Canopy requires an active subscription to use; signing in with Apple is required, and used to sync your chart across devices. Canopy stores the birth details you enter and — only if you grant permission — your current location, to compute your chart and daily readings. It records first-party usage, purchase, and diagnostic events tied to your account, and — on iOS — whether the install came from one of our own Apple App Store adverts. The data we collect for advertising or marketing is used in aggregate to measure and refine our own advertising; it is owned by us and kept private by us. We do not sell your data, we do not show advertising in the app.
1. Who we are
Canopy is an iOS application developed and operated by Stellar Apps LLC, a limited liability company registered in the United States, which is the data controller for the information described here.
You can reach us at:
- Email: canopyappsupport@stellarappsllc.com
- In the app: Settings → Support → Submit Support Request
2. Information we collect
We collect the following, each linked to your account:
- Display Name and birth details — the display name you enter for your chart, and the date, time, and place (including geographic coordinates) of birth. Birth details are sent to our backend to compute and cache your natal chart, Arabic lots, essential dignities, and related readings; the display name you enter is stored with your profile when you sign in.
- Location (optional) — your current location, accessed only if you grant permission in iOS; used for planetary hours and current-moment readings. You can instead set a location manually. Coordinates used to compute a reading are sent to our backend and cached so results return quickly; we do not build a history of your movements, and cached coordinates are deleted with your account. We also derive a coarse location (country or region) from your device settings and from the birth place you enter.
- Account and email address — Signing in with Sign in with Apple is required for authentication, and links your chart across devices. When you sign in, we receive an Apple-issued account identifier and, if you choose to share it, your email address. We keep the email address only as a one-way hash: we cannot read it back, and we use the hash to keep your account consistent and, in aggregate, to measure and refine our own advertising. If you use Apple's "Hide My Email", we receive Apple's relay address instead.
- Subscription and purchases — Canopy is a subscription app, and using it requires an active subscription billed through your Apple Account. We receive your subscription status (active, in trial, expired) and Apple-issued transaction identifiers from the App Store and StoreKit, and we record purchase events (trial started, subscribed, renewed, cancelled). We never receive or store your payment card details. See our Terms of Use for the subscription terms.
- Usage data — first-party events describing how the app is being used (onboarding completed, daily open, reading completed, paywall viewed, subscribe tapped, and similar) is tied to an account identifier, with the app version, device model, iOS version, language, timezone, and country. We use these in aggregate for analytics on how the app is used and on our users' interests and engagement, and to refine our own promotional activities.
- Device identifiers — requests to our backend include your device's vendor identifier (IDFV), and, only if you allow tracking, its advertising identifier (IDFA), and are verified with Apple's App Attest to confirm they come from a genuine copy of Canopy. If you open Canopy from a link in one of our adverts, the link's click identifier is recorded so we can attribute the install to our own campaign. These identifiers are used to protect the service, to keep your account consistent across launches, and to measure our own advertising.
- Diagnostics — crash reports and performance data collected by Apple's MetricKit on your device and sent to our backend so we can find and fix problems. They contain technical information about the app and device, not your readings.
- Calendar (optional) — if you choose to save an election window to your calendar, Canopy asks for iOS calendar permission and writes the event on your device. We never read or transmit your calendar's contents.
- Apple Ads attribution (iOS only) — shortly after you install Canopy from the App Store, the app asks Apple's AdServices framework for a short-lived attribution token and sends it, together with the device's vendor identifier described above, to our backend. Our backend asks Apple whether this install followed a tap on — or a view of — one of our own Apple Ads adverts. If it did, Apple returns the campaign, ad group, keyword and advert concerned, where the advert appeared, whether it was a tap or a view and on what date, whether this was a first download or a redownload, and your country or region. We store that record with your account and use it only to measure how our own advertising performs. The token is not the advertising identifier (IDFA), and Apple's response cannot identify you personally. It is deleted when you delete your account.
Canopy asks your permission, through Apple's tracking prompt, before it uses your device's advertising identifier (IDFA). If you allow it, our advert vendors can use it to tell us which of our own adverts led to your install. If you do not, we do not use it, and nothing in the app changes. You can change your answer at any time in iOS Settings → Privacy & Security → Tracking.
3. How we use your information
- Astrological calculation and personalisation — generating your natal chart, daily planetary hour schedule, lunar-mansion guidance, electional timing, fixed-star placements, and transit readings from your birth data and optional current location.
- Account — storing your chart data under your account identifier so it persists, and — when you sign in with Apple — syncing it across your devices.
- Subscription — verifying your subscription status with Apple's StoreKit to provide access to the app and prevent fraud.
- Service protection and improvement — verifying requests with App Attest, keeping short-term internal service logs (request metadata and device identifier) to protect the service, using diagnostics to find and fix crashes and slowdowns, and analysing the usage events described above.
