Astro Dadi logoAstro Dadi

Legal

Privacy Policy

Effective 19 July 2026. This policy explains how Astro Dadi collects, uses, shares, retains, and protects your personal data, and your rights under the Digital Personal Data Protection Act, 2023 (“DPDP Act”).

1. Data Fiduciary

The Data Fiduciary responsible for your personal data is {{LEGAL_ENTITY}}, registered office: {{REGISTERED_ADDRESS}}. We decide the purposes and means of processing your personal data.

2. Personal Data We Collect

  • Birth details you submit: date of birth, time of birth, and birth place.
  • Derived location data: latitude, longitude, and timezone for the birth place.
  • Account data (if you sign in with Google): name, email address, and profile image.
  • Usage data: charts you generate, chat messages with the AI, and saved sessions.
  • Billing data: subscription plan and payment status (card data is handled by Razorpay; we never see or store it).
  • Pseudonymous analytics data: sanitised page paths, broad product interactions, and a randomly generated browser identifier. If you sign in, we link this activity to an opaque internal account ID. We do not send your name, email address, birth details, chart or chat content, or payment details to analytics.
  • Technical data: IP address and user agent, used for security, rate limiting, and the temporary processing described in Section 6.

3. Purpose of Processing (per category)

  • Birth & location data — to compute your astrological chart and power AI chat answers.
  • Account data — to authenticate you and maintain your saved charts and chats.
  • Usage data — to provide the service, enforce plan limits, and improve reliability.
  • Billing data — to operate subscriptions and meet tax/accounting obligations.
  • Pseudonymous analytics data — to understand journeys across visits, measure aggregate use, and improve product flows.
  • Technical data — to protect the service from abuse and fraud.

4. Consent

We process your birth details on the basis of your consent, requested at the point you submit them. You may withdraw consent at any time from Settings → “Withdraw consent,” or by contacting the Grievance Officer. Withdrawing consent does not affect processing already carried out, and may mean we can no longer provide chart-based features.

5. Cross-Border Transfers

To deliver the service we share limited data with the following processors, some located outside India:

  • Google (Gemini AI, Google Sign-In) — AI processing and authentication (United States).
  • Nominatim / OpenStreetMap and Open-Meteo — geocoding place names (Germany).
  • Razorpay — payment processing (India).
  • Vercel — application hosting (United States).
  • Resend — transactional email (United States).
  • PostHog — pseudonymous product analytics (United States).
  • Sentry — operational error monitoring (United States).

We do not sell your personal data.

6. Pseudonymous Product Analytics

We use PostHog to understand page visits and broad product interactions. PostHog stores a randomly generated first-party analytics identifier in your browser so we can join activity across visits in that browser. If you sign in, we replace that analytics identifier with your opaque internal Astro Dadi user ID. We do not send PostHog your name, email address, or other profile properties.

PostHog may process technical request data such as your IP address, browser user agent, and hostname on its United States servers. We restrict event properties to sanitised routes and predefined product categories; URLs have query strings, fragments, and chart or chat identifiers removed before capture.

We disable session replay, surveys, heatmaps, automatic click capture, advertising profiles, and PostHog's own exception capture. We respect your browser's Do Not Track setting: browser analytics is not initialised, and billing analytics initiated from that browser carries the same suppression signal. Error monitoring is a separate, non-analytics function and is described in Section 7.

7. Operational Error Monitoring

We use Sentry solely to detect and diagnose software faults, so that broken pages, failed chart generation, and failed payments can be fixed. This is reliability engineering, not analytics and not tracking: Sentry receives no analytics identifier, no account identifier, no user record, and no behavioural event properties, and we do not use it to build any profile of you. Because it is not tracking, it is not governed by the Do Not Track behaviour described in Section 6 — but the categories excluded below are excluded for everyone, regardless of any browser setting.

Error reports are processed by Sentry in the United States and retained for 90 days, after which they are deleted. A report contains the error type and message, the source location in our own code, the normalised route (for example /chart/:id), the HTTP method and status, the runtime, the release, and the support request ID also shown to you when an error occurs.

We deliberately exclude, before any report leaves your browser or our servers: your name and email address; your IP address; birth date, birth time, birth place, coordinates, and timezone; chart data; chat questions, answers, and AI prompts or tool data; contact-form content; request and response bodies; form values; URL query strings and fragments; cookies and authorisation, session, and signature headers; chart, chat, session, and account identifiers; coupon codes; payment, subscription, and signature identifiers; API keys, tokens, and database credentials; and cache keys and values. Diagnostic console output is discarded rather than attached, and expected outcomes — validation failures, sign-in and permission checks, usage limits, and cancelled or stopped requests — are not reported at all.

We do not use Sentry for performance tracing, profiling, session replay, or logging.

8. Data Security & Storage

Personal data is stored in a managed PostgreSQL database that applies encryption at rest at the infrastructure level, and is transmitted over encrypted (HTTPS/TLS) connections. Access is restricted to the operation of the service.

9. Retention

We retain your personal data for as long as your account is active. Charts and chats of free-tier users may be deleted after 18 months of inactivity. Billing records are retained for 7 years to meet Indian tax law. On account deletion, data is purged within 30 days (see Section 11).

10. Your Rights

  • Access & portability — download all your data from Settings → “Export my data.”
  • Correction — edit your birth details and profile name in-app.
  • Erasure — delete your account from Settings → “Delete account.”
  • Withdraw consent — from Settings, at any time.
  • Grievance redressal — contact the Grievance Officer (Section 13).

11. Account Deletion

Deleting your account schedules permanent erasure after a 30-day grace period and cancels any active subscription. Signing in again within 30 days cancels the deletion.

12. Children's Data

Astro Dadi is not directed to children under 18. We do not knowingly collect personal data of minors, and we do not track, target advertising at, or profile minors. If you submit birth details on behalf of a minor, you confirm you are the parent or lawful guardian and consent to the processing. If you believe a minor’s data has been provided without proper consent, contact the Grievance Officer for removal.

13. Grievance Officer

In accordance with the DPDP Act and the IT Rules, 2021, our Grievance Officer is {{GRIEVANCE_OFFICER_NAME}}, reachable at {{GRIEVANCE_EMAIL}}. We aim to acknowledge and resolve grievances within 30 days. See our Grievance Redressal page for details.

14. Data Breach Notification

In the event of a personal data breach, we will notify the Data Protection Board of India and affected users in accordance with the timelines and manner prescribed under the DPDP Act.

15. Changes to this Policy

We may update this policy. Material changes will be communicated in-app or by email. The effective date above reflects the latest version.