Privacy and public sources
Data protection at Astrolabiy
We explain what we collect, why we use it, and how we remove public information when it is no longer available.
Public data and purpose
We use public sources to identify signals about startups and commercial opportunities. On X, we may process a post identifier, public text, the author's public profile, the date, and the post URL.
The recruiter experience shows derived signals and a link to verify the post on X. We do not reproduce raw content or internal collection metadata in the dashboard.
Use limitations
We do not use X data for candidate selection, background checks, surveillance, sensitive individual profiling, or decisions about credit, employment, housing, or insurance.
We also do not infer sensitive attributes or automatically contact people based on this data.
Essential cookies and your choice
We use essential first-party cookies to keep accounts signed in, protect authenticated sessions, remember security settings, and store your analytics choice. These cookies are required for the service and are not used for advertising.
Your analytics choice is stored for up to 12 months. If we materially change what optional analytics collect, the consent version changes and Astrolabiy asks again.
Optional PostHog analytics
PostHog product analytics and masked session replay remain off until you explicitly accept analytics. When enabled, we record page categories, product actions, outcomes, device and performance context, and a pseudonymous account identifier. We do not send form contents, passwords, email addresses, message text, source evidence, or private request tokens as event properties.
Session replay masks all input fields. You can decline on first visit or change your choice later through Privacy choices. Revoking consent stops future capture, stops session recording, opts this browser out, and resets its PostHog identity.
Sentry error and performance monitoring
Sentry helps us detect crashes, unexpected server failures, and slow requests. It is operational monitoring rather than advertising analytics, so it is not controlled by the optional PostHog switch.
We disable default personal-data collection and remove request bodies, cookies, headers, query strings, and sensitive route identifiers before sending an error. Access is limited to people responsible for operating Astrolabiy, and records are retained only as needed to diagnose and prevent incidents.
Search visibility
Google Search Console lets us understand whether public Astrolabiy pages can be crawled and indexed. It does not add a Google analytics script to the product or change your cookie choice. Google receives the public URLs it crawls, such as the landing page, sign-in page, Privacy Policy, and Terms of Use.
Artificial intelligence processing
We may use the OpenAI API to turn public evidence into structured company information. Astrolabiy does not use this data to train models. The provider may keep operational logs under its own security and retention policies.
Automated outputs go through provenance checks and fail closed when the required evidence is unavailable.
Deletion, correction, and your rights
When we determine that a post was removed, protected, materially changed, or is subject to a valid request, we immediately hide the evidence from recruiter surfaces and delete stored copies. Temporary storage failures do not make the content visible again.
To request access, correction, deletion, or information about analytics data, send the relevant URL or identifier to hello@astrolabiy.com. We prioritize requests related to X and handle them within the applicable timeframe.