Legal

Privacy Policy

Torvii is built to hold as little about you as it can. The free app needs no account and keeps your birth details on your own device. Your journal never leaves your phone at all. What we do collect is listed below by name, and so is everything we deliberately do not.

Last updated

What this policy covers

This policy covers both halves of Torvii: the mobile app for iOS and Android, and this website. They are very different in what they touch — the website has no reader account and sets no cookie, its measurement is anonymous and aggregate, and it holds personal data only for the creator partners who apply to work with us — so where a section applies to only one of them, it says so.

It does not cover the app stores. Apple and Google each decide for themselves what to collect when you download an app or pay for a subscription, and they answer for that under their own policies rather than under this one.

Who is responsible

The controller of the personal data described below is Tolaron s.r.o., Příčná 1892/4, 110 00 Praha 1, Czech Republic, registration number IČO 300 03 547, C 455064 vedená u Městského soudu v Praze.

For anything about your data — a question, a request, a complaint — write to privacy@torvii.com. That address exists so data requests are not lost among general enquiries, which go to hello@torvii.com. Either will reach us; the first is faster for anything on this page.

What we collect, and when

Grouped by what you have actually done, because most readers never reach the second group.

This website, as a reader: a count of the page, not a record of you. Nothing on the site asks you for anything until you choose to sign in. The natal chart calculator computes your chart inside your browser and sends nothing to us; the place search on it sends the town name you type — and only that — to the geocoding service described under your birth details. Our host records standard server logs for every request — IP address, user agent, the page requested and a timestamp — which exist to serve the site and defend it against abuse. On top of those we run two measurement tools from that same host: Vercel Web Analytics, which counts page views, and Vercel Speed Insights, which records how quickly a page actually loaded and responded for you. Neither writes anything to your device or reads anything from it — no cookie, no local storage, no identifier — and neither receives a name, an email address or any birth detail. Your IP address and browser are used to derive a hash that our host rotates daily, purely so that two page views in one day are not counted as two people; it cannot be turned back into you and it does not survive into tomorrow. We build no profile from any of it, and there is nothing else we hold that it could be joined to.

If you sign in on this website: a session cookie, and the same account as the app. The website account is the app account — one email address, one set of birth details — so signing in here adds nothing to what is described under “The app, with an account” below, and a chart you save here is the chart the app shows. To keep you signed in, your browser holds a session cookie set by our authentication provider. It is the only thing this website ever writes to your device; it is set only after you ask to sign in, it exists solely to provide the service you asked for, and it is not used to measure or recognise you anywhere else. That is why there is still no consent banner: a cookie strictly necessary for a service you requested does not need one. Signing out removes it.

If you arrive on a creator’s link: two counters, and nothing about you. A creator in our Creator Programme has a link of the form torvii.com/r/their-code. Opening one adds 1 to that creator’s count of visits for that day, and clicking a store button from it adds 1 to their count of store clicks for that day. That is the entire record: two whole numbers per creator per day. Nothing is written to your device — no cookie, no local storage, no identifier of any kind — nothing is read from it, and nothing about you is stored, so the counts cannot be traced back to a person because no person was ever recorded. Nothing is carried into the App Store or Google Play either; if you later want a creator credited, you type their code into the app yourself.

If you apply to the Creator Programme: an account, and real data in it. This is the one place on this website that holds personal data, and it applies to creator partners rather than to readers. Applying creates an account and stores what you put in the form: your email address, the name you go by, the referral code you chose, and — where you gave them — your country, your main platform, a link to your profile, a rough audience size and your niche. We also keep the payout currency you chose, which version of the programme terms you accepted, what your link has earned, and what we have paid you. Your payment details are deliberately not in that list: they are held outside this database, and all the creator record says is whether we have them.

The app, without an account: your birth details, on your device. The free tier has no account and no sign-up. The birth date you enter — and the birth time and place, if you give them — are stored on your phone and are not sent to us. What does leave the device is the request for a horoscope, which asks for one sun sign in one language; the same text is served to everyone who shares that sign.

The app, with an account: the same details, now stored by us. If you create an account we hold your email address, your birth date, and — where you gave them — your birth time, the name and coordinates of your birth place, and its time zone. We also store the language you read in, so a reading can be written in it, and a notification token if you turned notifications on. With the one addition below, that is the complete list.

