This Privacy Policy explains how [TBD — pending legal review] ("we,"
"us," or "our") collects, uses, retains, and
shares personal data when you use the service at [TBD — pending legal review] (the
"Service"). It is drafted principally for compliance with the
Digital Personal Data Protection Act, 2023 (India) ("DPDPA") and
is intended to also meet the substantive expectations of the
General Data Protection Regulation (EU) 2016/679 ("GDPR") for
visitors accessing the Service from the European Economic Area.
| Category | Fields | How collected |
|---|---|---|
| Birth details | Date of birth, time of birth, place of birth (geocoded to latitude, longitude, and time zone) | Directly from you when you request a Report |
| Email address | Email only — used for magic-link authentication and receipts | Directly from you at sign-in |
| Technical + minimal analytics | IP address, browser user-agent, referring URL, page timings | Automatically on visit |
| Generated Reports and chart images | SVG/PNG renderings + textual interpretations derived from your birth details | Server-side, at the moment of generation |
| Payment metadata | Razorpay payment_id, order_id, status, amount,
currency, timestamp. We never receive card, UPI, or bank account
numbers. |
Received from Razorpay after checkout |
We use the data listed above only for:
We do not sell your personal data. We do not use your personal data for third-party advertising. We do not build advertising profiles.
Under the DPDPA, we rely on your consent (§6 DPDPA) and on performance of the service you requested. Under the GDPR, we rely on Article 6(1)(b) (performance of contract) for generating and delivering Reports, and on Article 6(1)(a) (consent) for the research-mode opt-in and for marketing emails. Where birth data is treated as special-category data under Article 9, we rely on Article 9(2)(a) (explicit consent) — obtained via the layered consent flow described in §5.
We use the following processors. We do not share personal data with any other third party except as required by law.
/legal/subprocessors page) — transactional email delivery (magic-link
sign-in, receipts, Report links). Operated from the United States.A current sub-processor list is maintained at
[TBD — pending legal review]/legal/subprocessors and updated when a new processor is
onboarded.
Data is retained only for as long as necessary for the purpose for which it was collected, or as required by law. Specifically:
Research contributions derived from opt-in chart data are architecturally unlinkable from your account: at the moment of contribution creation, we discard the back-link to your chart identifier. This means we cannot later show you which specific studies used your contribution, because we do not keep a record connecting the contribution to you. This is a stronger privacy guarantee than "anonymised" — it is unlinkability by design. See §10.
As a Data Principal under the DPDPA (and, if applicable, a Data Subject under the GDPR), you have the following rights:
To exercise any right, contact [TBD — pending legal review].
Some processors we use (notably our transactional email provider) are located in
the United States. Where personal data is transferred outside India or the EEA, we
rely on Standard Contractual Clauses (SCCs) approved by the
relevant regulator, and on the recipient processor's own privacy commitments. A
current list of transfer destinations is available at
[TBD — pending legal review]/legal/subprocessors.
The Service is intended for users aged 18 years or older. We do not knowingly collect personal data from anyone under 18. If we become aware that we have collected personal data from a person under 18, we will delete it promptly.
We treat certain categories of information — including any labels that could
reveal medical, legal, political, or otherwise sensitive attributes — as
sensitive by policy, regardless of their classification under any
single statute. Our internal audience-scoped visibility policy
(extensions/cohort_visibility.py) governs which research categories are
accessible to which internal audiences, with a fail-safe default of the most
restrictive audience for any unclassified category.
When you opt in to "Help improve astrology" for a given chart, only the birth-chart scope becomes research-eligible by default. Annotations, journal entries, and any sensitive labels remain private to you and are never eligible for research contributions — this is enforced in code, not only in policy.
In the event of a personal data breach that is likely to result in risk to your rights and freedoms, we will notify you and the appropriate regulator without undue delay and, where feasible, within [TBD — pending legal review] hours of becoming aware of the breach.
We may update this Privacy Policy from time to time. Material changes will be announced by email to registered users and by a notice on the Service at least fourteen (14) days before taking effect.
As required by the DPDPA and the IT Rules 2021:
Where applicable under the GDPR, our Data Protection Officer (or equivalent contact) is: [TBD — pending legal review].