Privacy Notice — My Cosmic Code

Last updated: 29 September 2026

My Cosmic Code is an astrology, numerology, and dream-journal app that runs almost entirely on your device. This notice explains, in plain language, exactly what the app does and does not do with your information. Every statement below is checked against the code that ships with this version. If a future version changes how data is handled, this notice changes in the same release — a privacy promise that outlives its truth is worthless.

The short version: the app has no account server, no cloud sync, and no analytics. Everything you enter is stored on your phone, and that includes anything you dictate — voice recognition is required to run on your device.


Who is responsible for this app

Controller: Krist Code Taylor, a sole proprietorship (obrt) established in Croatia, which publishes My Cosmic Code. Because the app stores data only on your own device, there is no central database of users; the "controller" designation applies to the published software and the decisions about how it processes data, not to a server holding your information.

Questions about privacy: kristcodetaylor@gmail.com

Supervisory authority: Agencija za zaštitu osobnih podataka (AZOP), Selska cesta 136, 10000 Zagreb, Croatia — azop.hr. This is the Croatian data protection authority, and it is where a complaint would be lodged. It applies because the controller is established in Croatia; if that ever changes, this section changes with it.


What information the app handles

You may choose to enter the following. All of it is optional; the core chart and numerology features are usable without providing any of it beyond your own birth date.

The app also derives values from the above (for example, your life-path number or a planet's sign). These derived values are computed on your device and stored on your device alongside the inputs.

Where this information lives

All of it is stored only on your device, in the app's private storage (AsyncStorage, protected by your operating system's app sandbox). For transparency, here is the complete list of on-device storage keys and what each holds:

Storage keyWhat it holds
mcc.profile.v1Your own birth data
mcc.journal.v1Your journal entries
mcc.account.v1Optional local account: email + a locally-computed password check value (see The optional local account)
mcc.session.v1Whether you're currently signed in to the local account (no personal data itself)
mcc.compatibility.partner.v1A partner's birth data, if you've added one
mcc.futureview.saves.v1Any Future View readings you've chosen to save
mcc.deck.readings.v1Any Deck readings you've chosen to save
mcc.reminder.v1Your local reminder time and whether it's on
mcc.locale.v1Your language choice
mcc.recentSearches.v1Text you've typed into in-app search, kept so you can see your own recent searches
mcc.lastExport.v1The timestamp of your last export, nothing else
mcc.identSeen.v1, mcc.tutorialSeen.v1, mcc.ambientMuted.v1Interface flags — not personal data

What is transmitted off your device

Nothing, for everything above, with two narrow, explained exceptions. This app has no account server, no cloud sync, no backup service, no crash reporting, no analytics, no advertising, and no third-party SDK that phones home on your birth data, journal text, account, partner data, or saved readings. There is no code in the app that sends any of that anywhere.

The two exceptions:

Voice dictation

If you tap the microphone in the journal capture sheet, the app uses your operating system's built-in speech-recognition service to turn your speech into text — the same service any keyboard's dictation button would use. The app is configured to prefer Android's Google-provided recognition service.

Since 5 August 2026 the app requires this to run strictly on your device. Every time it starts listening it demands on-device recognition, so your voice is not sent to Google or to anyone else for transcription. The transcript is then handled exactly like typed text: stored only in your journal, on your device, nowhere else.

The honest cost of that choice: if your phone has no offline language pack for your language, dictation will not work, and the app tells you so. It does not quietly fall back to sending your voice to a server. Since 5 August 2026 the app also offers to download that pack for you — Android fetches it, and dictation then runs entirely on your phone. You can still install it yourself in Android's speech settings, or type instead.

One exception, only with your yes (since 28 September 2026). Some languages have no offline model on some phones at all — Croatian on current Android phones is the known case — so there is nothing to download. For such a language only, the app asks you, in the capture sheet, whether your voice may go to Google's speech-recognition service so it can be written down. Only after you tap Allow and speak does it do so, and only while Speak is listening. The audio goes from your phone's speech service to Google, not to us: we never receive, see or store the recording, and the transcript stays in your journal on your device like typed text. Google processes the audio under its own privacy policy. You can withdraw that permission at any time with Stop allowing in the same sheet; languages your phone can transcribe offline never take this path.