If you enter a creator’s code: which creator, and when. Typing a creator’s code into the app while signed in writes one row against your account: the creator that code belongs to, and the moment it was entered. It is the whole of how a creator is paid on a subscription you later buy, and it is why nothing has to be tracked between our website and the store. The creator never sees it — they get counts, never who. Deleting your account deletes it with everything else.

If you sign in with Apple or Google: we receive the email address that provider releases to us and a stable identifier, and nothing else — no contacts, no profile, no other account data. If you use Apple’s Hide My Email, we only ever see the relay address.

When subscriptions open: the store tells us that you have an active subscription and when it expires. It does not tell us your name, your address or your payment method, and we never see your card.

Your birth details, specifically

Birth date, time and place are what Torvii is for, so they deserve their own section rather than a line in a list.

They are ordinary personal data, not a special category. A birth date and place are not health data, biometric data, or data about your religion or sexual orientation, and we do not treat them as revealing any of those. What they are is unusually identifying: a full date, an exact time and a place together are close to unique to one person. We hold them accordingly — they are never used for advertising, never sold, never shared with anyone outside the list below, and never sent to the system that writes the readings.

The birth time is optional and stays optional. Torvii works without it and says plainly what it cannot tell you as a result. We would rather compute less than ask for more than we need.

When you search for a birth place, the text you type is sent to a geocoding service to be turned into coordinates. It receives the place name only — not your birth date, not your account, not an identifier for your device.

What never leaves your phone

Some things in the app are stored only on your device. Not "encrypted", not "kept private" — never transmitted, so there is nothing for us to keep, disclose, lose, or hand over.

  • Your journal. Every entry stays on your phone. We never receive a word of it, it is not backed up to us, it is not sent to the system that writes the readings, and it is not in the analytics. The practical consequence, which you should know before you rely on it: if you delete the app or lose the phone, the entries are gone, and we cannot restore them because we never had them.
  • Your birth details, while you have no account. See above.
  • A second person’s birth details, if you use two charts. Whoever you enter for “two charts read together” — their name, if you gave one, and their birth date, time and place — stays on your device the same way yours does, whether or not you have an account.
  • Which guide you chose to be read by, the language you set, the country whose local figures you want to see, which chart lenses you have opened, and the celebrities you follow.

If that ever changes for the journal — if entries are ever synced or backed up — this policy will describe it before the first entry is uploaded, not after.

Advertising

The free tier is paid for by advertising, served by Google AdMob. Torvii Plus removes it.

In the EEA, the UK and Switzerland you are asked first. The consent form you saw when you first opened the app is Google’s certified consent tool, and nothing is loaded before it settles. If you say no, you still get the app and the ads become non-personalized — they are chosen without building a profile of you.

You can change your mind at any time from Settings → Privacy choices, which reopens the same form. Your device also has its own advertising controls, which sit above anything we do: “Limit ad tracking” on iOS and “Delete advertising ID” on Android.

Some parts of the app can be unlocked for the day by watching a rewarded advertisement. That is a choice you make each time, it unlocks the feature on that device for that day only, and declining it costs you nothing else.

Your birth details are never used to target advertising. No advertiser receives your chart, your birth date, your journal, or anything derived from them.

Analytics

We measure how the app is used, so we can tell which parts are worth building. It runs on PostHog, hosted in the European Union, and follows the same consent as advertising, above — not a second, separate question.

In the EEA, the UK and Switzerland, it only runs if you allowed “store and access information on this device” in that consent form; decline, and nothing is sent rather than queued for later. Elsewhere, including the United States, no consent form is legally required for this and analytics runs by default — you can still see and change what you have allowed at any time from Settings → Privacy choices, wherever you are.

What it records is a fixed list of events — the app was opened, a reading was viewed, the paywall was shown, a chart lens was opened, a journal entry was saved — each tagged with a device-generated identifier and, once you have an account, that account’s identifier too, so we can tell that one person did several things without that telling us who the person is.

What it never records is content. The journal sends two facts — that it was opened, and that something was saved. Not the text, not its length, not the date it was written about, not the sky at the time. A moon sign and a date together describe a private moment closely enough to identify it, so neither is sent.

