Legal
Privacy Policy
This privacy policy explains which personal data we process when you use the Moonjourn app and this website, for what purpose, and on what legal basis. It applies together with our legal notice (Imprint).
Contents
- 01Data Controller
- 02Core Principles
- 03Data We Process
- 04Local Processing
- 05Cloud Synchronization (optional)
- 06Algorithmic Personalization
- 07In-App Purchases and Subscriptions
- 08Friend System and Visibility
- 09Push Notifications
- 10Data Processors
- 11Data Retention
- 12Your Rights
- 13Data Deletion
- 14What We Do NOT Do
- 15Changes to This Policy
- 16This Website
- 17Reports and moderation
01
Data Controller
The data controller within the meaning of GDPR is:
Moonjourn GmbH i. G.
Hohenzollerndamm 8
10717 Berlin
Germany
Email: support@moonjourn.app
For any privacy-related inquiries, please contact us directly via email. We respond within 30 days, usually much sooner.
02
Core Principles
Moonjourn is built around Privacy by Design and Privacy by Default:
Minimum data: We only collect what the app technically needs.
Local first: Journal entries remain encrypted on your device by default and only leave it when you actively turn on cloud sync. The one exception is the safety check described in section 6.
Opt-in over opt-out: Sharing with other users, activity visibility, and birthday display are off by default. You turn them on consciously.
No advertising, no ad trackers, no selling of your data to third parties. Ever. To keep the app stable and improve it, we record pseudonymous usage events in our own EU database as well as crash reports, see sections 10 and 14.
03
Data We Process
When you use Moonjourn, the following data categories may be processed:
Profile data: Name or pseudonym, gender (optional), date of birth, time of birth (optional), place of birth (optional), zodiac sign, ascendant, moon sign, life theme, language.
Account data: Email address, hashed password, authentication tokens. We also offer Sign-In via Apple and Google.
Usage data: Streak days, light points, level, app settings, achievements, avatar and frame selection.
Content: Journal entries with mood and gratitude notes, completed rituals, drawn tarot cards, saved affirmations, manifestation wishes.
Friend system (only when actively used): Display name, your Sternkreis code (10 characters), connection requests, birthday month and day (only if you opt in), list of blocked users.
Birth-place coordinates (optional): If you provide a birth place, we fetch latitude and longitude through the OpenStreetMap geocoding service Nominatim to compute your natal chart. We send only the place name, no personal data.
Device and push tokens: When you grant notification permission, a push token is generated by Apple or Google. It contains no plain data about you. We store it on our server together with your app language and zodiac sign so we can send you messages such as moon-phase notes, see section 9.
04
Local Processing
Journal entries with mood, gratitude, and reflection stay exclusively on your device as long as you have not set a journal password; without a journal password they are not transmitted. They are encrypted in secure device storage, with the key held in iOS Keychain or Android Keystore. If you delete the app or lose your device, these local entries are irretrievably lost. Even we cannot restore them.
With a journal password set, your entries are synchronized with your account end-to-end encrypted (section 5) and survive device changes and reinstalls.
Your program progress, streak, and profile, on the other hand, are always synchronized with your account (section 5) so they survive device changes and reinstalls.
05
Cloud Synchronization (optional)
If you create an account, profile basics and progress are synchronized with our backend so you can continue on a second device or after reinstall. Synchronization runs through Supabase (Supabase Inc., 970 Toa Payoh North #07-04, Singapore, with EU region in Frankfurt).
We use the EU region. Data is physically located in the European Union (Frankfurt am Main). Connections are TLS-encrypted throughout.
Journal entries in cloud sync: journal entries are only transmitted once you have set a journal password, and then end-to-end encrypted. Encryption happens on your device and the key never leaves it. We can never read such entries, and without your journal password we cannot restore them either. Without a journal password, entries remain exclusively on your device.
Entries that earlier app versions transmitted without a journal password remain readable in our database until re-encryption; we do not read them. As soon as you set a journal password, these existing entries are automatically re-encrypted.
Legal basis: Art. 6(1)(b) GDPR (contract performance) for the account and journal storage.
Supabase Privacy Policy: https://supabase.com/privacy
06
Algorithmic Personalization
Moonjourn uses Google Gemini (Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4) for personalized card interpretations, horoscope texts, oracle answers, partner analyses, and program reviews.
