, currency, gift flag and an opaque order token. Technical request data the tag processes automatically: IP address, user agent, page URL and referrer, its own cookie identifiers (_ga, _ga_<id>), timestamps and your consent state. Never your email, name, birth data, promo code, payment or download identifiers. Google Analytics keeps event-level data for 2 months (our setting) |
Ireland (EU); Google may process in other countries where it or its sub-processors operate | Google Ads Data Processing Terms, with the EU Standard Contractual Clauses they incorporate for restricted transfers and Google LLC's EU-US Data Privacy Framework certification |
| Google Ireland Ltd (Google Ads tag; website only, Advertising category) | Independent controller under the Google Ads Controller-Controller Data Protection Terms | Measures whether a Google ad led to a report view, a checkout start or a purchase, and holds the two 30-day remarketing audiences described in Section 3.1 | The same event fields as the Analytics row. Technical request data the tag processes automatically: IP address, user agent, page URL and referrer, its cookie and click identifiers (_gcl_au, _gcl_aw, _gcl_gb, and the gclid/gbraid/wbraid value from the ad link if you accept Advertising in that visit), timestamps and your consent state |
Ireland (EU); Google may process in other countries where it or its sub-processors operate | Google's controller terms, with the EU Standard Contractual Clauses they incorporate for restricted transfers and Google LLC's EU-US Data Privacy Framework certification |
| Meta Platforms Ireland Ltd (Meta Pixel; website only, Advertising category) | Joint controller with us for the event data the pixel collects for ad delivery and optimisation, and our processor for matching and measurement, under the Meta Business Tools Terms | Measures whether a Facebook or Instagram ad led to a report view, a checkout start or a purchase, and holds the two 30-day remarketing audiences described in Section 3.1 | The same event fields as the Analytics row. Technical request data the pixel processes automatically: IP address, user agent, page URL and referrer, its cookie and click identifiers (_fbp, _fbc, and the fbclid value from the ad link if you accept Advertising in that visit), timestamps and your consent state |
Ireland (EU); Meta's onward transfers to Meta Platforms, Inc. (United States) | Meta Business Tools Terms; transfers under the Global Data Transfer Addendum they incorporate (EU Standard Contractual Clauses) and Meta Platforms, Inc.'s EU-US Data Privacy Framework certification |
| Reddit Netherlands B.V. (Reddit Pixel; website only, Advertising category) | Independent controller for event data under the Reddit Advertising Data Processing Agreement | Measures whether a Reddit ad led to a report view, a checkout start or a purchase, and holds the two 30-day remarketing audiences described in Section 3.1 | The same event fields as the Analytics row. Technical request data the pixel processes automatically: IP address, user agent, page URL and referrer, its cookie identifier (_rdt_uuid), timestamps and your consent state. The rdt_cid value an ad link carries is removed before any tag loads and is never passed on |
Netherlands (EU); onward transfer to Reddit, Inc. (United States) | EU-US Data Privacy Framework (Reddit, Inc. self-certified), with the EU Standard Contractual Clauses in Reddit's agreement as the fallback |
| TikTok Technology Ltd | Not enabled | No TikTok tag runs on the website and no data goes to TikTok. If we enable it, we update this policy and the cookie banner first | None | n/a | n/a |
| Law enforcement and regulators | Independent recipient | When legally required or to protect our rights, your rights, or the rights of others | As required by applicable law | Varies | As permitted by applicable law |
Processors act only on our written instructions, under confidentiality and data protection terms. Where a recipient is a joint or independent controller (Apple and Google for payments; Google Ads, Meta and Reddit for the advertising events you consent to), its own privacy notice governs what it does with the data after receipt, and we cannot recall data already sent. The consent banner software we use (CookieConsent by Orest Bida, self-hosted under the MIT licence) runs from our own servers and sends nothing to its author; it is not a recipient. We update this list before a new recipient receives your data.
For the joint processing described above, we and Meta have agreed how to divide our responsibilities under the Meta Controller Addendum. We provide the notice, obtain the required consent and are responsible for the correct, secure integration on our site. Meta is responsible for security of its own product and for enabling access, correction, deletion, restriction and portability rights for personal data it holds after the joint processing. Each party remains responsible for the lawfulness of its own processing. You may exercise your rights against either party: contact us at legal@starbind.me, or use the contacts and rights information in Meta's Privacy Policy. We forward requests requiring Meta's action.
6. Cookies and Tracking Technologies
6.1 The App and the Website Are Different
The app (iOS and Android) stores only what it needs to run: your sign-in token, your settings and cached content, in the app's own storage. It contains no analytics or advertising SDK, sets no tracking cookies and sends its first-party telemetry (Section 2.2) under a random per-session identifier. Nothing in this Section 6 beyond that paragraph applies to the app.
