Privacy information

Privacy policy information

Last updated:

The plain-language version

Your data is yours. We collect the minimum we need to run Cosmic, never sell it, and give you practical ways to export, correct, or delete it.

Most Cosmic app data starts on your device. The charts, preferences, and device information needed for Cosmic Sync are also stored on Cosmic’s servers.

Astrology data can be deeply personal. Cosmic Sync is protected from unauthorized external access in transit and at rest. That means a small number of authorized people and service providers can access it when operating, securing, or supporting the service.

We do not use your data for advertising, for marketing or sales purposes, or to train machine learning models.

The promises behind this page

  1. Your data, your choice. Cosmic is a tool you use, not a trap you get locked into. You can export and import your app data, ask for a copy of account data, and request deletion.
  2. Collect with a purpose. We collect what is needed to calculate charts, keep devices in sync, manage an account or purchase, communicate with you, and keep Cosmic reliable and secure—not extra information “just in case.”
  3. No selling. No ad profile. We neither sell nor rent personal information. We do not sell chart data in identifiable, aggregated, or de-identified form, and we do not build advertising profiles from it.
  4. Protect what matters. We use proportionate technical and organizational safeguards and limit access to people and providers who need it for a stated purpose.
  5. No surprises. We explain where data lives, what we do with it, and the choices available. If our practices materially change, this page changes too.

Who is responsible and who this covers

Cosmic B.V. is the controller of personal data covered by this page. “Cosmic,” “we,” and “us” mean:

Cosmic B.V.
Keizersgracht 75-K
1015CE Amsterdam
The Netherlands
support@cosmic.plumbing

This page covers the Cosmic website, astrology app, Account Center, Sync service, purchases and subscriptions, newsletters, research forms, and support conversations. A third-party site you choose to visit—such as a payment page, video site, or linked article—has its own privacy practices.

It also covers personal data about someone else that a Cosmic member enters into a chart and then chooses to Sync. We explain the member’s responsibilities for that data below.

The information we handle

Some information is required. Without an email address and password, for example, we cannot create an account; without chart inputs, Cosmic cannot calculate the requested chart. Newsletter subscriptions, research participation, and most support details are optional.

App and astrology data

What this includes
Chart titles; dates, times, locations, and types of moments; custom perspectives; display and calculation preferences; and calculated chart information.
Where it comes from
You enter or create it in Cosmic. The app derives calculated chart information from those inputs.
Why we use it
To calculate, display, organize, import, export, and synchronize your work.
Legal basis
Performance of our contract with you.

Account and authentication data

What this includes
Email address, a securely hashed password, account and verification status, account identifiers, login timestamps, and session tokens.
Where it comes from
You provide your email and password; our systems create the identifiers, tokens, and timestamps.
Why we use it
To create and secure your account, verify your email, sign you in, recover access, and connect app data to the right account.
Legal basis
Performance of our contract and our legitimate interests in account security and preventing misuse.

Device and Sync data

What this includes
Random device and change identifiers, browser or app user-agent information, last-Sync times, and compact copies of the charts, settings, and perspectives.
Where it comes from
The app and device create it when you register a device or use Sync.
Why we use it
To recognize a device, send only the changes it needs, resolve Sync state, and troubleshoot failures.
Legal basis
Performance of our contract and our legitimate interests in operating a dependable Sync service.

Purchase and subscription data

What this includes
The product or subscription, price and currency, payment and customer references, payment status, access rights, renewal or expiration dates, and related correspondence. Cosmic does not receive or store any payment information, including your bank card or bank account details.
Where it comes from
You, Cosmic’s purchase flow, and our payment provider Mollie.
Why we use it
To take payment, grant paid features, manage renewals and cancellations, provide support, prevent fraud, and keep legally required financial records.
Legal basis
Performance of our contract, compliance with tax and accounting law, and legitimate interests in preventing fraud and resolving payment issues.

