01 Who we are
Ally (“Ally,” “we,” “our”) is a mobile application developed and operated by Stellar Ally AB, a company incorporated in Sweden. The App is available on iOS and Android at allyguide.app. This policy covers both the app and this website. If you have any questions about this policy, please contact us via chat.
02 Information we collect
Information you provide directly
- Account information — your name and email address, provided through Google Sign-In or Apple Sign-In during registration.
- Birth information — your date of birth, birth time (optional), and birth city. This is used solely to compute your personal blueprint and generate your daily messages.
- Your notes — if you write a note against a daily message, we store what you wrote, alongside that message. Notes are yours: you can edit or delete any of them at any time, including after a subscription ends, and they are included in the data export described in section 06.
Details you give us about someone else
A Compatibility reading compares your blueprint with another person’s, so it asks you for their birth details.
- Their birth information — the name, date, time (optional) and city you enter for them. It is used to compute the reading, and it is stored with that reading so you can open it again later without re-entering anything.
- Please ask them first. Only enter details for someone who is happy for you to. We have no way to contact them ourselves, so you are the only person who can tell them.
- How it is deleted — these details belong to your account. Delete your account and they are permanently deleted along with everything else, on the same schedule described in section 05. You can also delete an individual reading from inside the app: open the reading and choose “Delete this reading” at the end of it. If someone contacts us asking us to remove details you entered about them, we will find and delete them.
Information generated by using the service
- Feedback — ratings (thumbs up / thumbs down) and optional reasons you submit on daily messages.
- Follow-up questions — when you ask Ally about one of your daily messages, we store your question and the answer, so the exchange is still there when you come back to it. You can delete your account to remove them, as with everything else.
- Consent records — timestamps and version numbers of the privacy policy and terms of service you agreed to, and whether you have switched on letting Ally read your notes or telling you about what is happening in the sky.
- Push notification token — a device token used to deliver notifications you have asked for: your daily message, and, if you switch it on, a note when something is happening in the sky. We do not include any personal information in the notification payload itself.
- When you last used the app — the date and time you last opened Ally. We keep only the most recent one, never a history of your visits, and nothing about what you did while you were there. Section 03 says what it is for.
- Sign-in sessions — one record for each device you are signed in on, so signing in on a new phone does not sign you out of the old one. It holds a scrambled version of the token that keeps that device signed in, when the session began, and when it expires (a week after sign-in). It says nothing about what you did. A session is removed when you sign out on that device, when it expires, and with your account.
- Purchase records — what you bought and when, and when a reading was delivered or deleted. They show what you paid for, and they are deleted with your account.
When you visit this website
This site uses Cloudflare Web Analytics, so we can tell whether anyone is finding it. We chose it because it is one of the few analytics tools that needs no cookie banner — and the reason it needs none is that it does not track you.
- It stores nothing on your device — no cookies, no local storage, no identifier of any kind. Nothing about you carries from one visit to the next, which means we cannot tell a returning visitor from a new one. We accepted that trade deliberately.
- What it records — the page you opened, the site that linked you to it if there was one, your browser and device type, the country your connection appears to come from, and how quickly the page loaded.
- Your IP address is not stored — Cloudflare uses it in the moment to work out a country, then discards it. It is never written down and never joined to an Ally account.
- This is the website only — the app carries no analytics of this kind. The one thing the app records about use is when your account was last used, described above. And because there is no identifier involved, nothing recorded here can be connected to you as a person, whether or not you have an account.
- Separately, our host keeps server logs — as every web host does. Loading a page here means Render, which serves it, records the request in its logs. We do not read those logs to learn anything about visitors, and they are not joined to anything else.
Information we do not collect
- We do not store your IP address — not in the app, and not on this website.
- We do not collect precise GPS location or device sensor data.
- We do not track you across other websites, and we use no device fingerprints and no advertising identifiers.
- We do not collect any data for targeted advertising. Ally contains no advertising.
03 How we use your information
- To provide the service — your birth information is used to compute your personal energetic blueprint via a third-party calculation service. Your name and blueprint data are used to generate your daily personalised messages.
- To send notifications — your device token is used to deliver your daily message alert. Separately, and only if you switch it on, we can tell you on the morning of a new moon, a full moon, an eclipse, or the day one of the personal planets changes direction. That is free information about the sky, the same for everyone, and it is never used to advertise to you. It is off unless you ask for it, you can switch it off again in the app at any time, and you can disable notifications entirely in your device settings.
- To manage your subscription — subscription status is managed by your app store. We receive anonymised subscription events to gate access to premium features.
- To improve the service — aggregated, anonymised feedback helps us understand which messages resonate.
- To apply our retention rules — the last time you used the app is how we know an account has gone unused for 12 months (section 05), and counted across all accounts it tells us whether Ally is being used at all.
- To comply with legal obligations — we retain consent records as required by applicable law.
We do not use your personal information to train AI models, and our AI provider does not use it to train theirs. Your birth data is used as input to compute your blueprint; it is never sent to AI models directly. AI models receive only blueprint-derived data (energy type, profile, key traits) — never your name, email, birth date, or birth city. One exception: in a Compatibility reading, the first name you enter for the other person is included so the reading can refer to them by name. Their birth details are not.
