iambecoming.one
HomeHow it worksFAQPricingLoginCreate your mandala
HomeHow it worksFAQPricingLoginCreate your mandala

iambecoming.one

Privacy Policy

Last updated: September 2026

Protecting your personal data matters to us. This policy explains which data we process when you use iambecoming.one, for which purposes and on which legal basis, and what rights you have.

iambecoming.one is a self-reflection tool. It combines Human Design charts calculated from birth data, behavioural questionnaires, and an AI-assisted reading. The content is intended for personal reflection and does not replace medical, psychological, legal, or financial advice.

Controller

The controller responsible for data processing under the GDPR is:

Stellar Foundry GmbH
iambecoming.one
Thomas-Mann-Str. 19, 53111 Bonn, Germany
Registergericht Bonn, HRB 30834
Marion Hillebrecht
privacy@iambecoming.one

Privacy contact

For any privacy questions and to exercise your rights, you can reach us at privacy@iambecoming.one or by post at the address above.

We are not legally required to appoint a data protection officer; for privacy matters, please contact the address above directly.

Hosting and AI processing in our own data centre

The application, the database, and the AI model used for the readings are operated by Stellar Foundry GmbH on its own infrastructure in a data centre in Bonn, Germany. No external AI services are used; your data is not shared with third parties for the AI reading.

The website loads no resources from external content delivery networks, no external fonts, and no third-party scripts. Fonts are served locally.

Data we process, purposes and legal bases

We process personal data only where necessary to provide the app or where you have consented. In detail:

  • Registration and account: your name (or chosen display name) and email address, to create your account and give you access to your personal area. Legal basis: Art. 6(1)(b) GDPR (contract) and your explicit consent to storage (Art. 6(1)(a) GDPR).
  • Birth and profile data: date of birth, time of birth, place of birth (country, city, geographic coordinates and time zone) and your questionnaire answers. We process these to calculate your Human Design mandala and create your personal readings. Legal basis: Art. 6(1)(b) GDPR and your consent.
  • AI-assisted readings: to generate your analyses, our self-operated AI model processes your name, your gender (if provided), your date of birth, your country of birth and the derived mandala data. Your email address is not passed to the AI model. Legal basis: Art. 6(1)(b) GDPR.
  • Email code sign-in: for passwordless login we send a one-time, time-limited code to your email address. We store the code only in hashed form. Legal basis: Art. 6(1)(b) and (f) GDPR (secure sign-in).
  • Friend invitations: if you invite another person to a joint reading, we process their first name and email address to send the invitation. You confirm that you have informed the invited person and/or have their consent. Legal basis: Art. 6(1)(f) GDPR (operating the invitation feature).
  • Details about your child: for the “Your child and you” reading you enter your child’s first name, gender (if given), and their date, time and place of birth. From this we calculate your child’s mandala and place it next to your own. The reading is produced for you as the parent; your child gets no access and no account of their own. Legal basis: Art. 6(1)(b) GDPR (performance of the contract with you). See the section “Details about your child”.
  • Payments: if you purchase paid features, we process the payment via our payment provider Stripe (see "Recipients"). We process invoice-relevant data to perform the contract and meet tax obligations. Legal basis: Art. 6(1)(b) and (c) GDPR.
  • Newsletter/product updates: only if you explicitly opted in during registration do we occasionally send you product updates, tips and offers by email. Legal basis: Art. 6(1)(a) GDPR. You can withdraw your consent at any time with future effect, e.g. via the unsubscribe link in every email.
  • Analytics: only with your consent do we measure how the app is used (see "Cookies and analytics"). Legal basis: Art. 6(1)(a) GDPR.
  • Anonymous page counting: regardless of consent we count page requests per day without any identifier and without IP addresses (see "Anonymous page counting without consent"). Legal basis: Art. 6(1)(f) GDPR, to the extent personal data is involved at all.
  • Operation and security: for troubleshooting and to secure operations we process technical log data (see "Server logs and records"). Legal basis: Art. 6(1)(f) GDPR.