- Promotional activities and analytics — using the Apple Ads attribution record and other items described above, in aggregate, to measure how our own advertising performs and to refine where and how we advertise Canopy. This data is owned by us and kept private by us. We do not sell it, and we do not use it to target advertisements at people who already use Canopy.
- Customer support — responding to requests you send through the in-app support form or to canopyappsupport@stellarappsllc.com. When you submit an in-app support request, the app opens your device's Mail app with your message plus your device model, iOS version, and app version attached, so we can help — this is sent only when you choose to send it. If no mail account is set up, the app shows our email address so you can contact us directly.
4. Third-party services
Canopy relies on service providers, each only to perform the function described and only under our instructions:
- Supabase — provides our backend (database storage, authentication, and API). Supabase securely stores your encrypted account data, chart data, usage, purchase, diagnostic and attribution records on our behalf, and does not use them for its own purposes. Supabase is engaged under a data processing agreement; see Supabase's Privacy Policy.
- Apple — provides Sign in with Apple, processes subscriptions through StoreKit, and answers our backend's Apple Ads attribution query described in Section 2. If you request a refund from Apple, we may provide Apple with a summary of your app usage (such as whether the app was delivered and how long it was used) solely to help Apple resolve your request. See Apple's Privacy Policy.
- Our advert vendors — receive the usage and purchase events and device identifiers described in Section 2 so that we can learn whether our own adverts are working.
No third party receives your personal data for its own purposes.
5. Data security
We take reasonable measures to protect your personal data. Data exchanged between the app and our backend is encrypted in transit using HTTPS/TLS, and data stored with our backend provider (Supabase) is encrypted at rest. Access to stored data is limited to authorised personnel. No method of transmission or storage is completely secure, but we work to safeguard your information and review our practices regularly.
6. Data retention and your choices
We retain your data while your account is active. When you delete your account, we remove your name, birth details, chart data, cached readings, hashed email, usage and purchase events, diagnostics, click identifiers, any Apple Ads attribution record, service-log entries, and account identifier from our systems. We may retain fully anonymised aggregate statistics, which cannot be linked back to you. You are always in control:
- Edit or delete your birth details — open Settings → Profile & Birth Data in Canopy to change or remove what you have entered.
- Delete your account — open Settings → Account → Delete Account in Canopy. This permanently and immediately deletes your account and all associated data, and cannot be undone. You can also request deletion by contacting us through the in-app support form or at canopyappsupport@stellarappsllc.com; we will complete email requests within 30 days.
- Revoke location access — go to iOS Settings → Canopy → Location and choose "Never" at any time.
Need help? Visit Canopy Support or email canopyappsupport@stellarappsllc.com.
7. Your rights — GDPR (EEA and UK)
If you are in the European Economic Area or the United Kingdom, we process your personal data on these lawful bases: consent (for location access, which you grant explicitly via iOS permissions), performance of a contract (for your birth details, account, and subscription, which are necessary to provide the service you have requested), and legitimate interests (for the usage, purchase and diagnostic events, the hashed email, the click identifiers, the Apple Ads attribution record, and the service-protection logs described above, which we keep to secure the service, to understand how it is used, and to measure and refine our own advertising).
Under the GDPR and UK GDPR, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — ask us to delete your personal data ("right to be forgotten").
- Restriction — ask us to restrict processing in certain circumstances.
- Portability — receive your data in a structured, machine-readable format.
- Object — object to processing based on our legitimate interests, including our own advertising measurement.
- Withdraw consent — withdraw permission (for example, by revoking location access) at any time.
- Complaint — lodge a complaint with your local supervisory authority (a list of EEA authorities is available at edpb.europa.eu).
To exercise any of these rights, email canopyappsupport@stellarappsllc.com. We will respond within 30 days.
8. Your rights — California (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you the right to:
- Know — the categories and specific pieces of personal information we have collected, and why.
- Delete — request deletion of personal information we have collected, subject to certain exceptions.
- Correct — request correction of inaccurate personal information.
- Opt out of sale or sharing — we do not sell or "share" (for cross-context behavioural advertising) your personal information, so there is nothing to opt out of.
We will not discriminate against you for exercising these rights. To make a request, email canopyappsupport@stellarappsllc.com.
9. Children
Canopy is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If we learn we have inadvertently collected such information, we will delete it promptly. If you believe a child has provided us with personal data, contact us at canopyappsupport@stellarappsllc.com.
10. Changes to this policy
We may update this Privacy Policy at any time without prior notice. When we do, we will revise the "Last updated" date above. Continued use of Canopy after the effective date constitutes acceptance of the revised policy.
Questions about a change? Contact us at canopyappsupport@stellarappsllc.com or via the Support page.
11. Contact
For any privacy question, data request, or concern, reach us at canopyappsupport@stellarappsllc.com or through Canopy Support. We respond to all privacy inquiries within 30 days.