PLANCKSTARUPDATED 13 AUG 2026

Privacy Policy

Planckstar, operated by Aster Solutions LLC Last updated: 19 August 2026

The short version

We collect what the product needs to work and nothing else. There is no advertising, no behavioural profiling, and no advertising cookies in Planckstar. We do not sell your data or use your content to train machine-learning models. Your private clusters stay private.

We use two measurement services — one for privacy-friendly page counts, one so that crashes reach us instead of going unnoticed. Neither uses cookies to follow you between sites, and neither receives the contents of your clusters. Sections 4 and 7 say exactly what they do get.

The rest of this document is the detail behind those sentences.

1. Who is responsible

Aster Solutions LLC is the controller of the personal data described here.

Aster Solutions LLC 8206 Louisiana Blvd NE, Ste A #6371 Albuquerque, NM 87113, United States

2. What we collect

You give us

DataWhy
Email address and passwordTo create and secure your account. Handled by Amazon Cognito — we never see your password.
First name and last nameTo address you in the product. Never published — your username appears on clusters instead. Editable in your account settings.
Date of birthTo check the minimum age in section 2 of the Terms. Stored on your account and not shown to anyone.
UsernameShown as the author of clusters you publish. It is generated for you when your subscription starts — something like iron-keel-3234 — and you can change it in your account settings once a week. It is deliberately not your real name, and changing it updates every cluster you have already published.
Payment card detailsTaken directly by Stripe. We never receive or store your card number.
Cluster content — milestones, notes, checklists, links, images, vectors, documents, 3D modelsIt is the product.
Report details — the reason and description you writeTo review reports about published clusters.

Created as you use it

DataWhy
Cluster and milestone identifiers, timestampsTo store and order your work.
A city and approximate coordinates for published clustersTo place the cluster on the public discovery globe. See section 3.
Stars you giveTo show totals and stop you starring twice.
Subscription status and Stripe customer identifierTo know whether your account is active.
Server and security logs, which may include IP addressTo keep the service running and to investigate abuse.
Error diagnostics — the fault, the code path that produced it, and the browser and operating system versionTo find and fix crashes. See section 7 for what is deliberately excluded.
Notices we send you, and whether you have acknowledged themSo an important message about your account is shown once and not repeatedly.

What we do not collect

No advertising or analytics identifiers. No behavioural profiling. We do not use your device's location services — Planckstar never asks for GPS permission. No contact list, microphone or camera access. No special category data — please don't put health, biometric, political or similar sensitive information into Planckstar.

3. How the city on a published cluster is chosen

When you publish a cluster it is pinned to a city on our public globe.

To suggest a starting city, we read the coarse location headers that your hosting connection already carries — city name, country, and approximate latitude and longitude at city-level accuracy. This is the same information any website receives about the region you are connecting from.

The globe shows counts, not your cluster's position. Pins are aggregated into grid squares roughly seven kilometres across, and what the globe sends a visitor is how many clusters are in each square — not a list of where each one is. The city you chose is on your cluster's own page, but the map itself is a count.

If you would rather not be associated with your region at all, set the pin to a different city before you publish.

4. Cookies and local storage

The only cookies Planckstar sets are the ones that keep you signed in. Amazon Cognito writes a small group of them together — your identity and access tokens, a refresh token, the account they belong to, and a clock correction. They are strictly necessary, and there is nothing to consent to because there is nothing optional about them.

We use Vercel Analytics for page counts. It records that a page was viewed, the referring site, and coarse device information such as browser and country. It does not set a cookie, does not use a device fingerprint, and does not build a profile that follows you between sites or between visits. It runs on public pages and inside the app alike.

We also use your browser's own localStorage and IndexedDB to keep drafts and uploaded file bytes on your device so you don't lose work. That data stays on your machine, is not sent to us except when you save or publish, and clearing your browser data removes it.

No advertising cookies. No third-party advertising pixels. No consent banner, because nothing we set is optional and nothing we measure identifies you.

