Privacy Policy
Last updated: 2026-09-04
1. Who is responsible
The data controller for personal data processed by Almugea is Fábio Miguel Rodrigues Barbosa, Rua Miguel Bombarda 35, 2590-035 Sobral de Monte Agraço, Portugal. Privacy contact: support@almugea.com. This policy covers almugea.com and app.almugea.com.
2. The short version
- With a free account, your chart data never leaves your browser. Charts and settings live in your device's local storage; on our servers we keep only your account data.
- Pro (and trial) accounts can sync charts to our servers — where chart data is encrypted at rest so that not even a database administrator can read it.
- Payment data goes to Sold through Link, LLC (Stripe), the merchant of record — we never see card numbers.
- Everything is hosted in the European Union. Our analytics are self-hosted and cookieless.
- Marketing email is strictly opt-in.
3. What we collect, why, and on what legal basis
Free accounts. A free account's charts, settings, and session are stored only in your browser (localStorage and IndexedDB) and stay on your device; the only server-side data we hold for a free account is the account data below.
Account data — email address, display name, password (stored as a hash), interface language, and, if you enable it, two-factor-authentication secrets and backup codes. Purpose: creating and securing your account, signing you in, sending you essential service email. Legal basis: performance of a contract; security measures rest on our legitimate interest in protecting the Service.
Chart data — the charts you sync to your account (available during the trial and with Pro), including birth data (name, date, exact time, and place — of you or of the people whose charts you cast), chart notes, and your settings. Purpose: cloud storage and synchronisation across your devices. Legal basis: performance of a contract. Chart rows, notes, and settings are stored as AES-256-GCM ciphertext, sealed under a key held only by the running application — a database administrator sees account names, emails, and timestamps, never birth data.
Subscription data — your plan, subscription status, period dates, and the Stripe customer and subscription identifiers. Purpose: granting the features you paid for. Legal basis: performance of a contract. We never receive or store card numbers or bank details.
Marketing consent — whether you ticked the (unticked by default) newsletter checkbox, and when. Newsletters are sent only while consent stands; you can withdraw at any time in your account page or via the unsubscribe link in every message. Legal basis: consent.
Technical data — IP addresses appear transiently in server logs and in rate-limiting counters that protect the Service from abuse; logs rotate automatically. Legal basis: legitimate interest in security and abuse prevention.
Analytics — we run a self-hosted Plausible instance on our own server in Finland (EU). It is cookieless, collects aggregate page statistics only, and never tracks you across sites. Legal basis: legitimate interest in understanding aggregate usage.
After account deletion — we retain a SHA-256 hash of the deleted account's email address (pseudonymous — it cannot be read back as an address, but the same address hashes to the same value). Purpose: preventing repeated free trials through delete-and-re-sign-up. Legal basis: legitimate interest in preventing abuse of the trial. This hash is the only thing that survives erasure.
4. Who receives data
- Stripe — Sold through Link, LLC (United States), an affiliate of Stripe, sells you the Pro plan as merchant of record and processes your payment as an independent controller under Stripe's privacy policy. The checkout at checkout.stripe.com and the Link account at link.com may set their own cookies under that policy.
- Hetzner (Germany/Finland): hosts our servers and encrypted backups. All application data resides in the EU.
- Mailgun (EU region): delivers our transactional and, with consent, marketing email; message data is processed in the EU.
- UptimeRobot: checks whether the public site is up; it processes no user data.
- Professional advisers or public authorities, where the law requires it.
We sell data to no one.
5. International transfers
Application data is stored and processed in the European Union. Stripe processes payment data in the United States under the EU-U.S. Data Privacy Framework and the European Commission's standard contractual clauses.
6. Retention
- Account, chart, and subscription data: for as long as the account exists.
- On account deletion: server-side data is removed immediately; encrypted backups rotate out on a fixed schedule (roughly three months at most), after which no copy exists.
- The pseudonymous email hash described above: retained after deletion.
- Server logs: rotate automatically after a short period.
- Data in your own browser (local charts and settings) is yours and is never deleted by us — deleting your account does not touch it.
7. Your rights
Under the GDPR (and the Brazilian LGPD, which we honour equivalently) you have the right to access, rectify, erase, restrict, object, and to data portability, and to withdraw consent at any time. Two of these are self-serve in your account page: export your library as JSON, and delete your account. For anything else write to support@almugea.com; we answer within one month. You may complain to the Portuguese supervisory authority, the CNPD (cnpd.pt), or to your local data-protection authority — in Brazil, the ANPD.
8. Security
TLS everywhere; application-level encryption of chart data at rest (AES-256-GCM); passwords stored only as hashes; optional two-factor authentication; access controls and rate limiting; nightly backups encrypted before they leave the server, stored in the EU.
9. Cookies and local storage
We use only strictly necessary cookies — no advertising or third-party analytics cookies, so no cookie banner:
| Purpose | What it is | Lifetime |
|---|---|---|
| Session | Keeps you signed in (essential) | Session/limited |
| Language | Remembers your interface language | Persistent |
| Trusted device | Skips the 2FA prompt on a device you marked as trusted (essential, only if you use it) | 30 days |
The app also uses localStorage and IndexedDB to keep your charts and settings on your device — that is where a free account's chart data lives, and it never reaches our servers. Stripe's checkout may set its own cookies (§ 4). You can clear all of this through your browser settings; note that clearing IndexedDB deletes locally-stored charts.
10. Children
The Service is not directed at children under 16 and we do not knowingly open accounts for them.
11. Changes
We will announce material changes to this policy on the site or by email. The English text prevails; Portuguese translations are provided for convenience.