This Privacy Policy explains how MAVK ANALYTICS LTD ("we", "us", "our", "Duetto") collects, uses, shares, and protects personal data when you use the Duetto service — the Telegram bot and Mini App, the Duetto iOS app, and the website at theduetto.com (together, the "Service").
The Service is operated from the United Kingdom. It is not directed at, or offered to, people in the European Economic Area: the app is not distributed in EEA App Store storefronts, we do not price it in euro, and we do not market it in the EEA. This Policy applies to users worldwide, with specific provisions for residents of the United Kingdom and California. If you are in the EEA and choose to use the Service anyway, we will still honour the rights described in § 10.
1. Who we are
Duetto is operated by MAVK ANALYTICS LTD, a private limited company registered in England and Wales.
- Company number: 17024096
- Registered office: 20 Wenlock Road, London, England, N1 7GU
- ICO data protection register reference: ZC186644
- Privacy contact: privacy@theduetto.com
- General contact: support@theduetto.com
For the purposes of the UK GDPR, MAVK ANALYTICS LTD is the data controller of your personal data.
2. Data we collect
We collect the following categories of personal data. Which ones apply depends on the platform you use.
a) Telegram account data (Telegram bot and Mini App only — received automatically when you open the Mini App):
- Telegram numerical user ID (
tg_id) - Username (if set on your Telegram account)
- First name and last name (as shown on your Telegram account)
- Profile photo URL
- Telegram language code (used to set your initial Duetto locale)
b) iOS app account data:
- A device identifier generated by the app itself (a random value stored in the device keychain). We use it to recognise your guest account. It is not Apple's advertising identifier (IDFA) and we do not request one.
- If you use Sign in with Apple (where the app offers it): the Apple-issued user identifier. We do not store the name or email address Apple may pass along at sign-in.
- Push notification token (APNs), if you enable notifications
c) Birth data (provided by you during onboarding):
- Your name (free-text, you choose)
- Date of birth
- Time of birth (optional)
- Place of birth (city label and geographic coordinates resolved from your selection)
- Time zone of birth (derived from coordinates)
- A record of previous values, if you later correct your birth date or time. We keep it to detect abuse of the correction limit described in § 10; it is encrypted like the rest of your birth data.
d) Partner birth data (provided by you for synastry and composite readings):
- Same fields as above, for any partner you create
e) Reading content (generated by us):
- Astrological calculations performed by our deterministic engine (Swiss Ephemeris)
- Narrative text generated by an AI language model based on your data
- Reading metadata (type, timestamp, locale)
- If you create a share link for a reading, the link identifier and a count of how many times it has been opened. A share link is public by design: anyone who has it can read that reading without signing in.
f) Support messages (only if you contact us in-app):
- The free-text message you send, our reply, and the timestamps. Please do not put health information or other sensitive details into a support message.
g) Payment data (when you make a purchase):
- Telegram Stars: the payment record Telegram sends us — charge ID, amount in Stars, product code, currency, timestamp, and the rest of the payload Telegram includes with it. We store that payload as received.
- Apple App Store: the App Store transaction identifier, original transaction identifier, product identifier, and subscription status, received from Apple's servers so we can grant and maintain your entitlement.
- In neither case do we receive your payment card or bank details.
h) Usage and technical data:
- Product analytics events (e.g. "reading_started", "paywall_viewed") with timestamps, platform (telegram / ios / web), and feature. These events are linked to your account, so they are pseudonymous rather than anonymous.
- The IANA time zone reported by your device, used to send daily notifications at the right local hour
- Activity timestamps used to run the product — when you last opened the app, when you completed onboarding, when you first purchased, and similar
- IP address, used as a short-lived counter to rate-limit sign-in and other endpoints, and recorded in our server logs
- Session identifiers: a hash of your refresh token is stored so sessions can be revoked. Access tokens are short-lived and are not stored.
- Error diagnostics (crash and exception reports)
i) Referral data:
- Your unique referral code (assigned automatically)
- The referral code, if any, you used to sign up
- Aggregate counts of users you have referred
3. Why we collect this data and our legal basis
| Purpose | Categories | Legal basis (UK GDPR) |
|---|---|---|
| Authenticate you and deliver the Service | a, b, h | Contract (Art. 6(1)(b)) |
| Compute your astrological chart and generate readings | c, d, e | Contract (Art. 6(1)(b)) |
| Answer your support requests | f | Contract (Art. 6(1)(b)) |
| Process payments and maintain purchases and subscriptions | g | Contract (Art. 6(1)(b)) |
| Detect and prevent abuse of the Service | a, b, h | Legitimate interest (Art. 6(1)(f)) |
| Improve the Service, debug errors, and understand aggregate usage | h | Legitimate interest (Art. 6(1)(f)) |
| Send daily transit notifications (if you enable them) | a, b, c, h | Consent (Art. 6(1)(a)) |
| Operate the referral program | i | Contract (Art. 6(1)(b)) |
| Comply with legal obligations (e.g. tax records) | g | Legal obligation (Art. 6(1)(c)) |
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of earlier processing.
