Privacy Policy
This policy explains what personal data the Nora app collects, how it reaches us, why we process it, the legal basis we rely on, who receives it, how long we keep it and what you can ask us to do. Nora is operated by Aydin Emre Iskender ("we", "us"), who is the data controller. Write to support@iskae.dev with any question about this policy, or to exercise any of the rights in section 8.
1. Data we collect, why, and on what legal basis
Account details — your email address, a salted hash of your password, and the sign-in method you used. If you sign in with Google, we store the account identifier Google gives us instead of a password.
- Purpose — to create your account, verify your email address, sign you in and keep the account secure.
- Legal basis — performance of the contract you enter into when you create an account (GDPR Article 6(1)(b)); for Turkish users, KVKK Article 5(2)(c), because the processing is directly related to entering into and performing that contract.
Your display name — the name the app greets you with. The field on the sign-up form may be left empty. If you leave it empty, the app substitutes a standard word in your language — "Friend" in English, "Arkadaş" in Turkish — and sends that instead, so a display name is always stored against your account. If signing in with Google creates a new account, we store the name on your Google account, or your email address when that account carries no name; if you already had a Nora account with the same email address, the display name it already had is kept.
- Purpose — to address you in the app.
- Legal basis — performance of the contract (GDPR Article 6(1)(b); KVKK Article 5(2)(c)).
Your questions and readings — the question you ask, the reading Nora generates for it, and the follow-up questions in the same conversation, together with the rating and any written comment you give a reading.
- Purpose — to produce the reading, to show it to you again in your history, and to see which readings people find useful.
- Legal basis — performance of the contract for producing and storing the reading (GDPR Article 6(1)(b); KVKK Article 5(2)(c)); our legitimate interest in improving Nora for the ratings (GDPR Article 6(1)(f); KVKK Article 5(2)(f)).
The place a chart is cast for — a horary chart can only be cast for a place and a moment, so Nora works out a location before you ask a question. It does this in one of three ways, and the first one is what you get unless you change it:
- From your device's time-zone setting, with no permission and without asking you. When you open the ask screen and no location is set yet, Nora reads the time-zone identifier your device is set to (for example Europe/Istanbul), takes the city name out of it, and looks that city up in the offline place database on our own server. The result is a city-level location marked as approximate. This needs no location permission, it shows no prompt, and it requires no action from you. It is the default path.
- From a place you type in. If you search for a city on the location screen, the text you type is sent to our server and matched against that same offline place database.
- From your device's location service, only if you choose it. If you open the location screen and grant the coarse-location permission, Nora asks Android for your approximate position. Those coordinates are then sent to our server to be turned back into a city name. This path never runs unless you start it and grant the permission.
Whichever path produced it, the coordinates and the time-zone identifier are sent to our server with your question so the chart can be calculated, and they are stored with the reading: the saved chart records the latitude and longitude it was cast for. They are removed together with the reading when your account is deleted.
The derivation above happens on its own, but a location worked out that way is marked approximate, and the app will not cast your first chart until you confirm it or replace it. Confirming or changing the location is your action; deriving it and looking it up on our server is not.
- Purpose — to cast the chart for the question you asked.
- Legal basis — performance of the contract, because a chart cannot be produced without a place (GDPR Article 6(1)(b); KVKK Article 5(2)(c)). Where you grant the location permission, we rely on your consent for reading the device's location service (GDPR Article 6(1)(a); KVKK Article 5(1)), and you can withdraw it at any time in Android's app settings.
Birth details — if you use the birth-chart feature, the name, date, time and place of birth you type in. They are sent to our server, used to calculate the chart, and returned to you. We do not store them: there is no birth data in our database.
- Purpose — to calculate the birth chart you asked for.
- Legal basis — performance of the contract (GDPR Article 6(1)(b); KVKK Article 5(2)(c)).
Purchases — the Google Play purchase token, order identifier and product identifier for each reading bundle you buy, and a record of the readings you have used.
- Purpose — to give you the readings you paid for, to keep your balance, and to stop one purchase being claimed twice.
- Legal basis — performance of the contract (GDPR Article 6(1)(b); KVKK Article 5(2)(c)); our legitimate interest in preventing payment fraud (GDPR Article 6(1)(f); KVKK Article 5(2)(f)).
Device and installation identifiers — two identifiers reach our server with your requests: a Firebase installation identifier, which Firebase generates for this installation of the app, and an Android device identifier (the app-scoped Settings.Secure.ANDROID_ID value). We also ask Google's Play Integrity service for a verdict on whether the app and the device are genuine before we grant the free reading.
