Privacy policy

1. Controller

The controller responsible for processing data on this website is:

Mirko Strick
Pastor-Löh-Str. 13
51399 Burscheid
E-Mail: info@mirkoalexander.de

2. Collection and processing of personal data

When an astrological birth-chart analysis is ordered, the data provided voluntarily is processed. This includes in particular:

This data is processed exclusively to prepare the astrological analysis and for any subsequent support.

3. Data storage

The email address entered in the order form is uniquely associated with the active user account for its duration. It is used to process the contractual relationship, send order and account messages, restore account access and communicate a forgotten username. The last name continues not to be stored in the user database. The personal assignment message is sent to my email inbox and retained there to process and document the order.

For the user account, the web server stores in particular the freely chosen unique username, unique email address, a password hash, first name, birth details, selected place of birth, calculated birth-chart data and technical information about the access status. The email address is processed for account management and access recovery in order to perform the contractual relationship pursuant to Art. 6(1)(b) GDPR.

3a. Account recovery

When registering for a free test account, the entered email address, first and last name, password hash, birth data, selected place of birth and accepted document versions are initially stored as a pending registration. A random, single-use confirmation link is sent to the specified address. Only the cryptographic hash of the confirmation key is stored in the database. The link is valid for 24 hours. The user account is created only after the link is opened. Unconfirmed registrations are regularly deleted after expiry; the last name is not transferred to the subsequently created user account.

When a new password is requested, a random, single-use link is sent to the stored email address. The database stores only a cryptographic hash of the token, not the link itself. The link is valid for 30 minutes. When a forgotten username is requested, it is sent to the uniquely associated email address.

To protect against excessively frequent abusive requests, hashes of the entered email address and requesting IP address, together with the time and type of request, are stored for no more than seven days. Expired and used reset tokens are also regularly deleted after no more than seven days. Form responses do not reveal whether an entered email address is registered.

3b. Login, session cookie and app-to-web link

A technically necessary session cookie containing a random session identifier is used for protected login on the website. It normally ends with the browser session. After a regular login with a username and password, an additional persistent-login cookie is created. It remains stored for up to 400 days and enables automatic login again if the PHP session has ended or expired on the server. The cookie contains a random identifier and a random secret; only a SHA-256 hash of the secret is stored on the server. On automatic login, the secret is replaced and the retention period is renewed. Short-lived one-time links from the app do not create a persistent login. Both cookies are used exclusively for login, access control and security of the customer area. They are not used for advertising, audience measurement or cross-site tracking and are restricted to the relevant domain. Logging out on the website, changing the password, deleting the account or deactivating the account revokes the persistent login. Deleting the browser cookies also ends it. Storage and access are necessary for the expressly requested protected service and persistent-login function (section 25(2), no. 2 TDDDG); the related processing is necessary to perform the user relationship pursuant to Article 6(1)(b) GDPR.

If a blog post is opened from the signed-in Android app, the app can request a random, single-use web login link. Only the cryptographic hash of the key is stored in the database. The link is valid for two minutes, is invalidated upon first use and then creates the normal protected web session. Test and production systems each use their own domain and user database.

When paying via PayPal, PayPal processes the data required for the payment independently. The web server stores technical identifiers, payment status, amount, currency and timestamps. Complete PayPal webhook messages are not stored permanently.

3c. Sign in with Apple and purchases in the iOS app

In the iOS app, you can use Sign in with Apple to sign in and register. Apple provides a stable app-specific identifier and an Apple-verified email address, which may be a private Apple relay address if you choose. The Apple identity token is checked on the server for its signature, audience, validity, and a unique random sign-in identifier. The app-specific Apple identifier and verified email address are stored, but your Apple password is not. For a new registration, the freely chosen unique public username, first name, birth details, place of birth, and accepted document versions are also stored in the user account. The last name is processed only for the confirmation message and is not stored in the user account.

Purchases and subscriptions in the iOS app are processed by Apple. RadixChat receives and stores the technical transaction identifiers, product identifier, status, price, currency and time details, and the signed transaction record required for assignment, activation, duration, restoration, and accounting. RadixChat does not receive complete payment details such as card or bank details from Apple.

