Privacy Policy
Summary (plain English)
- We make Numeea, a numerology app. We are a company registered in Romania (full legal details in Section 1).
- To create your reading we collect your name, email, and date of birth, and, if you use the compatibility feature, the name and date of birth of the other person you enter.
- We use Google Gemini (and, as a fallback, OpenAI) to generate your readings. We send them your first name, date of birth, and numerology numbers, never your email. We use these providers' paid API tiers, which do not use your inputs or the generated readings to train or improve their models (see Section 6).
- Subscriptions and purchases are handled by Apple and Google through Adapty. We never see or store your card details.
- We use PostHog (hosted in the EU) for privacy-friendly product analytics. We do not show ads, we do not use advertising identifiers, and we do not sell your data.
- Our servers run on AWS in the United States; our analytics stay in the EU. Where data leaves the EU we rely on Standard Contractual Clauses and the EU–US Data Privacy Framework.
- You can access, correct, export, or delete your account and data at any time. Email support@numeea.com.
- Questions or complaints: support@numeea.com, or your local data protection authority.
This summary is for convenience only; the full policy below governs.
1. Who we are
Numeea is operated by:
Dreamcraft S.R.L.
Str. A. Vlahuță, Cluj-Napoca 400310, Romania
VAT / CUI: 34467389
Email: support@numeea.com
We are the data controller for the personal data described in this policy. We are not required to appoint a Data Protection Officer, but you can reach our privacy team at the email above for any request.
2. Scope
This policy covers the Numeea mobile apps for iOS and Android and the numeea.com website that hosts our legal documents. It explains what we collect, why, who we share it with, how long we keep it, and the rights you have.
By using Numeea you confirm you are at least 16 years old. Numeea is not directed at children and we do not knowingly collect data from anyone under 16 (see Section 11).
3. What we collect
We only collect what we need to run the app. We do not collect your location, contacts, photos, camera, microphone, phone number, or any advertising identifier.
3.1 Data you provide
| Data | When | Why |
|---|---|---|
| First name, last name | Onboarding profile | Personalise your readings |
| Date of birth | Onboarding profile | Core input for numerology calculations |
| Email address | Sign-in (from your Google/Apple account) | Account identity, account recovery, service messages |
| Other person's first name, last name, date of birth | When you create a compatibility reading | Generate the compatibility result you requested |
About compatibility data: when you enter another person's details, you confirm you have a lawful basis to do so (for example, their consent, or that you are simply comparing yourself with a public figure or acquaintance). We use these details only to produce the reading you asked for and to cache that specific result.
3.2 Data from your sign-in provider
You sign in with Google (Android and iOS) or Apple (iOS). Your provider gives us:
- your email address and name, and
- a unique provider account ID, which we immediately convert to an irreversible SHA-256 hash and use as your internal user ID. We do not store the raw provider ID.
The app may momentarily receive your provider display name and profile picture to show during sign-in, but these are not sent to or stored on our servers.
3.3 Purchase and subscription data
When you subscribe or make a one-time purchase, Apple or Google processes the payment and Adapty relays the transaction to us. We receive and store:
- product ID, transaction IDs, store (Apple/Google), purchase and expiry dates,
- price and currency, your country code, and net proceeds.
We never receive your full card number or bank details: those stay with Apple and Google.
3.4 Content we generate
We store the numerology readings we generate for you (daily readings, compatibility results) so we can show them again and support offline access.
3.5 Usage analytics
We use PostHog to understand how the app is used and to improve it. Analytics events include:
- event names (e.g. "opened daily reading"), your hashed user ID, platform (iOS/Android), subscription status/plan, and connectivity state.
- For compatibility, only true/false flags (e.g. "partner name provided"), never the actual partner values.
We have disabled session replay and screen-content auto-capture in PostHog. We do not send your email, name, or date of birth to analytics. You can turn analytics off at any time in the app's settings.
3.6 Technical data
Standard technical data needed to deliver an internet service, such as IP address and connection metadata, is processed transiently by our hosting and security providers (AWS, Cloudflare) to route traffic, secure the service, and prevent abuse. We do not maintain IP addresses as part of your user profile.
