Plain-language summary #
This is the short version in human language. The full legal document follows — every section is a plain-English expansion of the same promises.
We store your birth data to calculate your blueprint. We store your conversations so KAXANTA has context. We never sell any of it and never use it to train AI models. You can export or delete everything at any time.
If you only read one section, read this one. The rest is elaboration.
What we collect #
When you create an account, we collect the minimum data required to calculate and maintain your blueprint across the nine systems and provide KAXANTA with context.
Foundational data
- Account data — name, email, and password (stored as a bcrypt hash).
- Birth data — date, time, location (city, coordinates, timezone), and gender. Required for Human Design, Western Astrology, Ba Zi, Numerology, Feng Shui, Qi Men Dun Jia, Xuan Kong Da Gua, Water Formula, and Zi Wei Dou Shu.
- Current location (optional) — for transit calculations and directional advice.
- Relationship status (optional) — for personalised insights. Can be cleared at any time.
Derived data
- Nine-system chart calculations (HD, Western, Ba Zi, Numerology, Feng Shui, Qi Men, XKDG, Water, Zi Wei) computed from your birth data.
- Conversations with KAXANTA, stored to enable conversation continuity.
- Memory facts extracted from your conversations — visible to you in Settings → Memory.
Technical data
- Pseudonymous product analytics (PostHog). The browser SDK is opt-in and stays disabled until you accept the cookie banner. A small number of server-side events — account created, subscription started — are recorded without cookies whether or not you accept, because otherwise a declined banner would make conversions uncountable; they carry no birth data, chart content or chat messages, and you can object to them — see Your rights.
- Device and browser info for security and compatibility.
- IP address, used only to detect unusual account access. Not stored beyond 30 days.
Data about other people #
The Compatibility feature compares your chart against one other person's. To do that we store birth data about someone who is not our customer, so this section says exactly what that means. It applies only if you use the feature — nothing here is collected otherwise.
What we store
- A label you choose — a first name or nickname. We never ask for their full name.
- Their birth date, and their birth time if you know it. The time is optional; without it we compute less, and say so in the reading.
- Their birth place — city, country, coordinates, and timezone, needed to place a chart on the sky.
- The chart we derive from it — planetary positions, house cusps, and Human Design gates, computed once when you save them.
Your obligation
Only add someone whose agreement you have. You are responsible for having that person's permission before you enter their birth details, and for telling them that KAXANTA holds this data on your behalf. If you cannot ask them, do not add them.
Lawful basis
We process this data under legitimate interests (GDPR Art. 6(1)(f)) — delivering the comparison you asked for — balanced against that person's rights by keeping the data minimal, never contacting them, never using it for any purpose beyond your reading, and deleting it the moment either of you asks. Your obligation above is the safeguard that makes that balance hold. Our position on whether birth data is a special category under GDPR Art. 9 — and the safeguards we apply while that question is under external review — is set out in Why we are allowed to below, and applies to this person's data exactly as it does to yours.
How long we keep it
- Until you remove them. Removing a person deletes their birth data immediately, from the Compatibility screen, in one step. Removal is never behind a paid plan — reading the comparison is, erasing the data is not.
- When you delete your account, their data goes with it, in the same operation.
- Their data is included in your data export, because it is held inside your account.
If you are the other person
You have the same rights over this data as any other data subject — access, correction, and erasure. Email privacy@kaxanta.com and we will act on it, including deleting the record without needing the account holder's permission. We may need enough detail to identify the specific record; we will not use anything you send for any other purpose.
How we use it #
Data you provide is used exclusively to make KAXANTA work for you. Specifically:
- Compute and display your blueprint across all nine systems.
- Give KAXANTA contextual memory so its answers are grounded in who you are.
- Send transactional emails (billing, security alerts, your opted-in morning digest).
- Improve product reliability via aggregate, non-identifying analytics.
- Measure which adverts bring people here, if — and only if — you accept optional cookies. See Advertising and measurement below for exactly what that involves.
Why we are allowed to #
GDPR Art. 13(1)(c) requires us to name a lawful basis for every purpose, not one basis for the whole product. Here is the complete list.
- Your account — name, email, password hash, and the settings that make the app yours. Art. 6(1)(b), performance of a contract. Without it there is no account to log into.
- Your birth data and every chart derived from it — the nine systems, your transits, your daily readings. Art. 6(1)(b), performance of a contract. This is the service you signed up for; we cannot deliver it without this data, and we do not use it for anything else.
- Your conversations with KAXANTA — stored so it remembers what you already told it. Art. 6(1)(b), performance of a contract.
- Memory facts extracted from those conversations — Art. 6(1)(a), consent. Memory is opt-in, listed for you in Settings → Memory, and every fact can be deleted individually. Withdraw consent and extraction stops.
- Optional analytics and advertising measurement in your browser — PostHog, Google Analytics, the Meta Pixel. Art. 6(1)(a), consent, given through the cookie banner and withdrawable in one click. Nothing loads until you accept.
- Server-side conversion measurement — a small number of events (account created, subscription started) recorded by us and sent to PostHog from our server. Art. 6(1)(f), legitimate interest: knowing how many people finish signing up is necessary to run the service, and a banner-only signal would count only the people who accept banners. No cookies are set and nothing is read from your device. The events carry a pseudonymous account identifier and never birth data, chart content or chat messages. You have an absolute right to object underArt. 21; see Your rights for how, and objecting stops these events without affecting your account.
- Marketing email — Art. 6(1)(a), consent. Separate from transactional mail, which is contractual and cannot be unsubscribed from while your account is open.
