Privacy Policy
This policy explains what Lucezora collects, why, who else sees it, and how you get it deleted. It covers the mobile app and this website.
1. Who is responsible for your data
The data controller is DVA MEDVEDA d.o.o. Beograd, društvo sa ograničenom odgovornošću, registered in Serbia under number 21880655 (MB), PIB 113513017, at Strahinjića Bana 73, 11000 Beograd (Stari Grad).
For any question about this policy or about your personal data, write to admin@dvamedveda.com. Full company details are on the company details page.
2. What we collect
Data you give us
- Account data. Your email address, and a password hash if you sign up with a password. If you sign in with Apple or Google, we receive an identifier from them and the email address they release to us — we never receive your password for those accounts.
- Birth data. The name or label you give a chart, and the date, exact time and place of birth. The place is stored as geographic coordinates and a time zone offset. This is the core of the service: without it no chart can be calculated.
- Charts of other people. If you add someone else’s birth data — for a compatibility analysis, for example — you are responsible for having their agreement to do so.
- Anything you send us. The content of support emails and any information you choose to include in them.
Data created as you use the app
- Subscription status. Which plan you are on, when it renews or expires, and the pseudonymous purchase identifiers our billing provider gives us. We never see your card number — payment happens entirely inside the App Store or Google Play.
- Usage counters. How many AI analyses and compatibility calculations you have used, so we can apply the limits of your plan.
- Generated analyses. The AI texts produced for you, together with the chart labels used to produce them, so that repeating the same request returns instantly and does not count against your limit.
- Referral data. If you use a referral code, the link between the invited and inviting account.
- Technical data. Interface language, the standard technical metadata of each request, and server logs including your IP address and the time of each request. Logs exist for security, abuse prevention and debugging. Our subscription provider’s SDK additionally reports the app version and operating system version as part of processing purchases.
Lucezora does not use advertising networks, does not build advertising profiles and does not sell personal data.
3. Why we use it, and on what legal basis
| Purpose | Data used | Legal basis |
|---|---|---|
| Calculating charts, forecasts and compatibility | Birth data | Performance of our contract with you |
| Generating personalised analyses | Birth data, chart results | Performance of our contract with you |
| Creating and securing your account | Account data, technical data | Performance of contract; legitimate interest in security |
| Applying plan limits and subscriptions | Subscription status, usage counters | Performance of contract |
| Answering support requests | Account data, message content | Performance of contract; legitimate interest |
| Preventing abuse and fraud | Technical data, logs, email address of a deleted account | Legitimate interest |
| Meeting legal obligations | As required by the applicable law | Legal obligation |
4. AI-generated analyses
Personalised analyses are produced by large language models operated by third parties. To generate an analysis, we send the AI provider the calculated attributes of your chart — such as type, profile, authority, defined centres and channels, and the current transits — and, for compatibility analyses, the labels you gave the two charts, which may be names. The birth date, time and place themselves, your email address, account identifier and payment data are never sent.
We currently use OpenAI, L.L.C. and Anthropic PBC, both located in the United States. This means your chart data is transferred outside your country, including outside the European Economic Area. The transfer is based on your explicit consent and on the providers’ standard contractual clauses.
Our agreements with these providers require that data sent through their business interfaces is not used to train their models and is retained only briefly for abuse monitoring. They are required to provide protection equivalent to that described in this policy. Generated analyses are also stored on our own servers so that repeated requests are served from cache; the retention periods are set out below.
AI output can be wrong. Analyses are generated text about a symbolic system, not verified statements about you, and should be treated accordingly.
5. Who else receives data
We share data only with the service providers that make the app work, and only with the data each of them needs. Every one of them is bound by contract to protect it to the standard set out in this policy.
| Recipient | What they receive | Why |
|---|---|---|
| OpenAI, L.L.C. (USA) | Calculated chart attributes; for compatibility analyses also the chart labels | Generating analyses |
| Anthropic PBC (USA) | Calculated chart attributes; for compatibility analyses also the chart labels | Generating analyses |
| RevenueCat, Inc. (USA) | Purchase and subscription identifiers: an anonymous ID, or your account ID once you sign in | Managing subscription status across stores |
| Apple Inc.; Google LLC | Purchase data; sign-in identifier if you use their sign-in | Payments, sign-in, app distribution |
| Our hosting and email provider | All data stored by the service; email address for transactional email | Running the servers and sending confirmation emails |
We also disclose data where the law requires it — for example, in response to a lawful order from a competent authority.
6. How long we keep it
- Account and birth data — for as long as your account exists. When you delete your account, this data is deleted from the live database immediately.
- Generated analyses — the latest analysis for each request is kept for as long as your account exists; earlier versions are deleted after 180 days. All of them are deleted together with the account.
- Email address after account deletion — kept for 30 days on its own, so that deleting and re-creating an account does not hand out the free trial calculations again. It holds only the address and the dates of deletion and expiry, and is then deleted automatically. Legal basis: our legitimate interest in preventing abuse.
- Backups — we keep database backups for at most 30 days, so deleted data leaves them within that time.
- Server logs — up to 90 days, then deleted.
- Transaction records — retained for as long as accounting and tax law requires, which is usually several years. These records are kept even after account deletion, because we are legally obliged to keep them.
- Support correspondence — up to 12 months after the request is closed.
7. Your rights
Depending on where you live, you have some or all of the following rights. If you are in the European Economic Area or the United Kingdom, you have all of them under the GDPR.
- Access — a copy of the personal data we hold about you.
- Rectification — correction of inaccurate data. Most of it you can edit yourself in the app.
- Erasure — deletion of your account and data. See how to delete your account.
- Portability — your data in a structured, machine-readable format.
- Restriction and objection — you can ask us to limit processing, or object to processing based on legitimate interest.
- Withdrawing consent — at any time, without affecting what was lawfully done before you withdrew it.
- Complaint — you may complain to your national data protection authority.
To exercise any of these, write to admin@dvamedveda.com. We reply within 30 days. We may ask you to confirm control of the email address on the account, which is a safeguard against someone else requesting your data.
8. Deleting your account
There are two ways, and both delete the same things:
- In the app — Settings, then Delete account.
- On the web — the account deletion page, without installing or reopening the app.
Deletion removes your account, your saved charts and birth data, your usage counters and your referral links. What survives is described in how long we keep it: transaction records we are legally required to retain, and backups that rotate out within 30 days. Your email address is also kept for 30 days on its own, so that deleting and re-creating an account does not hand out the free trial calculations again.
Deleting your account does not cancel a paid subscription. Subscriptions live with Apple or Google, and only they can cancel one. Cancel it first, then delete the account.
9. How we protect it
- All traffic between the app and our servers is encrypted with TLS.
- Passwords are stored only as salted hashes and cannot be read back, by us or anyone else.
- Sessions use short-lived access tokens with rotating refresh tokens, so a stolen token has a narrow window of use.
- Access to production data is limited to the people who need it to operate the service.
No system is perfectly secure. If a breach ever affects your rights, we will notify you and the competent authority as the law requires.
10. Age
Lucezora is for adults aged 18 and over, and you confirm your age on the consent screen before first use. We do not knowingly collect data from children. If you believe a child has given us personal data, write to admin@dvamedveda.com and we will delete it.
11. Changes to this policy
When this policy changes materially, we update the date at the top and notify you in the app before the change takes effect. Where the change concerns something you consented to, we ask for consent again rather than assume it.