How Cosmic KPI collects, uses, shares, and protects your information.
Effective date: August 5, 2026 · Last updated: August 8, 2026
Cosmic KPI ("we," "us," "our") operates cosmickpi.com. This policy explains what we collect when you use cosmickpi.com, why we collect it, who we share it with, and what control you have over it.
Cosmic KPI is a research instrument for exploring relationships between astronomical positions and your own dated records. Astronomy is computed on our servers from the Swiss Ephemeris; your chart and notes are stored against your account.
Cosmic KPI is currently available to users in the United States only.
Cosmic KPI is intended for adults. You must be at least 18 years old to create an account. We do not knowingly collect information from anyone under 18. If we learn that we have collected information from a minor, we will delete it. If you believe a minor has provided us with information, contact us at hello@cosmickpi.com.
Account information. Your email address and a password, which we store only as a cryptographic hash. You can also create your account by signing in with Google — see Section 9 for exactly what that shares with us; accounts created that way have no password. We assign your account an internal identifier that is not derived from your name or email.
Birth information. To calculate a natal chart, we collect your birth date, your birth time (or your indication that it is unknown), and your birth place. Your birth place is converted into geographic coordinates and a timezone.
Chart labels. Names or labels you assign to charts you save. These often contain personal names.
Notebook entries. Text you write, along with any categories or labels you create, and any timing windows you link entries to.
Ancestry information. If you use Ancestry features, the names, birth dates, birth times, birth places, and life events of family members you add.
Calendar information. Events you bring in yourself — from an .ics file you paste, a calendar feed URL you subscribe to, or events you enter manually — may include titles, dates, times, locations, and descriptions, and we store what the event contains. If you would rather we did not hold that detail, remove it before importing.
Subscription information. If you subscribe to a paid plan, we record which plan you have and its status. Payment card details are collected and processed directly by Stripe. We never see or store your full card number.
Updates list. If you enter your email address in the updates form at the bottom of the Home page, or in the waitlist form on a paid plan card, we store that address, the date you submitted it, and which form it came from. We use it only to send you occasional product news and updates, including letting you know when paid plans open. Joining the list is optional and separate from having an account, and you can ask us to remove your address at any time (see Section 11).
Support and correspondence. Anything you send us directly.
Some Cosmic KPI features involve information about people other than you.
These individuals are not our users and have no relationship with us. By entering another person's information, you confirm that you have the authority to do so. You are responsible for ensuring you have any consent or permission required.
We use this information only to provide the features you asked for. We do not build separate profiles of these individuals, contact them, or use their information for any purpose other than generating results for you. If you delete your account, this information is deleted with it.
If you are not a Cosmic KPI user and believe your information has been entered by someone else, contact us at hello@cosmickpi.com and we will help you locate and remove it.
We use PostHog, a product analytics service, to understand how Cosmic KPI is used. PostHog stores this data in the United States. Analytics requests are routed through our own domain (cosmickpi.com/relay-ckpi) before reaching PostHog; this is a technical measure to ensure reliable delivery, and PostHog remains the recipient.
Through PostHog we collect:
We do not use advertising cookies, advertising networks, or third-party trackers.
We record sessions on Cosmic KPI using PostHog's session replay feature. A recording reconstructs what happened on screen during a visit — pages viewed, clicks, scrolling, and navigation. We use recordings to find usability problems and understand where the product is confusing.
We mask sensitive areas so they do not appear in recordings. This includes every form field, the birth data form, your account birth summary, notebook composers and entries, your saved chart names, Ancestry information, calendar event contents, sign-in fields, and calendar feed addresses.
However, recordings do show the results Cosmic KPI generates for you. Screens such as your transits, calendar, and echoes display astrological content calculated from your birth information — planetary positions, aspects, and interpretations. This content is visible in recordings. We have chosen not to hide it because these screens are the ones we most need to observe in order to improve the product.
Recordings are retained for up to 30 days and are then deleted automatically.
You can turn off all analytics and session recording at any time using the privacy control in your account settings. This applies to the browser where you set it.
We do not use your information to train machine learning models, and we do not use it for advertising.
Connecting your Google account for calendar sync is optional, and we request the narrowest scope that makes it work.
To sync your published forecast, if you opt in, we request one scope:
https://www.googleapis.com/auth/calendar.app.created
This scope lets Cosmic KPI create and manage only its own dedicated "Cosmic KPI" calendar. It grants no access to your existing calendars or events, so Cosmic KPI is structurally unable to read, edit, or delete anything you created. Nothing is written when you connect — events are added only after you review a preview and confirm, and you can remove every Cosmic KPI event from the app at any time. We never request broader write access.
