Privacy Policy
How Infoash UG (haftungsbeschränkt) handles personal data in Pocketstone, Vaara and Sunsign Daily.
- Controller
- Infoash UG (haftungsbeschränkt), Germany
- Last updated
- 18 August 2026
- Applies to
- Pocketstone · Vaara · Sunsign Daily
1. In short
We collect the minimum needed to produce your daily reading, and we do not sell it, do not show advertising, and do not embed advertising SDKs. We use Google’s Firebase Crashlytics so we learn when the app crashes, and Firebase Analytics only if you turn usage statistics on (adults only; it is off until you do). You can delete everything from inside the app, at any time, without contacting us and without giving a reason.
2. What we collect, and why
2.1 Every app
| Data | Why | Legal basis |
|---|---|---|
| Age band (not your date of birth) captured at the age gate | To confirm you meet the minimum age for your storefront | Legal obligation; legitimate interest in age-appropriate access |
| Country of residence, self-declared at onboarding | Determines which data-protection regime applies to you, including whether an EU child-consent age is engaged | Legal obligation |
| Check-in and streak history | The daily loop and progression | Contract — you asked for a daily habit product |
| Journal entries — free text you choose to write in the in-app journal (Pocketstone and Sunsign Daily) | So you can keep a daily note beside what the app showed you that day. Stored on your device only. Never transmitted to us or anyone, never analysed, never used to change what the app shows you — the app stores your words and displays them back to you verbatim, and does nothing else with them. | Consent — the journal asks before your first entry, works only if you agree, and the rest of the app is unchanged if you decline. Because free text can contain anything you choose to write about yourself, we treat it with the same care as special-category data even where it is not. |
| Subscription and entitlement state | To know what you have access to | Contract |
| Crash reports (Firebase Crashlytics): the crash trace, device model, operating-system and app version, and a random installation ID. Never your birth data, journal, name or stone | To find and fix faults | Legitimate interest |
| Usage statistics (Firebase Analytics), only if you turn them on: which screens and buttons are used, with a random app-instance ID. Never your birth data, journal, name or stone | To see what confuses people and fix it | Consent — off by default, offered only to users aged 18 and over, and you can switch it off at any time in Settings |
2.2 Birth data — Vaara and Sunsign Daily
| Data | Which app | Why |
|---|---|---|
| Date of birth | Both | Required to compute your sign or chart. This is a separate collection from the age gate, and it is retained |
| Time of birth | Vaara required, Sunsign Daily optional | In Vaara it determines the ascendant, the nakshatra and the pada; without it the reading is explicitly marked reduced-confidence. In Sunsign Daily it is optional, and in this version it is not used for anything — the app computes your sun sign from the date alone. If you enter it, it stays on your device and you can clear it at any time. We would rather tell you that than hold it and imply a use it does not have. |
| Place of birth | Vaara | Resolved to coordinates and a historical timezone so the chart is computed against the correct local time |
We treat birth data, and any answer that could reveal a belief, as special-category data under Article 9 and collect it only with your separate, explicit consent, given through a card that states the purpose before anything is captured. We take that position because it is the more protective one, not because the law compels a single reading of astrology-derived output. You can decline and still use the app.
2.3 Pocketstone — quiz answers
The optional matching quiz asks about intentions and how you want to feel. Those answers can reveal beliefs, so we treat them as special-category data under Article 9 and collect them only with your separate, explicit consent. You can decline and still use the app — the self-select path exists precisely so the quiz is never the only route in.
We store derived weights, not your raw answers. If you withdraw consent, the weights are deleted, not flagged — and the app tells you what that does to your match before you confirm.
2.4 What we do not collect
No advertising identifiers. No advertising SDKs. No analytics unless you turn usage statistics on. No contacts, photos, precise location, or health data. No behavioural profiling of under-18 accounts: usage statistics are not offered to them at all.
