SkyWiser
Legal

Privacy Policy

Effective 11 August 2026 · Applies to the SkyWiser iOS application and skywiser.app

1. The short version

Your journal is encrypted on your device and stored in your own iCloud. We cannot read it and we cannot recover it. Your birth date, time, and place are never sent to our servers. We do not know your name or your email address. There are no ads, no third-party trackers, and nothing is sold.

What we do hold: a one-way hash of the identifier Apple gives us, your subscription status, and a cached copy of the readings written for you, which expires after 24 hours. Deleting your account removes all of it.

The rest of this page is the detail behind those sentences. We have tried to write it so that it is worth reading rather than worth skipping, and to be honest about the trade-offs rather than only the flattering parts.

2. Who we are

SkyWiser is operated by Vipin Kumar (Bangalore, India), the data controller for the personal data described here. You can reach us at [email protected].

3. What we store on our servers

This is the complete inventory. If something is not on this list, we do not have it.

Your account identifier

When you sign in with Apple, Apple gives us a subject identifier — an opaque string, unique to you and to this app, that means nothing outside it. Our server does not keep that string. It replaces it with a one-way SHA-256 hash the moment your sign-in token is verified, and it is the hash, not Apple's identifier, that is written to our database and used everywhere below. The identifier Apple issued exists on our server only for the fraction of a second it takes to handle one request.

There is a single exception, and it is not stored. To connect an App Store purchase to your account, both the app and the server compute the same purchase token from Apple's identifier. The app can only do that with the original string, so the server computes its half the same way. The token that results is itself one-way, and it is the token — not the identifier — that is saved.

Apple's sign-in sheet asks whether you want to share your name and email with SkyWiser, and lets you hide your real address behind a private relay. Whatever you choose, our servers read only the subject identifier out of the token Apple issues. We never read, store, or log your name or your email address — there is no column for either one in our database, and no code that looks at them.

Your subscription status

The product you bought, your tier, whether you are in a trial, when the period expires, whether it will renew, and the Apple transaction identifier for it. We need this to know whether to unlock personalised readings. Apple also sends us server notifications when a subscription renews, lapses, or is refunded, and we record which notifications we have already processed so we don't act on the same one twice.

A cache of your readings

When a reading is generated for you, we store the resulting text against your account identifier, together with the date, the mood you selected, and a short non-reversible signature of your chart used as a cache key. This is so that re-opening the app on the same day returns the reading you already read instead of writing a new and different one.

Each cached reading carries an expiry — 24 hours after it was written — and a job on our server deletes expired rows outright. They are not merely hidden after that point; they are removed.

A daily request counter

We count how many readings your account has requested during the current day, to enforce a fair-use limit and to keep costs predictable. The counter is recorded against your account identifier and expires at the end of that day (UTC), after which the same job deletes it. It is a running total for one day, not a history: nothing about how much you used SkyWiser last week is kept.

Aggregate counters

Per-day totals with no account attached: how many readings were generated across all users, how many subscription notifications Apple sent us, how many rows the clean-up job removed. These are kept indefinitely, because a number like "412 readings on 3 June" says nothing about any individual and is what tells us whether the service is working. No account identifier is recorded in them.

Server logs

Our servers log the method, path, response status, and duration of each request, plus errors. Logs do not contain request bodies, IP addresses, or device identifiers. Where an account needs to be referenced in a log line, we write a short one-way hash of the stored identifier — itself already a hash — so a log line cannot be matched back to a database row. Logs are retained by our hosting provider for a limited period and are used for debugging and abuse prevention.

4. What never reaches us

  • Your name and your email address. We want to be exact here rather than flattering: if you allow Apple to share them, they travel inside the sign-in token your phone sends us, because Apple puts them there. Our server reads a single claim out of that token — the subject identifier — and discards the rest with the token itself. Neither value is read, stored, logged, or forwarded anywhere, and the database has no column for either one.
  • Your birth date, birth time, or birth place.
  • Your journal entries.
  • Your device's location. We never ask for location permission, and the app has no ability to read where you are.
  • Your payment details. Apple processes payment; we never see a card number.
  • Your IP address. It is not logged or stored.
  • Any advertising identifier.