Where we rely on legitimate interest, we have balanced our interest in operating and securing the Service against your rights and freedoms. You may object to such processing — see § 10.
4. Special categories of data
Birth data (date, time, place) is not, by itself, a "special category" of personal data under the UK GDPR. We nonetheless treat it as sensitive and protect it accordingly — see § 12. We do not knowingly collect health data, racial or ethnic origin, religious beliefs, political opinions, sexual orientation, or biometric data. You should not enter such information into free-text fields. If you do, you acknowledge that you have voluntarily provided it and consent to its processing as part of your reading.
5. What we do not do
- We do not track you across other companies' apps or websites.
- We do not use Apple's advertising identifier (IDFA), and the app does not present an App Tracking Transparency prompt because it does not track.
- We do not use advertising, retargeting, or marketing SDKs.
- We do not sell or "share" (as defined under the CPRA) your personal data.
- We do not allow our AI provider to train models on your data.
6. AI and automated processing
We use OpenAI as our AI language model provider to generate the narrative portion of your readings. The astrological calculations themselves are deterministic and performed by our own engine using the Swiss Ephemeris.
What we send the AI provider is your name and the computed positions of your chart (signs, houses, aspects). We do not send your raw date of birth, time of birth, or place of birth. For a synastry or composite reading, the same applies to the partner you entered.
We use the provider's API under data-processing terms that prohibit training their models on your data. We do not make decisions about you that produce legal or similarly significant effects through automated means.
If you object to AI processing of your data, you should not use the Service, as it is integral to delivering readings.
7. Who we share data with
We share your data with the following categories of recipients ("subprocessors"):
| Recipient | Purpose | Country |
|---|---|---|
| Telegram FZ-LLC | Authentication, message delivery, Telegram Stars payments | United Arab Emirates |
| Apple Inc. / Apple Distribution International Ltd. | App distribution, in-app purchases and subscriptions, push notification delivery (APNs), Sign in with Apple | United States / Ireland |
| OpenAI, L.L.C. | AI-generated reading narratives | United States |
| Railway Corp. (data hosted in Amsterdam) | Application hosting and database | Netherlands (EEA) |
| Functional Software, Inc. (d/b/a Sentry) | Error monitoring | United States |
| Cloudflare, Inc. | DNS, edge network, website hosting, email routing | United States |
We do not sell your personal data. We do not share it with advertisers. We may disclose data to law enforcement or regulators if we are legally compelled (e.g. a UK production order) or to protect the rights, property, or safety of users or third parties.
8. How long we keep your data
| Data | Retention period |
|---|---|
| Active account data (categories a, b, c, d, e) | While your account is active |
| Support messages (category f) | 24 months after we reply, or after you sent the message if we never replied |
| Account deletion record (platform user ID + deletion timestamp) | As long as the payment records it is attached to (see below) |
| Payment and subscription records | At least seven (7) years after the transaction, to comply with UK tax and accounting law |
| Server logs (including IP addresses) | The retention period set by our hosting and error-monitoring providers, currently up to 90 days |
| Analytics events | Individual events are deleted after six months. The daily statistics derived from them are kept indefinitely; the per-account part of those statistics is deleted together with your account |
| Refresh token records | Until expiry (up to 90 days) or until you delete your account, whichever comes first; the expired record itself is removed within a further seven days |
| Push notification tokens | Until you disable notifications, the token is invalidated by Apple, or you delete your account |
Deletion record. When you delete your account, we remove your name, username, profile photo, birth data, partner data, reading content, and other identifying information.
What remains is a record that an account existed for your platform user ID, together with the payment and referral records attached to it. We keep it for one reason: a purchase has to stay attributable. Tax and accounting law requires us to hold payment records for seven years, a refund has to be traceable to the transaction it reverses, and the referral program has to stay consistent for the person who referred you. Legal basis: legal obligation (Art. 6(1)(c) UK GDPR) for the tax records, and contract (Art. 6(1)(b)) for the rest.
We do not use it to profile you or to limit what you can do if you sign up again. If you object to this processing on grounds relating to your particular situation, contact privacy@theduetto.com.
Backups. Our database is backed up on a rolling schedule. Data you delete stops being reachable through the Service immediately, but a copy remains inside existing backup snapshots until those snapshots expire, and we do not edit backups. The same applies to server logs held by our hosting and error-monitoring providers for the periods above.