The website (starbind.me, including the reports storefront at starbind.me/reports) asks before it measures. On first visit a banner offers three choices of equal weight: Accept all, Reject all, or Manage (choose per category). Nothing optional is pre-ticked. No analytics or advertising tag loads until you accept its category, and the banner never shows on its own on the pages that carry no tags at all, whatever you chose elsewhere: this site's Big Three and free chart tools, the reports Big Three page, order form, library, download, redeem and deletion pages, and the legal pages. Every page you enter birth details on is one of them.
6.2 Categories
- Necessary (always on, no consent needed under ePrivacy Directive Article 5(3) and the Bulgarian Electronic Communications Act): your cookie choice itself, sign-in and session state, your report cart and promo code, checkout recovery, the birth details you hand from the free chart widget to the order form, dismissed notes, and Cloudflare Turnstile checks on forms.
- Analytics (off until you accept): Google Analytics 4 through Google Tag Manager; our own arrival and page-view counts, per-tab link attribution (
sb:attr) and per-step funnel counters (report viewed, sample opened, cart add, store button); and the marker that stops a purchase being reported to Google Analytics twice. Until you accept this category your browser sends us no measurement request of any kind; if you accept it later in the same visit, that page is counted from then on. - Advertising (off until you accept): the Google Ads, Meta and Reddit tags; the ad-click identifier the platform added to the link you arrived on (
gclid,gbraidorwbraidfor Google,fbclidfor Meta); and the markers that stop a purchase being reported to each platform twice. TikTok is not enabled. Accepting Advertising does not switch on Analytics, and the other way round.
The tag container itself (Google Tag Manager) loads as soon as you accept either optional category, and fires only the tags of the categories you accepted. Loading it means your browser requests the container from Google, which sees your IP address, user agent and page address in that request.
What we deliberately send to a tag is limited to: page path (without query string), surface (site or reports), language, the SKU, name, price and currency of a report you view, a checkout start, which app-store button you clicked, and after a confirmed purchase the order value, currency, gift flag and an opaque order token. Never your email or a hash of it, your name, birth data, promo code, payment, access or download identifiers, or free text.
Every vendor tag, once loaded, also processes technical request data on its own: your IP address, user agent, the page URL and referrer, its cookie or click identifiers, timestamps and your consent state. Section 5 names the vendor, its role and its transfer basis for each tag.
Before any tag or even the banner runs, our own script removes the ad-click identifier and any unlisted query parameter from the page address. If you accept Advertising in that same visit, the Google or Meta identifier is written into that vendor's own cookie (_gcl_aw or _gcl_gb, _fbc) so the platform can attribute a later purchase to its ad; otherwise it is discarded when you leave the page. Reddit and TikTok click identifiers (rdt_cid, ttclid) are always discarded: neither platform publishes a cookie format or a browser interface that would let us hand one over without putting it back in the page address.
6.3 What Is Stored on Your Device
| Name | Set by | Purpose | Category | Lifetime |
|---|---|---|---|---|
sb_consent (cookie) |
StarBind | Your cookie choice, the wording revision you answered and the receipt id of the evidence record | Necessary | 6 months |
| App sign-in token and settings (app storage) | StarBind | Keeps you signed in to the app | Necessary | Until you sign out or delete the app |
sb_reports_session (cookie, HttpOnly) |
StarBind | Reports library sign-in | Necessary | 90 days, renewed while you use the library |
Report cart, promo code (sb:promo), checkout recovery (sb:success), order-form hand-off (browser storage) |
StarBind | Operate the reports storefront; the tab-scoped items are cleared when the tab closes | Necessary | Cart: 7 days after the last change; the rest: the browser tab |
Dismissed-note flag (localStorage) |
StarBind | Remembers you dismissed an informational note | Necessary | Until you clear browser storage |
starbind:sun-sign (session storage) |
StarBind | Remembers the sign the free chart widget computed while you stay in the tab | Necessary | The browser tab |
| Cloudflare Turnstile | Cloudflare | Anti-bot check on forms; cookieless | Necessary | None |
sb:attr (session storage) |
StarBind | Which tagged link brought you to this tab, so each funnel step is counted once and an order can name its channel | Analytics | The browser tab |
sb:mk:ga4:<order> (local storage) |
StarBind | Stops a purchase being reported to Google Analytics twice | Analytics | 90-day validity; see deletion note below |
_ga, _ga_<id> (cookies) |
Google Analytics 4 | Distinguishes visitors and sessions | Analytics | 2 years |
sb:mk:google_ads:<order>, sb:mk:meta:<order>, sb:mk:reddit:<order> (local storage) |
StarBind | Stops a purchase being reported to that platform twice | Advertising | 90-day validity; see deletion note below |
_gcl_au (cookie) |
Google Ads | Conversion measurement | Advertising | 3 months |
_gcl_aw, _gcl_gb (cookies) |
Google Ads | Holds the Google ad-click identifier from the link you arrived on | Advertising | 3 months |
_gcl_ls (local storage, when used by the Google tag) |
Google Ads | Ad-click attribution state | Advertising | No browser-set expiry; cleared here on withdrawal |
_fbp, _fbc (cookies) |
Meta | Distinguishes browsers; holds the Meta ad-click identifier from the link you arrived on | Advertising | 3 months |
_rdt_uuid (cookie) |
Distinguishes browsers for conversion measurement | Advertising | 3 months |
Purchase markers sb:mk:* are valid for 90 days. Expired entries are removed on the next use with consent for their category; withdrawal clears that category's markers. No deletion code runs while the site is closed, so entries may remain until such a return visit or browser clearing.
