Astari
Privacy Terms Support Impressum

Privacy

Privacy Policy

Last updated: September 1, 2026

Who We Are

Astari is a daily check-in and reflection app. The data controller responsible for the processing described in this policy is Linus Victor Menkhoff, trading as Astari, Erhardtstraße 1, 80469 München, Germany (see the Impressum). For privacy or support requests, contact [email protected].

Scope

This policy applies to the Astari iOS app, its backend services, and the website at getastari.app. Astari is intended for people aged 16 or older and is not directed to children under 16.

What Astari Processes

Astari processes the following categories of information:

  • Account information: a pseudonymous user ID and, if you choose account recovery with Sign in with Apple, your Apple account identifier and any name or email address Apple provides.
  • Reflection content: onboarding choices, selected categories, timezone, reminder preferences, daily check-ins, mood entries, sleep-, movement-, health-, or fitness-related answers, notes, moment answers, and other reflections you choose to enter.
  • Personalization and generated content: a display name, goals, values, constraints, preferences, saved context, personalization signals, and generated weekly, monthly, and yearly reflections.
  • Purchase information: subscription status, product identifiers, transaction status, and related purchase information provided by Apple and RevenueCat.
  • Technical and security information: app version, device and operating system information, operation names, status and timing information, crash and session details, a pseudonymous account identifier, and short-lived hashed rate-limit identifiers.
  • Support communications: your email address and anything you include in a support message or attachment.
  • Website request information: your IP address, browser and request headers, and security events needed to deliver and protect the website.

Astari does not access Apple Health, HealthKit, or another health or fitness service. Any health- or fitness-related information in Astari comes only from what you choose to enter. You can use Astari without entering health-related information.

Purposes and Legal Bases

  • Astari processes account information, reflection content, saved context, generated content, and purchase information to provide the app, synchronize your data, recover your account, provide requested Core and Reflections features, and manage subscriptions. The legal basis is performance of the service contract (Article 6(1)(b) GDPR).
  • Astari processes technical, security, and limited diagnostic information to protect the service, prevent abuse and fraud, investigate failures, and improve reliability. The legal basis is Astari's legitimate interest in operating a secure and reliable service (Article 6(1)(f) GDPR).
  • Astari processes support communications to answer your request and administer the service. The legal basis is Article 6(1)(b) GDPR or, where the request is not contractual, Astari's legitimate interest in providing support under Article 6(1)(f) GDPR.
  • Astari may retain transaction or other limited records where required by tax, accounting, consumer-protection, or other law. The legal basis is Article 6(1)(c) GDPR.

Reflection fields are optional. A pseudonymous account, at least one selected category, and the information needed to save a check-in are required to provide the corresponding app features. If you do not provide optional context or notes, Astari still works but its reflections may be less personalized. Sign in with Apple and a paid subscription are optional, and Astari Core can be used without them.

AI Processing

Astari Core does not use a language model to write its factual weekly recap. The recap is assembled on your device from information already stored there.

The first two eligible weekly letters are included with Astari Reflections. Ongoing weekly letters, personalized questions, and monthly and yearly reflections require an active subscription. When an included or subscribed Reflections feature is generated, Astari sends relevant check-ins, notes, moment answers, saved reflection context, earlier summaries, and continuity information to Anthropic's commercial API. This processing happens automatically when the feature is generated.

Astari does not intentionally add your email address, Apple account identifier, or Astari account ID to an Anthropic prompt. However, anything you write in a check-in, note, moment answer, or saved context may be included, including personal information you enter yourself.

Astari also uses Anthropic to infer limited personalization signals, such as a preferred writing tone, categories that appear sensitive, and categories with higher engagement. These signals are stored with your Astari account and used to shape later reflections. They are not used for advertising, credit, insurance, employment, access, or other eligibility decisions.

Under Anthropic's commercial terms and Astari's current Anthropic settings, inputs and outputs are not used to train Anthropic's models. Astari has not enabled optional feedback or development data sharing. Anthropic ordinarily deletes API inputs and outputs from its backend within 30 days. Anthropic may keep content for longer where required by law or to enforce its usage rules; content flagged as a potential usage-policy violation may be retained for the longer periods described in Anthropic's commercial data-retention policy.

AI-generated reflections may be false, incomplete, misleading, or outdated. Check factual claims independently. Astari is for personal reflection and does not provide medical, mental-health, legal, or financial advice.

Astari does not sell personal data, does not use reflections for advertising, and does not track you across other companies' apps or websites.

