Legal · Privacy

Privacy Policy

Effective
27 July 2026
Last updated
27 July 2026
Version
1.1

This Privacy Policy explains how MAVK ANALYTICS LTD ("we", "us", "our", "Duetto") collects, uses, shares, and protects personal data when you use the Duetto service — the Telegram bot and Mini App, the Duetto iOS app, and the website at theduetto.com (together, the "Service").

The Service is operated from the United Kingdom. It is not directed at, or offered to, people in the European Economic Area: the app is not distributed in EEA App Store storefronts, we do not price it in euro, and we do not market it in the EEA. This Policy applies to users worldwide, with specific provisions for residents of the United Kingdom and California. If you are in the EEA and choose to use the Service anyway, we will still honour the rights described in § 10.

1. Who we are

Duetto is operated by MAVK ANALYTICS LTD, a private limited company registered in England and Wales.

For the purposes of the UK GDPR, MAVK ANALYTICS LTD is the data controller of your personal data.

2. Data we collect

We collect the following categories of personal data. Which ones apply depends on the platform you use.

a) Telegram account data (Telegram bot and Mini App only — received automatically when you open the Mini App):

b) iOS app account data:

c) Birth data (provided by you during onboarding):

d) Partner birth data (provided by you for synastry and composite readings):

e) Reading content (generated by us):

f) Support messages (only if you contact us in-app):

g) Payment data (when you make a purchase):

h) Usage and technical data:

i) Referral data:

3. Why we collect this data and our legal basis

PurposeCategoriesLegal basis (UK GDPR)
Authenticate you and deliver the Servicea, b, hContract (Art. 6(1)(b))
Compute your astrological chart and generate readingsc, d, eContract (Art. 6(1)(b))
Answer your support requestsfContract (Art. 6(1)(b))
Process payments and maintain purchases and subscriptionsgContract (Art. 6(1)(b))
Detect and prevent abuse of the Servicea, b, hLegitimate interest (Art. 6(1)(f))
Improve the Service, debug errors, and understand aggregate usagehLegitimate interest (Art. 6(1)(f))
Send daily transit notifications (if you enable them)a, b, c, hConsent (Art. 6(1)(a))
Operate the referral programiContract (Art. 6(1)(b))
Comply with legal obligations (e.g. tax records)gLegal obligation (Art. 6(1)(c))

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of earlier processing.

Where we rely on legitimate interest, we have balanced our interest in operating and securing the Service against your rights and freedoms. You may object to such processing — see § 10.

4. Special categories of data

Birth data (date, time, place) is not, by itself, a "special category" of personal data under the UK GDPR. We nonetheless treat it as sensitive and protect it accordingly — see § 12. We do not knowingly collect health data, racial or ethnic origin, religious beliefs, political opinions, sexual orientation, or biometric data. You should not enter such information into free-text fields. If you do, you acknowledge that you have voluntarily provided it and consent to its processing as part of your reading.

5. What we do not do

6. AI and automated processing

We use OpenAI as our AI language model provider to generate the narrative portion of your readings. The astrological calculations themselves are deterministic and performed by our own engine using the Swiss Ephemeris.

What we send the AI provider is your name and the computed positions of your chart (signs, houses, aspects). We do not send your raw date of birth, time of birth, or place of birth. For a synastry or composite reading, the same applies to the partner you entered.

We use the provider's API under data-processing terms that prohibit training their models on your data. We do not make decisions about you that produce legal or similarly significant effects through automated means.

If you object to AI processing of your data, you should not use the Service, as it is integral to delivering readings.

7. Who we share data with

We share your data with the following categories of recipients ("subprocessors"):

RecipientPurposeCountry
Telegram FZ-LLCAuthentication, message delivery, Telegram Stars paymentsUnited Arab Emirates
Apple Inc. / Apple Distribution International Ltd.App distribution, in-app purchases and subscriptions, push notification delivery (APNs), Sign in with AppleUnited States / Ireland
OpenAI, L.L.C.AI-generated reading narrativesUnited States
Railway Corp. (data hosted in Amsterdam)Application hosting and databaseNetherlands (EEA)
Functional Software, Inc. (d/b/a Sentry)Error monitoringUnited States
Cloudflare, Inc.DNS, edge network, website hosting, email routingUnited States

We do not sell your personal data. We do not share it with advertisers. We may disclose data to law enforcement or regulators if we are legally compelled (e.g. a UK production order) or to protect the rights, property, or safety of users or third parties.

