Privacy Policy
Last updated: 6 June 2026
This Privacy Policy explains what personal data Kundli Saathi ("we", "us") collects from you, why we need it, and the rights you hold under the Digital Personal Data Protection Act, 2023 (DPDP Act). We have written it in plain language; the legally operative terms are still binding.
What data we collect
To compute a Vedic astrological chart and personalize a reading, we collect: your first name and (optionally) last name; date, time, and place of birth; phone number (for OTP login and order confirmations); email address (optional, for receipts and editorial newsletters); and payment references (order ID, payment ID, transaction status) returned to us by Razorpay.
When you read articles or interact with the site, we additionally collect aggregate behavioural signals (page views, time on page, scroll depth) via Cloudflare Web Analytics — a cookieless, privacy-preserving analytics service. No individual identifier is attached to these aggregates.
If you allow it, we also use Google Analytics 4. Unlike the Cloudflare measurement above, it stores cookies (`_ga`, `_ga_*`) that let Google recognise your browser across visits, and it processes your data in the United States. In the EU and UK it runs only after you switch it on in the cookie banner — choosing "Accept essential only" keeps it off. Everywhere else it is on by default and you can turn it off from the same banner. We do not link it to your account, and we run no advertising or remarketing features.
Why we collect it
Birth details are the only inputs that allow a Jyotisha chart to be computed at all. Phone and email enable order confirmations and account recovery. Payment references let us verify that an order was actually paid before we deliver a reading. Behavioural signals let us understand which articles are useful to readers and which should be rewritten or retired.
We do not sell your data. We do not use your data to train third-party AI models. We do not run targeted advertising.
Data we do NOT store
We do NOT store: card numbers, CVV, UPI ID, banking credentials, Aadhaar, PAN. Card-based payments are handled directly by Razorpay (PCI-DSS Level 1 certified) on their hosted checkout — your card data never reaches our servers. We retain only the transaction reference identifiers that Razorpay returns to us after the payment is complete.
We do not store your billing address beyond what is necessary for invoice generation, and we do not store any government-issued identity number.
Where your data lives and how it is protected
All personal data is hosted on Supabase infrastructure in the Mumbai (ap-south-1) region. Database records are encrypted at rest. Per-row access control (RLS) ensures that only your authenticated session can read rows belonging to your account, and our application servers enforce the same boundary on their side.
Backups are encrypted, region-resident, and retained for 30 days. Access to production credentials is restricted to a small operations team and rotated on a schedule.
Third parties we share data with
Razorpay Software Pvt Ltd — payment processing. They receive the data necessary to charge your card or UPI account; we receive only the transaction reference back.
Anthropic, PBC — large-language-model inference for generating personalized readings. We send a structured prompt that includes your first name and computed chart attributes; we do NOT send raw birth coordinates. Anthropic processes inputs on a no-training basis under our Zero Data Retention configuration.
Supabase Inc. — database and storage hosting in the Mumbai region.
Cloudflare, Inc. (US) — cookieless Web Analytics; no individual identifier is collected.
Google LLC (US) — Google Analytics 4 audience measurement, only where you have consented (see above). Google receives your IP address, the pages you view, and a cookie identifier for your browser.
No third party other than the above receives your personal data.
Data retention
Generated readings, charts, and order records are retained for as long as your account is active, so you can re-open them. If you delete your account, we keep records in a soft-deleted state for 90 days (in case of accidental deletion or chargeback dispute), after which they are permanently erased except for the minimum tax/accounting record we are legally required to retain (transaction amount and date).
You may delete your account yourself at any time by sending an authenticated POST to /api/account/delete. We immediately mark your data as soft-deleted, sign you out of all devices, and start the 90-day cancel window — you can restore your account during that window via /api/account/delete/cancel. After 90 days the data is permanently erased except for the legally required tax/accounting record. Email privacy@kundlisaathi.com if you would prefer human-assisted deletion or have questions.
Your rights under DPDP §11–§13
You have the right to (a) access the personal data we hold about you, (b) correct inaccuracies, and (c) request erasure. Erasure is now self-serve via /api/account/delete (90-day soft-delete window with cancel via /api/account/delete/cancel). For access and correction, write to privacy@kundlisaathi.com from the email or phone number associated with your account; we will respond within 30 days, as required by law.
For data portability (DPDP §11 / GDPR Art. 20), signed-in users can download a JSON export of their account at /api/account/export — the file contains your kundlis, readings, matches, comments, saves, chat history, non-sensitive payment references, and your consent attestations (DPDP §6 prove-ability, joined by sha256(your phone)).
You have the right to nominate a person who may exercise these rights on your behalf in case of incapacity or death (DPDP §14). Include the nominee’s contact in the same email.
If you are not satisfied with our response, you may approach the Data Protection Board of India.
Children
Kundli Saathi is not intended for children. We do not knowingly serve readings to anyone under 18 years of age and do not knowingly collect personal data from minors. If you believe we hold data about a minor, write to privacy@kundlisaathi.com and we will erase it.
Security incidents
In the event of a personal data breach, we will notify affected users and the Data Protection Board within 72 hours of becoming aware of the breach, in line with DPDP §8(6). The notification will include the nature of the breach, the categories of data involved, and the steps we have taken or recommend you take.
Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent change. Material changes (new categories of data, new third-party recipients, new retention periods) will be notified to you by email at least 14 days before they take effect.
Contact
For any privacy-related question or to exercise your DPDP rights, write to privacy@kundlisaathi.com. Please include your registered phone number or email so we can locate your account.
Birth data as special category data (GDPR Article 9)
For visitors in the United Kingdom and the European Union: your date, time, and place of birth — together with the astrological readings we generate from them — can reveal, or be treated as, "special category" personal data under Article 9 of the UK and EU GDPR. We therefore process this data only on the basis of your explicit consent (Article 9(2)(a)), which you give through the dedicated processing-consent checkbox at sign-in.
You can withdraw that consent at any time by deleting your account (see "Data retention" above), which erases the associated birth details and readings after the 90-day soft-delete window. We do not use your birth data for any purpose other than generating and storing your own readings, and we never sell it or use it to train third-party AI models.
California residents — CPRA rights
If you are a California resident, the California Privacy Rights Act (CPRA) gives you the right to limit how we use your sensitive personal information. Submit an opt-out request below.
Limit the Use of My Sensitive Personal Information
If the link is not responsive, email privacy@kundlisaathi.com with "CPRA Limit Use" in the subject line.