Mystogian — Privacy Policy

Last updated: August 5, 2026

Mystogian (“the app,” “we,” “us”) is an astrology and personal-reflection app operated by an independent developer based in the Philippines. This policy explains what the app collects, why it is used, who processes it, how long it is kept, and the choices you have.

Contact for any privacy question: mystogianastro@gmail.com

Who can use Mystogian

Mystogian is available worldwide, in English only, and is intended for people 13 and older. When you create an account, you check a box confirming you meet this minimum age. We do not verify it beyond that. We also do not cross-check it against any birth date you enter for a chart, since the birth data you add doesn't have to be your own (you can build a chart for someone else, like a friend or partner).

What we collect

Mystogian collects information you provide, information created as the app works for you, and a limited amount of technical information needed to operate and improve the app.

  • Account and setup information — your email address, a display name you enter during setup, your age confirmation, and your sign-in method. You can sign in using an email one-time code or Continue with Google. If you use Google, Google and Supabase handle the authentication exchange and Google provides the identity information needed to sign you in, including your email address.
  • Your birth information — the birth date, birth time if known, and birth place you enter. The app also stores the coordinates and time zone returned for the selected place. These details are used to calculate and display your charts. If you say that the birth time is unknown, the app calculates a time-unknown chart and does not present time-dependent details as certain.
  • Your writing and activity in the app — journal entries, check-in text, mood and energy logs, decisions, decision outcomes, goals, focus areas, active and resolved concerns, and details you explicitly choose to save from a chat.
  • Memories and other generated records — short structured summaries derived from eligible journal entries, AI-generated interpretations and reports, calculated charts, timing information, patterns, and other records needed to provide the app's guidance and history features.
  • Bonds information — if you add another person, the app can store their name, relationship to you, pronouns, optional notes, birth date, birth time if known, birth place, place coordinates, time zone, calculated charts, and relationship readings involving you and that person. You are responsible for having an appropriate reason or permission to add someone else's information.
  • Preferences and device time zone — choices such as Western or Vedic display, journal-analysis and notification preferences, reminder settings, theme, forecast filter, whether decision text may appear in a reminder, and the device time zone used to present dates and run time-based features.
  • Subscription and billing status — Mystogian has RevenueCat subscription processing in its backend even though a paywall is not currently available in the app interface. The backend can receive a Mystogian account identifier, product identifier, subscription tier, subscription status, event type, and renewal or expiration time from RevenueCat. Mystogian does not receive or store your payment-card number.
  • Crash and diagnostic information — technical information about crashes and a limited class of non-fatal on-device storage errors. The content of these reports is restricted as described below.

We do not collect your phone contacts, precise device location, or advertising identifiers. A birth-place coordinate describes a place entered for a chart. It is not a reading of your device's current location. Mystogian does not show ads, connect to ad networks, or sell personal data.

Information stored on your device

Mystogian uses on-device storage so setup can be resumed, preferences can survive a restart, reminders can work, and previously generated interpretations can load without another AI request.

The app may store:

  • An unfinished setup draft, including the name, birth details, selected place coordinates and time zone, focus areas, goals, challenge, tone, and astrology-system choice entered so far.
  • Theme, journal, forecast, and notification preferences.
  • Locally scheduled reminder details.
  • A cache of AI-generated interpretations. The cache is capped at 300 entries and automatically removes the oldest entries when it reaches that limit.
  • Authentication-session information needed to keep you signed in.

An unfinished setup draft stays on the device until setup is completed, the draft is reset, or the app's local data is cleared. Birth-place search text is still sent to Open-Meteo while you search, as described below.

Uninstalling the app or clearing its app data removes this on-device information. After a successful in-app account deletion, Mystogian signs you out, resets the setup and preference stores, and cancels its scheduled reminders. The current deletion flow does not explicitly erase the persisted interpretation cache at that moment. Cached entries are keyed to the deleted account and are not shown to another account, but they can remain in the app's local storage until you uninstall the app or clear its app data.

How we use your information

Mystogian uses this information to create and explain charts, provide daily and weekly guidance, support chat and decision tools, keep the journal and decision history you ask it to keep, create relationship readings, generate and manage memories, show dates in the correct time zone, schedule reminders you enable, manage account access and subscription status, enforce feature limits, and diagnose technical problems.

