Privacy Policy
Last updated: 17 May 2026.
1. What we collect
- Account data: email, display name, authentication tokens.
- Birth chart data: name, date, exact time, and place of birth that you provide. Used only to compute your kundli and to personalize AI responses.
- Chat & journal content: messages you send and the AI's responses, stored so you can revisit them.
- Vision uploads (palm/face): the image is sent to the AI vision model for reading and then permanently deleted from our storage and database. Only the text reading is retained.
- Voice audio: recordings are transcribed and may be retained briefly to verify the transcription, after which the audio is deleted.
- Billing data: we receive a payment-success token from Razorpay; we do not see or store your full card number, CVV, or UPI PIN.
- Operational data: IP, browser, timestamps, error traces, and rate-limit counters for security and abuse prevention.
2. How we use it
- To provide and personalize the Service (compute charts, generate readings, remember context across turns).
- To process payments and grant the corresponding plan access.
- To prevent fraud, abuse, and unauthorized access.
- To comply with legal obligations and respond to lawful requests.
- To send service-related notifications you opt into.
We do not sell your personal data. We do not use your private chats to train third-party AI models without your explicit consent.
3. Third-party processors
- Supabase — database, authentication, file storage.
- Razorpay — payment processing.
- AI provider (e.g. Groq, OpenAI, xAI) — generates text, vision, and voice responses from the prompts and chart data we send. Prompts may transit through these providers per their own privacy terms.
- Hosting / CDN — to serve the website.
4. Retention
- Account, birth profile, chat, journal, and reading text are retained until you delete them or close your account.
- Uploaded photos and voice files are deleted automatically after processing as described above.
- Backups may persist for up to 30 days for disaster recovery.
5. Your rights
Subject to applicable law, you may request access, correction, portability, or deletion of your personal data. You can:
- Export all your data as JSON from Settings.
- Delete individual journal entries, chats, or readings.
- Request full account deletion via our Contact page.
6. Children
The Service is not intended for children under 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us data, contact us and we will delete it.
7. Security
We use industry-standard measures including TLS in transit, row-level security in the database, and least-privilege service keys. No system is perfectly secure; you use the Service at your own risk.
8. International transfers
Your data may be processed in countries other than your own. By using the Service you consent to such transfers under the safeguards of this Policy.
9. Changes
We may update this Policy by posting a revised version. Material changes will be highlighted at the top of this page.
10. Contact
Privacy questions or requests may be sent via the Contact page.