Legal
Privacy Policy
This privacy policy explains which personal data we process when you use the Moonjourn app and this website, for what purpose, and on what legal basis. It applies together with our legal notice (Imprint).
Contents
- 01Data Controller
- 02Core Principles
- 03Data We Process
- 04Local Processing
- 05Cloud Synchronization (optional)
- 06Machine-Generated Texts
- 07In-App Purchases and Subscriptions
- 08Friend System and Visibility
- 09Push Notifications
- 10Data Processors
- 11Data Retention
- 12Your Rights
- 13Data Deletion
- 14What We Do NOT Do
- 15Changes to This Policy
- 16This Website
- 17Reports and moderation
01
Data Controller
The data controller within the meaning of GDPR is:
Moonjourn GmbH
Friedrichstraße 155
10117 Berlin
Germany
Email: support@moonjourn.app
For any privacy-related inquiries, please contact us directly via email. We respond within 30 days, usually much sooner.
02
Core Principles
Moonjourn is built around Privacy by Design and Privacy by Default:
Minimum data: We only collect what the app technically needs.
Local first: Journal entries remain encrypted on your device and only leave it end-to-end encrypted once you set a journal password. The text of your entries never goes to the service that creates your personal texts.
Opt-in instead of preset: Usage statistics and the activity display for friends are off by default. You turn them on consciously.
No advertising, no ad trackers, no selling of your data to third parties. Ever. To keep the app stable, we process crash reports without any link to your account, see sections 10 and 14.
03
Data We Process
When you use Moonjourn, the following data categories may be processed:
Profile data: Name or pseudonym, gender (optional), date of birth, time of birth (optional), place of birth (optional), zodiac sign, ascendant, moon sign, life theme, language.
Account data: Email address, hashed password, authentication tokens. We also offer Sign-In via Apple and Google.
Usage data: Streak days, light points, level, app settings, achievements, avatar and frame selection.
Content: Journal entries, completed rituals, drawn tarot cards, saved affirmations, manifestation wishes.
Friend system (only when actively used): Display name, your Sternkreis code (10 characters), connection requests, list of blocked users. What confirmed friends see about you is described in section 8.
Place of birth (optional): The place search uses our own list of places on our servers in the EU. What you type goes to no other service. We store the place, its coordinates and time zone to compute your birth chart.
Device and push tokens: When you grant notification permission, a push token is generated by Apple or Google. It contains no plain data about you. We store it on our server together with your app language and zodiac sign so we can send you messages such as moon-phase notes, see section 9.
Usage statistics (only with your consent): Usage events without any link to your account, see section 14.
Records: When and which version of the terms of use you accepted, and your choices about usage statistics.
04
Local Processing
Journal entries stay exclusively on your device as long as you have not set a journal password; without a journal password they are not transmitted. They are encrypted in secure device storage, with the key held in iOS Keychain or Android Keystore. If you delete the app or lose your device, these local entries are irretrievably lost. Even we cannot restore them.
With a journal password set, your entries are synchronized with your account end-to-end encrypted (section 5) and survive device changes and reinstalls.
Your program progress, streak, and profile, on the other hand, are always synchronized with your account (section 5) so they survive device changes and reinstalls.
05
Cloud Synchronization (optional)
If you create an account, profile basics and progress are synchronized with our backend so you can continue on a second device or after reinstall. The backend is operated for us by a cloud provider (section 10).
We use the EU region. Data is physically located in the European Union (Ireland). Connections are TLS-encrypted throughout.
Journal entries in cloud sync: journal entries are only transmitted once you have set a journal password, and then end-to-end encrypted. Encryption happens on your device and the key never leaves it. We can never read such entries, and without your journal password we cannot restore them either. Without a journal password, entries remain exclusively on your device.
Entries that earlier app versions transmitted without a journal password remain readable in our database until re-encryption; we do not read them. As soon as you set a journal password, these existing entries are automatically re-encrypted.
Legal basis: Art. 6(1)(b) GDPR (contract performance) for the account and journal storage.
06
Machine-Generated Texts
Personalized card interpretations, horoscope texts, oracle answers and partner analyses are machine-generated. For this we use a technology provider; processing may also take place in the USA (section 10).
We transmit only what each feature needs, without names or email addresses: for example, the drawn tarot symbol with your zodiac sign, for the oracle your question and your age, for partner analyses the calculated results of both people without names, for the soul type at most three theme keywords from a fixed list of twelve themes that your device derives from your latest journal entries. Health and crises are not on this list.
