ASTRO Privacy

Updated October 2, 2026.

Optional anonymous MCP trials store a random installation credential and API key in your native OS credential store. First intelligence use sends the installation credential to ASTRO over HTTPS. We retain a keyed hash of that identity, its entitlement, and trial dates to prevent renewal by reconnecting. We do not use hardware fingerprinting. Network-address hashes limit activation requests for an hour and new grants for up to 30 days. Anonymous access does not collect an email or enroll you in marketing. Changing devices or clearing credentials can lose this identity; contact support or use verified signup rather than seeking repeated trials.

For account delivery and trials we store your email address, supplied use case, entitlement dates, delivery status, and revocation state. We retain trial eligibility records to prevent automatic repeat grants. Verification proofs expire after ten minutes. Trial signup is not consent to marketing emails.

Signup rate limiting uses keyed hashes of email and network address with short-lived counters (up to one day). Hosting and email providers may process network information and email content to deliver the service. We use Vercel for the website, Upstash for account storage, Gmail for account email, and DigitalOcean for the API. Payment processing remains with Stripe.

API monitoring retains bounded request counts, response status, timing, and pseudonymous active-key identifiers for 24 hours; these are not a count of individual people. The MCP connector saves your key in a supported local OS credential store and sends it to ASTRO over HTTPS. The AI client receives requested market data, not the saved key. Your AI client's own data policies also apply.

We do not sell your personal information. Reply to an ASTRO account email to request help, correction, or deletion, subject to records needed for legitimate accounting and abuse prevention. Do not post API keys or verification codes publicly.

ASTRO