We do not use personal data for advertising or create a marketing profile to sell or share with advertisers.

How AI processing works

Mystogian uses OpenAI's GPT models for chat, journal extraction, daily and weekly guidance, decision analysis, chart interpretations, reports, and relationship readings. The exact context depends on the feature being used.

Information sent to OpenAI can include:

  • The message, journal text, decision, or other request being processed.
  • Recent non-private journal entries and check-ins.
  • Your display name, time zone, selected focus areas, and other relevant profile settings.
  • Your calculated chart and birth-place coordinates or birth date when needed for an astrology feature.
  • Goals, concerns, mood logs, decision history, decision outcomes, derived memories, patterns, and previously generated context relevant to the request.
  • Recent chat turns needed to answer the current chat message.
  • For Bonds features, the added person's name, pronouns, relationship, chart information, and other relevant Bonds details.

OpenAI processes this information to return the requested result. OpenAI states that data sent to its API is not used to train its models by default. OpenAI also states that abuse-monitoring logs, which can contain prompts and responses, are retained for up to 30 days, unless longer retention is required by law or is reasonably necessary to protect its services or a third party from harm.

Private entries and the journal-analysis setting are different

Marking an entry private is the control that keeps that entry out of Mystogian's AI processing. Private entries are excluded from chat context, daily and weekly guidance, decision analysis, journal extraction, memory generation, and other AI features. If an entry is changed from non-private to private, memories derived from that entry are removed.

Turning off journal analysis does something narrower. It stops Mystogian from running the journal-extraction step that creates new memories and classifications from journal entries. It does not stop non-private journal entries from being included in AI context for chat, daily or weekly guidance, decision analysis, and other features that use recent journal history.

If you do not want the text of a particular entry sent to OpenAI at all, mark that entry private. Do not rely on the journal-analysis setting for that purpose.

Chat conversations

Chat uses temporary working memory. Recent visible turns are sent with the next message so the AI can follow the conversation. The transcript is held in the running app and is not currently saved as a server-side chat transcript. It clears when the app process closes.

If you explicitly confirm a save action from chat, the confirmed item can be stored as a decision or journal entry. The surrounding conversation is not stored with it. A saved non-private journal item may later be processed like another non-private journal entry.

Who processes information for us

Mystogian relies on a small number of services to operate. Each receives only the information needed for its role, subject to its own terms and privacy practices.

  • Supabase hosts the database, authentication, and server functions. Core records are protected with row-level security so an ordinary signed-in user can access only records belonging to that account. Authorized server functions use elevated access when needed to calculate results, run background work, process billing events, or delete an account.
  • Google authenticates you if you choose Continue with Google. Google provides the sign-in token and identity information needed by Supabase to sign you in.
  • OpenAI processes the AI context described above and returns generated responses.
  • Open-Meteo receives the birth-place search text and ordinary request parameters such as result count, language, and response format. Mystogian does not add your email, account ID, journal, birth date, or other Mystogian account data to that request. Like any internet service, Open-Meteo also receives ordinary network information involved in the request, such as an IP address.
  • RevenueCat sends server-to-server subscription events used to maintain subscription tier and status. Those events can contain an app user identifier, product and transaction-related information, event timestamps, and subscription lifecycle information. The Mystogian backend stores only the subscription fields it needs, including product, tier, status, and renewal or expiration time.
  • Sentry receives the restricted crash and diagnostic reports described below.

We do not share personal data with data brokers or ad networks.

Where information is stored and processed

Supabase is Mystogian's main server-side data store. Some information is also stored on your device as described above. Google, OpenAI, Open-Meteo, RevenueCat, and Sentry process information for their specific roles.

These providers operate internationally, so information may be processed outside the Philippines, including in the United States. Their own privacy notices describe their locations and retention practices in more detail.

Data security

Connections between the app and its online services use HTTPS/TLS. Supabase row-level security limits ordinary account access to the account owner's records. Sensitive server credentials are kept in server functions rather than in the app. Sentry reporting uses a restrictive allowlist so personal content is dropped before a report is sent.