Cookies and local storage

We use necessary cookies to operate the app and — only with your consent — cookies and local storage for analytics. Via the cookie notice you can allow analytics or permit only the necessary functions. You can change your decision at any time via "Cookie settings" in the footer. Without consent, no analytics take place and no analytics identifiers are set.

NamePurposeCategoryStorage period
ibo_user_sessionKeep you signed in (login session)Necessary30 days
ib_cookie_consentStores your cookie decisionNecessary180 days
ibo_session_idSession identifier for analyticsConsent2 hours
ibo_visitor_idReturning-visitor identifier (local storage)Consentpersistent, until deleted
Local storage (app)Temporary store for inputs, questionnaire progress, last used email and display settingsNecessary/functionaluntil cleared in your browser

Analytics (first-party)

If you have consented, we collect aggregated usage data using our own first-party analytics. We deliberately keep this data-minimal: no IP addresses and no full browser identifiers are stored, and no third-party analytics service is used.

We process a random session and visitor identifier, the view opened, triggered events and funnel steps, a coarse source (e.g. search engine or social network), any campaign parameters, device type as well as browser and operating-system family, language and time zone. Legal basis: Art. 6(1)(a) GDPR.

Anonymous page counting without consent

Regardless of your cookie decision, we keep a purely anonymous count: for every day and every page requested we increment a counter. No identifier, no IP address and no timestamp of the individual request is stored, and nothing is written to or read from your device. Automated requests (search engines, preview services) are filtered out by their browser identification; that identification itself is not stored.

We likewise count how often the cookie notice was shown and how it was answered — accepted, declined or left unanswered. Here too, only a daily figure without any link to a person is created.

These figures allow neither a usage history nor any link to your account. They serve solely to judge the reach and clarity of our pages. Since nothing is stored on or read from your device, no consent under section 25 TTDSG is required. Should the figures exceptionally be considered personal data, the legal basis is our legitimate interest in a clear and economically viable service (Art. 6(1)(f) GDPR). The counters are deleted after 14 months.

Server logs and records

When you access the website, the upstream server (reverse proxy) processes technically necessary access data, in particular the IP address, date and time of access, and the requested resource. These access logs serve secure operation and troubleshooting; they are rotated regularly and deleted within about four weeks. Legal basis: Art. 6(1)(f) GDPR.

For error diagnosis we additionally keep internal operational logs that may contain technical error messages. In the event of serious errors, we send automated alerts to our operations team.

Recipients and processors

We do not share your data for the purpose of selling it. To provide our services we use carefully selected providers with whom, where required, data processing agreements under Art. 28 GDPR are in place:

ProviderPurposeLocation
IONOS SEEmail inbox (receiving) and sending of transactional and, with consent, marketing emailsGermany (EU)
Stripe Payments Europe, Limited (and, for regulated payment services, Stripe Technology Europe, Limited)Payment processing (only for paid features)Dublin, Ireland (EU); processing also in the USA and, for certain regulated data, in India

Payment processing via Stripe

We sell and bill paid features ourselves and also issue the invoice. For processing the payment we use Stripe. Our contracting party is Stripe Payments Europe, Limited, based in Dublin, Ireland; for regulated payment services Stripe Technology Europe, Limited (also Dublin, Ireland) is additionally involved, which is supervised by the Central Bank of Ireland as an electronic money institution.

You enter your full payment-method details, such as the card number, directly with Stripe; we do not receive them, only the information needed to allocate the payment and issue the invoice. Stripe also processes payment and invoicing data (e.g. name, billing address, payment method) on its own responsibility, in particular to execute the payment, to prevent fraud and to meet its own legal obligations. Stripe’s own privacy notices apply to the processing for which it is responsible.

Transfers to third countries

Our own infrastructure (hosting and AI processing in the data centre in Bonn) and our email provider (IONOS) process your data within the EU.

If you access the app from outside the EU/EEA, your own data is, for technical reasons, transmitted to your device. You, as the data subject, accessing your own data is not a transfer initiated by us to a recipient in a third country within the meaning of Art. 44 et seq. GDPR.