5. Why we may process your data, legally

For users in the EEA and UK, our lawful bases are:

6. Published clusters are public

When you publish a cluster it becomes visible to anyone with the address, may be listed on our discovery pages, pinned to the city shown, and indexed by search engines. We also list published clusters in our sitemap, which actively tells search engines they exist. Your username appears with it. Your real name never does.

The files inside it are copied to a public address. Images, documents and models in a published cluster are copied to assets.planckstar.com and served from there at stable addresses that do not expire. This is what makes a published page load quickly for a stranger. It also means that while a cluster is public, anyone holding a file's address can open it directly — so treat a file in a published cluster as public, not merely as visible inside the page.

Publishing is not reversible in the world. Unpublishing deletes the cluster, its snapshot and its published files from both of our storage providers, but copies may remain in search engine caches, archives, or on the devices of people who saw them. Don't publish anything you would be harmed by having permanently public.

Private clusters are not published, not indexed, and not shared.

7. Who else processes your data

We use a small number of providers. They act on our instructions and may not use your data for their own purposes.

ProviderWhat they handleWhere
Amazon Web ServicesDatabases (DynamoDB) and storage of your private, working files (S3)us-east-1, United States
Amazon CognitoAccounts, sign-in, passwordsus-east-1, United States
StripePayments and subscriptionsUnited States / global
VercelServing the website, page-view counts, and the coarse location headers in section 3Global edge network; server functions in us-east-1, United States
CloudflareStorage and delivery of published clusters, their snapshots and the files inside them (R2)Global network
SentryError diagnostics and performance timingsUnited States

What Sentry does not receive. Error monitoring is the one place where diagnostic data could quietly become surveillance, so it is configured against that: no IP addresses, no request bodies, no session or screen recording, and no cookies — which matters because your sign-in token is a cookie. Addresses of your uploaded files have their access signatures stripped before being recorded. What it receives is the fault, the code path, and the browser version.

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We may disclose data if legally required, or to protect the rights and safety of our users, and we will tell you when we are permitted to.

8. Reports about content

When you report a published cluster we record your user identifier, the cluster and its author, your chosen reason, and what you wrote.

We do not reveal your identity to the author of the cluster you reported.

Reports outlive account deletion. If reports could be erased by closing an account, deleting your account would destroy the record of why it was actioned. Retained reports are kept for enforcement and to defend legal claims.

9. How long we keep things

DataRetention
Account and clustersWhile your account is open
Deleted clusters and account contentRemoved from active systems within 30 days
BackupsRotate out within 90 days
Reports and enforcement records3 years after the decision
Payment and tax records7 years, as required by law
Security logs90 days
Cancelled or lapsed subscriptionsContent kept 90 days, then deleted after an email warning

10. Security

Data is encrypted in transit (HTTPS) and at rest. Passwords are handled by Cognito and never reach our servers. Access to production data is limited to those who need it.

No service can promise perfect security. If a breach affects your personal data we will notify you and the relevant regulator as the law requires.

11. Your rights

Wherever you live, you can access, correct, export or delete your data, and object to or restrict some processing. Most of it you can do yourself from your account settings; for anything else, write to contact@astersts.com and we will respond within 30 days.

EEA and UK: you also have the right to complain to your data protection authority. In the UK that is the ICO (ico.org.uk).

California: you have the right to know, delete, correct, and to opt out of sale or sharing — we do none of the latter — and not to be discriminated against for exercising these rights.

We will never make the service worse for you because you exercised a privacy right.

12. International transfers

Our infrastructure is in the United States. If you are outside the US, using Planckstar means your data is transferred there. For transfers from the EEA or UK we rely on the European Commission's Standard Contractual Clauses and the UK Addendum, which our providers offer as part of their terms.

13. Children

Planckstar is not for children under 13, and we do not knowingly collect their data. If you believe a child has given us personal data, write to contact@astersts.com and we will delete it.

14. Changes

We will post any update here and change the date at the top. For material changes we will give at least 30 days' notice by email or in-app before they take effect.

15. Contact

Aster Solutions LLC 8206 Louisiana Blvd NE, Ste A #6371 Albuquerque, NM 87113, United States contact@astersts.com