4. Notifications
Numeea can show local daily-reminder notifications generated on your device. These are scheduled locally. We do not operate a push-notification server and do not use Firebase Cloud Messaging. You can turn notifications off at any time in your device settings.
5. Why we use your data and our legal bases (GDPR)
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and run your account | Name, email, hashed user ID | Contract (6(1)(b)) |
| Generate numerology and compatibility readings | Name, date of birth, partner details | Contract (6(1)(b)) |
| Process subscriptions and purchases | Purchase/transaction data | Contract (6(1)(b)) |
| Keep financial and tax records | Purchase data | Legal obligation (6(1)(c)) |
| Product analytics and improvement | Usage events, hashed user ID | Legitimate interests (6(1)(f)), to improve the app |
| Security, fraud and abuse prevention | Technical data, IP | Legitimate interests (6(1)(f)) |
| Local reminder notifications | Device notification permission | Consent (6(1)(a)), your OS-level permission |
Where we rely on legitimate interests, we have weighed them against your rights; you can object at any time (Section 9). Where we rely on consent, you can withdraw it at any time without affecting prior processing.
6. Who we share data with (sub-processors)
We do not sell your personal data and do not share it for cross-context behavioural advertising. We share data only with the service providers needed to run Numeea:
| Provider | Purpose | Data shared | Location |
|---|---|---|---|
| Google (Gemini AI) | Generate readings | First name, date of birth, numerology numbers (and both people's name + DOB for compatibility). Not email. | EU / US |
| OpenAI | Fallback AI generation (used only if the primary provider is unavailable) | Same as above | US |
| Adapty | Subscription management | Hashed user ID, transaction and purchase data | US |
| Apple / Google | App stores, payment processing, sign-in | Purchase data, authentication tokens | Global |
| PostHog | Product analytics | Event names, hashed user ID, non-identifying properties | EU |
| Amazon Web Services (AWS) | Cloud hosting and database | All stored account and content data | US (us-east-1) |
| Cloudflare | DNS, CDN, bot/abuse protection | Connection metadata, IP | Global |
Each provider processes data under a data-processing agreement and only on our instructions (except Apple and Google, which act as independent controllers for payment and store functions under their own policies).
AI providers and your inputs
To generate your readings we send your first name, date of birth, and numerology numbers (and, for a compatibility reading, the other person's first name, last name, and date of birth) to Google (Gemini) and, as a fallback, OpenAI. We do not send your email.
- Purpose and legal basis: generating the content you request: performance of our contract with you (GDPR Art. 6(1)(b)).
- Retention: the generated reading is stored in your account as described in Section 8; we do not maintain a separate copy of your inputs at the AI provider beyond what is needed to return the reading.
- Training: we use these providers' paid API tiers, whose terms state that your inputs and the generated responses are not used to train or improve their models. A provider may retain inputs for a limited period only to detect abuse and keep the service secure. If you do not want your inputs processed by these providers, do not use the AI features.
- Transparency: where content is AI-generated, the app indicates this, so you know you are viewing automated output.
Provider processing may take place in the EU or the United States (see Section 7).
7. International data transfers
Numeea is offered worldwide. Some providers process data outside the EU/EEA, principally in the United States:
- Our core database and servers run on AWS in the United States (us-east-1).
- Adapty and OpenAI are US-based.
- PostHog analytics are hosted in the EU.
For transfers outside the EU/EEA we rely on the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework, together with additional safeguards. You can request a copy of the relevant safeguards at support@numeea.com.