How the readings are written

The horoscope text is generated by an AI system, and is marked as artificially generated wherever it appears. This section is about what that system is given.

Today, it is not given anything about you. Every reading currently generated — the free daily horoscope — is written overnight, in a batch, before anyone asks for one. Each request contains a sun sign, a language, and the day’s planetary positions — the same positions for everybody. There is no reader on the other end of it, because the reading is written hours before you open the app.

Torvii Plus is not on sale yet, and its daily reading is not generated yet either. When it is, the request will carry more than a sun sign: a chart-derived category built from your sun sign, moon sign, a coarse rising band and a transit-intensity level, shared by everyone whose chart lands in the same category — still not your birth date, time, place, name or account. This policy will describe that precisely before the first such reading is generated, not after.

The parts of Torvii that are genuinely about your own chart — your placements, your aspects, today’s sky measured against your birth chart — are computed on your device from astronomical data, not generated. That arithmetic never leaves the phone.

We do not use anything you provide to train an AI model, and our providers are contractually barred from doing so with what we send them.

What we do not do

Unusually specific on purpose, because “we value your privacy” is not information.

  • We do not sell your personal data, and we do not share it with data brokers. There is no arrangement under which anyone pays us for information about you.
  • We do not track you across other companies’ apps and websites, and Torvii carries no advertising or social-media pixel of any kind.
  • We do not ask for your contacts, your photos, your location, your calendar or your microphone. The app requests no location permission at all — a birth place is a thing you type, not a thing we read off the device.
  • We do not build advertising profiles from birth data, and we do not infer anything about your health, beliefs, relationships or sexual orientation.
  • On this website there is no tag manager, no advertising pixel and no cookie — including on a creator’s referral link, which counts a visit on our own server and stores nothing on your device. The page-view and performance measurement described above is the only measurement here: it is anonymous and aggregate, it is served from our own domain, and it follows nobody between websites or between days. Fonts are served from our own domain too, so loading a page makes no request to Google or any other font host. There is no cookie banner because nothing is stored on or read from your device — which is the thing a banner exists to ask about.
  • We do not tell a creator who came from their link. They see how many visits, how many store clicks, how many accounts entered their code and how many of those subscribed — as counts, and only as counts. The data we give them contains no identifier for any reader, and there is nothing in it they could work one out from.
  • We do not measure installs, and we do not claim to. Nothing survives the journey from a link on this site into an app store — no click identifier, no fingerprint, no attribution software of any kind, and none is planned. A reader is connected to a creator only if the reader types that creator’s code into the app.

Why we are allowed to hold it

Each thing above rests on one of four grounds.

  • To give you what you asked for — your account, your chart, your subscription. Without a birth date there is no horoscope, so this is a contract we cannot perform without it (Article 6(1)(b) GDPR).
  • Because you said yes — advertising personalization and analytics together, from the one consent choice described above, and notifications separately as your device’s own permission prompt. Each can be withdrawn without losing the rest (Article 6(1)(a)).
  • Because we have a legitimate interest — keeping the service running and secure, the server logs that make that possible, and the anonymous page-view and performance measurement on this website. We do not use this ground for anything you would be surprised by (Article 6(1)(f)).
  • Because the law requires it — tax and accounting records, once there are any (Article 6(1)(c)).

Where the ground is consent, withdrawing it is as easy as giving it, and takes effect from the moment you do — it does not undo what happened while it was in force.

Who else touches it

Most act only on our instructions, under contract. Two, set apart in the table, are independent controllers: they decide part of what they do with this data for their own purposes and answer for that under their own policy, not this one.