Follow-up questions. When you ask Ally about a message, your question is sent to the AI model along with that message and your blueprint-derived data, so it can answer you. Your question is your own words, so please treat it as you would anything you write down. It is not used to train any model.
Your notes are yours. They are never used to train AI models, and our AI provider does not use them to train theirs — that will not change.
By default your notes are stored for you to re-read and nothing more: they are not sent to any AI model, and they play no part in how anything is written. You can choose to change that. Beside the note box there is a switch that lets Ally read your notes when it answers your follow-up questions, so its answers can take account of what you are actually going through. It is off unless you turn it on, you can turn it off again at any moment, and we keep a record of both so you can see what you agreed to and when. Turning it off stops it immediately; your notes stay yours either way.
05 Data retention
- Active accounts — data is retained for the duration of your use of the service.
- Deleted accounts — when you delete your account, your data enters a 30-day grace period during which you can reactivate by signing in again. After 30 days, all data — including your chart, messages, and feedback — is permanently and irreversibly deleted within 90 days. Backups containing your data are also purged within that window.
- Details about other people — birth details you entered for a Compatibility reading are stored with that reading and deleted with your account, on the same schedule.
- Inactive accounts — accounts not used for more than 12 months, counted from the last time the app was opened, may receive a re-engagement notification before being scheduled for deletion.
- Audit logs — system logs are retained for 1 year and contain no personally identifiable information.
06 Your rights
Depending on where you live, you may have the following rights regarding your personal data. You can exercise all of them directly within the app or by contacting us via chat:
- Access — request a copy of all personal data we hold about you.
- Portability — export your data in machine-readable format (You → the ⋮ button → Purchases, data and deletion → Export my data).
- Rectification — correct or update your birth data at any time (You → the ⋮ button → Your birth details → Refine birth time).
- Erasure (“right to be forgotten”) — permanently delete your account and all associated data (You → the ⋮ button → Purchases, data and deletion → Delete account), or see Deleting your account.
- Restriction — request that we restrict processing of your data while a dispute is being resolved.
- Objection — object to processing based on our legitimate interests.
- Withdraw consent — you may withdraw consent at any time by deleting your account. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
California residents (CCPA/CPRA)
You have the right to know what personal information we collect, to delete it, and to opt out of its sale. We do not sell personal information.
EU/UK residents (GDPR/UK GDPR)
Our lawful basis for processing your account, birth and blueprint data is consent (Article 6(1)(a)) — given when you create an account, and withdrawable as described above.
The website analytics in section 02 is the one exception. It involves no cookie, no identifier and nothing that can be traced back to a person, so we rely on legitimate interest (Article 6(1)(f)) in knowing whether this site reaches anyone at all. You can object to it at any time under “Objection” above, and blocking scripts from static.cloudflareinsights.com in your browser stops it outright.
Recording when you last used the app also relies on legitimate interest (Article 6(1)(f)). Deleting accounts that have gone unused, as section 05 promises, is impossible without knowing when an account was last used; and knowing whether anyone uses Ally at all is basic to running it. It is a single timestamp rather than a record of what you do, and it is deleted with your account. You can object under “Objection” above.
You have the right to lodge a complaint with your local supervisory authority.
We will respond to all requests within 30 days.
07 International data transfers
Ally is operated on Google Cloud infrastructure in the European Union (europe-west3, Frankfurt, Germany). AI and model processing of your blueprint-derived data is performed within the European Union (EU multi-region endpoint) and does not leave the EU. Some data is also processed in the United States by our service providers (see Section 4). Google Cloud, Firebase, and RevenueCat process data under Standard Contractual Clauses approved by the European Commission where required. On iPhones, push notifications are delivered by Apple’s own notification service, which receives the device token and the text of the notification.
This website is separate from all of that. It is hosted by Render and its analytics script is served by Cloudflare, both United States companies, so loading a page here means your connection reaches the United States. Each processes visitor data under its own data processing agreement with us; Cloudflare is additionally certified under the EU–US Data Privacy Framework. What they receive is described in section 02, none of it is stored against you, and none of it comes from the app or touches your account, birth data, messages or notes — those stay in the European Union as described above.
08 Children's privacy
Ally is intended for users aged 18 and over. We do not knowingly collect personal information from anyone under 18. If you believe a minor has created an account, please contact us via chat and we will delete the account promptly.
09 Security
We use industry-standard safeguards: TLS 1.3 for all data in transit, encryption at rest on our servers, access controls, and regular security audits. Authentication tokens are stored in your device's secure keychain (iOS Keychain / Android Keystore) — never in unprotected storage. No method of transmission or storage is 100% secure; we cannot guarantee absolute security, but we take every reasonable precaution.
10 Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page. For material changes we also give the policy a new version number and, the next time you open the app, show you what changed and ask you to agree before you continue. If you do not agree, you can sign out or delete your account from that same screen.
11 Contact us
For privacy questions, data requests, or general support, use the chat widget on this site or in the app. We respond within one business day.