Privacy Policy
App: Northnode ("the app")
Data controller: Bastian Alejandro Cuesta Hidalgo
Privacy contact: privacy@northnode.app
Last updated: July 25, 2026
Your chart and birth details live on your device. Anything you share with your connections travels end-to-end encrypted — only you and that person can read it. There are no accounts tied to your real identity, your Apple ID or your Google account, we don't sell data, and we don't use advertising trackers.
What data we handle, and where
- Your birth details (the name you type, date, optional time and place) and the birth chart derived from them: stored on your device. They are not sent to our servers.
- People you add by their birth date (contacts): also on your device. We don't upload address books or third-party data.
- Real connections between users (optional, by code): to connect with someone else on Northnode, we create a pseudonymous account for you (a random identifier plus the display name you choose; no Apple ID, no Google account, no email, no legal name). Our backend (Supabase, EU region) stores: the display name you choose (in the clear, so the other person sees "X wants to connect"), your pseudonymous identifier, an invite code and a public key, and the connection graph (who connects with whom, as pseudonymous identifiers). The birth details and chart you share with a connection travel end-to-end encrypted (Curve25519 + AES-GCM): the key lives on the devices, and we cannot read them.
- The premium deep analysis (deep-dive and weekly read): to write the richer text, we send a third-party cloud AI provider only non-identifying facts (the astrological aspects, the scores and the relationship type). Never your birth date, your name or your place. To authenticate this request we create a pseudonymous session (a random identifier, no name, email, Apple ID or Google account); this is not the same as connecting with another person. The rest of the app works without this (it falls back to template-based text).
- Pseudonymous usage stats (optional, off by default): to measure retention and improve the app, we send our backend (EU) a random, persistent install identifier (generated on your device; not derived from your Apple ID or Google account, nor from your birth date, name, place or social identity), the version, the language and whether you're premium, along with which screens are used. Never your birth date, your name, your chart or who you connect with. Because the identifier is persistent, this data is pseudonymous (not directly identifying, but not fully anonymous either). You can turn this off in Settings → Privacy; doing so, and using "Delete my data", rotates the identifier.
- Moderation reports (only if you use "Report and block"): so that we can review abuse and meet the App Store and Google Play rules, our backend (EU) stores the reason you pick from a fixed list, who reported whom, the connection involved and a copy of the display name the reported person was using at the time. We don't store charts, birth dates or the encrypted content. Because these records are the evidence behind a report, they outlive the deletion of the reported person's account for the period set out under "Retention".
- Blocks: if you block someone, we store the pair of identifiers for that block so we can stop the two of you connecting again. It is deleted if you lift the block.
- Anti-abuse protection: when you redeem an invite code and when you send stats, the server works out an irreversible technical identifier derived from your internet connection (we don't store your IP address) to limit how often attempts can be made. It is kept for a few hours and then purged.
- Notifications (optional daily reminder): scheduled on your device. We don't send any notification tokens to a server. You can disable them in your phone's settings (iOS Settings, or Settings → Notifications on Android).
Date and place of birth are personal data, but not special-category data under Article 9 GDPR (they are not health, religion, etc.).
Website waiting list
If you join the waiting list at northnode.app, we store your email address and your browser language on our backend (Supabase, EU region) for a single purpose: letting you know when the app is available, in your language. No newsletters, no sharing with third parties. The legal basis is your consent when you submit the form. To prevent abuse of the form we also store, temporarily and without linking it to your email, an irreversible technical identifier derived from the connection. We delete all of it after the launch announcement; you can opt out earlier by writing to privacy@northnode.app.
What we don't do
- No accounts tied to your real identity (no Apple ID, no Google account, no email, no legal name).
- No advertising SDKs, no trackers, and no identifiers for cross-app or cross-site tracking (which is why you won't see Apple's tracking prompt, and why we never ask for Android's advertising ID).
- We don't sell your data or share it with data brokers.
Purchases (App Store and Google Play)
Subscriptions and purchases are handled by the store you downloaded the app from: Apple (StoreKit) on iPhone and iPad, Google Play on Android. We don't receive your card details; payment processing is done by Apple or Google under its own policy, and refunds are requested from whichever store charged you.
Where data is hosted
The backend (connections, pseudonymous stats, the moderation queue and the website waiting list) is hosted in the European Union region (Supabase). The cloud AI provider may process the non-identifying facts of the analysis; where that involves an international transfer outside the EEA, it relies on appropriate safeguards (e.g. standard contractual clauses).
Legal basis (GDPR)
- Consent to enter and process your birth details (you enter them when you create your chart) and for the social features you choose to use.
- Legitimate interest in running and securing the app and improving it via pseudonymous stats (which you can turn off).
- Legitimate interest in keeping the service free of abuse: moderation reports, blocks and anti-abuse protections. On top of that come the moderation obligations the App Store and Google Play require of apps with user-generated content.
Your rights
You control your data from within the app:
- Access and portability: Settings → Export my data generates a file with what the app stores about you.
- Erasure: Settings → Delete my data removes your profile and contacts from the device and, if you've used connections, your pseudonymous account data on the server too (profile, encrypted envelopes and connections). With two narrow exceptions, neither of which contains your legal name or your birth details:
- a technical anti-fraud counter for the premium quota (an identifier derived from your subscription), kept for a limited period, after which it is purged; and
- the moderation reports that involve you, kept for the period set out under "Retention", because they are the evidence behind a report and we need them to handle it and to defend ourselves against claims.
- Rectification: edit your profile in the app.
You can also write to privacy@northnode.app. You have the right to lodge a complaint with your data protection authority (in Spain, the AEPD).
Retention
Local data stays on your device for as long as the app is installed and you don't delete it. Your account data on the server is kept while you use the social features. Disconnecting from a person removes that connection (the link and the encrypted envelopes you exchanged), but does not delete your account; to remove the account and all its content, use "Delete my data". Pseudonymous usage stats (if you enable them) are kept for a limited period (max. 180 days) and then automatically purged; when you turn them off in Settings or use "Delete my data", the installation identifier is replaced with a new one. The website waiting list is deleted after the launch announcement.
Moderation reports are kept for a maximum of 12 months and are then deleted automatically. They hold the reason, the identifiers involved and a copy of the reported display name; never charts, birth dates or encrypted content. Blocks are kept for as long as the block is in place. The technical anti-abuse identifier derived from the connection is kept for a few hours.
Minimum age
The app is for people 16 or older. It is not directed at children under that age, and we do not knowingly process children's data.
Changes
If we change how we handle data, we'll update this policy before the change takes effect and reflect it in the date above.
Contact
Bastian Alejandro Cuesta Hidalgo — privacy@northnode.app