Privacy Policy

Last updated: April 3, 2026

Version 1.2 — Effective date: April 3, 2026

This Privacy Policy explains how ZodAI ("we," "our," or "us"), operated by Rico Schurter (Bellinzona, Switzerland), collects, uses, shares, and protects your personal information when you use the ZodAI mobile application ("App") and related services.

By downloading, installing, or using ZodAI, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use the App.

TABLE OF CONTENTS

  1. Who We Are
  2. Information We Collect
  3. How We Use Your Information
  4. AI & Third-Party Processing (OpenAI)
  5. Third-Party Services
  6. International Data Transfers
  7. Data Sharing and Selling
  8. Data Retention
  9. Security
  10. Your Rights — California Residents (CCPA/CPRA)
  11. Your Rights — Other US States
  12. Your Rights — Swiss & EU Residents (nDSG/GDPR)
  13. Children's Privacy (COPPA)
  14. Email Communications (CAN-SPAM)
  15. Automated Decision-Making
  16. Changes to This Policy
  17. Contact Us

1. Who We Are

ZodAI is operated by:

Rico Schurter
Bellinzona, Canton Ticino, Switzerland
Email: support@zodai.io
Support: support@zodai.io
Website: https://zodai.io

Rico Schurter acts as the data controller for personal data collected through the ZodAI application, as defined under the Swiss Federal Act on Data Protection (nDSG/FADP), the EU General Data Protection Regulation (GDPR), and applicable US privacy laws.

2. Information We Collect

2.1 Information You Provide Directly

2.2 Information Collected Automatically

2.3 Derived Information

2.4 Categories Under CCPA (California)

CategoryExamplesCollected?
IdentifiersName, email address, account IDYes
Personal information (Cal. Civ. Code §1798.80(e))NameYes
Characteristics of protected classificationsDate of birth (age)Yes
Commercial informationSubscription history, purchasesYes
Internet or network activityApp usage, feature interactionsYes
Geolocation dataBirth city/country (not real-time location)Yes
InferencesAstrological profile, reading preferencesYes
Sensitive personal informationNone beyond date of birthLimited

We do NOT collect: real-time location, contacts, photos, payment card numbers (handled by Apple), or any biometric data.

3. How We Use Your Information

PurposeData UsedLegal Basis (nDSG/GDPR)
Calculate your personal birth chart (10 planets)Birth date, time, place + coordinatesContract performance
Geocode your birth city to coordinates and timezoneBirth city name → Google Places API (server-side)Contract performance
Generate your daily AI reading via LyraBirth chart data, name → OpenAIContract performance + Consent
Power your chat conversations with LyraMessages, birth chart → OpenAIContract performance + Consent
Generate Cosmic Compatibility readingsYour chart + partner's data → OpenAIContract performance + Consent
Manage your account and authenticationEmail, password hashContract performance
Process and manage subscriptionsSubscription status via RevenueCat/AppleContract performance
Cache daily readings (one per user per day)Reading text stored in SupabaseLegitimate interest
Store recent chat history (last 60 messages)Chat messages stored in SupabaseContract performance
Send daily reading push notificationsPush token via ExpoConsent
Send transactional and waitlist emailsEmail address via BrevoContract performance + Consent
Referral programUser ID, referral codeLegitimate interest
Improve the App and fix bugsAggregated usage dataLegitimate interest
Comply with legal obligationsAs required by applicable lawLegal obligation

4. AI & Third-Party Processing (OpenAI)

⚡ AI DISCLOSURE — Required under Apple App Store Guidelines 5.1.2(i)

Before using Lyra for the first time, the App displays a consent dialog requesting your explicit agreement to this data sharing. You may decline, in which case AI-powered features will not be available.

OpenAI's Privacy Policy: https://openai.com/privacy

ZodAI has executed a Data Processing Agreement (DPA) with OpenAI Ireland Ltd. (effective March 18, 2026), ensuring compliance with Swiss nDSG, EU GDPR, and applicable US privacy law.

5. Third-Party Services

ProviderPurposeData SharedPrivacy Policy
OpenAI, LLC AI content generation (Lyra responses, readings) Birth chart, name, chat messages openai.com/privacy
Supabase, Inc. Database, authentication, Edge Functions (hosted on AWS) All account and app data supabase.com/privacy
RevenueCat, Inc. Subscription management and analytics Device ID, subscription status revenuecat.com/privacy
Apple, Inc. App distribution, in-app purchases, push notifications (APNs) As per App Store terms apple.com/privacy
Expo (Expo Go / EAS) App build infrastructure and push notification delivery Push notification token, device info expo.dev/privacy
Google LLC Geocoding birth city to geographic coordinates and IANA timezone (Google Places API + Google Timezone API). Called server-side at onboarding and profile edit — only the city name is transmitted to Google's servers to retrieve latitude, longitude, and timezone. The result is stored in our database; no further data is shared with Google. Birth city name only policies.google.com/privacy
Brevo (Sendinblue SAS) Transactional emails (account confirmation, password reset) and waitlist communications Email address, first name brevo.com/legal/privacypolicy

All providers are contractually bound to process your data only as instructed by ZodAI and in compliance with applicable data protection law.