5. Your journal

Journal entries are encrypted on your device using AES-GCM (Apple's CryptoKit) before they are written anywhere. The encryption key is generated on your device and kept in your iCloud Keychain, so it travels between your own devices and never to us. The encrypted entries are stored in your own iCloud private database — your storage, your Apple Account, under your control.

We hold no copy of your entries and no copy of your key. We cannot read your journal, produce it in response to a request, or lose it in a breach of our systems, because it is not in our systems.

The honest flip side. Because we hold no key, we cannot help you recover your journal. If you lose access to your Apple Account, or you turn off iCloud Keychain and lose the key, your entries cannot be decrypted by anyone — including us. There is no reset, no support ticket, and no back door. If your journal matters to you, keep your Apple Account recovery options current.

One detail worth stating plainly: the date of each entry is stored alongside the encrypted content without encryption, so that the app can sort and display entries without decrypting everything. This means Apple's iCloud infrastructure can see when you wrote, though never what you wrote. Your entries are governed by Apple's privacy policy while at rest in your iCloud account.

6. Your birth details

Your birth date, time, and place are entered on your device and stay there. The entire astrological calculation — ascendant, planetary positions, nakshatras, sub-lords, and your Vimshottari dasha periods — runs locally on your iPhone. Your birth details are never sent to SkyWiser's servers. Like your journal, your computed chart is encrypted on-device and stored in your own iCloud private database.

There is one exception you should know about. To turn the birthplace you type into coordinates and a historical timezone, the app asks Apple's geocoding service to look it up. That means the place name you typed is sent to Apple, handled under Apple's privacy policy. Nothing else about you is included in that lookup, and it is the only time any part of your birth information leaves your device.

7. How readings are generated

Personalised readings are written by a large language model. We want to be exact about what that involves.

Who writes the reading

The text is generated by Anthropic's Claude API. SkyWiser's server sends the astrological data described below to Anthropic, receives the generated reading, and returns it to your phone. Anthropic processes it under their commercial terms, which provide that inputs and outputs submitted through their API are not used to train their models. See Anthropic's Commercial Terms of Service and their privacy documentation.

What is sent

Your device sends, and we forward to Anthropic:

  • Planetary positions and the ascendant from your natal chart, expressed as zodiacal longitudes, signs, nakshatras, and sub-lords
  • Today's transits and how they aspect your chart
  • Your current Vimshottari dasha periods, as start and end timestamps
  • Your ruling planets for the day
  • The mood you selected, or a short custom mood word you typed (letters only, up to 20 characters)
  • The local date and time offset the reading is for

What is not sent

Your name, your email, your birth date, your birth time, your birth place, your coordinates, your device location, and your journal are not included. The request format rejects any field it does not expect, and the model is instructed never to address you by name or refer to your identity.

We won't overstate this. The chart data we send is derived from your birth details, and a determined expert could work backwards from an ascendant degree and dasha boundaries to approximate when and roughly where you were born. So we describe this as personal data and protect it as such — we do not claim the payload is anonymous. What we can say precisely is that your birth details themselves are never transmitted, and that nothing in the payload identifies you by name, contact detail, or device.

Free readings, generated without a subscription, are not personalised at all: they are written once per day from the current transits and the same text is served to everyone who picks that mood.

8. What we don't do

  • No advertising. There are no ads in SkyWiser and no advertising networks in the app.
  • No third-party analytics or trackers. The app contains no analytics, attribution, or crash-reporting SDK. Nothing measures your behaviour and reports it onward.
  • No tracking across apps or websites. We do not link your activity to data from other companies, and the app declares no tracking domains.
  • No sale or sharing of personal data. We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in US state privacy laws.
  • No data brokers. We do not buy, enrich, or append data about you from anyone.

9. Who processes data for us

We use three service providers. This is the complete list.

Apple
Sign in with Apple, App Store payments and subscription notifications, iCloud storage of your own encrypted journal and chart, and geocoding of the birthplace you type. Privacy policy.
Anthropic
Generates the text of your readings from the chart data described in section 7, under commercial terms that exclude API inputs from model training. Commercial terms.
Railway
Hosts our server and its database, in the United States, and retains our server logs. Privacy policy.