We transmit the details needed for each feature, without real names or email addresses: for example, the drawn tarot symbol plus your zodiac sign, or the question you ask the oracle.
We do not use your journal entries for card, horoscope, oracle, or partner texts. There are two places where journal text does reach the AI service, and you should know about both.
Safety check on saving: after you save an entry, the app checks the text for signs of an acute crisis so that it can show you helpline numbers immediately if needed. The first step is a word list that runs on your device. If it does not match clearly and the text is longer than 20 characters, the text is sent once to the AI service for assessment. The entry itself stays where it is. If there is a match, we store a note without the text: category, feature concerned, language, and time.
Review at the end of a program: on the last day of a program, the app explicitly asks whether your entries may be summarized. Only if you agree are they decrypted on your device and sent once. If you decline, you receive a prepared text and nothing is transmitted.
Google states that data submitted through the paid API is not used to train Gemini models. We use this paid API exclusively.
Legal bases: Art. 6(1)(f) GDPR (legitimate interest in a personalized user experience and in the safety of our users), in cases of acute danger additionally Art. 6(1)(d) GDPR (vital interests), and for the program review Art. 6(1)(a) GDPR (your consent).
Google Privacy: https://policies.google.com/privacy
Gemini API Terms: https://ai.google.dev/gemini-api/terms
Where the check finds an indication, the note we store concerns your health and is therefore a special category of personal data under Art. 9 GDPR. We base this processing on Art. 9(2)(c) GDPR, the protection of vital interests, limit it to what is necessary, and store no text.
07
In-App Purchases and Subscriptions
Premium subscriptions are processed through the Apple App Store or Google Play Store. Billing runs through your store account. We do not receive any payment data such as credit card or bank details.
The management of your subscription status (premium active, trial, renewal) is handled by RevenueCat (RevenueCat Inc., 169 Madison Avenue, New York). RevenueCat receives your anonymous Supabase user ID and purchase receipts.
Legal basis: Art. 6(1)(b) GDPR (contract performance).
RevenueCat Privacy: https://www.revenuecat.com/privacy
Apple Privacy: https://www.apple.com/legal/privacy
Google Play Privacy: https://policies.google.com/privacy
08
Friend System and Visibility
Moonjourn includes an optional friend system (Sternkreis). It is empty and passive by default. You control it completely:
Your Sternkreis code (10 characters) is generated on registration. It is only visible if you share it. You can reset it at any time.
Connections require mutual confirmation. No one can pull you into their Sternkreis without an invite.
Activity sharing (which card you drew, whether you completed a ritual) is OFF by default. You opt in per activity type (tarot, journal, rituals, path).
Birthday display (only day and month, never the year) is its own opt-in.
Blocking is immediate: a blocked person loses all visibility of your profile and can no longer send you requests.
Legal basis: Art. 6(1)(a) GDPR (your explicit consent per toggle).
09
Push Notifications
Morning and evening reminders are scheduled locally on your device.
In addition, with notification permission granted, we may send you messages from our server, such as moon-phase notes or special offers. For this we store your push token together with your app language and zodiac sign. Delivery runs through the Expo Push Service (650 Industries Inc., USA) to Apple or Google. Contents of your journals or other sensitive data are never transmitted this way.
You can disable notifications at any time in the app settings or system settings; we then stop sending messages. When you disable, existing scheduled reminders are reliably cancelled.
10
Data Processors
The following service providers process data on our behalf, with data processing agreements pursuant to Art. 28 GDPR:
Supabase (Singapore / EU region Frankfurt): Account authentication, cloud synchronization, database.
Google Ireland Ltd. (Ireland): Algorithmic personalization via Gemini API.
RevenueCat Inc. (USA): Subscription management. Data transfer to the USA is based on EU Standard Contractual Clauses.
Apple Inc. (USA) and Google LLC (USA): Payment processing and push notifications. Transfers are based on EU Standard Contractual Clauses.
Functional Software Inc. (Sentry, USA): Crash and error reports to keep the app stable, without real names and without journal contents. Transfers are based on EU Standard Contractual Clauses.