- Purpose — to attach readings you make before you sign up to the right installation, to hand them to your account when you sign in, and to stop one person claiming the free reading over and over.
- Legal basis — our legitimate interest in preventing abuse of the free reading and in giving you back the readings you made before signing up (GDPR Article 6(1)(f); KVKK Article 5(2)(f)).
Crash reports and app usage events — crash reports from the app, and events recording which screens you open and which in-app actions you take, such as starting a purchase or rating a reading. Every value in these events is a fixed code word, an enum name or a count. The text of your question, the text of a reading, your email address and your account identifier are never included, and we never set a user identifier or a user property on the analytics service. On our server, unexpected errors are reported to Sentry with personal data switched off and request bodies, headers and cookies stripped out.
- Purpose — to keep the app stable and to understand how it is used.
- Legal basis — our legitimate interest in a working, improving product (GDPR Article 6(1)(f); KVKK Article 5(2)(f)).
Technical request data — your IP address is passed to our server by the hosting layer and used, in memory, to apply request rate limits. Requests are also written to our server's operational logs.
- Purpose — to keep the service available and to protect it from abuse.
- Legal basis — our legitimate interest in the security and availability of the service (GDPR Article 6(1)(f); KVKK Article 5(2)(f)).
We do not show ads, do not use an advertising identifier, and do not profile you or take automated decisions producing legal or similarly significant effects. We do not ask you for special categories of data; note only that your question is free text, so whatever you choose to put in it is stored as you wrote it.
2. Using Nora before you have an account
You can ask a question without signing up. When you do, the question and the reading are stored on our server straight away, tied to your installation identifier rather than to an account. Data is therefore collected and stored before any account exists. If you later sign in on the same installation, those readings are transferred to your account and appear in your history. The transfer happens when you log in or sign in with Google, and only if the app sends us the installation identifier with that request; registering a new account does not by itself transfer them.
If you never sign in, those readings stay on our server against the installation identifier. Because they were never attached to an account, deleting an account does not remove them, and we cannot connect them to you in order to act on a request about them unless you give us the installation identifier.
3. How we obtain your data
We collect personal data by automated means, through the Nora mobile app and our server, in these ways:
- Directly from you, when you type it in — your email address, password, display name, question, rating, the name of a place you search for, and, where you use that feature, your birth details.
- From your device, automatically — the time-zone setting your location is derived from, the installation and device identifiers, crash reports and usage events, and your IP address. Apart from the location permission described in section 1, none of this involves a prompt.
- From your device's location service, if you ask for it and grant the coarse-location permission.
- From Google — your Google account identifier, email address and name if you sign in with Google; purchase confirmations from Google Play when you buy readings; and an integrity verdict from Play Integrity.
4. Who receives your data
We use a small number of service providers to run Nora. We do not sell personal data and we do not share it for advertising.
- OpenAI — to generate a reading we send OpenAI the text of your question and the calculated chart, which is a list of planetary positions, houses, aspects and dignities. For a follow-up question we also send the earlier messages of that conversation. We do not send OpenAI your name, email address, account identifier, device identifiers, purchase data, birth details, or the coordinates the chart was cast from. Data held on OpenAI's systems is outside our reach: we can neither read it nor delete it.
- Google Firebase — Crashlytics for crash reports, Google Analytics for Firebase for usage events, and Firebase Installations for the installation identifier.
- Google Play Billing and Play Integrity — to verify your purchases and to check that the app and the device are genuine.
- Google Sign-In — if you choose to sign in with Google.
- Resend — receives your email address in order to deliver your email-verification message and account-security notices.
- Sentry — receives server error reports. Personal data collection is switched off and request bodies, headers and cookies are removed, but a report also carries the recent server log lines that led up to the error, and those can contain account, chat and installation identifiers.
- Cloudflare — every request from the app reaches our server through Cloudflare, which terminates the encrypted connection and forwards the request. It therefore handles everything you send us, including your question, your email address and your password.
- Hosting — our server runs on Google Cloud Run and stores data in a Neon PostgreSQL database.
Place names you type are turned into coordinates and time zones on our own server using an offline dataset; they are not sent to any geocoding service.
We may also disclose data where the law requires it, or where we need to establish, exercise or defend a legal claim (GDPR Article 6(1)(c) and 6(1)(f); KVKK Article 5(2)(ç) and 5(2)(e)).
