Privacy Policy
Last updated: July 16, 2026
Effective date: July 16, 2026
TerraLamp (“we”, “us”, “the Service”) is operated by David Lanier (“the operator”), based in Washington, United States. This policy explains what personal information we collect, why, how we protect it, and the choices and rights you have. We’ve tried to write it in plain language; where a term has a specific legal meaning we say so.
We collect the information needed to build you a personalized planner — your account email and, if you choose to use astrology features, the event details (date, time, and place) you enter. We do not run advertising, we do not use advertising or tracking SDKs, and we never sell or share your data with data brokers or advertisers. You can delete your data at any time by request at the contact page.
1. Who this applies to
This policy applies to anyone who creates an account on, or uses, TerraLamp, wherever you are located. The Service is operated from the United States, and you are welcome to use it from anywhere. Whoever you are, we honor the core rights described in Section 10 — access, correction, export, and deletion. If you are located in the European Economic Area (EEA), the United Kingdom, or California, you have additional, specific rights described in Section 10 and Section 11.
TerraLamp is not directed to children. You must be at least 18 years old (or the age of digital consent in your jurisdiction) to create an account. We do not knowingly collect information from children under that age; if you believe a child has provided us information, contact us and we will delete it.
2. What we collect
We collect only what we need to operate the Service. There are three buckets.
2.1 Information you give us
| Data | Why we have it | Required? |
|---|---|---|
| Email address | Account identity, sign-in, verification, password reset, and essential service messages | Required to have an account |
| Password | Authentication. Stored only as a salted cryptographic hash — we never see or store your actual password | Required |
| Birth / event profiles — a label or name, and the date, time, and location (place name and/or coordinates) you enter | To compute charts and personalize your planner. These are the details you choose to enter — they may be your own birth data, someone else’s, or any date/time/place you want a chart for | Optional — only if you use astrology personalization |
| Planner configurations | The choices that make up a saved planner, so you can reload and re-download it | Created as you use the Service |
2.2 Information we derive
- Computed astrological data (e.g. natal chart positions) calculated from the birth/event details you enter, and stored alongside the profile so we don’t recompute it on every request.
- Generated PDFs you create, based on planner configuration.
2.3 Information collected automatically or by our providers
- Operational logs — IP address, browser/device type, timestamps, and error diagnostics, used to keep the Service running, secure, and debuggable. Retention window: 7 days.
- Error tracking — we use Sentry.io to catch and diagnose crashes and errors so we can fix them. This is an operational tool, not a profiling one: we configure it to scrub personal data and birth details from error reports before they are sent.
- Privacy-respecting analytics — we plan to use a cookieless, privacy-respecting analytics tool to understand aggregate usage (e.g. which pages are visited). It will not set tracking cookies, not build profiles of you, and not track you across other websites.
- Email delivery — transactional emails (verification, password reset) are sent through Resend.com, which processes your email address to deliver them.
We do not run advertising, use advertising or behavioral-tracking SDKs, set advertising cookies, or sell or share your information with data brokers or advertisers. This is a deliberate commitment.
3. How we treat birth data
Birth date, exact time, and precise place, taken together, are a strongly identifying combination, and the fact that you use astrology features can imply something about your beliefs. Even though this kind of data is not formally a “special category” under the GDPR, we treat it with heightened care: it is access-controlled to your account, encrypted at rest — see Section 6, never sold, and never shared for advertising. You are always free to use the Service without entering any birth data, or to enter data for a date/place that is not your own.
4. How we use your information
We use your information to:
- Create and secure your account, and sign you in;
- Compute charts and generate the personalized planner you configure;
- Store your configurations and generated files so you can return and re-download them;
- Send essential service messages (verification, password resets, and important changes to the Service or this policy);
- Keep the Service reliable, debug problems, and prevent abuse and fraud;
- Comply with legal obligations.
We will not use your birth/event data for anything beyond providing the Service to you without asking you first.
Legal bases (EEA/UK users)
Where the GDPR applies, we rely on: performance of a contract (operating your account and producing what you configure); legitimate interests (security, abuse prevention, keeping the Service working); consent (any optional processing, such as non-essential analytics or marketing, if introduced); and legal obligation (e.g. tax records for purchases).
5. How we share information
We do not sell your personal information, we do not share it for advertising, and we do not disclose it to data brokers or embed third-party advertising/tracking SDKs in the Service.
We share information only with service providers (“processors”) who help us run the Service, and only as needed:
- Hosting / infrastructure: Railway.com — stores the application database and files.
- Email delivery: Resend.com.
We may also disclose information if required by law, or to protect rights, safety, or the integrity of the Service, or in connection with a business transfer (e.g. if the Service is acquired) — in which case we will notify you and this policy will continue to apply to your data.
6. How we protect your information
- In transit: all traffic is encrypted with HTTPS/TLS.
- At rest: birth/event details are encrypted at rest in the database, so they are not readable in raw database backups.
- Passwords: stored only as salted hashes; never in plaintext.
- Access control: your profiles, configurations, and files are tied to your account and served only to you after an ownership check.
- Secrets: application secrets and provider keys are kept out of source control and rotated as needed.
No system is perfectly secure, but we take reasonable, industry-standard measures.
7. How long we keep it
- Account data and birth/event profiles: kept while your account is active. When you delete a profile, it is removed immediately. When you delete your account, your personal data is deleted immediately, except where we must retain limited records (e.g. transaction/tax records) for a legally required period.
- Generated PDFs and configurations: kept so you can re-download them, until you delete them or close your account.
- Operational logs: kept for 7 days then deleted or anonymized.
8. Your choices
- Edit a profile at any time from account settings.
- Delete your account by contacting us; this removes your personal data subject to the retention exceptions above.
- Email preferences transactional/service emails are required while you have an account; any marketing email (if introduced) will be opt-in and unsubscribable.
9. International transfers
The Service is operated from the United States, and our providers may process data in the United States and other regions used by our providers. If you access the Service from outside the United States — including from the EEA or UK — your information will be transferred to and processed in the United States. Where required for such transfers, we rely on appropriate safeguards (e.g. the Standard Contractual Clauses offered by our providers).
10. Your rights
Depending on where you live, you may have the right to: access the data we hold about you; correct it; delete it; export/port it; object to or restrict certain processing; and withdraw consent where processing is based on consent. To exercise any of these, contact us at our contact page.
If you are in the EEA/UK and believe we have mishandled your data, you may lodge a complaint with your local supervisory authority.
11. Region-specific disclosures
California (CCPA/CPRA). In the past 12 months we have collected the categories described in Section 2: identifiers (email), account credentials, and the birth/event details and outputs you create. Note that precise geolocation and inferences are treated as “sensitive personal information” under California law — we use such information only to provide the Service and do not use or disclose it for other purposes. We do not sell or “share” personal information as those terms are defined under California law. California residents may exercise the rights in Section 10, including through an authorized agent.
EEA / UK (GDPR / UK GDPR). Legal bases are described in Section 4. The data controller is David Lanier, operating from the United States. You have the rights in Section 10 and the right to complain to a supervisory authority. We welcome users from the EEA and UK; note that we do not specifically target or market to the EEA/UK, and we have not appointed an Art. 27 representative on that basis.
12. Changes to this policy
We may update this policy. If we make material changes, we will notify you (e.g. by email or an in-app notice) and update the “Last updated” date above. Continued use after changes take effect means you accept the revised policy.
13. Contact
Questions, requests, or complaints: use the contact page.