Google LLC is based in the United States. Data transferred to Google is governed by Google's Terms of Service and Privacy Policy. Google may process this data in accordance with its own retention policies. ZodAI does not receive or store any data from Google beyond the coordinates and timezone returned for the queried city name.

6. International Data Transfers

ZodAI is operated from Switzerland. Our service providers are primarily located in the United States. When we transfer your personal data from Switzerland or the EU/EEA to the USA, we rely on:

You may request a copy of applicable transfer safeguards at support@zodai.io.

7. Data Sharing and Selling

We do NOT sell your personal information. We do not share your personal information with third parties for cross-context behavioral advertising or targeted advertising purposes.

We share your data only in these limited circumstances:

8. Data Retention

Data CategoryRetention Period
Account data (name, email, birth data)Until account deletion, then immediately purged
Daily readings cacheRetained while account is active (one reading per day)
Chat messages with LyraLast 60 messages stored per user in Supabase. When the 60-message limit is exceeded, the oldest messages are automatically deleted. All messages are permanently deleted upon account deletion.
Compatibility readingsUntil account deletion
Data sent to OpenAIMaximum 30 days at OpenAI for abuse monitoring, then deleted per OpenAI's API policy
Data sent to Google (birth city name)Not retained by ZodAI beyond the geocoding response. Google's own retention applies per their Privacy Policy.
Subscription data (RevenueCat)Per RevenueCat's data retention policy
Push notification tokensUntil account deletion or notification permission revoked
Email address (Brevo — waitlist)Until you unsubscribe or request deletion
App usage logs12 months rolling

When you delete your account through the App (Profile → Delete Account), all your personal data on our servers is permanently and irreversibly deleted within seconds, including your profile, birth data, readings, chat history, and referral records.

9. Security

In the event of a data breach that affects your rights and freedoms, we will notify you and applicable authorities within 72 hours of becoming aware, as required by law.

10. Your Rights — California Residents (CCPA/CPRA)

Submit requests via: in-app deletion (Profile → Delete Account) or email support@zodai.io with subject "CCPA Privacy Request." We respond within 45 days.

11. Your Rights — Other US States

Residents of Colorado, Connecticut, Virginia, Texas, Florida, Montana, Oregon, and other states with comprehensive privacy laws have similar rights including access, deletion, correction, portability, and opt-out of targeted advertising. Contact support@zodai.io to exercise these rights.

Texas residents: Under the Texas Data Privacy and Security Act (TDPSA), you may submit a complaint to the Texas Attorney General.

12. Your Rights — Swiss & EU Residents (nDSG/GDPR)

Under the Swiss Federal Act on Data Protection (nDSG, effective September 1, 2023) and the EU General Data Protection Regulation (GDPR), you have the following rights:

To exercise these rights: support@zodai.io

Swiss residents may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC): www.edoeb.admin.ch

EU residents may lodge a complaint with the supervisory authority in their country of residence or establishment.

13. Children's Privacy (COPPA)

ZodAI is not directed at children under the age of 13.

We do not knowingly collect personal information from children under 13 years of age. The App includes an age verification mechanism at registration: if a user's date of birth indicates they are under 13, their account will not be created and no personal data will be stored.

If you are a parent or guardian and believe your child under 13 has provided personal information to ZodAI, contact us immediately at support@zodai.io. We will promptly delete any such information.

Users between 13 and 18 years of age should review this Privacy Policy with a parent or guardian before using ZodAI.

This policy is maintained in compliance with the Children's Online Privacy Protection Act (COPPA).

14. Email Communications (CAN-SPAM)

ZodAI sends transactional emails (account confirmation, password reset) via Brevo from support@zodai.io and, with your consent, promotional communications about new features or offers.

In compliance with the CAN-SPAM Act:

To unsubscribe: click the "Unsubscribe" link in any email or email support@zodai.io.

15. Automated Decision-Making

ZodAI uses automated processing (AI) to generate personalized astrological readings. These outputs are for entertainment and personal insight only and do not produce legal effects or similarly significant decisions affecting users.

If you wish to question any AI-generated output, contact support@zodai.io. We will provide human review upon request.

16. Changes to This Privacy Policy

When we make material changes, we will:

17. Contact Us

Rico Schurter — ZodAI Data Controller
Bellinzona, Canton Ticino, Switzerland
Email: support@zodai.io
Support: support@zodai.io
Website: https://zodai.io

We aim to respond to all privacy-related inquiries within 30 days.


© 2026 ZodAI — Rico Schurter — All rights reserved.
ZodAI is for entertainment and personal insight purposes only. Not a substitute for professional advice.