privacy policy

Last updated: May 11, 2026

1. Who we are

Moonketu is operated from Montreal, Québec, Canada. This policy explains what personal information we collect, why we collect it, and how we handle it — in compliance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and Québec's Act respecting the protection of personal information in the private sector (Law 25).

2. What we collect

When you create an account and use Moonketu we collect:

  • Email address — used for passwordless sign-in.
  • First and last name — collected when you register.
  • Birth data — date, time, and city/coordinates you enter when saving a chart. This is sensitive personal information and is only ever used to calculate your astrology chart.
  • Session data — a secure, httpOnly cookie that keeps you signed in. It contains no personal information.
  • IP address and user agent — stored with each session for security purposes.
  • Stripe customer ID — if you subscribe, we store a Stripe-issued customer identifier to manage your subscription. We do not store your payment card details — those are held exclusively by Stripe.
  • Anonymous visit data — pages visited, device type, browser, and referring domain. Approximate country and city are inferred from network headers provided by our CDN (Cloudflare); your IP address is never stored. This data is not linked to your account or identity and is used only to understand overall site usage.

We do not use advertising trackers or third-party analytics scripts. All analytics data is collected server-side and stays on our own infrastructure.

3. How we use your data

  • To authenticate you via one-time email codes.
  • To save and display your birth charts.
  • To associate saved charts with your account.
  • To manage your subscription status (active, cancelled) via Stripe.

We do not sell, rent, or share your personal information with any third party, except as described in section 4.

4. Third-party services

We use the following trusted third-party services to operate Moonketu:

  • Amazon Web Services Simple Email Service (AWS SES) — used solely to deliver sign-in code emails to your address. Your email address is transmitted to AWS for this purpose only and is not retained by AWS beyond delivery. AWS is bound by its own privacy policy.
  • Cloudflare — provides our content delivery network (CDN) and DDoS protection. All traffic to Moonketu passes through Cloudflare's network. Cloudflare processes visitor IP addresses to provide network security and supplies approximate country and city data via request headers, which we use for anonymous analytics. Cloudflare's handling of data is governed by Cloudflare's privacy policy.
  • Stripe — used to process subscription payments. Stripe acts as the Merchant of Record for all transactions, meaning they independently collect and process your name, email address, location, and payment details for the purpose of completing your purchase and handling tax compliance. Stripe's handling of your data is governed by Stripe's privacy policy. We do not have access to your full payment card details.

5. Data retention

We retain your account and saved charts indefinitely while your account is active. You may request deletion of your account and all associated data at any time by emailing [email protected]. We will complete deletion within 30 days.

6. Your rights

Under PIPEDA and Québec Law 25, you have the right to:

  • Access the personal information we hold about you.
  • Correct inaccurate information.
  • Request deletion of your data.
  • Withdraw consent (which will result in account deletion).

To exercise any of these rights, contact us at [email protected].

7. Cookies

We use four first-party cookies, all strictly functional:

  • _moonketu_session_id — keeps you signed in. httpOnly, same-site, contains only an opaque token. Expires after 35 days.
  • _moonketu_session — internal system security session cookie used to protect against unauthorized submissions (CSRF protection) and securely manage temporary interface messages. httpOnly, same-site, expires at the end of your browser session.
  • _moonketu_prefs — remembers your chart preferences (ayanamsha, chart style, node type, theme, karaka scheme, and divisional chart selection). Expires after one year.
  • _moonketu_drawer_open — remembers whether the settings panel was open so it stays open after you change a setting. Expires at end of browser session.

None of these cookies contain personal data. We do not use tracking or advertising cookies.

8. Children's privacy

Moonketu is not intended for users under 18. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected such information, please contact us and we will delete it promptly.

9. Future changes

This policy may be updated from time to time. Changes are posted on this page with a revised "last updated" date. Continued use of Moonketu after changes are posted constitutes acceptance of the updated policy.

10. Privacy Officer & Contact

In accordance with Québec Law 25, the person responsible for personal information at Moonketu is the site operator. For any privacy questions, access requests, or to exercise your rights, please contact us at [email protected].