WhoWhat they do for usWhere, and on what basis
VercelHosts and serves this website, produces the server logs described above, and runs the website measurement described in “What we collect” — Vercel Web Analytics and Speed Insights, both cookieless and served from our own domain.United States, with edge caching worldwide. Covered by Vercel’s data processing addendum and the EU standard contractual clauses.
SupabaseHosts the database and the sign-in system behind Torvii accounts: the account itself, the birth details of readers who have one, language preference, notification tokens and subscription status. The Creator Programme’s partner accounts, referral counters and commission records are in the same database.Inside the European Union — the exact region is named in the “International transfers” section. Covered by Supabase’s data processing addendum.
RailwayRuns the overnight jobs that write each day’s horoscope text, check that they ran, and send the morning notification, and hosts the private dashboard we use to see whether all of that worked. These have the same database access our own servers do. In practice the notification job touches your device’s push token, and the dashboard shows us totals rather than people — it is built so that it never fetches a birth date, time or place at all, and counts them inside the database instead. If you are a creator partner, your contact and payment details are visible to us there.United States. Covered by Railway’s data processing addendum and the EU standard contractual clauses.
Google AdMobServes the advertising that pays for the free tier. Google’s consent tool, which runs the form you saw when you first opened the app, is part of the same service.Google operates globally. What Google is allowed to do with an ad request depends entirely on the choices you made in that form, and you can reopen it at any time from Settings → Privacy choices.
PostHogProduct analytics — which screens are opened and which features are used. Each event carries a device-generated identifier and, once you have an account, that account’s identifier too. It never receives the content of anything you write.PostHog’s EU Cloud, hosted in the European Union. Runs under the consent described in “Analytics” below, which differs by where you are.
ExpoDelivers the daily notification to your device, if you turned notifications on. It receives the push token and the text of the notification, not your chart.United States. Only used if you enabled notifications, which requires an account.
ResendSends the transactional email an account needs — password resets and address confirmations. It receives your email address and the text of that message, and nothing else. It is not a mailing list and there is nothing to unsubscribe from.Ireland (eu-west-1), inside the European Union. Being configured as of this version; until it is, account email is sent by our database provider instead.
CloudflareRoutes mail sent to our published addresses — hello@ and privacy@ — to the inbox we actually read. It receives what you write to us and nothing else; it does not send anything on our behalf.United States, with global infrastructure. Covered by Cloudflare’s data processing addendum and the EU standard contractual clauses.
Photon (Komoot)Turns the birth place you type into coordinates. It receives what you typed in the place field and returns matching places.Germany. It receives a place name and nothing that identifies you — not your birth date, not your account, not a device identifier.
AnthropicGenerates the written horoscope text overnight, in batch, before anyone asks for it. See “How the readings are written”.United States. It receives a sun sign, a language and the day’s planetary positions. It never receives your birth details, your account, or anything you have written.
RevenueCatSubscription infrastructure. The library is present in the app, but Torvii Plus is not on sale yet, so no purchase data exists to process.United States. This entry will describe real processing when subscriptions open; it is listed now because the library ships in the app rather than because it holds anything.
Google FontsDelivers the typefaces used in the account emails we send — password resets and address confirmations. Loading them tells Google the IP address and browser of whoever opens that email, the same as loading any image from a remote server would.Google operates globally. This is not something Settings can turn off, because it happens when an email client renders the message, not when the app runs.
Apple, Google (sign-in)When you sign in with one of them, it decides what to release to us — the email address and the stable identifier described in “If you sign in with Apple or Google” above. What it does with the sign-in itself is between you and them.Each is its own controller for what it collects when you sign in, under its own privacy policy, not ours.
App Store, Google PlayDistribute the app, and — when subscriptions open — take the payment. We never see your card details.Each store is its own controller for what it collects about you, under its own privacy policy, not ours.

International transfers

The things we hold about you stay in the European Union. The database with your account, your birth details and your notification settings is in Frankfurt, Germany — Supabase’s eu-central-1 region — inside the European Union, and the mail that account needs is sent from inside the EU too. Neither leaves it, so for the most sensitive thing here — a birth date, time and place, which together are close to unique to one person — there is no international transfer to justify.

Three of the companies listed above do operate outside it. This website is served from the United States — Vercel’s iad1 region in Washington, D.C. — with pages cached and served worldwide from Vercel’s edge network, so a server log of your visit is held there. Notification delivery and the overnight text generation are also handled by US companies — the first receives a device token, the second receives no personal data at all. Where any of that leaves the European Economic Area, the transfer relies on the European Commission’s 2021 standard contractual clauses, which Vercel’s data processing addendum incorporates for transfers out of the European Economic Area.

If you are in the United Kingdom, the equivalent instrument is the UK International Data Transfer Addendum rather than the EU clauses.