3d. Contact and withdrawal form

When the contact and withdrawal form is used, the name, email address, message and, where provided, username, order date and PayPal subscription ID are processed. Processing takes place to answer the contact request, process and document a withdrawal, or perform the contractual relationship.

The form data is not stored in the user database. It is sent by email to my internal inbox. A confirmation of receipt is sent to the specified email address. Messages are retained in the email inbox only for as long as necessary for processing and to comply with statutory evidence and retention obligations.

4. Use of ChatGPT within RadixChat

The OpenAI API is used for the AI chat.

When a request is made, the following information in particular is transmitted to OpenAI:

The following are not routinely transmitted to OpenAI:

Please do not share directly identifying or particularly sensitive information in the AI chat unless it is necessary for your question.

5. Pseudonymization

The freely chosen username can be used to sign in instead of the email address. The email address remains uniquely associated with the account for sign-in, order communications and account recovery.

Use is therefore pseudonymized in relation to the AI service, but not fully anonymous because birth-chart and chat data is processed.

6. Community and private messages

When AI pre-review is enabled, forum posts and comments are sent to OpenAI for content moderation. For comments, the parent post and up to five previously published comments are included as context. Account data is not added; personal data entered in the text itself is part of the text. Private messages are not sent to this AI review. Clearly acceptable content is published automatically; uncertain or problematic content is reviewed manually. The result, a brief reason and API usage are stored on the server. Private messages in conversations with “Mirko Alexander” are automatically sent to OpenAI for translation: incoming messages are translated into German for him, and his German replies are translated into the other participant’s most recently detected language. The current message and up to eight preceding message texts are transmitted as context, but no names, user identifiers, email addresses or attachments. The API request does not use persistent response storage (store: false); the translation, detected original language and API usage are stored on the RadixChat server.

When automatic translation is enabled, a subscriber’s own future forum posts and comments added later are sent to OpenAI for translation. Private messages are translated only after both participants have consented for that conversation. Only the text and limited conversation context are sent; attachments and account data are not added. Consent can be withdrawn at any time. The API request uses no persistent response storage (store: false). Translations and API usage are stored on the RadixChat server.

In the protected customer area, registered users can publish posts for all community members, comment on posts and exchange private messages. Public posts and comments are visible to other community members who are not blocked. Private messages are intended for the respective participants and are stored on the server to provide the conversation.

New forum posts and comments are reviewed by administrators before publication. Private messages are not routinely submitted for review. When explicitly reported, only the selected content, its image attachment, report reason and relevant user identifiers are stored as evidence and made available to administrators. The rest of the private conversation is not copied. Spam prevention operates locally using rate limits and briefly stored content fingerprints; no external moderation service is used.

If a private community message is sent to “Mirko Alexander”, an additional email containing the display name and message content is sent to my internal inbox for notification. Private messages between other users do not trigger email forwarding.

Community profiles use a display name, a planetary symbol automatically derived from the birth chart and a randomly assigned profile color. Users can block other users. Blocked users cannot hold private conversations with each other and no longer see each other’s community posts.

An explicit button on a community post or private message can open a read-only view of the respective author’s birth chart. The astrological positions, houses, aspects and stored birth data belonging to the chart may also become visible. Therefore, publish community content only if you agree to this intended chart sharing with other registered users.

7. External services used

The service uses in particular PayPal for payment and subscription processing, an email provider for sending messages, and OpenAI for the AI functionality. In each case, only the data intended for the relevant purpose is transmitted.

I use the information provided to me exclusively to deliver my “Astrology for self-discovery” service.

8. Access and deletion

You have the right at any time to obtain information about the data I store about you.

You may also request correction or deletion of your data, provided that statutory retention obligations do not prevent this.

9. Information about astrological guidance

My service is intended exclusively for self-reflection and self-knowledge.

It is not a substitute for psychotherapeutic, medical or other healthcare treatment.

No predictions of the future or promises of healing are made.

×