Privacy Policy

Your trust is sacred to us. This policy explains how Stellaxa collects, uses, and protects your personal information in compliance with GDPR and applicable data protection laws.

Effective Date: February 10, 2026 | Last Updated: July 10, 2026

Who We Are

Stellaxa is operated by a sole proprietor based in Slovenia, European Union. We develop and maintain the Stellaxa mobile application (available on Google Play) and the Stellaxa website at www.stellaxa.com.

For the purposes of applicable data protection laws, including the General Data Protection Regulation (GDPR), Stellaxa acts as the data controller for the personal data described in this policy — both for the website and for the Stellaxa mobile application.

Contact: info@stellaxa.com | Website: www.stellaxa.com

What Data We Collect

We are committed to data minimisation and only collect what is needed to provide our services. This section covers both the mobile app and the website.

Mobile app — Account data: When you create an account we collect your email address and a password (stored in hashed form by our authentication provider), and the name you choose to share.

Mobile app — Profile and birth data: To personalise readings you may provide your date of birth, time of birth, place of birth, language, and device timezone. Providing birth time and place is optional.

Mobile app — Reading inputs: Depending on which readings you use, we process the content you submit: photos of your palm (palm reading), photos of your coffee cup (coffee reading), dream descriptions, questions you ask, details you enter about another person for compatibility readings (such as their name and birth date — please only enter information you are allowed to share), and your chat messages with Stella, including any photos or documents you choose to attach.

Mobile app — Generated content: The readings and chat replies generated for you are stored in your account so you can revisit them.

Mobile app — Purchases: Purchases are processed by Google Play. We receive purchase state (e.g. which product, whether a subscription is active) via our payments provider (RevenueCat); we never receive your card or bank details.

Mobile app — Device and usage data: push notification token (if you enable notifications), device type and app version, anonymised usage events (which features are used), and crash reports. Advertising identifiers are used only as described in the Cookies and Tracking section and subject to your consent choices.

Website (stellaxa.com) — Waitlist form: email address and interest selections. Automatically collected: our hosting provider (Railway) may collect standard server logs (IP address, browser type, pages visited, timestamps, referring URL).

We do not create user accounts on the website and do not process payment information on the website.

How We Use Your Data

We use the data we collect for the following purposes:

Providing readings and the Stella chat — Your reading inputs (photos, questions, birth data, chat messages) are processed to generate your readings and replies. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

AI generation — Reading and chat content is generated with the help of artificial-intelligence models (see Third-Party Services). The content generated is guidance for entertainment and self-reflection; it produces no legal or similarly significant effects about you.

Account management, purchases and entitlements — Managing your account, star balance and subscription status. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

Push notifications — Sending daily guidance and app messages if you enable notifications. Legal basis: consent (Art. 6(1)(a) GDPR); you can disable notifications at any time in the app or system settings.

Analytics and crash reporting — Understanding aggregate usage and fixing errors, subject to your in-app privacy choices. Legal basis: consent / legitimate interest (Art. 6(1)(a)/(f) GDPR).

Advertising — Showing ads in the free tier, subject to the consent choices you make in the ad-consent dialog. Legal basis: consent (Art. 6(1)(a) GDPR).

Security and abuse prevention — Rate limiting and protecting the service. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).

Website waitlist — Sending launch updates you opted into. Legal basis: consent (Art. 6(1)(a) GDPR).

We do not sell, rent, or trade your personal data.

Data Storage and Security

Where Your Data Is Stored: App data (account, profile, readings, chat) is stored with our backend provider Supabase on servers in the European Union (Frankfurt, Germany). The website is hosted on Railway on EU servers (Amsterdam, Netherlands).

How We Protect Your Data: All traffic between the app or your browser and our servers is encrypted in transit (TLS). Photos and chat attachments are stored in private storage accessible only to your account. Access to production systems is restricted.

Retention: Your data is kept while your account exists. When you delete your account, your personal data and readings are deleted. You can delete individual readings in the app at any time. Website waitlist data is retained until you request deletion; server logs are retained per our host's standard period (typically 7–30 days).

How to delete: In the app, go to Profile → Settings → Privacy & Data → Delete Account, or use the Delete Account page on our website, or email info@stellaxa.com.

Your Rights Under GDPR

As a resident of the European Economic Area (EEA) or where otherwise applicable, you have the following rights regarding your personal data:

Right of Access (Art. 15) — You can request a copy of the personal data we hold about you.

Right to Rectification (Art. 16) — You can ask us to correct inaccurate or incomplete data. You can edit your profile data directly in the app.

Right to Erasure (Art. 17) — You can delete your account and data directly in the app (Profile → Settings → Privacy & Data), via the Delete Account page on our website, or by emailing us.