The vendor lifetimes are the values each vendor documents; we re-verify every row in a clean browser, for each consent combination, before the tags are enabled and again whenever a tag changes. Payment for reports happens on Stripe's own checkout pages (checkout.stripe.com), where Stripe's cookie policy applies.
6.4 Your Choices and Withdrawal
"Cookie settings" in the website footer, available in the site footer (static legal pages link back to the site's preferences), reopens the preference sheet. Withdrawing a category takes effect at once: the vendors are told the category is now denied, the items listed for that category in Section 6.3 are deleted from your browser as far as this site can reach them, and if code for the withdrawn category had already loaded on the page, the page reloads so the withdrawn tags stop running. A cookie a vendor set on its own domain rather than ours is not something a script on this site can delete; it stays until your browser or that vendor drops it, and you can remove it yourself in your browser settings. Withdrawal is as easy as consent and needs no email or account.
Withdrawal stops future collection. It cannot recall data a vendor already received; what a platform keeps after receipt, including your membership of a remarketing audience until it lapses after 30 days, is governed by that platform's own terms and by the rights you can exercise with it directly. If we change the banner wording, the categories or the vendors, the banner asks you again.
You can also block or delete cookies in your browser. Deleting sb_consent means the banner asks again; deleting the other necessary items signs you out of the reports library or empties your cart.
6.5 Consent Evidence
Whenever you make, change or withdraw a choice in the banner, your browser sends our server one record: a random receipt id, the wording revision you answered, the language you saw it in, your Analytics and Advertising answers, the kind of action (first choice, change, withdrawal) and the server's time. The receipt id is stored in sb_consent so the stored preference and the evidence can be matched; a granted category is activated only after the record is saved. The record holds no IP address, user agent, page address, email, account or order, and it is deleted 13 months after it is written. Rejections and withdrawals apply immediately whether or not the record is saved.
6.6 Global Privacy Control (GPC)
If your browser sends a Global Privacy Control signal, the website treats the Advertising category as refused on every page, whatever the banner or an earlier choice says, and no advertising tag loads. You can still accept Analytics.
7. Data Retention
We keep each category of personal data only for as long as it is needed to provide the Service to you. Where a fixed period isn't meaningful, we delete data after a defined period of inactivity. Specifically:
| Data | Retention Period |
|---|---|
| Your account and the content you create or save in it (other than chat conversations) | Until you delete it. Inactive accounts are deleted 24 months after the last sign-in. |
| Chat conversations (the messages you send and the responses you receive) | Deleted 12 months after the conversation's last message |
| Usage and crash telemetry (session-scoped, never linked to your account) | Up to 24 months |
| Anonymized audit-log entries (post-deletion accountability records, see §2.4) | 24 months from the date of the event |
| Payment records | As required by Bulgarian tax and accounting law (10 years, Accountancy Act art. 12) |
| Server logs | Up to 90 days |
| Report download access logs | 90 days |
| Website cookie-consent evidence (receipt id, wording revision, language, two category answers, action, time; see §6.5) | 13 months from the record's date |
Website purchase once-markers (sb:mk:*, on your device only) |
90-day validity; expired entries cleared on next consented use, or on category withdrawal (Section 6.3) |
| Data held by the website tag vendors | Google Analytics event data: 2 months (our setting). Remarketing audiences at Google Ads, Meta and Reddit: 30 days. Other vendor-side data: per that vendor's terms (Section 5) |
Account deletion removes your data from our live systems immediately (see Section 11.1). Copies in our encrypted database backups age out within 7 days. Anything we must keep by law is retained for the periods in the table above.
8. Data Security
We implement industry-standard technical and organizational measures to protect your personal data, including:
- Encryption of data in transit (TLS/HTTPS) and at rest.
- Salted password hashing (passwords are never stored in plaintext).
- Access controls limiting employee access to personal data on a need-to-know basis.
- Regular security assessments.
