Celestys

Celestys — Privacy Policy

Last updated: July 20, 2026 Effective date: July 20, 2026

This Privacy Policy explains how Verde Fish Entertainment SRL ("Celestys," "we," "us," or "our"), registered at Bd. Mareșal Alexandru Averescu nr. 7, Sector 1, Bucharest, Romania, registration number CUI 27503489, collects, uses, stores, shares, and protects personal data when you use the Celestys mobile application (the "App"), a wellness app designed for women, including its:

(collectively, the "Services").

Because Celestys processes information about your menstrual cycle and reproductive health alongside photographs of your face and body, we want to be direct about this upfront: this is among the most sensitive personal data that exists, and we have designed our data practices, retention rules, and sharing restrictions around that fact, not as an afterthought.

This Policy is written to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, and the app data-disclosure requirements of the Google Play Store and the Apple App Store. If you do not agree with this Policy, please do not use the App.

Contact for all privacy matters: info@celestys.com Data Protection Officer (if applicable): dpo@celestys.com


1. Who We Are (Data Controller)

Verde Fish Entertainment SRL is the data controller responsible for your personal data processed through the App. For any question, request, or complaint regarding your data, contact us at info@celestys.com.


2. What Personal Data We Collect

We collect the minimum data necessary to provide the Services. This includes:

2.1 Account & Identity Data

2.2 Photographs You Submit (Sensitive / Special Category Data)

This is the most sensitive category of data we process, and we treat it accordingly:

Module What is photographed Purpose
SkinAI Your face AI analysis of skin condition and personalized skincare recommendations
NailsAI Your nails/hands AI analysis of nail condition
SuperBodyAI — Body Scan Your body AI analysis of body composition/posture and recommendations tailored to your selected goal
SuperBodyAI — NutriLog Photos of meals/food AI analysis of nutritional content of meals

Important clarifications: - We use these photographs only to generate the AI analysis and recommendations you request. We do not use facial photographs for biometric identification, facial recognition, or to create a unique biometric identity template. The photographs are used descriptively (e.g., visual assessment of skin condition), not to identify or authenticate who you are. - Even so, because photographs of your face and body can reveal information about your health and physical characteristics, we treat all photographs submitted to SkinAI, NailsAI, and SuperBodyAI as special category data under Article 9 GDPR, and we process them only on the basis of your explicit, separate, and freely given consent, obtained within the App before each module's first use. - You may decline to submit any photograph and use the App's other features. Declining will simply mean that AI-photo-based features are unavailable to you (e.g., in SuperBodyAI you may tap "Skip" to bypass photo-based steps). - Meal photos (NutriLog) are treated as regular personal data (not health data), since they depict food, not you.

2.3 Menstrual Cycle Data (Special Category Data)

If you use the Cycle Calendar, we collect the dates you log (period start/end, symptoms, mood, or other markers you choose to enter) to estimate your cycle phase and predict upcoming dates. This is health data under Article 9 GDPR and we apply the highest level of care to it:

2.4 Wellness Content Usage (Grounding, Frequencies, Self-Knowing)

For the Grounding, Frequencies (audio tone) and Self-Knowing modules, we collect only basic usage data (which sessions you open, playback duration, favorites/bookmarks). This content is editorial/wellness in nature; we do not require or collect any additional sensitive inputs to provide it.

2.5 Supplement & Vitamin Recommendations

Celestys may display editorial recommendations for supplements and vitamins tailored to your profile (e.g., your SuperBodyAI goal or logged cycle phase). We do not sell these products directly, operate a checkout, or process payments for them within the App. We may record which recommendations you viewed or saved for the purpose of improving relevance of future suggestions. See our [Disclaimer] for important information about supplement recommendations, which are not medical advice.

2.6 Automatically Collected / Technical Data

2.7 Data We Do Not Collect

We do not knowingly collect government ID numbers, precise real-time geolocation, financial/payment card data (payments, if any, are processed by Apple/Google directly and are never seen by us), or biometric identification templates.


3. How We Use Your Data (Purposes & Legal Basis)

Purpose Data used Legal basis (GDPR Art. 6/9)
Create and manage your account Name, email, password Performance of a contract (Art. 6(1)(b))
Generate SkinAI / NailsAI / Body Scan analysis Photographs, goal selection Explicit consent (Art. 9(2)(a))
Generate NutriLog nutritional analysis Meal photographs Performance of a contract (Art. 6(1)(b))
Generate your final SuperBodyAI report (calorie/macro targets, recommendations) Profile data, body scan results, nutrition logs Performance of a contract (Art. 6(1)(b)) + consent for sensitive inputs
Track your menstrual cycle and predict future dates Cycle dates, symptoms, mood entries Explicit consent (Art. 9(2)(a))
Provide Grounding, Frequencies, and Self-Knowing content Basic usage/playback data Performance of a contract (Art. 6(1)(b))
Personalize supplement/vitamin recommendations Profile, goal, cycle phase (only if you've consented to Cycle Calendar) Consent (Art. 6(1)(a)); explicit consent where cycle data is used (Art. 9(2)(a))
Maintain, secure, and debug the App Technical/diagnostic data Legitimate interest (Art. 6(1)(f))
Respond to support requests Contact details, correspondence Legitimate interest / contract
Comply with legal obligations Any relevant data Legal obligation (Art. 6(1)(c))