650 Industries Inc. (Expo, USA): Delivery of app updates and push messages. Transfers are based on EU Standard Contractual Clauses.
11
Data Retention
Profile and account data is stored as long as your account is active. If you delete your account, all server-side data is deleted immediately and local remnants are removed from the device. Only legal retention obligations (e.g., tax records for paid purchases) lead to limited retention of billing metadata at the store provider.
Friend lookup attempts are automatically deleted after 24 hours (rate limiting).
Referral reward audit logs are retained for 12 months, then pseudonymized.
12
Your Rights
You have the following rights:
Right of access (Art. 15 GDPR): Information about the data stored about you.
Right to rectification (Art. 16 GDPR): Correction of inaccurate data.
Right to erasure (Art. 17 GDPR): Deletion of your data. In the app: Settings > Delete Account. Deletion is immediate and irreversible.
Right to restriction (Art. 18 GDPR): Restriction of processing.
Right to data portability (Art. 20 GDPR): Receiving your data in a common format. You can export it through the app settings or request it by email.
Right to object (Art. 21 GDPR): Object to processing based on legitimate interest.
Right to withdraw consent (Art. 7(3) GDPR): Withdraw given consents at any time via the privacy toggles in the settings.
Right to lodge a complaint (Art. 77 GDPR): Lodge a complaint with a data protection supervisory authority. In Berlin: Berliner Beauftragte für Datenschutz und Informationsfreiheit, Friedrichstraße 219, 10969 Berlin.
13
Data Deletion
Three ways:
In the app: Settings > Reset Data deletes all local data, the account remains.
In the app: Settings > Delete Account performs a full GDPR-compliant deletion. All server-side and local data is removed, the auth account is deleted. Founding-Member slots are released.
Via email to support@moonjourn.app. We delete within 30 days, usually much sooner.
14
What We Do NOT Do
We use no advertising and no third-party analytics: no Google Analytics, no Mixpanel, no Amplitude, no Facebook SDK, no TikTok pixel, no advertising IDs.
What we do instead: to improve the app, we record pseudonymous usage events (for example, which section was opened and how long a session lasted) in our own database in the EU, linked to your account ID, never to real names and never to journal contents. Crash reports run through Sentry (section 10).
We use no cookies in the app.
We use no fingerprinting technologies.
We never sell your data to third parties.
We never share the contents of your journals with other users, not even in the friend system.
Journals with a journal password set are technically impossible for us to read.
15
Changes to This Policy
If we change this privacy policy substantially, we will notify you the next time you launch the app. For mere clarifications, only the date at the top is updated.
16
This Website
This privacy policy also covers moonjourn.app. For the website, the following applies in addition:
No cookies, no tracking, no analytics, no advertising networks. The site stores nothing in your browser that would make you recognizable.
Fonts, images, and videos are served from our own server. Opening the page establishes no connection to Google Fonts, to a content delivery network, or to any other third-party service.
Server logs: when you open the page, our host creates technical logs containing the IP address, time, requested address, amount of data transferred, and browser identification. They serve secure operation. We do not analyse them and do not combine them with other data. The host is Hostinger International Ltd., Lithuania. Legal basis: Art. 6(1)(f) GDPR.
Waiting list: if you sign up, we store your email address, your name if you provide it, the language selected, the page you came from, and the IP address and browser identification of your request. The IP address serves solely to block automated sign-ups. We will write to you exactly once, when Moonjourn is available in the App Store and on Google Play, and delete the list afterwards. No newsletter, no advertising, no sharing with third parties. You can request deletion at any time beforehand at hello@moonjourn.app. Legal basis: Art. 6(1)(a) GDPR.
17
Reports and moderation
When you report a person or a piece of content, we store your account identifier, the identifier of the reported person, the reason selected, your description, the time, and the processing status together with any measure taken. The reported person does not learn who submitted the report.
The purpose is to handle the report, to enforce the terms of use, and to prevent misuse of the reporting function.
Legal bases: Art. 6(1)(c) GDPR in conjunction with Articles 16 and 17 of Regulation (EU) 2022/2065, and Art. 6(1)(f) GDPR, our legitimate interest in a safe service.
We keep reports for as long as they are needed to handle the case and to document our decision, and delete them afterwards.