We do not request read access to your calendars: Cosmic KPI cannot see the events in your own Google Calendar. To show your real-life events alongside transits, use an .ics export or a calendar feed URL instead (Section 2).
Tokens. Access and refresh tokens are encrypted at rest and remain on our backend. They are never sent to your browser and never appear in logs.
Disconnecting. You can disconnect at any time from calendar settings. Disconnecting immediately removes the stored tokens and Cosmic KPI's record of the connection; the dedicated "Cosmic KPI" calendar stays in your Google account until you remove its events from the app or delete the calendar in Google. You can also revoke access at myaccount.google.com/permissions.
Cosmic KPI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically: we do not transfer, sell, or share Google user data with third parties for advertising, credit assessment, or any purpose other than providing and improving the features you requested. We do not allow humans to read your Google data except with your explicit permission, for security purposes, to comply with law, or where the data has been aggregated and de-identified.
You can create a Cosmic KPI account, or log in to one, with your Google account instead of a
password. This uses Google's standard sign-in with the three basic identity scopes only —
openid, email, and profile. Signing in requests no
access to your Google Calendar, your files, your mail, or anything else in your Google
account.
What we receive and store. During sign-in, Google sends us your email address, whether Google has verified that address, your Google account's permanent identifier, and basic profile details such as your name and picture. We store only the identifier and the email address; we do not store your name or picture.
Linking to an existing account. If your Google email matches an existing Cosmic KPI account that has a password, we ask for that password once before connecting the two — this prevents someone else from attaching a sign-in method to an account that isn't theirs. Accounts created with Google have no password and sign in with Google.
No ongoing access. Sign-in is a one-time identity check at the moment you log in. We do not request or hold ongoing access to your Google account, and there is nothing to sync or disconnect afterwards. You can review Cosmic KPI's access at myaccount.google.com/permissions.
Unlinking. To remove the Google connection from your account, or to delete the account entirely, contact us (Section 15).
Turn off analytics and session recording. Use the privacy control in your account settings. It takes effect immediately in that browser.
Get a copy of your information. Email hello@cosmickpi.com from the address on your account and we will send you an archive containing everything we hold for it — your birth charts, journal entries, evidence verdicts, Connections tree, calendar settings and published forecast — as JSON and as spreadsheet files, plus a manifest listing anything held back and why. Credentials and secret calendar URLs are the only exclusions. There is no charge, we verify who is asking before we send it, and the copy deletes nothing. Data held only in your own browser — a birth chart entered without signing in, and your local calendar layer — never reaches us, so it is not in the archive; it stays on your device.
Correct your information. Most of it you can edit directly in the app. For anything else, contact us.
Delete your account. Contact us at hello@cosmickpi.com and we will delete your account and its contents, including any Ancestry and calendar information you entered. We will also delete your associated analytics records and recordings.
Leave the updates list. Email hello@cosmickpi.com and we will remove your address. Leaving the updates list does not affect your account.
Disconnect Google Calendar. In Cosmic KPI settings, or through your Google account.
We will not treat you differently for exercising any of these rights.
If you are a California resident, the CCPA as amended by the CPRA gives you additional rights.
Categories we have collected in the last 12 months:
We collect this for the purposes described in Section 6, from the sources described in Sections 2 through 4.
We have not sold or shared personal information in the last 12 months, as those terms are defined by the CCPA, and we do not do so. We do not sell or share the personal information of minors.
Your rights: to know what we have collected, to obtain a copy, to correct inaccuracies, to delete it, and to be free from discrimination for exercising these rights. To exercise the right to a copy, email us and we will send you a complete archive — see Section 11.
To exercise them, email hello@cosmickpi.com with the address associated with your account. We will verify your identity before acting and will respond within 45 days. You may use an authorized agent, in which case we may ask for written proof of authorization.
Because we do not sell or share personal information, there is nothing for a Global Privacy Control signal to opt out of. We honor such signals where they apply.
We protect your account with hashed passwords and token-based authentication, encrypt data in transit, encrypt third-party access tokens at rest, and restrict access to production systems. No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your information, we will notify you as required by law.
We may update this policy. If we make a material change — particularly to what we collect or who we share it with — we will notify you in the app or by email before it takes effect. The date at the top always reflects the current version.
Cosmic KPI
For privacy questions, requests, or complaints, email hello@cosmickpi.com and we will respond within 30 days.