The app asks your device which packs it actually has before it starts listening, and only ever falls back between regions of the same language (for example Croatian as spoken in Bosnia). It will not transcribe one language with another language's recogniser, because that does not fail — it silently produces nonsense.

Before 5 August 2026 this was not forced, and on some phones Android's speech service may have sent dictated audio to Google for transcription — the same way its keyboard dictation does. Nothing else in the app ever transmitted anything, and any resulting transcripts stayed in your journal on your device.

Someone else's data

If you use Compatibility, you provide a second person's birth data. That person is not a user of this app and has not agreed to this notice themselves. That data is stored on your device only, in the same way your own data is, and is never transmitted. If you enter another person's data, you are responsible for having a lawful basis to do so (for example, their consent, or a legitimate personal/household-activity basis) — the app has no way to verify this and stores whatever you enter.


The optional local account

Registering does not create a real, cross-device account. There is no server to verify a credential against. The email and password you enter are checked only against a copy stored on this device (mcc.account.v1), and the password is protected by a fast, non-cryptographic check value — good enough that it isn't stored as plain text, not the kind of protection a real backend account uses (which would use a proper cryptographic hash such as bcrypt or argon2). "Forgot password" does not send an email — there is no mail server — it simply lets you reset the locally-stored value after re-entering the same email. Treat this account the same way you'd treat any other data on an unlocked phone: it protects against casual access, not against someone who has your unlocked device or a copy of its storage.


No third parties, no advertising, no tracking


Legal basis (GDPR)

For users in the European Economic Area, we note the following under the General Data Protection Regulation:

Because processing happens on your device, much of the GDPR's machinery around transfers, processors, and breach notification has limited subject matter here. See the internal Record of Processing Activities for how this is tracked.


How long information is kept

Until you delete it. There is no server-side copy and no automatic expiry. Your data remains in the app's private storage until you remove it in-app or uninstall the app, which removes all of the app's on-device storage.


Your rights and how to exercise them

All of these are available directly in the app, free, with no account required and no gate:

Because there is no account server, you do not need to contact anyone to exercise these rights, and there is no identity-verification step: the data is already, and only, in your hands.


Children

My Cosmic Code is not directed to children. It is intended for users aged 16 and older — which is also the age of digital consent under GDPR Article 8 in Croatia, where the controller is established. We do not knowingly collect information from children — and, structurally, we do not collect information from anyone on any server.

Since 5 August 2026 setup asks and refuses: the birth date you enter for your chart is checked, and if it puts you under 16 the app does not continue. No separate age question is asked, because your birth date already answers it.

Be clear about what that gate is and is not. It is an honest check, not a verification: nothing stops someone from typing a different year, and we do not attempt to detect that. It means the app asks rather than looking away. Please also do not let a child enter another person's data via Compatibility without a parent or guardian's involvement.


Security

Your information is protected by your device's operating-system app sandbox, which keeps one app's private storage from being read by other apps, and by any device-level protection you have enabled (passcode, biometrics, disk encryption). See the internal Security Policy for the technical detail behind this notice's claims.

The strongest security property of this app is architectural: for the data covered by the "nothing transmitted" section above, there is no server to breach. Data that never leaves your device cannot be intercepted in transit or exposed in a company data breach, because there is no transit and no company database for that data.


Changes to this notice

If the app changes in a way that affects privacy — most importantly, if any future version adds cloud sync, a real account server, or any new server-side processing — this notice will be updated in the same release that introduces the change, and the "Last updated" date above will change. Material changes will be reflected in the app's in-app privacy screen as well. Continuing to use a version whose notice has changed constitutes acknowledgement of the updated notice for that version.


Contact

kristcodetaylor@gmail.com. This is the only channel needed for most requests; there is no central account system, so there is no login help or password-reset queue to route beyond what's already available in-app.