We do not use your photographs or personal data to train third-party AI models, and we do not sell your personal data. This applies with particular emphasis to your menstrual cycle data, which is never used for advertising or analytics profiling and is never shared with data brokers or marketing partners under any circumstances.


4. How Your Data Is Processed — Sub-processors & AI Technology

To provide the Services, we use the following processors. Each is bound by a Data Processing Agreement (DPA) and, where data leaves the EU/EEA, appropriate safeguards (e.g., Standard Contractual Clauses) are in place.

Processor Role Data involved
Google Firebase (Google Ireland Ltd. / Google LLC) Authentication, database hosting (Firestore), cloud functions, app infrastructure All account data, photographs (transiently, during processing), app data
Anthropic (Claude Vision / Claude API) AI analysis of submitted photographs and generation of recommendations Photographs submitted to SkinAI, NailsAI, SuperBodyAI, and meal photos; profile/goal data for personalization
[PAYMENT PROCESSOR, if applicable — e.g., Apple / Google in-app billing] Subscription/payment processing Purchase transaction data (we do not receive card numbers)
[ANALYTICS/CRASH REPORTING PROVIDER, if used — e.g., Firebase Crashlytics/Analytics] App stability and usage analytics Device/diagnostic data

On AI photo processing specifically: photographs are transmitted securely (encrypted in transit) to the Anthropic Claude Vision API solely to generate the requested analysis. We configure our integration so that submitted images are used only to generate your response and are not used by our sub-processor to train its general-purpose models, in line with Anthropic's API terms. We do not control third-party AI providers' infrastructure directly, but we select providers that contractually commit to data protection standards equivalent to the GDPR.


5. Data Retention


6. Your Rights (including GDPR / UK GDPR Data Subject Rights)

If you are located in the European Economic Area (EEA), the UK, or another jurisdiction granting equivalent rights, you have the right to:

To exercise any right, contact us at info@celestys.com. We will respond within one month as required by Article 12 GDPR (extendable by two further months for complex requests, with notice to you).

You may also manage most of your data directly in-app: edit your profile, delete individual photos/scans, or delete your account entirely from Settings.


7. Children's Privacy

Celestys is not directed at children and is not intended for use by anyone under the age of 16 (or the higher age of digital consent applicable in your country of residence, or 18 where required for App Store age-rating purposes). We do not knowingly collect personal data, and in particular photographs, from children. If we learn that a child's data has been submitted, we will delete it promptly. Parents/guardians who believe their child has provided us data should contact info@celestys.com.


8. International Data Transfers

Our sub-processors (including Google Firebase and Anthropic) may process data on servers located outside your country, including in the United States. Where personal data is transferred outside the EEA/UK, we ensure an adequate level of protection through mechanisms such as the European Commission's Standard Contractual Clauses (SCCs), UK International Data Transfer Addendum, or equivalent safeguards under applicable law.


9. Data Security

We apply technical and organizational measures appropriate to the sensitivity of the data we process, including: - Encryption of data in transit (TLS) and at rest (via Firebase/Google Cloud infrastructure encryption) - Access controls limiting who within our organization can access photographs and personal data - Authentication via Firebase Auth (industry-standard secure credential handling) - Regular review of Cloud Functions and API integrations

No system is 100% secure. In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours (Art. 33 GDPR) and, where required, notify affected users without undue delay (Art. 34 GDPR).


10. Google Play Data Safety & Apple App Privacy Disclosures

In compliance with Google Play's Data Safety section and Apple's App Privacy ("Nutrition Label") requirements, we disclose:


11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified via in-app notice or email before they take effect. The "Last updated" date above reflects the most recent revision.


12. Contact Us

Verde Fish Entertainment SRL Bd. Mareșal Alexandru Averescu nr. 7, Sector 1, Bucharest, Romania Email: info@celestys.com


This Privacy Policy should be reviewed by a qualified data protection lawyer before publication, to confirm accuracy of the bracketed company details, retention periods, and applicability of local laws (e.g., CCPA/CPRA if you have California users, or other regional data protection laws) to your specific business setup.