Legal
Privacy Policy
This policy explains what personal data Periapsis processes, why it is needed, where it goes, and the choices available to you.
1. Who is responsible
The independent operator of Periapsis, based in Switzerland, is responsible for and determines the purposes of the personal-data processing described here. For privacy questions or requests, contact info@periapsis.space.
2. Data we process
When you use the public application
- Request and security data: IP address, request time and route, browser or user-agent information, and signals needed for rate limiting, abuse prevention, troubleshooting, and service security.
- Local application data: the PWA may store code, WebAssembly, textures, map tiles, models, public orbital data, and compatibility preferences in browser cache, Cache Storage, IndexedDB, local storage, or session storage. This keeps repeat loads fast and supports recovery from browser limitations.
When you create an account
- Email address, username, optional display name, email-verification status, and account timestamps.
- An Argon2 password hash for password-based accounts. Periapsis does not store your plaintext password.
- Random session and CSRF credentials. Only cryptographic hashes of server-side session credentials are stored.
- Satellites you create, including their names, selected central bodies, TLEs or Keplerian elements, visual parameters, and any mesh or texture files you upload.
When you use Google sign-in
Periapsis requests only the OpenID Connect scopes openid, email, and profile. Google provides a unique account identifier, email address, email-verification status, and display name. These fields are used only to authenticate you, create or link your Periapsis account, and populate its basic profile.
Periapsis does not receive your Google password, does not request contacts, Drive, calendar, or advertising data, and does not persist Google access or refresh tokens. A short-lived access token is used server-side to retrieve the identity response and is then discarded. Periapsis's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
3. Why we process it
Where applicable law requires a legal basis, the bases described below apply:
- Provide the service and your account: to authenticate you, persist your satellites and assets, and return your account content. The basis is performance of the service you request.
- Google sign-in: to complete an authentication method you choose and link the verified identity to your account.
- Email verification: to confirm account ownership and prevent abuse.
- Security and reliability: to rate-limit traffic, prevent attacks, diagnose failures, and protect users and infrastructure. The basis is our legitimate interest in operating a secure service.
- Legal duties: where processing or retention is required by applicable law or a valid authority request.
4. Cookies and device storage
Periapsis uses only storage required for authentication, security, application delivery, and compatibility. Authentication uses secure, HttpOnly, SameSite cookies for the session and a readable CSRF cookie/header pair; Google sign-in also uses a short-lived secure OAuth state cookie. Periapsis does not use advertising cookies and does not currently run third-party analytics.
You can remove local caches and preferences through your browser or installed-app settings. Blocking essential cookies prevents account sign-in but the public visualizer remains available.
5. Sharing and service providers
Periapsis does not sell personal data and does not share it for targeted advertising. Data is disclosed only as needed to operate the service:
- Google: when you choose Google sign-in, the OAuth exchange is handled with Google. Google processes its side of the interaction under the Google Privacy Policy.
- Porkbun email infrastructure: the address and verification message are submitted through Porkbun's SMTP service when Periapsis sends account email.
- Infrastructure and authorities: limited data may be disclosed to infrastructure operators, professional advisers, or competent authorities when necessary for operations, security, legal claims, or a binding legal duty.
Scientific catalogues, launch records, maps, textures, and models are synchronized or bundled independently of user accounts. Periapsis does not send your account profile or uploaded content to those scientific-data publishers.
6. International processing
The core Periapsis application and account API are self-hosted by the operator. Google and Porkbun may process data in countries outside Switzerland when they provide sign-in or email delivery. Their processing locations and transfer protections are governed by their applicable terms and privacy documentation. You may contact Periapsis for further information about a transfer involving your account data.
7. Retention
- Account records and user-created satellites or uploads are retained while the account exists, then deleted or de-identified following a valid deletion request, subject to limited legal or security retention.
- Normal web sessions expire after 30 days. Email-verification links expire after 24 hours. Google OAuth flow records expire after 10 minutes and native handoff records after 2 minutes.
- Expired authentication records are removed automatically. Operational and security logs are subject to host-level rotation. No fixed log-retention period is promised; retention depends on what is reasonably necessary to investigate failures, prevent abuse, protect legal claims, or meet legal duties.
- Public scientific and launch data is not account data and may be retained as part of the application's historical archive.
8. Security
Periapsis uses TLS, restricted-origin writes, CSRF protection, HttpOnly session cookies, hashed session credentials, Argon2 password hashing, rate limiting, and access controls for user-owned content. No system is completely secure; please use a unique password and report suspected compromise promptly.
9. Your choices and rights
Depending on where you live and the conditions of applicable law, you may request access, correction, deletion, restriction, portability, or object to processing, and may withdraw consent where consent is the basis. You may also complain to the Swiss Federal Data Protection and Information Commissioner or your competent local data-protection authority.
To delete an account and its associated satellites and uploads, follow the public deletion instructions below. We may ask you to verify control of the registered account before acting.
Account deletion instructions10. Children
Periapsis is not directed to children under 16 and does not knowingly collect their personal data. A parent or guardian who believes a child submitted personal data should contact us for deletion.
11. Changes and contact
Material changes will be published on this page with a revised effective date. Questions and privacy requests can be sent to info@periapsis.space.