Despite these measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
9. Access by StarBind Staff
We strictly separate the data our staff can routinely view from content you create inside the Service.
Operational metadata: Authorised staff can view your account email, account status, subscription tier and free-credit balances, transaction history (records of purchases, spends, and refunds, without the prompt or response text of any individual feature), device identifier, the IP addresses recorded on security audit events (consent records, password changes, failed device-attestation attempts), and audit-log events. We use this access to provide support, process billing and refunds, prevent fraud, and enforce our Terms.
User-generated content: Conversations you have through the Service, dream journal entries you write, custom names and birth data you save for other people in your circle, and image-generation prompts you submit are not routinely accessible to staff. Staff review such content only when:
- it is automatically flagged by our safety systems (for example, content blocked by the provider's safety classifiers or matched against patterns we use to detect prompt injection or abuse),
- you report it to us through an in-app or written report, or
- we are required to produce it under valid legal process.
Each instance in which staff access user-generated content is logged in our audit log and is auditable.
10. International Data Transfers
Your data is primarily processed and stored on servers located in the European Union. Some recipients listed in Section 5 process specific, limited data in the United States under the safeguards described there. The website tag vendors contract with us through their EU entities (Google Ireland Ltd, Meta Platforms Ireland Ltd, Reddit Netherlands B.V.); their onward transfers to the United States rest on the safeguards named per row in Section 5, and they receive data only after your consent. If you access the Service from outside the EU, your information may be transferred to and processed in a country with different data protection laws.
For EU/EEA/UK users: Where we transfer personal data outside the EU/EEA/UK, we rely on:
- EU-US Data Privacy Framework (where the receiving organization is certified under the Framework), or
- Standard Contractual Clauses approved by the European Commission.
You may request a copy of the applicable safeguards by contacting us.
11. Your Rights
11.1 For All Users
Regardless of your location, you may:
- Access your personal data through your account settings, including a full JSON export of everything we hold about you.
- Update or correct your information through your account settings.
- Delete your account and associated data through the Service. Deletion is hard: all account data is removed in a single transaction, except as described in §2.4.
11.2 For EU/EEA/UK Users (GDPR)
Under the General Data Protection Regulation, you have the following additional rights:
- Right of access: request a copy of all personal data we hold about you.
- Right to rectification: request correction of inaccurate data.
- Right to erasure ("right to be forgotten"): request deletion of your data.
- Right to restrict processing: request that we limit how we use your data.
- Right to data portability: receive your data in a structured, machine-readable format.
- Right to object: object to processing based on legitimate interests, including profiling.
- Right to withdraw consent: where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
To exercise these rights, contact us at legal@starbind.me. We respond without undue delay and at the latest within one month of receiving your request. For complex or numerous requests we may take up to two further months; if so, we tell you within the first month and explain why (GDPR Art. 12(3)).
If you believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local supervisory authority. Our lead supervisory authority is the Bulgarian Commission for Personal Data Protection (Комисия за защита на личните данни / КЗЛД), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria: https://www.cpdp.bg.
11.3 For California Residents (CCPA/CPRA)
Under the California Consumer Privacy Act and California Privacy Rights Act, you have the right to:
- Know what personal information we collect, use, and share.
- Delete your personal information.
- Opt out of the sale or sharing of your personal information. We do not sell your personal information. The website's advertising tags (Section 6) may count as "sharing" for cross-context behavioural advertising; they run only if you accept the Advertising category, and refusing or withdrawing it via "Cookie settings" in the footer, or sending a Global Privacy Control signal, opts you out.
- Non-discrimination: we will not discriminate against you for exercising your rights.
To submit a request, contact us at legal@starbind.me. We will verify your identity before processing your request.
11.4 For Residents of Other US States
If you reside in Colorado, Connecticut, Virginia, Utah, or other states with consumer privacy laws, you may have similar rights to access, delete, correct, and opt out of certain data processing. Contact us at legal@starbind.me to exercise your rights.
12. Children's Privacy
The Service is not directed to children under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at legal@starbind.me, and we will promptly delete such information.
13. Changes to This Privacy Policy
We update this Privacy Policy when our processing changes and publish the current version with its effective date. Where applicable law requires consent for new processing, we request that consent before the processing begins. Where applicable law requires direct notice of a change, we provide it through an appropriate channel.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Email: legal@starbind.me
- Address: STORMVIBE Ltd. (EIK 208809995, VAT BG208809995), 27E Srebarna Street, Bldg. 7, Entr. A, Apt. A2, Lozenets District, Sofia 1407, Bulgaria
For EU/EEA data protection inquiries: contact us at the address above. The Company is established in the European Union (Bulgaria) and an Article 27 representative is not required.
This Privacy Policy was last updated on 2026-09-18.