Messages, newsletter, and research data

What this includes
Your name, email address, message or form responses, support attachments, subscription status, and newsletter delivery or engagement information such as an open or link click when the newsletter service records it.
Where it comes from
You provide it directly; Google Forms, Buttondown, Postmark, or your email provider may supply delivery and subscription events.
Why we use it
To answer you, send requested account messages or newsletters, conduct research you agreed to join, and understand whether requested communications are delivered.
Legal basis
Performance of our contract for service messages; consent for newsletters and optional research; and legitimate interests in answering requests and maintaining reliable communications.

Technical, security, and diagnostic data

What this includes
IP address, time, requested page or service route, app and browser version, operating system, user agent, error details, recent app actions, and debugging context.
Where it comes from
Your browser, app, device, service requests, diagnostic provider, and information you choose to send to support.
Why we use it
To deliver requests, detect abuse, secure Cosmic, investigate errors, and improve reliability. We use diagnostics for these purposes but also as product-usage analytics to understand patterns of use, detect errors, and enhance our products and services.
Legal basis
Our legitimate interests in security, support, and reliable operation, balanced against the personal patterns that can be shown in diagnostic data.

What stays local and what Sync changes

Cosmic stores app data in a database on your device. If you use the app without an internet connection, Cosmic B.V. normally cannot see or recover that local-only chart data. Your device security, backups, exported files, and anyone with access to your device remain your responsibility.

When you sign in with an active internet connection, you are using Sync. Cosmic sends the minimum reproducible version of syncable charts and preferences to our servers. We leave calculated placements and other information that can be recalculated out of the synced copy. Sync also sends a random device identifier, its user-agent description, and change history needed to keep devices consistent.

An important distinction: removing or uninstalling Cosmic removes access from that device, but does not by itself delete an account or its synced server copy. Use Account Center → Data & Account → Delete Account or contact us to remove the server copy too.

Who receives information

We do not sell or rent personal information. We share only what is needed with providers that help deliver a stated part of Cosmic:

  • Fly.io for service hosting, and Amazon Web Services for backups and download infrastructure.
  • Sentry for production error reporting and diagnostics.
  • Postmark for verification, password, security, and other account emails.
  • Mollie for payments and subscriptions. Mollie collects payment details on its own checkout and may act as an independent controller for its legal and fraud-prevention duties.
  • Google Forms for submitted newsletter and research forms, and Buttondown for newsletter subscription and delivery.

We may also disclose limited information to professional advisers such as accountants or lawyers, or to public authorities when we reasonably believe a valid law requires it. If Cosmic is reorganized, data may transfer as part of that change subject to this page and applicable law; it is not a sale for advertising.

Cookies, local storage, and diagnostics

Cosmic does not use advertising cookies or third-party product-usage analytics on its website or in the app.

The Account Center uses a strictly necessary, secure, HTTP-only session cookie to keep you signed in. The app uses device storage for charts, preferences, a session token, device and Sync state, and pending changes. These are functional storage, not advertising trackers.

In production, Sentry receives error and diagnostic events. Depending on the error, these can include an IP address, device and app details, recent app actions, and related state. Although we do not intentionally attach chart contents to every report, debugging context can unexpectedly include user-provided information. We use these reports to fix failures and secure the service, not to measure which astrology features you use for marketing.

Payment, form, newsletter, video, and other third-party pages may use their own cookies or storage. Their notices and controls apply once you visit them.

Where information is processed

Cosmic is based in the Netherlands. Our core service infrastructure is currently hosted in Canada, and some providers process data in the United States or other countries. Privacy protections can differ between countries.

When personal data moves outside the European Economic Area, we rely on a lawful transfer mechanism where required—such as an adequacy decision or the European Commission’s Standard Contractual Clauses— and apply additional safeguards when appropriate. Contact us if you would like information about the safeguard relevant to a particular transfer.