8. How long we keep data
| Data | Retention |
|---|---|
| Account data (name, email, DOB) and compatibility results | While your account is active; deleted when you delete your account |
| Daily readings | Up to 48 hours on our servers, then automatically deleted; a copy may remain in your device's local cache for offline access |
| Purchase/subscription records | 10 years, to meet Romanian accounting and tax law |
| Raw subscription webhook events | 60 days after processing, then automatically deleted |
| Database backups | 7 days rolling |
| Sign-in sessions / refresh tokens | Until expiry or sign-out |
| Analytics events | 90 days, then automatically deleted |
Deleting your account deletes your data. You can delete your account at any time, in the app or by emailing support@numeea.com. When you do, we permanently erase your personal data, your profile (name, email, date of birth), your readings, your sessions, and your purchase and subscription records, by cascading deletion across our database. The only exceptions are: (a) records we are legally required to retain (for example, for tax and accounting law); (b) copies in routine backups, which are overwritten within 7 days; and (c) anonymised or aggregate analytics that can no longer identify you.
9. Your rights
Depending on where you live, you have some or all of these rights:
Everyone / GDPR (EU/EEA):
- Access: get a copy of your data.
- Rectification: correct inaccurate data (you can edit your profile in the app).
- Erasure: delete your account and data.
- Restriction and Objection: limit or object to certain processing (including legitimate-interest analytics).
- Portability / data export: receive a copy of your data in a portable format; request an export by emailing support@numeea.com.
- Withdraw consent: e.g. turn off notifications.
- Complain to a supervisory authority: in Romania, the National Supervisory Authority for Personal Data Processing (ANSPDCP), or the authority where you live.
California (CCPA/CPRA):
- Know / access the categories and specific pieces of personal information we collect.
- Delete your personal information.
- Correct inaccurate personal information.
- Opt out of sale/sharing: we do not sell or share personal information for cross-context behavioural advertising, so there is nothing to opt out of.
- Non-discrimination for exercising your rights.
How to exercise them: you can edit your profile in the app, and you can delete your account, request a copy/export of your data, or make any other request by emailing support@numeea.com. All GDPR data-export and data-subject requests are handled via this email. We will respond within the timeframes required by law (generally 30 days under GDPR, 45 days under CCPA). We may need to verify your identity first.
10. Security
We protect your data with:
- Encryption in transit (HTTPS/TLS 1.2–1.3) between the app and our servers,
- Encryption at rest for our database (AWS-managed KMS),
- Hashing of provider IDs and session refresh tokens,
- private network isolation, IAM-based database authentication, and secret management.
No system is perfectly secure, but we work to protect your data using industry-standard measures.
11. Children
Numeea is intended for users aged 16 and over. We do not knowingly collect personal data from children under 16. If you believe a child has provided us data, contact support@numeea.com and we will delete it.
12. The website and cookies
numeea.com is a static marketing and legal site hosted on Cloudflare. It does not require an account. It uses the following cookies and similar technologies:
- Strictly necessary: Cloudflare may set security and performance cookies to protect and deliver the site. These do not require consent.
- Analytics: Google Analytics 4 (measurement ID
G-EZRM73931T). Google Analytics sets first-party cookies (_ga,_ga_<id>) and sends usage data, including a truncated IP address, to Google, so we can measure website traffic. Google processes this data under its own privacy policy. - Fonts: the site's fonts are self-hosted on our own servers; loading the site makes no font request to Google or any other third party.
A banner notifies you about cookie use on your first visit. You can block or delete cookies in your browser settings, and you can opt out of Google Analytics with Google's opt-out browser add-on (https://tools.google.com/dlpage/gaoptout).
We do not run advertising or cross-site behavioural-advertising cookies on the website. The app itself (as opposed to the website) uses no cookies.
13. Changes to this policy
We may update this policy. We will change the effective date and version at the top and, for material changes, provide a more prominent notice in the app. Continued use after an update means you accept the revised policy.
14. Contact
Please send all inquiries (questions, support, privacy and data-protection requests, and complaints) to us by email. This is also the address for GDPR data-subject requests (access, correction, deletion, portability, objection); we respond within the timeframes required by law (generally within 30 days for GDPR requests, and within 45 days under CCPA).
support@numeea.com
Our full legal name, registered address, and VAT number are in Section 1.
You also have the right to lodge a complaint with the Romanian ANSPDCP (www.dataprotection.ro) or your local supervisory authority.