Privacy policy template
This template explains the intended data flows in the Northgleam starter. It is not legal advice and cannot be published unchanged.
Template updated July 22, 2026. Replace every placeholder and obtain jurisdiction-specific legal review before public launch.
Who controls the data
Replace this section with the legal business name, registered address, privacy contact, representative, and data-protection officer details where required. Identify the controller for account and product data and clarify whether any enterprise customer acts as controller.
Data the service processes
The starter can process account email, password hash, display name, subscription state, consent choices, birth date, birth time or uncertainty flag, birthplace, coordinates, timezone, calculated chart data, private profile labels, questions, generated readings, share metadata, usage records, fraud-prevention identifiers, support messages, and payment identifiers supplied by Stripe.
- Do not collect identity documents or unnecessary sensitive profile fields.
- Avoid full names for third-party connection profiles.
- Document every analytics or advertising tool added after launch.
Purposes and legal bases
Map each purpose to the legal basis available in the launch jurisdictions: contract for delivering the account and requested calculations; legitimate interests for proportionate security, fraud prevention, and service reliability; consent for optional marketing or nonessential cookies; and legal obligation for tax, accounting, or valid requests. Obtain counsel review before relying on legitimate interests.
AI and service providers
The intended architecture sends structured chart factors and the user’s question to OpenRouter and the selected model provider. It should avoid sending password data, payment card data, or unnecessary direct identifiers. Geoapify may receive place-search text; Stripe handles payments; Cloudflare hosts the Worker, assets, and D1 database; Turnstile handles abuse checks; and an email provider may handle transactional email. List final providers, locations, terms, transfer mechanisms, and retention before launch.
Retention and user controls
Define concrete retention periods. The starter supports account export, profile deletion, share revocation, and account deletion after active billing is canceled. Add a documented backup-deletion timeline, support-ticket retention, security-log retention, and inactive-account policy.
Rights and contact
Describe access, correction, deletion, restriction, objection, portability, consent withdrawal, and complaint rights where applicable. Provide an authenticated request flow and a monitored privacy email. Verify identity proportionately without collecting more data than necessary.
Security and limitations
Use TLS, HTTP-only secure cookies, CSRF protection, origin checks, rate limits, hashed IP identifiers, encrypted Worker secrets, restricted database access, webhook verification, dependency updates, backups, and an incident plan. No service can guarantee absolute security.
Children and changes
The starter is configured for adults and should not be marketed to children. Set and enforce the appropriate minimum age for every target market. Explain how material policy changes will be communicated and preserve the effective date.