Right to Restrict Processing (Art. 18) — You can ask us to limit how we use your data.

Right to Data Portability (Art. 20) — You can request your data in a structured, commonly used, machine-readable format by emailing info@stellaxa.com.

Right to Object (Art. 21) — You can object to data processing based on legitimate interests.

Right to Withdraw Consent — Where processing is based on consent (ads, analytics, notifications), you may withdraw it at any time in the app's settings or system settings, without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at info@stellaxa.com. We will respond within 30 days.

If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local data protection authority. In Slovenia, this is the Information Commissioner (Informacijski pooblaščenec): https://www.ip-rs.si | gp.ip@ip-rs.si

Cookies and Tracking Technologies

Mobile app: The app does not use cookies. It uses device identifiers for the following, always subject to your choices: an advertising identifier for ads in the free tier (governed by the Google UMP consent dialog shown in the app — you can change your choice in the app's privacy settings), anonymised analytics events, and crash reporting (both shown as choices in the app's privacy dialog on first launch).

Website: Our website uses analytics cookies and session recording technologies, activated only after you give explicit consent via our cookie consent banner.

Analytics cookies (Google Analytics 4): _ga — distinguishes unique users, duration 2 years; _ga_* — maintains session state, duration 2 years.

Session recording cookies (Microsoft Clarity): _clck — identifies user across page views, duration 1 year; _clsk — connects session events, duration 1 day.

Consent mechanism: On your first visit, a consent banner is shown before any analytics load. Your choice is stored locally in your browser (localStorage) under the key 'stellaxa-consent'. If you reject, no analytics cookies are set. You can change your choice at any time using the Cookie Settings link in the footer. We implement Google Consent Mode v2, which ensures analytics_storage defaults to 'denied' until explicit consent is granted.

Strictly necessary: The only cookies that may be present without consent are essential functional cookies set by our framework (Next.js) for locale preferences. These do not require consent under GDPR.

Third-Party Services

We use the following processors and service providers:

Supabase — App backend and database (EU servers, Frankfurt). Data processed: account, profile, readings, chat, photos and attachments.

Google Gemini API (Google) — AI generation of readings and chat replies. Data sent: the inputs needed for your reading (questions, birth details relevant to the reading, palm/coffee photos, chat messages and attachments). Per Google's API terms, this data is not used to train Google's models.

Google Play and Google AdMob (Google) — App distribution, billing, and advertising in the free tier. AdMob shows ads subject to the consent you give in the ad-consent (UMP) dialog. Google's privacy policy: https://policies.google.com/privacy.

RevenueCat — Subscription and purchase management. Data processed: purchase state and pseudonymous app user id. https://www.revenuecat.com/privacy.

Firebase (Google) — App analytics and push-notification infrastructure.

Expo — Push-notification delivery. Data processed: push token.

Sentry — Crash and error reporting. Data processed: crash traces and device metadata.

Railway — Website hosting (EU). Google Analytics 4 and Microsoft Clarity — website analytics, only after cookie consent (see Cookies and Tracking).

Google Fonts — Typography, self-hosted at build time; no requests reach Google at runtime.

International Data Transfers

Your core app data is stored in the European Union (Supabase, Frankfurt; Railway, Amsterdam).

Some of our processors are US companies (Google, RevenueCat, Sentry, Expo), and processing a reading or delivering a notification can involve a transfer of the relevant data outside the EEA. Where that happens, the transfer is protected by appropriate safeguards: the EU–US Data Privacy Framework where the provider is certified, and/or Standard Contractual Clauses (SCCs) in the provider's data-processing terms.

We do not transfer your data outside the EEA in any other circumstances.

Children's Privacy

Stellaxa's website and app are intended for a general audience and are not directed at children. We do not knowingly collect personal data from children under the age of 16 (or the applicable age of digital consent in your jurisdiction).

If you are a parent or guardian and believe your child has provided us with personal data, please contact us at info@stellaxa.com, and we will promptly delete that information.

Entertainment Disclaimer

Stellaxa provides divination and fortune-telling experiences (palm reading, tarot, astrology, the Stella chat, and related readings) for entertainment and self-reflection purposes only. Readings and chat replies are generated with the help of artificial intelligence. They are not a substitute for professional advice in areas such as health, finance, legal matters, or personal decisions.

Changes to This Policy

We may update this privacy policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make changes, we will update the "Last Updated" date at the top of this policy. For significant changes, we will provide notice on our website.

We encourage you to review this policy periodically.

Contact Us

If you have questions, concerns, or requests regarding this privacy policy or our data practices, you can reach us at:

Email: info@stellaxa.com

Website: www.stellaxa.com