- Security, abuse prevention and rate limiting — login-attempt counts, IP addresses, device and browser fingerprint-free signals. Art. 6(1)(f), legitimate interests — keeping accounts from being taken over. You can object; see Your rights.
- Invoices, payment records and tax data — Art. 6(1)(c), legal obligation, retained for the statutory period under Lithuanian accounting and tax law even after you delete your account.
- Birth data about another person (Compatibility) — Art. 6(1)(f), legitimate interests, as described in Data about other people above.
Profiling and automated decisions
We should be straightforward about this, because the whole product is a profiling engine: we build a detailed picture of you from your birth data and your conversations, and KAXANTA tailors what it says accordingly. That is profiling in the GDPR Art. 4(4) sense, and you are entitled to know it happens.
What we do not do is make automated decisions that produce legal effects or similarly significantly affect you within the meaning of Art. 22. Nothing here decides whether you get credit, a job, insurance, a price different from anyone else's, or access to any service. The output is interpretation for you to read and use as you see fit. Your subscription tier is set by what you chose to buy, not by any assessment of you.
Special categories (Art. 9)
Our assessment is that a birth date, time, and place are not in themselves special-category data: they are astronomical coordinates, and the interpretations we build on them are our own editorial content rather than findings about your health, beliefs, sex life, or ethnicity. We do not ask for, infer, or record any special category from your chart.
Two honest caveats. First, this classification is genuinely contested for belief-adjacent services and we have it under external legal review; if that review concludes otherwise we will publish the change and ask for explicit consent. Second, you can always volunteer special-category information yourself — telling KAXANTA about an illness, a pregnancy, a religion, or a relationship makes that a special category in our records, processed under Art. 9(2)(a) on the explicit consent implied by your choosing to type it. You can delete any such message or memory fact at any time. Pending the review, we apply special-category-grade safeguards to all birth data as a precaution, and our internal breach procedures treat it as high-risk by default.
Your rights #
You have the following rights over your data, always, regardless of jurisdiction. These are not privileges we grant — they are obligations we follow under GDPR Articles 15–21 and equivalent laws in the UK, US, Canada, Australia, New Zealand, Brazil, India, Singapore, and South Africa.
- Access — export everything as structured JSON from Account Settings.
- Rectification — edit your profile, birth data, or memory facts directly.
- Erasure — delete your account, which permanently removes all data from our systems immediately.
- Portability — the blueprint JSON is an open format readable by other tools.
- Restriction (Art. 18) — you can require us to freeze processing rather than delete it: while you contest the accuracy of something, while we assess an objection, or when you need the data preserved for a legal claim even though we no longer need it. Your account and data stay intact; we simply stop using them beyond storage. Email us and we will confirm when it is in place, and again before we lift it.
- Objection (Art. 21) — you can object to any processing we base on legitimate interests, which means our security and abuse-prevention logging, and the third-party birth data held for Compatibility. We will stop unless we can show compelling legitimate grounds that override your interests, and we will explain our reasoning either way. Objection to direct marketing is absolute: say no and it stops, with no balancing test. Optional analytics and advertising run on consent rather than legitimate interests, so for those the switch in Account Settings → Privacy is the mechanism.
- Withdraw consent — you may revoke processing consent at any time without affecting the lawfulness of prior processing.
- Complain to a regulator (Art. 77) — you can lodge a complaint with a supervisory authority without going through us first. Ours is the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, VDAI), and you may also complain to the authority where you live or work — in the UK, the ICO.
Exercise any of these from Account Settings → Privacy, or email privacy@kaxanta.com. We respond within 30 days, free of charge. If a request is genuinely complex we may extend by a further two months, and we will tell you why within the first month.
How long we keep things #
We retain data only as long as it serves your account:
- Active account — all data retained until you delete it.
- Deleted account — erased from primary storage immediately; cached derived data within 30 days; backups within 90.
- Server logs — 90 days, then auto-purged.
- IP logs — 30 days maximum.
- Error events (Sentry) — 90 days.
- Redis cache — ephemeral, TTL-based; never persisted long-term.
- Billing records — retained as required by tax law (typically 7–10 years).
- Anonymised analytics — aggregated indefinitely; cannot be traced back to you.
AI transparency #
The KAXANTA chat feature uses Google AI (Gemini Developer API) to generate responses. All chat responses are generated by artificial intelligence and are labelled as such in the interface. AI-generated content may contain inaccuracies.
When you use the chat feature, your chart data, transit information, and recent conversation history are sent to Google's AI service for processing with each message. This processing is based on your explicit consent, which you can withdraw at any time by ceasing to use the chat feature.
Google may retain input and output for up to 30 days for abuse monitoring and service integrity purposes. Under the paid Gemini Developer API tier, Google does not use customer prompts or responses to train its foundation models.
When this changes #
If we make a material change — anything that expands what we collect or how we use it — we will email you at least 30 days before it takes effect, with a plain-language explanation of what is different and why.
Non-material changes (clarifications, typos, or replacing a sub-processor with one doing the same work) are reflected in the "Last updated" date at the top and do not trigger an email.
How to reach us #
For privacy questions, data requests, or complaints that cannot be resolved in-product:
- Email — privacy@kaxanta.com (30-day response SLA)
- Data controller — Marius Misiūnas, Gėlių g. 13, Kalviškės, Rudaminos sen., LT-14106 Vilniaus r. sav., Lithuania. Registration number 1508672. VAT ID Not registered.
- EU supervisory authority — State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija), vdai.lrv.lt.
- UK residents — Information Commissioner's Office, ico.org.uk.