Privacy
What we collect and why.
Last updated: 9 July 2026
Who is responsible for your data
The data controller is the operator of Kalendom, whose full legal identity — registered name, address, and P.IVA — is set out in our Terms. For any privacy request or question, email support@kalendom.com.
Birth data
To compute your chart we need your birth date, time (when known), and place. This is used solely to compute your chart. When you search for a birth place, the text you type is sent to Mapbox to turn it into coordinates; we store the result against an opaque chartId attached to your account — never your email or name in the same record. Delete your account (Account → Settings) and the chart record is deleted with it.
Birth data is processed under GDPR Article 6(1)(b) — necessary to perform the service you signed up for.
Personal events (optional)
You can log real events on dates to compare them against your chart timeline. Events are tied to your account, private by default, and not shared with anyone.
You can also opt in to the anonymous events pool — a research dataset stripped of all identifying fields (no uid, no email, no city). This is off by default and requires an explicit toggle in Account → Settings. Lawful basis: Article 6(1)(a) consent.
Who processes your data
We keep the list of third parties short, and each has a specific job:
- Google Firebase — authentication and secure storage of your account, chart, and unlock state.
- Mollie — payment processing at checkout — we never receive or store your full card details.
- Mapbox — birth-place search — turning the place you type into coordinates.
- PostHog — privacy-friendly product analytics — only if you opt in (see below).
- Plausible — cookieless, EU-hosted aggregate analytics — stores no personal data and cannot identify you (see below).
Payments
Payments are processed by Mollie. Your card or payment details are entered on the processor's secure page and are never seen or stored by us — we only receive confirmation that a payment succeeded, so we can unlock the right account.
Analytics
We use Plausible, a cookieless EU analytics service that stores no personal data and uses no cookies; it cannot identify you. It counts visits in aggregate (which pages, from where) so we know the site works — consent law exempts it because there is nothing personal to consent about, but we tell you anyway.
We use PostHog for privacy-friendly product analytics, and it is off until you allow it. Until you accept analytics in the consent banner, the PostHog SDK is not even loaded — no code runs, nothing is sent; decline (or ignore) the banner and it stays that way. There are no advertising or cross-site tracking cookies, ever.
How long we keep it
Your birth data, chart, and events are kept for as long as your account is active, and are removed when your account-deletion request is completed. Records of your purchases are kept for as long as tax and accounting law requires us to keep them.
Your rights
From the Settings page you can review your data, file a birth-data correction, and request account deletion. Deletion is fulfilled by us manually: we remove your chart, events, consent state, and entitlement, and confirm at your account email within 30 days. EU residents have additional rights under GDPR — rectification, restriction, portability, and the right to lodge a complaint with a supervisory authority (in Italy, the Garante per la protezione dei dati personali). For any of these, email support@kalendom.com.