3. Who processes it
| Processor | Role | Location |
|---|---|---|
| Your device | All of it — readings, chart, streak, preferences | On the device, in app storage. No server-side database is used and there is no account |
| RevenueCat | Subscription state and receipt validation | United States — transfers under Standard Contractual Clauses |
| Google (Firebase) | Crash reports (Crashlytics) for everyone; usage statistics (Analytics) only if you turn them on | EU and United States — transfers under the EU–US Data Privacy Framework and Standard Contractual Clauses |
| Apple / Google | Payment processing and delivery. They are independent controllers for payment data; we never see your card details | Per their own terms |
| Expo | Build and over-the-air updates | United States |
We do not sell personal data and have no advertising partners. Google processes crash reports and, if you allow them, usage statistics on our behalf; it does not use them for advertising.
4. How long we keep it
- Your data: until you delete it. There is no account to close, because there is no account.
- If you lose or reset your device: the data is gone, because it was only ever on the device. There is no account and no server copy, so there is nothing for us to restore and nothing for us to hand over. That is the trade this design makes deliberately — no recovery, and no copy of your birth data anywhere but in your own hand.
- Failed age gate: nothing is retained except a device-local block flag. No date of birth is stored.
- Crash reports: 90 days (Firebase Crashlytics retention).
- Usage statistics: 2 months (Google Analytics data-retention setting). Switching them off stops collection straight away.
5. Your rights
Journal entries are covered by every right on this page. "Delete my data" in the app deletes every journal entry with everything else, and the in-app export includes them. Because entries never leave your device, deletion is immediate and complete — there is no copy anywhere else to chase.
Under GDPR you may request access, correction, deletion, restriction, portability, and object to processing. Where processing rests on consent you may withdraw it at any time, and withdrawal is as easy as giving it.
Deletion is self-serve, unconditional, and inside the app. You do not have to email us, give a reason, or speak to anyone. Export is available in the same place.
You may complain to your supervisory authority. Ours is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit).
We determine which regime applies to you from a country-of-residence question you answer yourself, with your store region retained only as a documented cross-check. We ask you rather than inferring it from your network address, because an IP address describes a router and not a person.
The minimum age is 13 in every storefront. Where local law sets a higher digital-consent age, that law applies to you regardless of what this app enforces, and we will raise the threshold if we are required to.
6. Children
Minimum age is 13, applied as a per-storefront configured value so a jurisdiction requiring a higher age is a settings change and not a rebuild. We do not behaviourally profile or send targeted notifications to under-18 profiles.
7. What these apps are not
They are for reflection and intention-setting. They are not medical, psychological, or financial advice. There is no scientific evidence that crystals or astrology affect health, mood or events. They do not diagnose, treat, cure, or prevent anything, and nothing in them should replace a qualified professional.
Content is produced by a deterministic rules engine over a written content library. It is not generated per request, and it is not written by a person about you — two people with the same sign or stone on the same day see closely related text, and we would rather say so.
8. Contact
Infoash UG (haftungsbeschränkt)
Bernauer Straße 49, 10435 Berlin, Germany · hello@infoash.de
Write to hello@infoash.de for any request under this policy — access, correction, erasure, portability or objection. We aim to reply within 30 days, the Article 12(3) deadline. You may also complain to your local supervisory authority; ours is the Berlin Commissioner for Data Protection and Freedom of Information.
9. Grievance Officer
Ashwin Shekhar, on behalf of Infoash UG (haftungsbeschränkt), is the named Grievance Officer for all three apps. Write to hello@infoash.de with any complaint about the content of an app, your privacy, or how your data has been handled.
This is a named role rather than a relabelled support queue. It shares an inbox with ordinary support mail, so say plainly that you are raising a grievance and it will be handled as one. We aim to reply within three working days. Requests made under section 5 of this policy keep the 30-day Article 12(3) deadline stated above, which is the longer and binding commitment where the two overlap.
This section names the officer, which is the part that does not depend on an open question. The response period that India's DPDP Rules require of that role, and whether one person may hold both this role and the support role, are still with counsel — so the times above are our own commercial commitments and are not offered as a statement of what any statute requires.