Our servers and database are located in the United States. If you use SkyWiser from outside the United States, the limited data described in section 3 is transferred there. Where required, we rely on the European Commission's Standard Contractual Clauses or an equivalent transfer mechanism with our providers.

We may also disclose data if we are legally required to — but the practical value of such a request is low, because we hold no name, no email, no birth information, and no journal content.

10. How long we keep things

  • Account identifier and subscription record — kept while your account exists, and deleted when you delete your account. We may keep a minimal record of a transaction where tax or accounting law requires it.
  • Cached readings — each cached reading expires 24 hours after it is written, and a job on our server deletes expired rows. Deleting your account removes any that have not expired yet.
  • Daily request counters — kept for the current day only. The same job deletes each counter once its day (UTC) has ended, and deleting your account removes the current one immediately.
  • Aggregate counters — kept indefinitely. They carry no account identifier, so there is nothing in them to link to you or to erase.
  • Server logs — retained by our hosting provider for a limited period, then rotated out. They contain no request bodies and no IP addresses.
  • Journal and chart — kept in your iCloud for as long as you keep them. We have no role in this and cannot delete or retain them.

11. Deleting your account

You can delete your SkyWiser account from within the app, in Profile. Deletion is immediate and permanent.

What deletion removes from our servers:

  • Your account identifier and your subscription record
  • Every cached reading generated for you
  • Your daily request counter
  • The link between your account and our record of Apple subscription notifications. We keep those records themselves, stripped of any connection to you, because they are a replay guard: discarding them would let an old notification be re-processed as if it were new.

That is every place your account identifier appears. Nothing keyed to you is held back — the only rows that survive are the notification records above, with the link to you removed, and aggregate counters that never carried an identifier in the first place. An automated test checks every column of our database after a deletion and fails the build if any value still matches the deleted account.

We also ask Apple to revoke the Sign in with Apple tokens issued for SkyWiser, so the app's link to your Apple Account is severed.

What deletion does not touch:

  • Your journal and chart in iCloud. They are in your own storage, not ours, so we have no ability to reach them. Delete entries in the app before deleting your account, or remove the app's iCloud data in Settings, Apple Account, iCloud, Manage Account Storage.
  • Your subscription. Only Apple can cancel it. Deleting your account does not stop billing — cancel in your Apple Account settings separately, or you will continue to be charged.
  • Data held by Apple or Anthropic under their own retention policies.

If you cannot access the app, email [email protected] from a device where you are signed in and we will delete your server-side data for you.

12. Your rights

Depending on where you live — including in the EEA and UK under the GDPR, and in California and other US states with comparable laws — you have rights to access, correct, delete, and receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent. You also have the right to complain to your local data protection authority.

You can exercise most of these yourself: your journal and chart are already in your own iCloud, and account deletion in the app removes what we hold. For anything else, write to [email protected] and we will respond within the time your law requires, and in any case within 30 days. We will not charge you or treat you differently for exercising a right.

Where we need a legal basis under the GDPR: we process your account identifier and subscription status to perform our contract with you; we process the chart data in a reading request to perform that contract at your request; and we process request counters and logs for our legitimate interests in keeping the service running, affordable, and free from abuse.

13. Children

SkyWiser is rated 12+ and is not directed to children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has created an account, contact us and we will delete it.

14. Security

Traffic between the app and our servers is encrypted in transit with HTTPS. Journal entries and charts are encrypted on your device before storage. Sign in with Apple tokens are verified against Apple's public keys on every request, and we issue no long-lived session tokens of our own.

No system is perfectly secure, and we will not pretend otherwise. What we can say is that the amount of your data exposed by a breach of our servers is small by construction: an opaque identifier, a subscription record, and some astrological text.

15. Changes to this policy

We will update this policy when the app changes. The current version always lives at skywiser.app/privacy with its effective date at the top. If a change materially affects how we handle your data, we will give notice in the app before it takes effect.

16. Contact

Questions, requests, or concerns about privacy: [email protected]. A person reads that inbox.

Vipin Kumar
Bangalore, India

See also the Terms of Use and support.