Legal information
Website privacy policy
How data is processed when you visit Asterisk’s public website, browse its content and choose your display preferences.
Draft updated on 10 September 2026
Draft — controller details to be completed
This text is being prepared and is not yet the final privacy policy. The controller’s identity and contact details, legal bases, providers, transfers and retention periods still need confirmation. The technical information describes the current website.
What this policy covers
This policy covers Asterisk’s public website: product information, recipes, exercises and the blog. You can browse this content without creating an Asterisk account.
The app also processes account details, personal logs and AI conversations. Those activities are separate from visiting this website and are described in the app’s policy. The website does not offer health-data entry forms, personal chat or access to your diary.
Data controller and contact details
The legal name, postal address and privacy contact for the operator of Asterisk must be confirmed before the final version is published.
Data processed when you browse
When your browser requests a page or image, servers receive technical data needed to respond, including your IP address and request information. Server logs may include the date and time, requested path, response status, browser and referring page.
Catalog searches and filters are included in the page address. They may therefore appear in your browser history and request logs. Use these fields to find public content; do not enter personal details or confidential health information.
Purposes and legal bases
Technical data is used to deliver pages and images, respond to searches, identify problems and protect the website. The theme preference remembers your choice of a light or dark display.
Proposed legal bases, subject to confirmation by the controller: legitimate interests in operating and securing the website for technical data; compliance with legal obligations where applicable. The actual processing activities and the legal basis for each must be confirmed before the final version.
Cookies and browser preferences
The website saves your light or dark theme choice in browser local storage under the key asterisk-theme. The website code does not assign an automatic expiry to this preference. You can remove it by clearing the website’s data in your browser settings; choosing a theme again saves it again.
The current website code does not integrate traffic analytics tools, advertising pixels or profiling cookies. Your language choice is part of the page address. Fonts are hosted by the website.
Providers and external content
Hosting infrastructure handles requests to the website. Catalog images may load directly from Asterisk’s public services and Supabase storage. In those cases your browser sends the image server the technical data needed for the request, including your IP address.
Recipe, exercise and blog text is retrieved by the website server through a public interface. Those requests do not forward visitor cookies, app credentials or personal profiles.
Recipe source links may take you to external websites. When you open them, their operators’ privacy notices also apply. The full provider list, their roles and any safeguards for transfers outside the European Economic Area still need confirmation.
Retention and security
The theme preference lasts according to your browser’s local storage, as described above. Retention periods for technical logs and any backups must be confirmed by the operator before final publication.
The current public preview uses an HTTP address. It therefore does not provide TLS protection for the connection between your browser and this website. This policy does not attribute encryption-in-transit guarantees to the preview that it does not provide.
AI and app data
The blog publishes content generated by Asterisk AI. Reading an article on the website does not start a personal conversation with the coach or open your app account.
In the app, Privacy and data lets you request a data export and account deletion. These actions are not performed on the website. App AI features use server-side processing; this policy does not promise a local AI mode or switches to disable that processing.
Your rights
Where the GDPR applies and subject to its conditions, you can request access to your personal data, rectification, erasure and restriction of processing. You may object to processing based on legitimate interests; portability and withdrawal of consent apply where their conditions are met.
You may lodge a complaint with a competent supervisory authority, such as the Garante per la protezione dei dati personali in Italy. The controller’s contact for exercising rights will be added once the contact details are confirmed.
Updates to this policy
The date above identifies this version of the text. The policy will need updating when website processing changes, for example if forms, accounts or analytics tools are introduced.