For paid features, payment is handled by the Irish Stripe entities (see the section “Payment processing via Stripe”). According to Stripe, its data centres are located in the USA, and certain regulated data is processed in India; personal data is therefore transferred to affiliated companies outside the EU, in particular to Stripe, Inc. in the USA. Stripe, Inc. is certified under the EU-US Data Privacy Framework, and the transfer relies on the EU Commission adequacy decision to that extent. In addition, EU Standard Contractual Clauses under Art. 46 GDPR apply. Stripe engages its own sub-processors for payment processing and publishes a list of them; details, and Stripe’s data protection officer (reachable at dpo@stripe.com), are set out in Stripe’s privacy notices.

Companion chat

In the chat with your companion (Elias or Vera) we process your messages in order to answer them. The purpose is the performance of the user contract (Art. 6(1)(b) GDPR).

To produce an answer, the language model receives your question, the most recent messages of the conversation and the key figures of your mandala. The model runs on our own infrastructure in the data centre in Bonn; your messages are not transmitted to an external AI provider and are not used for training.

Question and answer are stored so that your conversation is still there on your next visit. You can delete your own messages in the chat at any time; the text is then removed and the place remains as a note. If you delete your account, the entire history is deleted.

Please do not share health data or other special categories of personal data in the chat. The chat is not a substitute for advice, diagnosis or therapy.

Retention periods

We store personal data only for as long as necessary for the respective purposes or as long as statutory retention periods require:

  • Account, profile, birth and reading data: until you delete your account.
  • Details about your child from the “Your child and you” reading: until you delete your account or the reading itself.
  • Invoice and payment data: up to 10 years due to tax and commercial retention obligations (§ 147 AO, § 257 HGB). According to Stripe, our payment provider generally keeps the data it processes for five years or more after the end of the business relationship, where its own regulatory obligations require this.
  • Sign-in codes and confirmation tokens: until their short validity expires.
  • Analytics: 14 months.
  • Anonymous page counters: 14 months.
  • Companion chat history: 24 months per message, unless you delete it sooner.
  • Server access logs: up to about four weeks.

Details about your child

The “Your child and you” reading processes details about a person who does not use the app themselves and is usually a minor. We therefore keep this to a minimum and describe it separately here.

We process only what the calculation needs: first name, gender (if given), and date, time and place of birth including coordinates and time zone. We do not collect your child’s address, contact details or health data, and we do not create an account for your child.

These details come from you. By entering them you confirm that you are entitled to provide them — as a person with parental responsibility, or with the consent of those who hold it. Whether and when you talk to your child about the reading is your decision.

The legal basis is Art. 6(1)(b) GDPR: the processing performs the contract you entered into with us. We do not obtain consent from your child; at this age it would regularly not be valid, and the reading is a service to you.

The details stay with the individual reading and are not turned into a profile of their own. They are not passed to third parties; the AI model runs on our own infrastructure as described. If you delete your account, the readings and the details about your child they contain are deleted in full — not anonymized. You can also exercise the rights described under "Your rights" with regard to the details about your child; please contact our data protection address.

Deleting your account

You can delete your account and your personal data yourself at any time. Simply sign in and open "Settings / account" in your area. On deletion, your name, email address, birth data, mandala, questionnaire answers and readings are irreversibly anonymized or deleted. Billing data for purchases you already made is retained separately for the statutory reasons stated above.

Your rights

Subject to the statutory conditions, you have the following rights:

  • access to the data stored about you (Art. 15 GDPR),
  • rectification of inaccurate data (Art. 16 GDPR),
  • erasure (Art. 17 GDPR),
  • restriction of processing (Art. 18 GDPR),
  • data portability (Art. 20 GDPR),
  • objection to processing based on legitimate interests (Art. 21 GDPR),
  • withdrawal of consent with future effect (Art. 7(3) GDPR).

Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, www.ldi.nrw.de. You may also contact the supervisory authority of your habitual residence.

Minimum age

iambecoming.one is intended for people aged 16 and over. If you are younger, please use the app only with the consent of a parent or guardian.

Changes to this privacy policy

We update this privacy policy when our data processing changes or when legal requirements make it necessary. The version published on this page applies.

(c) 2026 iambecoming.one.All rights reserved.
Feedback/ContactPrivacyTermsImprint

Illustrations and companion portraits are AI-generated.