Information stored on your phone also depends on the security of your device and operating system, such as its lock screen and app-data protections. No storage or transmission method is completely secure.

Crash and diagnostic reporting

When Sentry is enabled in a production build, it can receive automatic crash reports. Mystogian also reports a limited non-fatal error when an on-device storage read or write fails.

Before a report is sent, Mystogian builds a new restricted report containing only approved technical fields. These can include an event ID, time, severity, platform, app release and environment, error type, whether the error was handled, code filename and function, line and column numbers, and, for a storage failure, the app-defined storage-key name and whether the operation was a read or write.

The report does not include the error message, email, user identifier, journal or chat text, birth information, memories, decisions, URLs, request content, screenshots, screen recordings, breadcrumbs, source-code context, or arbitrary extra fields. Performance tracing, profiling, default personal-information collection, failed-request capture, screenshots, view hierarchy capture, and automatic session tracking are disabled.

Data retention

Active account records are kept while the account exists unless you delete individual records sooner. The app also keeps generated reports, charts, caches, patterns, and history needed to provide its features. Locally cached interpretations are capped and trimmed as described above.

When account deletion succeeds, Mystogian immediately hard-deletes the Supabase Auth account. User-owned database records linked to it are removed through database cascades, including profiles, charts, journal entries, mood logs, decisions, memories, Bonds records, reports, patterns, and subscription status.

Deletion from Mystogian's active systems does not guarantee that every service provider's backups, security logs, or transient processing copy disappears at the same instant. Providers may retain residual information according to their own retention schedules, safety rules, and legal obligations. On-device cache retention after account deletion is explained in “Information stored on your device.”

Your choices and rights

Mystogian gives you direct controls for the information you create. Some choices affect only one kind of processing, so the difference matters.

  • Mark a journal entry private to keep that entry out of all Mystogian AI processing.
  • Turn off journal analysis to stop new journal-derived memories and classifications. This does not keep non-private entries out of other AI requests.
  • Edit or delete journal entries. Deleting an entry also deletes memories derived from that entry.
  • View and delete memories.
  • Edit or remove people added through Bonds. Removing a person also removes their linked charts and relationship readings.
  • Change preferences and notification settings.
  • Delete your account in the app. Go to Settings, then Delete my account. Mystogian sends a fresh one-time code to the account email and requires that recent verification before permanent deletion. There is no recovery period and no in-app data-export feature, so save anything you want to keep first.
  • Request deletion without the app. Visit mystogian.com/delete-account or email mystogianastro@gmail.com. We will need to verify that you control the account before permanent deletion. An email request by itself is not proof of identity.

Your rights under Philippine law

Under the Philippine Data Privacy Act of 2012, you have the right to be informed, to access your data, to object to certain processing, to correct inaccurate data, to erase or block data, and, where technically feasible, to data portability.

You can use the controls in the app or email mystogianastro@gmail.com. We may ask you to verify control of the account before acting on a request. If you are not satisfied with our response, you can contact the National Privacy Commission at privacy.gov.ph.

If you are in the EEA, the UK, or elsewhere

Mystogian is operated from the Philippines and follows the Philippine Data Privacy Act. Where the law of your own country gives you additional rights, we honour those too. If you are in the European Economic Area or the United Kingdom, that includes the right to access, correct, erase, restrict, or object to our use of your data, and to complain to your local data protection authority.

Data you give us is stored and processed outside your country, including in the United States, by the providers named above.

We do not currently offer a self-service data export. If you want a copy of your data, email mystogianastro@gmail.com and we will verify you control the account before sending it.

If Mystogian is ever acquired

If Mystogian is acquired, merged, or its assets are transferred, information may be transferred as part of that transaction. It would remain subject to this policy unless a replacement policy is provided to you.

Children

Mystogian is not directed at children under 13. If you believe someone under 13 has created an account, contact mystogianastro@gmail.com so the account can be investigated and removed.

Changes to this policy

If we change how Mystogian handles information, we will update this page and the “Last updated” date above.

Contact

Privacy questions and requests: mystogianastro@gmail.com