8. How long we keep your data

DataRetention period
Active account data (categories a, b, c, d, e)While your account is active
Support messages (category f)24 months after we reply, or after you sent the message if we never replied
Account deletion record (platform user ID + deletion timestamp)As long as the payment records it is attached to (see below)
Payment and subscription recordsAt least seven (7) years after the transaction, to comply with UK tax and accounting law
Server logs (including IP addresses)The retention period set by our hosting and error-monitoring providers, currently up to 90 days
Analytics eventsIndividual events are deleted after six months. The daily statistics derived from them are kept indefinitely; the per-account part of those statistics is deleted together with your account
Refresh token recordsUntil expiry (up to 90 days) or until you delete your account, whichever comes first; the expired record itself is removed within a further seven days
Push notification tokensUntil you disable notifications, the token is invalidated by Apple, or you delete your account

Deletion record. When you delete your account, we remove your name, username, profile photo, birth data, partner data, reading content, and other identifying information.

What remains is a record that an account existed for your platform user ID, together with the payment and referral records attached to it. We keep it for one reason: a purchase has to stay attributable. Tax and accounting law requires us to hold payment records for seven years, a refund has to be traceable to the transaction it reverses, and the referral program has to stay consistent for the person who referred you. Legal basis: legal obligation (Art. 6(1)(c) UK GDPR) for the tax records, and contract (Art. 6(1)(b)) for the rest.

We do not use it to profile you or to limit what you can do if you sign up again. If you object to this processing on grounds relating to your particular situation, contact privacy@theduetto.com.

Backups. Our database is backed up on a rolling schedule. Data you delete stops being reachable through the Service immediately, but a copy remains inside existing backup snapshots until those snapshots expire, and we do not edit backups. The same applies to server logs held by our hosting and error-monitoring providers for the periods above.

9. International data transfers

Your core account and birth data are stored in our primary database, which is hosted within the EEA (Amsterdam, Netherlands). Some of our subprocessors are nonetheless located outside the UK and the EEA, primarily in the United States — for example, our AI provider and our error-monitoring provider. Where we transfer your personal data outside the UK/EEA, we rely on one of the following safeguards:

You may request a copy of the transfer safeguards we use by contacting privacy@theduetto.com.

10. Your rights

The UK GDPR gives you the rights below. We extend every one of them to everyone who uses the Service, wherever you live — you do not have to be in the UK to exercise them:

If you are a California resident, you have rights under the CCPA/CPRA including the right to know, delete, correct, and limit the use of sensitive personal information, and the right to non-discrimination for exercising these rights. We do not sell or "share" (as defined under the CPRA) your personal information.

To exercise any right, email privacy@theduetto.com from an email address you can verify, or use in-app self-service where available. We will respond within 30 days (or 45 days for complex requests, with notice). There is no fee for exercising your rights unless a request is manifestly unfounded or excessive.

Deleting your account removes your data as described in § 8. Note that deleting your account does not cancel an auto-renewable App Store subscription — cancel it in your Apple Account settings, as explained on our Support page.

11. Children

The Service is intended for users aged 18 and over. We do not knowingly collect data from anyone under 18. If you become aware that a person under 18 has provided us with personal data, contact privacy@theduetto.com and we will delete it.

12. Security

We use industry-standard technical and organisational measures to protect your data, including TLS encryption in transit; field-level (application-layer) encryption of the sensitive fields in your profile — your name and all birth data (date, time and place of birth, coordinates, and the computed natal chart), and the same fields for any partner you add — using authenticated encryption that supports key rotation; encryption at rest at the storage layer; access controls; and audit logging. Encryption keys are held as deployment secrets, separately from the database.

The narrative text of your readings is currently stored without that additional field-level layer, protected by storage-level encryption and access controls only. Because a reading addresses you by name, it can contain the name you entered. We are extending field-level encryption to cover reading content.

No method of transmission or storage is 100% secure; we cannot guarantee absolute security. If we become aware of a personal data breach affecting your rights, we will notify the UK ICO within 72 hours and notify you without undue delay if required by law.

13. Cookies and on-device storage

Our website at theduetto.com uses cookies — see our Cookie Policy for details and how to control them.

The Telegram Mini App and the iOS app do not use cookies for advertising or cross-site tracking. They store the following on your device so that you stay signed in and do not lose work in progress:

Inside Telegram, the Telegram client may synchronise some of these values through Telegram's own cloud storage rather than keeping them only on the device; we are changing this so that all of the above stays on your device. You can clear this data by deleting the app or the Mini App's data.

14. Changes to this Policy

We may update this Privacy Policy from time to time. We will update the "Last updated" date at the top. For material changes, we will notify you in-app or by message before the change takes effect, and where required by law we will obtain fresh consent.

15. Contact us

For any privacy question, request, or complaint:

If you are not satisfied with our response, you have the right to complain to:


This is the master English version. Translations are provided for convenience; in case of conflict, the English version prevails.