Privacy Policy
Last updated: 9 September 2026
This Privacy Policy explains how Astera Tarot & Astrology ("Astera", "we", "our") handles information when you use the Astera plugin/MCP service through ChatGPT or another compatible AI client. Astera is operated under the MAKS ASTERA brand by an individual developer.
1. Information we process
Depending on the feature you use, Astera may process:
- Astrology inputs: birth date, birth time, city/locality, country or region, timezone, Solar Return locality, and equivalent data for another person when you request synastry.
- Tarot inputs: the question, reading type, selected spread, date, language and other parameters needed for the requested reading.
- Account information: when you choose to connect an existing Astera account, a verified Firebase user identifier, email address, email-verification status and access/entitlement status.
- Technical and security information: limited server logs such as request identifier, tool name, request outcome, authentication/access events, error category and service diagnostics needed to operate and secure the service.
Astera does not request payment-card data, passwords, MFA/OTP codes, a street address or raw GPS coordinates as plugin tool inputs.
2. How we use information
- to perform the Tarot or astrology calculation requested by you;
- to render charts and structured plugin experiences;
- to authenticate an existing Astera account and determine its current access level when you choose to connect it;
- to prevent abuse, diagnose errors, maintain reliability and protect the service;
- to comply with applicable legal obligations.
3. Authentication
Astera uses Firebase Authentication for account sign-in. Your password is handled by Firebase Authentication and is not sent to the Astera MCP server. After Firebase verifies your identity, Astera issues a short-lived, resource-bound access credential for the plugin connection.
Connecting an account is optional for ordinary free features. It may be required only when you explicitly request functionality available to an already eligible Astera account.
4. Location resolution
Some astrological calculations require geographic context to calculate houses, angles or the Solar Return for the requested location. For those tools, you may provide a city/locality and country plus the relevant timezone. Astera does not ask for a street address or raw GPS coordinates.
When a locality is not already resolved by Astera, the locality text may be sent to a third-party geocoding service to convert it into approximate coordinates used only for the requested calculation. The third-party provider may process the locality and network metadata under its own terms and privacy practices.
5. Service providers and recipients
Limited data may be processed by service providers only as needed to operate Astera:
- Google Cloud / Cloud Run / Cloud Logging: hosting, application operation and security logging.
- Firebase Authentication and Firestore: optional account authentication, existing entitlement lookup and short-lived OAuth authorization records.
- Geocoding provider: locality resolution when needed for an astrology calculation.
- The AI client you use, including OpenAI/ChatGPT: receives the result returned for the tool request and independently handles your account/conversation under its own terms and privacy policy.
Astera does not sell personal information.
6. What Astera receives from ChatGPT
Astera receives only the inputs the AI client sends to a specific Astera tool to perform your request. The Astera MCP server does not request or reconstruct your unrelated ChatGPT conversations, your ChatGPT password, or your full OpenAI account.
7. Data retention timelines
| Data category | Astera retention |
|---|---|
| Tarot/astrology request inputs and generated calculation data | Processed for the requested tool call. Astera does not write a separate persistent archive of reading content through the MCP service. Request-specific calculation and locality caches expire after 15 minutes. |
| OAuth login ticket | Valid for 10 minutes; it is a signed short-lived ticket used only to complete the login flow. |
| OAuth authorization code | Usable for 5 minutes and one-time redemption only. Expired authorization-code records are configured for datastore TTL deletion; deletion is asynchronous and is normally completed within 24 hours after expiration. |
| Astera MCP access credential | Normally expires after 1 hour. It is resource-bound and must be re-issued after expiration. |
| Application operational/security logs | Retained for up to 30 days in the application logging bucket. These logs are designed not to contain the full tool request body, birth data or Tarot question. |
| Existing Astera account and entitlement records | Retained while the Astera account/entitlement remains active or until an applicable account/data deletion request is completed, except where a longer period is required by law or necessary to establish, exercise or defend legal claims. |
Cloud providers may retain provider-level mandatory audit or security records under their own documented retention rules. Those records are separate from Astera's application reading data.
8. Data sharing
We do not sell personal information. We share limited information only with the service-provider categories described above, only as needed to provide, secure and maintain Astera, or when required by law. Results are returned to the AI client that made the request.
9. International processing
Cloud, authentication, geocoding and AI services may process data in more than one country. Where applicable, processing relies on the safeguards provided by the relevant service providers and applicable law.
10. Your choices and rights
You may use supported free features without connecting an Astera account. You may disconnect the Astera account from ChatGPT at any time through ChatGPT's plugin/account connection settings.
Depending on your jurisdiction, you may request access, correction, deletion, restriction or other action concerning personal data associated with Astera. Use the Support page or email asteraspprt@gmail.com. Never send a password, authentication code or token.
11. Data about another person
If you submit another person's birth information for synastry or a related calculation, only provide information you are authorized to share and that is reasonably necessary for the requested calculation.
12. Children
Astera is not directed to children below the minimum age required to use the relevant AI service in their jurisdiction. Adults should not submit a child's personal data unless they are legally authorized to do so.
13. Sensitive decisions
Tarot and astrology outputs are interpretive. Do not use Astera as the sole basis for medical, mental-health, legal, financial, emergency, safety-critical or similarly high-impact decisions.
14. Changes to this policy
We may update this policy when the service, providers, legal requirements or data practices change. The current version will be published at this URL with the updated date.
15. Contact
For privacy questions, data-access requests, correction requests or deletion requests, contact Astera Support at asteraspprt@gmail.com or visit the Astera Support page.