9. International data transfers
Your core account and birth data are stored in our primary database, which is hosted within the EEA (Amsterdam, Netherlands). Some of our subprocessors are nonetheless located outside the UK and the EEA, primarily in the United States — for example, our AI provider and our error-monitoring provider. Where we transfer your personal data outside the UK/EEA, we rely on one of the following safeguards:
- UK International Data Transfer Agreement / EU Standard Contractual Clauses signed with the recipient
- UK Extension to the EU-US Data Privacy Framework where applicable (e.g. recipients certified under the DPF)
- Adequacy decisions of the UK Government or European Commission for certain countries
You may request a copy of the transfer safeguards we use by contacting privacy@theduetto.com.
10. Your rights
The UK GDPR gives you the rights below. We extend every one of them to everyone who uses the Service, wherever you live — you do not have to be in the UK to exercise them:
- Access the personal data we hold about you and receive a copy
- Rectify inaccurate or incomplete data (also available in-app via the profile editor). To stop abuse of the free tier, the app allows a limited number of changes to your birth data per calendar month; if you hit that limit and still need a correction, email privacy@theduetto.com and we will make it for you.
- Erase your data ("right to be forgotten") — also available in-app via "Delete account"
- Restrict processing in certain circumstances
- Data portability — receive your data in a structured, machine-readable format
- Object to processing based on legitimate interest
- Withdraw consent for any processing based on consent (e.g. daily transit notifications)
- Lodge a complaint with the UK Information Commissioner's Office (ico.org.uk), our supervisory authority. If you live elsewhere, your national data-protection authority may also accept a complaint.
If you are a California resident, you have rights under the CCPA/CPRA including the right to know, delete, correct, and limit the use of sensitive personal information, and the right to non-discrimination for exercising these rights. We do not sell or "share" (as defined under the CPRA) your personal information.
To exercise any right, email privacy@theduetto.com from an email address you can verify, or use in-app self-service where available. We will respond within 30 days (or 45 days for complex requests, with notice). There is no fee for exercising your rights unless a request is manifestly unfounded or excessive.
Deleting your account removes your data as described in § 8. Note that deleting your account does not cancel an auto-renewable App Store subscription — cancel it in your Apple Account settings, as explained on our Support page.
11. Children
The Service is intended for users aged 18 and over. We do not knowingly collect data from anyone under 18. If you become aware that a person under 18 has provided us with personal data, contact privacy@theduetto.com and we will delete it.
12. Security
We use industry-standard technical and organisational measures to protect your data, including TLS encryption in transit; field-level (application-layer) encryption of the sensitive fields in your profile — your name and all birth data (date, time and place of birth, coordinates, and the computed natal chart), and the same fields for any partner you add — using authenticated encryption that supports key rotation; encryption at rest at the storage layer; access controls; and audit logging. Encryption keys are held as deployment secrets, separately from the database.
The narrative text of your readings is currently stored without that additional field-level layer, protected by storage-level encryption and access controls only. Because a reading addresses you by name, it can contain the name you entered. We are extending field-level encryption to cover reading content.
No method of transmission or storage is 100% secure; we cannot guarantee absolute security. If we become aware of a personal data breach affecting your rights, we will notify the UK ICO within 72 hours and notify you without undue delay if required by law.
13. Cookies and on-device storage
Our website at theduetto.com uses cookies — see our Cookie Policy for details and how to control them.
The Telegram Mini App and the iOS app do not use cookies for advertising or cross-site tracking. They store the following on your device so that you stay signed in and do not lose work in progress:
- your session token, and on iOS the device identifier, in the device keychain
- the onboarding draft — the name, birth date, birth time, and birth city you have entered but not yet submitted
- the partner draft you are filling in for a synastry reading
- interface preferences and the identifier of your most recent natal reading
Inside Telegram, the Telegram client may synchronise some of these values through Telegram's own cloud storage rather than keeping them only on the device; we are changing this so that all of the above stays on your device. You can clear this data by deleting the app or the Mini App's data.
14. Changes to this Policy
We may update this Privacy Policy from time to time. We will update the "Last updated" date at the top. For material changes, we will notify you in-app or by message before the change takes effect, and where required by law we will obtain fresh consent.
15. Contact us
For any privacy question, request, or complaint:
- Email: privacy@theduetto.com
- Postal: MAVK ANALYTICS LTD, 20 Wenlock Road, London, England, N1 7GU
If you are not satisfied with our response, you have the right to complain to:
- Our supervisory authority: the UK Information Commissioner's Office (ICO) — ico.org.uk — 0303 123 1113
- Elsewhere: your national data-protection authority may also accept a complaint
- California: California Privacy Protection Agency — cppa.ca.gov
This is the master English version. Translations are provided for convenience; in case of conflict, the English version prevails.