Privacy Policy

Data controller:
Fabervant Teknoloji A.S.
Effective:

1. Who we are

Astrolect is operated by Fabervant Teknoloji A.S. (“Fabervant”, “we”, “us”), a joint stock company registered in Türkiye on 26 August 2026. Fabervant is the data controller (veri sorumlusu) for the personal data described here.

You can reach us about anything in this policy at [email protected].

2. What Astrolect is

Astrolect calculates astronomical positions for moments in time and scores them against a rulebook drawn from classical and modern electional astrology. It is an interpretive tradition, presented transparently — not a predictive or advisory service.

This policy describes what we do with your data. It makes no claim about what the service can tell you.

3. What we collect: your account

Your email address, which identifies your account and is where we send verification and password-reset messages.

Your password, stored only as a cryptographic hash. We never store the password itself. If you sign in with Google we store no password at all; we store the identifier Google gives us for your account instead.

Whether your email address has been verified, how much of your scan allowance remains, and the date your account was created.

4. What we collect: the people you add

To personalize a scan, Astrolect reads a birth chart, and a birth chart needs birth data. For each person you add — up to two people per account — we store a first name and surname, a date and time of birth, a place of birth with its coordinates and timezone, a gender if you give one, and a photograph if you add one. Gender and the photograph are optional; the rest is not.

Birth time is required to personalize a scan, and we do not substitute a noon chart when it is missing. An assumed birth time produces an arbitrary result rather than an approximate one, so we would rather ask than guess.

Photographs are reduced in size by your own browser before they are sent to us and are capped at 256 KB. They are stored in our database alongside the rest of that person’s record, not as loose files in a public folder, and they take no part in any calculation.

5. When the person is not you

A person you add need not be you. When you add someone else, you are giving us their name, their birth time and possibly their photograph — and they are not the one deciding to do it.

That is why the “Add person” dialog asks you to confirm that you have their permission, and why we will not save the record until you do. Please treat that as a real undertaking rather than a box to clear.

If you are that person and you did not agree to this, write to [email protected] and we will delete the record. You do not need an Astrolect account to ask.

6. What our servers record automatically

Web server access logs, which record the IP address a request came from, the time, the page requested and your browser’s user-agent string. These are ordinary web-server logs, kept for security and diagnosis.

Rate-limiting counters keyed on IP address, held in memory only and never written to the database. They exist so that one visitor cannot exhaust the service for everyone else.

Error logs. When something fails we record what failed. These can contain an email address — for example when a message to you could not be delivered — and an internal account number. They do not contain passwords or photographs.

We run no analytics and no advertising service. There is no tracking pixel, no analytics beacon and no advertising cookie on Astrolect, and we check that automatically against the live site rather than trusting our own configuration.

7. Why we process it

Your email address, password hash and verification state: to create and secure your account and to let you sign in. This is necessary to provide the service you asked for.

Your scan allowance: to provide the service and to prevent abuse.

The birth data of the people you add: to calculate and score the charts you asked for. This is the service itself, and it rests on your consent and on your declaration that you have that person’s permission.

Photographs: so that you can tell the people on a scan apart. Entirely optional, and not analyzed.

Access logs, rate-limit counters and error logs: security, abuse prevention and diagnosis.

Under Turkish law (KVKK) and the GDPR, a name combined with a date and time of birth is personal data, and a photograph identifying a person is personal data. We treat the birth records you enter as sensitive in practice however they are classified, because they identify a specific person at a specific moment.

8. Who else sees it

We do not sell your data and we do not share it with anyone for their own purposes. It is handled by the following providers, each only so that Astrolect can run: our hosting provider, which runs the server the application and database sit on; Cloudflare, which fronts our site and absorbs attacks; Zoho, which delivers our outbound email and therefore handles your address and the contents of those messages; and Google, only if you choose to sign in with Google, in which case Google tells us an identifier and your email address. We send Google nothing about your scans or the people on them.

Map imagery and place search are requested by our own server rather than by your browser, so the providers of those services never see your IP address and never learn what you searched for.

You should also know the plain operational truth: Astrolect is run by one person, who has direct administrative access to the database and therefore to every record and photograph in it. We tell you this rather than let the list above imply a larger organization with separated duties.

We will disclose data to a public authority only where the law obliges us to.

9. Where it is stored

On a server in Turin, Italy, inside the European Union, in a PostgreSQL database. Traffic between your browser and us is encrypted in transit.

10. How long we keep it

Your account and everything in it: until you delete it. We do not currently expire or delete dormant accounts, including accounts that were never verified. If you have abandoned an account holding someone else’s birth data, please delete it or ask us to.

A person you delete is deleted immediately, and their photograph is removed in the same operation. Deleting your account deletes every person in it and their photographs in the same operation. Nothing is kept in a recycle bin or a soft-deleted state.

Verification and password-reset links expire. The records behind them are retained after use and are not currently purged on a schedule.

Access logs are a genuine exception to the above, and we would rather be exact than reassuring: they are rotated by size rather than by age, so at our present traffic an IP address recorded today may persist for a long time — on the order of years — before it is discarded. Deleting your account does not remove it from those logs. We intend to move to a fixed retention period and will state it here as a number of days once it is in place.

11. Your rights

Under KVKK Article 11 and, where it applies to you, the GDPR, you may ask us whether we hold data about you, what it is, that it be corrected, that it be deleted, and that we stop processing it.

Two of these you can do yourself, immediately, inside Astrolect: delete a person, using the control on that person’s row, which removes their record and photograph; and delete your account, which removes the account and everyone in it.

For anything else — including access to a copy of your data and correction of it — write to [email protected]. There is no automated export, so these requests are fulfilled by hand, by one person. We answer within 30 days.

If you are a person whose data someone else entered, the same address reaches us and you need no account.

If you are not satisfied with our answer you may complain to the Turkish Personal Data Protection Authority (KVKK Kurumu).

12. If something goes wrong

If personal data we hold is exposed, lost or accessed by someone who should not have it, we will notify the Turkish Personal Data Protection Authority and the people affected in the shortest time possible, and in any case within 72 hours of becoming aware of it where the GDPR applies.

We will tell you what happened, what data was involved, and what we are doing about it — including where the answer is that we do not yet know.

13. Cookies

Astrolect stores three things in your browser, none of them for advertising or analytics: a session cookie that keeps you signed in, which JavaScript cannot read; your theme choice, light or dark; and your language choice.

The last two never leave your browser.

14. Security

Passwords are stored only as hashes. The session cookie is httpOnly, so a script running on the page cannot read it. The site is served over HTTPS. Photographs are held in the database and served only to the account that owns them, never from a public folder.

We would rather be plain about a limit than let you infer protection we have not built: the birth data and photographs described above are stored without encryption at rest. That means they are protected by the security of the server and the database rather than by a key, and a stolen copy of the database would be readable. Encryption at rest is planned; when it ships we will update this section and the effective date above.

No system is perfectly secure. If you believe your account has been accessed by someone else, write to us at the address above.

15. Children

Astrolect is not intended for people under 18, and we do not knowingly create accounts for them.

16. Changes to this policy

If we change this policy we will change the effective date at the top, and where the change is significant we will say so in the application. Continuing to use Astrolect after a change means you accept the updated policy.