Stellingo
Stellingo

Privacy policy

Stellingo is built to collect as little about you as it can. You can use the whole sky without an account, we don't use advertising or tracking cookies, and we don't sell or share your data. This page says exactly what we keep, why, and what you can do about it.

Who we are

Stellingo (stellingo.com) is responsible for your personal data ("controller" under the EU General Data Protection Regulation, GDPR). You can reach us at groundcontrol@stellingo.com about anything on this page.

Using Stellingo without an account

Your location, your settings and the places you save stay in your browser (its local storage). They are not sent to us. Your location is used on your device to draw your sky.

To count how many people visit and which parts of Stellingo are used, our own server keeps daily totals: the page (for example "/moon"), the kind of device (phone, tablet or computer) and a handful of named actions such as starting a tour. To count each visitor once a day it keeps a one-way code made from your IP address and browser together with a random value that is replaced every day and then thrown away — so it can't recognise you from one day to the next, or tell who you are. No cookies are used for this, and no analytics company is involved.

Like every website, our server and its proxy keep short technical logs (IP address, time, page requested, browser) for security and to fix problems. They are kept only briefly and overwritten automatically.

If you create an account

An account lets you keep your things across devices. We store:

  • your e-mail address, and your name if you give one;
  • your password, only as a secure one-way hash (we never see or store the password itself);
  • if you sign in with Google: your Google account's identifier, name, e-mail and picture, as Google shares them;
  • what you choose to save: your places (their name, coordinates and time zone), observations, reminders and preferences;
  • if you turn on notifications: your browser's push address, which lets us send your reminders;
  • when you created the account and when you last used it.

Why we use it (legal bases)

To provide the service you ask for — your account, syncing your saved things, sending the reminders you set (GDPR art. 6(1)(b), contract).

To keep Stellingo secure and working — rate limits against password guessing, error reports, the audit log of staff actions, the technical logs (art. 6(1)(f), our legitimate interest in a safe, reliable service).

To understand which parts of Stellingo are used, in aggregate only (art. 6(1)(f)).

To send account e-mails you need, such as resetting your password (art. 6(1)(b)). We don't send marketing e-mails unless you sign up for them separately, and every one of them has an unsubscribe link.

Error reports

When something breaks in Stellingo, your browser sends our own server a short error report: what failed, on which page, the version of Stellingo, and your browser and device type. It contains no account details and no location. Reports are grouped so we can fix the problem and are deleted after 90 days.

Who else is involved

We keep this list short, and each of them only gets what it needs:

  • Hetzner Online (Germany) hosts our server and database, in the EU.
  • Brevo (France) sends our e-mails (for example password resets): it receives your e-mail address and the message.
  • Your browser's push service (Apple, Google or Mozilla, depending on your browser) delivers the notifications you turn on.
  • Google, only if you choose "Sign in with Google".
  • Open-Meteo (Switzerland) provides the cloud forecast and the place search: when you use them, your browser asks Open-Meteo directly with an approximate position (rounded to about 100 m) or the name you typed. NOAA's Space Weather Prediction Center (USA) provides the aurora forecast, also asked directly by your browser, without your position.

Cookies

We use one cookie, only once you sign in: it keeps you signed in. It is strictly necessary, so it doesn't need consent. There are no advertising, tracking or analytics cookies.

How long we keep things

Your account and what you saved: until you delete it. Deleting your account (in Your account) removes it and everything attached to it straight away; backups that still contain it are overwritten within 30 days.

Error reports: 90 days. Technical logs: briefly, overwritten automatically. Daily visit totals: kept, as they contain nothing personal; the daily visitor codes are deleted after 2 days.

Your rights

You can see, correct, download and delete your data. Most of it you can manage yourself in Your account (including downloading everything we hold about you, and deleting the account). For anything else — or to object to how we use your data, or to ask us to limit it — write to us and we'll answer within a month.

If you think we've got something wrong, you can also complain to your data protection authority.

Children

Anyone can use the sky without an account. Accounts are for people aged 16 or over (or the age of digital consent in your country, if lower). If you believe a child has given us their data, tell us and we'll delete it.

Security

Everything travels encrypted (HTTPS). Passwords are hashed, staff accounts need two-step sign-in, every staff action is recorded, and the database is backed up every night. No system is perfectly safe; if something ever goes wrong that puts your data at risk, we'll tell you and the authorities as the law requires.

Changes

If we change this policy we'll update the date below, and tell account holders by e-mail before any change that matters to them takes effect.

Last updated 5 October 2026. Contact: groundcontrol@stellingo.com · Terms of use