How long we keep it

  • Your account and birth details: until you delete them. Deleting your account removes them immediately — this is in the app, under Settings, and does not require you to write to us.
  • Notification tokens: until you turn notifications off, delete your account, or uninstall the app, whichever happens first. A token the store tells us is dead is disabled the same night.
  • Analytics events: kept under PostHog’s own published retention terms for the plan we use — we have not shortened it and do not export a copy elsewhere. They carry the identifiers described in “Analytics” above, but no birth data and no content.
  • Server logs: held by our host under its own published retention terms and deleted once that period expires. We do not export or copy them.
  • Website page-view and performance figures: kept by our host in aggregate, under the same published retention terms as the server logs above. They carry no identifier we could resolve to a person, so there is no version of them that is about you specifically.
  • A creator partner’s account: for as long as the partnership lasts, and after it ends for as long as Czech accounting and tax law requires the underlying financial records to be kept — five years for general accounting records, up to ten years for tax documents where VAT registration applies. The daily referral counters carry no personal data and are kept as a record of what a creator was paid on.
  • Subscription records, once they exist: the same five-year general period, and up to ten years for tax documents, that governs the creator programme above — longer than your account may last, and not something we can shorten.

How it is protected

Everything travels encrypted. The database enforces access at the row level, so a signed-in reader can reach their own data and nothing else — this is enforced by the database itself rather than by the app asking politely, which matters because the difference is what a bug in the app can do.

The strongest protection here is not technical, though: most of what would be sensitive is never collected. There is no journal on our servers to leak, and for a reader with no account there are no birth details either.

If a breach ever puts you at risk, we will tell you and the supervisory authority within the time the law allows, and we will say what actually happened.

Your rights

We give everyone the same rights, wherever they live. The list below comes from European law, but we do not check where you are before honouring it. If your own country’s law gives you more, you keep that too.

  • A copy of what we hold about you (Article 15), and, where the legal conditions for portability are met — broadly, data you gave us that we process by your consent or to perform a contract — the same in a portable, machine-readable format (Article 20).
  • Correction of anything wrong (Article 16).
  • Deletion (Article 17). For your account this is a button in the app, not a request you have to make.
  • Restriction of what we do with it while a dispute is resolved (Article 18).
  • Objection to processing based on our legitimate interest (Article 21).
  • Withdrawal of consent for advertising personalization, analytics or notifications, at any time, from Settings.

Write to privacy@torvii.com and we will answer within one month. We do not charge for this and we will not make it difficult.

If you think we have handled your data badly you can complain to a supervisory authority — for us that is the Czech ÚOOÚ (Úřad pro ochranu osobních údajů / Office for Personal Data Protection, Pplk. Sochora 727/27, 170 00 Praha 7, https://uoou.gov.cz) — and you can always complain to the authority where you live instead.

Where you live

The policy above applies to everyone. A few places add something, and this section says only what we have actually checked rather than listing jurisdictions to look thorough.

  • European Economic Area: everything above, as written. The GDPR is the baseline this document is built on.
  • United Kingdom: the same rights under the UK GDPR. Your supervisory authority is the Information Commissioner’s Office, and transfers rely on the UK Addendum as noted above.
  • Switzerland: the same rights under the revised Federal Act on Data Protection.
  • United States: several states give you a right to opt out of “sale” or “sharing” of personal information for targeted advertising. Advertising is the only thing Torvii does that could fall under those words, and the opt-out is the same control as everywhere else: Settings → Privacy choices, plus your device’s own advertising setting. We do not sell personal information for money anywhere.
  • Everywhere else: we apply the whole of this policy to you as well. We have not researched your country’s law, and we would rather say so than imply a compliance claim we have not checked.

Children

Torvii is rated for teenagers and is not intended for children under 13, or under the higher minimum age that applies where you live — in parts of the European Union that is 16 for services relying on consent.

We do not knowingly collect data from a child below that age. If you believe a child has given us something, write to privacy@torvii.com and we will delete it.

Advertising shown to anyone we have reason to believe is a minor is not personalized, and we do not profile minors for advertising in any market.

Changes to this policy

When this policy changes we update the date at the top. If a change means we start collecting something new, it is described here before the collection begins, not after — and where the change needs your consent, we will ask for it rather than assume it.

See also our Terms of Use.