We do not use your journal entries for card, horoscope, oracle, or partner texts, and the text of an entry never leaves your device towards this service. Please do not write any health data into your questions.
Safety check: before a text goes to the service and when you save an entry, a word list on your device checks whether it points to an acute crisis; if so, the app shows helpline numbers right away. The check runs only on your device. If it matches, we only count how often that happened in a week and in which area of the app, without account, text, or language.
The provider states that data submitted through the paid interface is not used to train its models. We use this paid interface exclusively.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract), because the personal texts are part of the service. The transfer to the USA is based on EU Standard Contractual Clauses.
07
In-App Purchases and Subscriptions
Premium subscriptions are processed through the Apple App Store or Google Play Store. Billing runs through your store account. We do not receive any payment data such as credit card or bank details.
The management of your subscription status (premium active, trial, renewal) is handled by a subscription management provider based in the USA (section 10). It receives your pseudonymous account ID and purchase receipts.
Legal basis: Art. 6(1)(b) GDPR (contract performance).
Apple Privacy: https://www.apple.com/legal/privacy
Google Play Privacy: https://policies.google.com/privacy
08
Friend System and Visibility
Moonjourn includes an optional friend system (Sternkreis). It is empty by default. A friendship only exists once both of you agree.
Your Sternkreis code (10 characters) is generated on registration. It is only visible if you share it. You can reset it at any time.
Once you are friends, you both see each other's name, zodiac sign, soul type, gender, level, avatar, frame, rank, date of birth with the year, time and place of birth, the daily card and a shared book if you start one. The app shows you this before your first friendship.
The activity display is off by default. You turn it on in Settings under “Privacy & Security”. Your confirmed friends then see THAT you drew a card, finished a ritual or wrote in your journal today, never the content.
Blocking is immediate: a blocked person loses all visibility of your profile and can no longer send you requests. You can end a friendship at any time.
Legal bases: Art. 6(1)(b) GDPR for what a friendship makes visible, because you enter it yourself; for the activity display your consent under Art. 6(1)(a) GDPR, which is the switch in Settings.
09
Push Notifications
Morning and evening reminders are scheduled locally on your device.
In addition, with notification permission granted, we may send you messages from our server, such as moon-phase notes or special offers. For this we store your push token together with your app language and zodiac sign. Delivery runs through a push service based in the USA (section 10) to Apple or Google. Contents of your journals or other sensitive data are never transmitted this way.
You can disable notifications at any time in the app settings or system settings; we then stop sending messages. When you disable, existing scheduled reminders are reliably cancelled.
10
Data Processors
The following service providers process data on our behalf, each under a data processing agreement pursuant to Art. 28 GDPR. We list them by their function. On request to support@moonjourn.app we will tell you which companies they are.
Hosting, account and database: cloud provider based in Singapore. Your data is stored on servers in the EU (Ireland). Any access by the provider from Singapore is covered by EU Standard Contractual Clauses.
Machine generation of personal texts (interpretations, horoscopes, oracle answers, partner analyses): technology provider, processing also in the USA. Transfers are based on EU Standard Contractual Clauses.
Subscription management: software provider based in the USA. Transfers are based on EU Standard Contractual Clauses.
Payment processing and delivery of push messages: Apple Inc. (USA) and Google LLC (USA). Transfers are based on EU Standard Contractual Clauses.
Crash and error reports to keep the app stable, without account identifier, real names or journal contents: software provider based in the USA, processing on servers in the EU. Only with your consent to usage statistics does it also measure loading times. Additionally covered by EU Standard Contractual Clauses.
App updates and sending of push messages: software provider based in the USA. Transfers are based on EU Standard Contractual Clauses.
Protection of sign-in against automated access: network and security provider based in the USA. During registration, e-mail sign-in and password reset, it checks that a real person is operating the app and processes the IP address and technical characteristics of the device for that purpose. Transfers are based on EU Standard Contractual Clauses.
11
Data Retention
Profile and account data is stored as long as your account is active. If you delete your account, all server-side data is deleted immediately and local remnants are removed from the device. Only legal retention obligations (e.g., tax records for paid purchases) lead to limited retention of billing metadata at the store provider.
