Privacy Policy

Nora — horary & natal astrology assistant

Data controller: Aydin Emre Iskender · support@iskae.dev

Last updated: 18 August 2026

This policy explains what personal data the Nora app collects, how it reaches us, why we process it, the legal basis we rely on, who receives it, how long we keep it and what you can ask us to do. Nora is operated by Aydin Emre Iskender ("we", "us"), who is the data controller. Write to support@iskae.dev with any question about this policy, or to exercise any of the rights in section 8.

1. Data we collect, why, and on what legal basis

Account details — your email address, a salted hash of your password, and the sign-in method you used. If you sign in with Google, we store the account identifier Google gives us instead of a password.

Your display name — the name the app greets you with. The field on the sign-up form may be left empty. If you leave it empty, the app substitutes a standard word in your language — "Friend" in English, "Arkadaş" in Turkish — and sends that instead, so a display name is always stored against your account. If signing in with Google creates a new account, we store the name on your Google account, or your email address when that account carries no name; if you already had a Nora account with the same email address, the display name it already had is kept.

Your questions and readings — the question you ask, the reading Nora generates for it, and the follow-up questions in the same conversation, together with the rating and any written comment you give a reading.

The place a chart is cast for — a horary chart can only be cast for a place and a moment, so Nora works out a location before you ask a question. It does this in one of three ways, and the first one is what you get unless you change it:

Whichever path produced it, the coordinates and the time-zone identifier are sent to our server with your question so the chart can be calculated, and they are stored with the reading: the saved chart records the latitude and longitude it was cast for. They are removed together with the reading when your account is deleted.

The derivation above happens on its own, but a location worked out that way is marked approximate, and the app will not cast your first chart until you confirm it or replace it. Confirming or changing the location is your action; deriving it and looking it up on our server is not.

Birth details — if you use the birth-chart feature, the name, date, time and place of birth you type in. They are sent to our server, used to calculate the chart, and returned to you. We do not store them: there is no birth data in our database.

Purchases — the Google Play purchase token, order identifier and product identifier for each reading bundle you buy, and a record of the readings you have used.

Device and installation identifiers — two identifiers reach our server with your requests: a Firebase installation identifier, which Firebase generates for this installation of the app, and an Android device identifier (the app-scoped Settings.Secure.ANDROID_ID value). We also ask Google's Play Integrity service for a verdict on whether the app and the device are genuine before we grant the free reading.

Crash reports and app usage events — crash reports from the app, and events recording which screens you open and which in-app actions you take, such as starting a purchase or rating a reading. Every value in these events is a fixed code word, an enum name or a count. The text of your question, the text of a reading, your email address and your account identifier are never included, and we never set a user identifier or a user property on the analytics service. On our server, unexpected errors are reported to Sentry with personal data switched off and request bodies, headers and cookies stripped out.

Technical request data — your IP address is passed to our server by the hosting layer and used, in memory, to apply request rate limits. Requests are also written to our server's operational logs.

We do not show ads, do not use an advertising identifier, and do not profile you or take automated decisions producing legal or similarly significant effects. We do not ask you for special categories of data; note only that your question is free text, so whatever you choose to put in it is stored as you wrote it.

2. Using Nora before you have an account

You can ask a question without signing up. When you do, the question and the reading are stored on our server straight away, tied to your installation identifier rather than to an account. Data is therefore collected and stored before any account exists. If you later sign in on the same installation, those readings are transferred to your account and appear in your history. The transfer happens when you log in or sign in with Google, and only if the app sends us the installation identifier with that request; registering a new account does not by itself transfer them.

If you never sign in, those readings stay on our server against the installation identifier. Because they were never attached to an account, deleting an account does not remove them, and we cannot connect them to you in order to act on a request about them unless you give us the installation identifier.

3. How we obtain your data

We collect personal data by automated means, through the Nora mobile app and our server, in these ways:

4. Who receives your data

We use a small number of service providers to run Nora. We do not sell personal data and we do not share it for advertising.

Place names you type are turned into coordinates and time zones on our own server using an offline dataset; they are not sent to any geocoding service.

We may also disclose data where the law requires it, or where we need to establish, exercise or defend a legal claim (GDPR Article 6(1)(c) and 6(1)(f); KVKK Article 5(2)(ç) and 5(2)(e)).

5. International transfers

Your data is stored by the hosting providers named in section 4 and processed by our server. When a reading is generated, the question and chart described in section 4 are transferred to OpenAI, which processes them in the United States. Requests pass through Cloudflare's network, which operates worldwide, so a request may be handled outside the European Union and outside Turkey before it reaches us. Firebase, Google Play, Resend and Sentry may also process data outside the European Union and outside Turkey. We rely on the data-protection terms and safeguards these providers offer for such transfers.

6. How long we keep your data

7. Security

Data is transmitted over encrypted HTTPS connections. Passwords are stored only as salted hashes, and refresh tokens only as hashes. Access to your account requires a valid session token, and requests are rate limited.

8. Your rights

Under the EU General Data Protection Regulation (GDPR) you have the right to be told whether we process your data and to obtain a copy of it; to have inaccurate data corrected and incomplete data completed; to have your data erased; to have processing restricted; to object to processing based on our legitimate interests; to data portability; and to withdraw a consent you have given, without affecting processing carried out before you withdrew it. You may also lodge a complaint with the supervisory authority of the EU member state where you live or work.

Under Turkey's Personal Data Protection Law No. 6698 (KVKK), Article 11 gives you the right to learn whether your personal data is processed; to request information if it has been; to learn the purpose of processing and whether the data is used in line with that purpose; to know the third parties to whom it is transferred in Turkey or abroad; to have incomplete or inaccurate data corrected and to have that correction notified to those third parties; to request erasure or destruction under the conditions of Article 7 and to have that notified to those third parties; to object to a result produced solely by automated analysis that works to your detriment; and to claim compensation for damage caused by unlawful processing. You may bring a complaint to the Turkish Personal Data Protection Board.

The app itself offers one of these controls: you can delete your account from the profile screen. For anything else — access, correction, a copy of your data, restriction, objection — write to support@iskae.dev. If your request concerns readings you made before creating an account, say so, because we may need the installation identifier to find them.

9. Children

Nora is not directed to children, and we do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

10. Sharing a reading with a link

You can choose to share a reading. When you do, we create a link with an unguessable address and store a copy of that reading against it. Anyone who has the link can read it, with no account and no sign-in. Nothing is shared until you ask for a link, and the legal basis is your consent (GDPR Article 6(1)(a); KVKK Article 5(1)).

The shared page contains the question you asked, the answer, its confidence and reasoning, and every follow-up question and answer in that reading, exactly as they stood at the moment you shared. It does not contain your name, your email address, your account identifier, your installation identifier, your ratings, the chart, or the time and place the question was cast from. Be aware that the text of a reading may itself mention the positions the chart was cast from, and that your question is your own free text.

The copy is frozen. Follow-up questions you ask afterwards do not appear on the page unless you share the reading again, which republishes it and updates the same link.

The page asks search engines not to index it and is not listed anywhere on our site, but a link is only as private as the people you send it to: whoever receives it can forward it.

The link is removed when you delete the reading or your account. To turn a single link off on its own, write to support@iskae.dev with the link and we will remove it: the stored copy is deleted and the address stops working immediately. You do not need an account for this, because the link itself is what we act on.

11. Changes to this policy

We may update this policy from time to time. The "Last updated" date above shows the latest version; significant changes will be communicated in the app.