How long we keep information

We keep personal data for the shortest period that reasonably serves its stated purpose, then delete or de-identify it unless law requires longer retention. In practice:

  • Local app data stays on your device until you delete it, clear the app’s data, or use a logout flow that removes the local databases. Exported files remain wherever you save them.
  • Account and Sync data stays while your account is active and until you ask us to delete the account. Account inactivity does not currently trigger automatic deletion. Sync changes are compacted, but deletion markers may remain while the account exists so other devices can learn what was deleted.
  • Verification and password-recovery links stop working after three days. App sessions normally expire after 90 days and Account Center sessions after one hour.
  • Purchase, payment, invoice, refund, and tax records are kept for the legally required administration period. In the Netherlands this is generally at least seven years, and some VAT One Stop Shop records must be kept for ten years.
  • Newsletter details remain until you unsubscribe or we end the newsletter. We may keep a minimal suppression record so we respect an unsubscribe request rather than adding you again.
  • Support, research, security, and diagnostic records remain only as long as reasonably needed to complete the conversation, investigate the issue, protect the service, or defend a claim, then follow the relevant operational deletion schedule.

After deletion, limited copies may remain temporarily in protected backups until they are overwritten through the backup cycle. We do not use backup copies for ordinary business operations. A provider that acts as an independent controller may keep its own legally required records under its privacy notice.

How we protect information

We use safeguards appropriate to the nature of the information, including encrypted network connections, password hashing, protected authentication and recovery tokens, secure session cookies, access controls, backups, dependency maintenance, and error and security monitoring. Access by our team is limited to people who need it to operate, secure, support, or meet legal obligations for Cosmic.

Data stored on our servers is encrypted to help protect it from unauthorized access. However, Cosmic itself has access to read that data. We take every measure to ensure that your data is only accessed when authorized, however, Cosmic should not be used as a secure vault for secrets. Never store passwords or other highly sensitive information in Cosmic.

No service can promise perfect security. If a personal-data breach creates a risk that law requires us to report, we will notify the appropriate authority and affected people as required.

Your choices and privacy rights

You can edit or delete individual charts and preferences inside the app. Settings → Export Data creates a portable JSON copy of app data that can be imported again. The Account Center lets you change account details and request a full account export or deletion through Data & Account. You can unsubscribe from marketing using the link in any newsletter.

Depending on the law and circumstances, you may have the right to be informed, access data, correct it, delete it, restrict or object to processing, receive portable data, and withdraw consent. We aim to offer the same practical controls even when a particular right does not legally apply where you live.

Email support@cosmic.plumbing from the address associated with your account. We aim to process full account export and deletion requests within 72 hours. The GDPR normally allows one month for a formal response and, for complex or numerous requests, a further two months after we tell you why. We may ask for enough information to verify your identity. Requests are normally free, though the law allows limits for manifestly unfounded or excessive requests.

A right may have an exception. For example, we cannot delete a tax record while law requires us to keep it. We will explain any limit. If you are unhappy with our response, you can complain to the Dutch Data Protection Authority or another supervisory authority available to you.

Charts about other people and children

Cosmic lets a member create a chart about another person. If you do that, only enter information you have a lawful reason to use, tell the person how you will use and store it when required, honor their rights, and avoid unnecessary sensitive details. You are responsible for your relationship with that person; Cosmic remains responsible for how our service handles the synced copy.

If you believe someone has placed your personal information in Cosmic without a proper reason, contact that member when possible or write to us. We will assess what we can lawfully do without disclosing another member’s account information.

Cosmic is not designed specifically for children. If you are under 16, ask a parent or guardian to help before creating an account, subscribing, joining research, or sending personal information. A parent or guardian may contact us about a child’s data.

Changes and contact

We review this page as Cosmic changes. The date at the top shows the latest revision. If a change materially affects how we use personal data, we will give additional notice in the app, on the website, or by email when appropriate before the change takes effect.

Questions, requests, concerns, or suggestions are welcome. If you think our actions do not match these principles, please tell us:

Cosmic B.V.
Keizersgracht 75-K
1015CE Amsterdam
The Netherlands
support@cosmic.plumbing