5. International transfers
Your data is stored by the hosting providers named in section 4 and processed by our server. When a reading is generated, the question and chart described in section 4 are transferred to OpenAI, which processes them in the United States. Requests pass through Cloudflare's network, which operates worldwide, so a request may be handled outside the European Union and outside Turkey before it reaches us. Firebase, Google Play, Resend and Sentry may also process data outside the European Union and outside Turkey. We rely on the data-protection terms and safeguards these providers offer for such transfers.
6. How long we keep your data
- Your account and everything attached to it — kept for as long as your account exists. When you delete your account, your account record, chats, questions, readings and the charts inside them, ratings, purchase records, balance and sign-in tokens are deleted immediately, except for the items listed below. See how to delete your account.
- Purchase tokens — after deletion we keep a record of the purchase tokens already used, so the same purchase cannot be claimed a second time. That record holds the purchase token, the product and the time it was used, with no link to your account, and it is kept indefinitely. It is not anonymous: Google Play can still tie a purchase token to the buyer.
- Your device identifier, if you have used a free reading — the record that the device has already had its free reading is kept against the device identifier after deletion, so that the free reading cannot be taken again.
- Short-lived copies of a reading response — when the app sends a request key so a retry does not charge you twice, we store the response to that request against the key for 24 hours. That copy contains the reading and the chart. It is removed the next time the same key is presented, and it is not removed when you delete your account.
- Readings made before you signed up and never claimed — these stay on our server tied to the installation identifier. Deleting an account does not remove them, because they were never attached to one.
- A reading you shared with a link — the copy behind the link is kept until the link is turned off, or until the reading or your account is deleted. See section 10.
- Birth details — never stored.
- Crash reports, usage events and server logs — held by the providers named in section 4 under their own arrangements.
7. Security
Data is transmitted over encrypted HTTPS connections. Passwords are stored only as salted hashes, and refresh tokens only as hashes. Access to your account requires a valid session token, and requests are rate limited.
8. Your rights
Under the EU General Data Protection Regulation (GDPR) you have the right to be told whether we process your data and to obtain a copy of it; to have inaccurate data corrected and incomplete data completed; to have your data erased; to have processing restricted; to object to processing based on our legitimate interests; to data portability; and to withdraw a consent you have given, without affecting processing carried out before you withdrew it. You may also lodge a complaint with the supervisory authority of the EU member state where you live or work.
Under Turkey's Personal Data Protection Law No. 6698 (KVKK), Article 11 gives you the right to learn whether your personal data is processed; to request information if it has been; to learn the purpose of processing and whether the data is used in line with that purpose; to know the third parties to whom it is transferred in Turkey or abroad; to have incomplete or inaccurate data corrected and to have that correction notified to those third parties; to request erasure or destruction under the conditions of Article 7 and to have that notified to those third parties; to object to a result produced solely by automated analysis that works to your detriment; and to claim compensation for damage caused by unlawful processing. You may bring a complaint to the Turkish Personal Data Protection Board.
The app itself offers one of these controls: you can delete your account from the profile screen. For anything else — access, correction, a copy of your data, restriction, objection — write to support@iskae.dev. If your request concerns readings you made before creating an account, say so, because we may need the installation identifier to find them.
9. Children
Nora is not directed to children, and we do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
10. Sharing a reading with a link
You can choose to share a reading. When you do, we create a link with an unguessable address and store a copy of that reading against it. Anyone who has the link can read it, with no account and no sign-in. Nothing is shared until you ask for a link, and the legal basis is your consent (GDPR Article 6(1)(a); KVKK Article 5(1)).
The shared page contains the question you asked, the answer, its confidence and reasoning, and every follow-up question and answer in that reading, exactly as they stood at the moment you shared. It does not contain your name, your email address, your account identifier, your installation identifier, your ratings, the chart, or the time and place the question was cast from. Be aware that the text of a reading may itself mention the positions the chart was cast from, and that your question is your own free text.
The copy is frozen. Follow-up questions you ask afterwards do not appear on the page unless you share the reading again, which republishes it and updates the same link.
The page asks search engines not to index it and is not listed anywhere on our site, but a link is only as private as the people you send it to: whoever receives it can forward it.
The link is removed when you delete the reading or your account. To turn a single link off on its own, write to support@iskae.dev with the link and we will remove it: the stored copy is deleted and the address stops working immediately. You do not need an account for this, because the link itself is what we act on.
11. Changes to this policy
We may update this policy from time to time. The "Last updated" date above shows the latest version; significant changes will be communicated in the app.