Privacy Policy

How Infoash UG (haftungsbeschränkt) handles personal data in Pocketstone, Vaara and Sunsign Daily.

In force from 25 September 2026. Controller: Infoash UG (haftungsbeschränkt), Germany. Contact: hello@infoash.de .

1. In short

We collect the minimum needed to produce your daily reading, and we do not sell it, do not show advertising, and do not embed advertising SDKs. We use Google’s Firebase Crashlytics so we learn when the app crashes, and Firebase Analytics only if you turn usage statistics on (adults only; it is off until you do). You can delete everything from inside the app, at any time, without contacting us and without giving a reason.

2. What we collect, and why

2.1 Every app

DataWhyLegal basis
Age band (not your date of birth) captured at the age gate To confirm you meet the minimum age for your storefront Legal obligation; legitimate interest in age-appropriate access
Country of residence, self-declared at onboarding Determines which data-protection regime applies to you, including whether an EU child-consent age is engaged Legal obligation
Check-in and streak history The daily loop and progression Contract — you asked for a daily habit product
Journal entries — free text you choose to write in the in-app journal (Pocketstone and Sunsign Daily) So you can keep a daily note beside what the app showed you that day. Stored on your device only. Never transmitted to us or anyone, never analysed, never used to change what the app shows you — the app stores your words and displays them back to you verbatim, and does nothing else with them. Consent — the journal asks before your first entry, works only if you agree, and the rest of the app is unchanged if you decline. Because free text can contain anything you choose to write about yourself, we treat it with the same care as special-category data even where it is not.
Subscription and entitlement state To know what you have access to Contract
Crash reports (Firebase Crashlytics): the crash trace, device model, operating-system and app version, and a random installation ID. Never your birth data, journal, name or stone To find and fix faults Legitimate interest
Usage statistics (Firebase Analytics), only if you turn them on: which screens and buttons are used, with a random app-instance ID. Never your birth data, journal, name or stone To see what confuses people and fix it Consent — off by default, offered only to users aged 18 and over, and you can switch it off at any time in Settings

2.2 Birth data — Vaara and Sunsign Daily

DataWhich appWhy
Date of birth Both Required to compute your sign or chart. This is a separate collection from the age gate, and it is retained
Time of birth Vaara required, Sunsign Daily optional In Vaara it determines the ascendant, the nakshatra and the pada; without it the reading is explicitly marked reduced-confidence. In Sunsign Daily it is optional, and in this version it is not used for anything — the app computes your sun sign from the date alone. If you enter it, it stays on your device and you can clear it at any time. We would rather tell you that than hold it and imply a use it does not have.
Place of birth Vaara Resolved to coordinates and a historical timezone so the chart is computed against the correct local time

We treat birth data, and any answer that could reveal a belief, as special-category data under Article 9 and collect it only with your separate, explicit consent, given through a card that states the purpose before anything is captured. We take that position because it is the more protective one, not because the law compels a single reading of astrology-derived output. You can decline and still use the app.

2.3 Pocketstone — quiz answers

The optional matching quiz asks about intentions and how you want to feel. Those answers can reveal beliefs, so we treat them as special-category data under Article 9 and collect them only with your separate, explicit consent. You can decline and still use the app — the self-select path exists precisely so the quiz is never the only route in.

We store derived weights, not your raw answers. If you withdraw consent, the weights are deleted, not flagged — and the app tells you what that does to your match before you confirm.

2.4 What we do not collect

No advertising identifiers. No advertising SDKs. No analytics unless you turn usage statistics on. No contacts, photos, precise location, or health data. No behavioural profiling of under-18 accounts: usage statistics are not offered to them at all.

3. Who processes it

ProcessorRoleLocation
Your device All of it — readings, chart, streak, preferences On the device, in app storage. No server-side database is used and there is no account
RevenueCat Subscription state and receipt validation United States — transfers under Standard Contractual Clauses
Google (Firebase) Crash reports (Crashlytics) for everyone; usage statistics (Analytics) only if you turn them on EU and United States — transfers under the EU–US Data Privacy Framework and Standard Contractual Clauses
Apple / Google Payment processing and delivery. They are independent controllers for payment data; we never see your card details Per their own terms
Expo Build and over-the-air updates United States

We do not sell personal data and have no advertising partners. Google processes crash reports and, if you allow them, usage statistics on our behalf; it does not use them for advertising.

4. How long we keep it

5. Your rights

Journal entries are covered by every right on this page. "Delete my data" in the app deletes every journal entry with everything else, and the in-app export includes them. Because entries never leave your device, deletion is immediate and complete — there is no copy anywhere else to chase.

Under GDPR you may request access, correction, deletion, restriction, portability, and object to processing. Where processing rests on consent you may withdraw it at any time, and withdrawal is as easy as giving it.

Deletion is self-serve, unconditional, and inside the app. You do not have to email us, give a reason, or speak to anyone. Export is available in the same place.

You may complain to your supervisory authority. Ours is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit).

We determine which regime applies to you from a country-of-residence question you answer yourself, with your store region retained only as a documented cross-check. We ask you rather than inferring it from your network address, because an IP address describes a router and not a person.

The minimum age is 13 in every storefront. Where local law sets a higher digital-consent age, that law applies to you regardless of what this app enforces, and we will raise the threshold if we are required to.

6. Children

Minimum age is 13, applied as a per-storefront configured value so a jurisdiction requiring a higher age is a settings change and not a rebuild. We do not behaviourally profile or send targeted notifications to under-18 profiles.

7. What these apps are not

They are for reflection and intention-setting. They are not medical, psychological, or financial advice. There is no scientific evidence that crystals or astrology affect health, mood or events. They do not diagnose, treat, cure, or prevent anything, and nothing in them should replace a qualified professional.

Content is produced by a deterministic rules engine over a written content library. It is not generated per request, and it is not written by a person about you — two people with the same sign or stone on the same day see closely related text, and we would rather say so.

8. Contact

Infoash UG (haftungsbeschränkt)
Bernauer Straße 49, 10435 Berlin, Germany · hello@infoash.de

Write to hello@infoash.de for any request under this policy — access, correction, erasure, portability or objection. We aim to reply within 30 days, the Article 12(3) deadline. You may also complain to your local supervisory authority; ours is the Berlin Commissioner for Data Protection and Freedom of Information.

9. Grievance Officer

Ashwin Shekhar, on behalf of Infoash UG (haftungsbeschränkt), is the named Grievance Officer for all three apps. Write to hello@infoash.de with any complaint about the content of an app, your privacy, or how your data has been handled.

This is a named role rather than a relabelled support queue. It shares an inbox with ordinary support mail, so say plainly that you are raising a grievance and it will be handled as one. We aim to reply within three working days. Requests made under section 5 of this policy keep the 30-day Article 12(3) deadline stated above, which is the longer and binding commitment where the two overlap.

This section names the officer, which is the part that does not depend on an open question. The response period that India's DPDP Rules require of that role, and whether one person may hold both this role and the support role, are still with counsel — so the times above are our own commercial commitments and are not offered as a statement of what any statute requires.