01 / SCOPE
Who this notice covers
This notice covers the public pages and browser applications served from adrianotothestar.com. The website operator and data controller for information submitted directly to the site is Adriano To The Star, also styled I.T.A. — Interstellar Travel Agency, an independent UK-based website project.
Some links, embedded resources, and separately operated services have their own controllers and notices. A link to another organisation does not make Adriano To The Star responsible for that organisation’s processing. This notice does not claim control over unrelated subdomains or services that identify a different operator.
Most pages are pre-built files. They do not need an account and do not send form content to an Adriano To The Star application server merely because you read them.
02 / DATA MAP
Information, purpose, and legal basis
| Activity | Information | Why it is used | Legal basis where UK or EU data law applies |
|---|---|---|---|
| Deliver and protect pages | IP address, request URL, timestamp, network and browser headers, security events | Serve content, prevent abuse, diagnose faults, and maintain availability | Legitimate interests in secure and reliable delivery; legal obligation where applicable |
| Remember browser choices | Language, theme, audio state, dismissed notices, and feature settings | Return the site to the state you selected | Consent where required; otherwise strictly requested functionality |
| Respond to contact | Name or identifier, email address, message, and correspondence metadata you provide | Answer the request and retain an accountable correspondence record | Consent, steps requested before a service, and legitimate interests in support |
| Optional account or community feature | Details shown at sign-in or submission time, such as an email address, profile, post, or message | Provide the feature you deliberately request | Performance of the requested service; consent for optional fields |
| Optional AI or live-data feature | Prompt, attachment, selected model/provider, diagnostics, or public-data query when disclosed by that feature | Generate the requested result or retrieve the selected public data | Performance of the requested feature and consent for device permissions |
Adriano To The Star does not infer sensitive personal characteristics for advertising, sell personal information, or build a profile of your activity across unrelated websites.
03 / YOUR DEVICE
Cookies, local storage, caches, and permissions
The core static pages do not require advertising cookies. Browser features may use the following device-local mechanisms:
- Local storage
- Durable preferences such as language, visual theme, audio-player state, tutorial progress, bookmarks, or local lab settings.
- Session storage
- Temporary state for a tab or browser session, cleared by the browser when that session ends.
- Cache Storage / IndexedDB
- Downloaded static resources, offline data, or optional browser-local AI model files. Large model downloads begin only after an explicit action.
- Device permissions
- Microphone, camera, XR, serial, file-system, or similar access. Compatible browsers show a permission prompt and access can be revoked in browser settings.
You can clear website data, block storage, or reset permissions through your browser. Blocking storage can prevent preferences, offline resources, saved local work, or model caches from functioning. Global Privacy Control and Do Not Track signals are not used to sell or share data because the operator does not perform those activities.
04 / OPTIONAL SYSTEMS
Accounts, communications, AI, and public data
Browser-local AI
When a feature is clearly labelled browser-local, model weights and inference run on your device after you choose to download them. Prompts are not sent to an inference provider by that local mode. The model runtime may use browser caches or IndexedDB until you remove the model or clear site data.
Network AI and communication modes
If you deliberately choose a network model, live communication, or another externally operated mode, the prompt, message, media, selected settings, and technical metadata needed to provide it may be sent to the provider named at the point of use. Do not submit confidential, legally privileged, medical, financial, biometric, or other sensitive information unless the feature explicitly supports it and you accept the provider’s terms.
Public astronomy data
Dashboards and trackers prefer same-origin, build-cached snapshots of public scientific data. This avoids sending every visitor directly to the source archive and avoids exposing browsing activity through avoidable cross-origin requests. Source institutions are linked for provenance and independent verification.
Files and hardware
Experimental file, serial, microphone, camera, or XR tools should request access only after a user action. Files selected through a browser picker remain under the access model enforced by your browser and operating system. Hardware or local files are not uploaded merely because a compatible API is detected.
05 / PROCESSORS & SOURCES
Providers, external links, and international transfers
- GitLab Pages hosts the static production artifact. See the GitLab Privacy Statement.