Records of your acceptance of the terms of use and of your choices about usage statistics are kept as long as your account exists, so that we can prove them. They are deleted together with the account.
Usage statistics: events are deleted automatically after 180 days.
Friend lookup attempts are automatically deleted after 24 hours (rate limiting).
Referral reward audit logs are retained for 12 months, then pseudonymized.
12
Your Rights
You have the following rights:
Right of access (Art. 15 GDPR): Information about the data stored about you.
Right to rectification (Art. 16 GDPR): Correction of inaccurate data.
Right to erasure (Art. 17 GDPR): Deletion of your data. In the app: Settings > End contract and delete account. Deletion is immediate and irreversible.
Right to restriction (Art. 18 GDPR): Restriction of processing.
Right to data portability (Art. 20 GDPR): Receiving your data in a common format. You can export it through the app settings or request it by email.
Right to object (Art. 21 GDPR): Object to processing based on legitimate interest.
Right to withdraw consent (Art. 7(3) GDPR): You can withdraw a consent you gave at any time, usage statistics and the activity display with their switches in Settings under “Privacy & Security”.
Right to lodge a complaint (Art. 77 GDPR): Lodge a complaint with a data protection supervisory authority. In Berlin: Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59-61, 10555 Berlin.
13
Data Deletion
Three ways:
In the app: Settings > Reset Data deletes all local data, the account remains.
In the app: Settings > End contract and delete account performs a full GDPR-compliant deletion. All server-side and local data is removed, the auth account is deleted. Founding-Member slots are released.
Via email to support@moonjourn.app. We delete within 30 days, usually much sooner.
After deletion we keep a deletion record for twelve months (account identifier, time, result) so that we can prove the deletion. It contains no content and is removed automatically afterwards. The customer record at our subscription management provider is deleted in the same step.
14
What We Do NOT Do
We use no advertising and no third-party analytics: no Google Analytics, no Mixpanel, no Amplitude, no Facebook SDK, no TikTok pixel, no advertising IDs.
What we do instead: only if you allow usage statistics (when agreeing after signing in or in Settings) do we record usage events (for example, which section was opened and how long a session lasted) in our own database in the EU. They carry no link to your account, only a random identifier that expires when you withdraw consent, sign out or switch accounts. Crash reports are processed by a service provider on servers in the EU, without your account identifier (section 10).
We use no cookies in the app.
We use no fingerprinting technologies.
We never sell your data to third parties.
We never share the contents of your personal journals with other users, not even in the friend system. A shared book is something you start together on purpose.
Journals with a journal password set are technically impossible for us to read.
15
Changes to This Policy
If we change this privacy policy substantially, we will notify you the next time you launch the app. For mere clarifications, only the date at the top is updated.
16
This Website
This privacy policy also covers moonjourn.app. For the website, the following applies in addition:
No cookies, no tracking, no analytics, no advertising networks. The site stores nothing in your browser that would make you recognizable.
Fonts, images, and videos are served from our own server. Opening the page establishes no connection to Google Fonts, to a content delivery network, or to any other third-party service.
Server logs: when you open the page, our host creates technical logs containing the IP address, time, requested address, amount of data transferred, and browser identification. They serve secure operation. We do not analyse them and do not combine them with other data. The host is Hostinger International Ltd., Lithuania. Legal basis: Art. 6(1)(f) GDPR.
Waiting list: if you sign up, we store your email address, your name if you provide it, the language selected, the page you came from, and the IP address and browser identification of your request. The IP address serves solely to block automated sign-ups. We will write to you exactly once, when Moonjourn is available in the App Store and on Google Play, and delete the list afterwards. No newsletter, no advertising, no sharing with third parties. You can request deletion at any time beforehand at hello@moonjourn.app. Legal basis: Art. 6(1)(a) GDPR.
17
Reports and moderation
When you report a person or a piece of content, we store your account identifier, the identifier of the reported person, the reason selected, your description, the time, and the processing status together with any measure taken. The reported person does not learn who submitted the report.
The purpose is to handle the report, to enforce the terms of use, and to prevent misuse of the reporting function.
Legal bases: Art. 6(1)(c) GDPR in conjunction with Articles 16 and 17 of Regulation (EU) 2022/2065, and Art. 6(1)(f) GDPR, our legitimate interest in a safe service.
We keep reports for as long as they are needed to handle the case and to document our decision, and delete them afterwards.