Service Providers and Recipients

  • Supabase: authentication, the database, backend functions, synchronization, and security controls. Astari's primary database is hosted in Supabase's West EU (Ireland) region.
  • Anthropic Ireland, Limited: the server-side AI processing described above. Anthropic stores commercial API data in the United States and may route processing through infrastructure in the United States, Europe, Asia, or Australia.
  • Apple: Sign in with Apple and App Store purchase processing. Astari's reminders are scheduled locally on your device; Astari does not use Apple Health or HealthKit.
  • RevenueCat: subscription entitlement, purchase, and restoration management using a pseudonymous Astari account identifier and App Store purchase information.
  • Sentry: crash reporting, session health, performance diagnostics, and reliability monitoring in Sentry's German data region. Astari sends a pseudonymous account identifier with these reports.
  • Cloudflare: website hosting, delivery, abuse prevention, and security.
  • Google Workspace: receiving and storing messages sent to the Astari support email address.

Astari configures Sentry not to intentionally include journal text, check-in answers, notes, AI prompts, generated reflection text, screenshots, view hierarchies, network request contents, email addresses, or IP addresses in diagnostic reports. Automatic network collection and default personally identifiable information collection are disabled.

Astari may also disclose information where required by law, to establish or defend legal claims, or in connection with a business transfer, subject to applicable legal safeguards.

Website Cookies and Analytics

The Astari website currently uses no advertising or analytics cookies and does not run a third-party analytics service. Cloudflare may use strictly necessary security mechanisms and process ordinary request data to deliver and protect the site.

Anonymous Use and Account Recovery

You can use Astari without giving Astari your name or email address. Astari still creates a pseudonymous Supabase account and stores synchronized reflection data on its backend. Until you link that account to Sign in with Apple, the credentials needed to recover it exist only in the current app session. If you delete the app or lose the device first, access to the account and its reflections may be lost.

If you choose account recovery, Astari links your existing pseudonymous account to Sign in with Apple so the same reflections remain connected and recoverable on another installation.

Deletion and Retention

You can delete your account in Settings. This removes the Astari account and its reflection data from active Astari systems. Deleting Astari does not cancel an App Store subscription; subscriptions must be cancelled separately through Apple.

  • Reflection content and generated reflections are retained while your account exists.
  • Short-lived rate-limit and backend HTTP-response records are removed after seven days.
  • Scheduler records and incomplete generation placeholders are removed after 30 days.
  • AI-generation telemetry, protected generation source snapshots, terminal generation jobs, and full RevenueCat webhook payloads are retained for up to 90 days.
  • Empty anonymous accounts with no user content are eligible for deletion after 30 days.
  • Anthropic ordinarily deletes API inputs and outputs within 30 days, subject to the legal and usage-policy exceptions described above.
  • Sentry diagnostic data is retained for 30 days on the current plan and may be retained for up to 90 days if Astari moves to Sentry's standard paid plan.
  • Astari's current Supabase plan has no customer-restorable scheduled backups. If daily Supabase Pro backups are enabled, restorable database backups may remain for up to seven days.
  • Support messages are kept only as long as needed to handle and document the request, unless a longer period is required by law.
  • Transaction and accounting records are retained for the periods required by applicable law.

Processor records may remain after account deletion for the limited periods above or where a provider must retain them for security, fraud prevention, legal compliance, or reliable operation. Data in a backup is isolated from ordinary use and is overwritten or expires with the applicable backup cycle.

International Transfers

Some service providers process personal data outside Germany and the European Economic Area. In particular, Anthropic stores commercial API data in the United States and may process it in other regions. Where required, Astari uses safeguards such as the European Commission's Standard Contractual Clauses in processor data-processing agreements or an applicable adequacy decision. Anthropic's data-processing agreement, including Standard Contractual Clauses, is incorporated into its commercial terms. You can request information about the relevant safeguards from [email protected].

Automated Processing

AI-generated writing and personalization signals are automated, but Astari does not make decisions based solely on automated processing that produce legal or similarly significant effects about you.

Your Rights

Subject to applicable law, you may request access to and a copy of your personal data, correction of inaccurate data, deletion, restriction of processing, and data portability. You may object to processing based on legitimate interests.

To exercise a right, contact [email protected]. Astari may need to verify your identity before completing a request. You may also complain to the supervisory authority where you live or work. Astari's lead local authority is the Bavarian State Office for Data Protection Supervision (BayLDA).

Changes

Astari may update this privacy policy as the app or its service providers change. Material changes will be communicated in an appropriate way, and the updated policy will show a new "Last updated" date.

Astari Daily check-ins. A letter every Sunday.
Privacy Terms Support Impressum