- Cloudflare may deliver, cache, secure, and route requests for the public domain. See the Cloudflare Privacy Policy.
- Scientific archives such as NASA/IPAC and ESA/Gaia supply public source data and documentation. Same-origin snapshots reduce routine cross-origin requests; following a source link takes you to that institution.
- Optional feature providers are identified in the relevant interface before sensitive input or a large download. Their terms and privacy notices govern their own processing.
These organisations may process information in the United Kingdom, European Economic Area, United States, or other locations in which they operate. Where the operator directly arranges a restricted transfer, an adequacy regulation or appropriate safeguard should be used as required. Provider-operated transfers are described in the provider’s own notice.
06 / RETENTION
How long information remains
- Browser-local data: remains until the feature removes it, it expires, or you clear it. Private/incognito sessions may clear it sooner.
- Hosting, edge, and security logs: are retained according to the provider’s operational and legal retention schedules. The site operator does not promise a period it does not control.
- Support correspondence: is kept only as long as reasonably needed to answer the request, document the outcome, resolve disputes, and meet legal duties.
- Optional account or community content: follows the notice shown by that feature. Deletion may not immediately remove content from security backups or records that must be retained by law.
When information is no longer needed, the operator should delete it, anonymise it, or allow provider-controlled expiry. Aggregated scientific or performance measurements that no longer identify a person may be retained.
07 / YOUR CONTROL
Privacy rights and practical choices
Depending on your location and the circumstances, you may have rights to access, correct, erase, restrict, object to, or receive a portable copy of personal data; withdraw consent; and challenge a decision based solely on automated processing. These rights can have legal exceptions.
- 1Control the browser first
Clear site data, remove optional model caches, revoke permissions, or use a private window for temporary exploration.
- 2Contact the operator
Email the privacy contact with the right you want to exercise and enough information to locate the relevant record. Do not email passwords or identity documents unless specifically and securely requested.
- 3Verification and response
The operator may request proportionate verification and should respond within the period required by applicable law. Complex or repeated requests may lawfully take longer or incur limits.
Withdrawing consent does not make earlier lawful processing unlawful. You can object to direct marketing at any time; the current core site does not operate a behavioural-advertising mailing profile.
08 / YOUNGER EXPLORERS
Children and educational use
Astronomy content can be educational, but the site is not designed to knowingly collect personal information from children. A child should not create an account, publish content, contact a network AI service, or grant device permissions without the involvement of a parent, guardian, school, or other responsible adult where required.
If you believe a child supplied personal information without appropriate authorisation, contact the operator so the situation can be investigated and the information removed where appropriate.
09 / SECURITY
Security and honest limitations
The site uses HTTPS and separates browser-local features from network-enabled features where practical. Static delivery reduces the amount of application-server data processing, but no website, browser cache, email channel, CDN, third-party script, or storage system can be guaranteed completely secure.
Client-side code and values delivered to a visitor are public and must never be treated as secret authentication credentials. Do not rely on a password check implemented only in HTML or JavaScript. Report suspected exposure or misuse to the privacy contact.
Do not submit secrets, access tokens, private keys, precise personal location, or sensitive personal data to demonstration features. Use unique credentials on any separately operated account service.
10 / CONTACT
Questions, requests, and complaints
For privacy questions or rights requests, email [email protected] with the subject “Privacy request”. The operator may need to ask which page, feature, account identifier, or approximate date is involved.
If UK data-protection law applies and you remain dissatisfied, you may complain to the UK Information Commissioner’s Office. If another supervisory authority is appropriate for your location, you may contact that authority instead. You do not have to give up a legal right before contacting a regulator.
11 / CHANGE LOG
Policy changes
Material changes will update the review date and the summary below. If a future feature depends on consent, a policy update alone will not replace an appropriate consent request in the feature itself.
Added static-hosting boundaries, browser storage, optional AI and device features, scientific data provenance, providers, transfers, retention, rights, children’s privacy, security limitations, and contact routes.