Legal

Dasha Privacy Policy

Privacy Notice under the Digital Personal Data Protection Act, 2023 · Effective date: 2026-09-13 · Consent version: 2026-09-13a

This policy explains what personal data Dasha processes, why, where it goes, how long it is kept, and what you can do about it. It is written to be complete rather than short. Every statement in it has been checked against what the software actually does; if you find one that is not true, tell us and we will fix the software or the policy.

Back to App User Agreement summary Terms of Use Astrology & AI Disclaimer Refund & Subscription Policy Account deletion

Summary in plain words

  • Who: Shrey Soni, an individual developer in Shahdol, Madhya Pradesh, India, operating as Kiwi Agents, is the Data Fiduciary (controller). Contact: privacy@dasha-astro.com.
  • Without an account, your profiles, charts, chat history and preferences stay in your browser or on your device. We compute what you ask for and keep nothing about you afterwards except pseudonymous usage statistics.
  • With an account, we hold your email, a sign-in identifier, the profiles you choose to sync, your consent records, your subscription state, the facts Samay remembers, and a push token if you turn notifications on. You can see, export and delete all of it yourself.
  • Birth data is sensitive. Because it is used for astrology, it may reveal religious or philosophical beliefs. We process it only with your explicit consent, only to do what you asked, and we never sell it.
  • AI: when you ask Samay something, your birth details, chart and message go to Groq (USA), and if Groq is down, Google Gemini (USA); questions may also be embedded via Amazon Bedrock (Mumbai) to search classical texts. They process it under their API terms to generate your answer, and do not use it to train their models. You give explicit consent first and can withdraw it at any time in Settings. No AI answer is advice: not medical, not legal, not financial.
  • No advertising, no tracking, no sale. We run our own privacy-preserving analytics only. No ad networks, no third-party trackers, no cross-site tracking, no fingerprinting.
  • Children: you must be 18 or older, or 13 to 17 with verifiable parental consent where the law allows. Nobody under 13.
  • Your rights: access, correction, erasure, withdraw consent, export, nominate, complain. We acknowledge requests within 7 days and resolve within 30. Escalate to the Data Protection Board of India (or your local authority) if we fail you.
  • Breach: we notify affected users without undue delay and within 72 hours of becoming aware, and the Data Protection Board as the law requires.

1. Who is responsible (Data Fiduciary / Controller)

  • Data Fiduciary: Shrey Soni, an individual, trading as Kiwi Agents, Shahdol, Madhya Pradesh, India.
  • Person who can answer on our behalf (DPDP Act s.8(9)) and Grievance Officer (s.13): Shrey Soni, privacy@dasha-astro.com.
  • Scope: this policy covers the website dasha-astro.com, the Dasha iOS and Android apps, the AI guide Samay, our emails to you, and our support mailbox.
  • Language: this policy is available in English. The DPDP Act entitles you to request it in any language listed in the Eighth Schedule to the Constitution of India; write to us and we will provide a translation.
  • No Data Protection Officer is legally required for an operation of our size (GDPR Art. 37 does not apply; the DPDP Act requires one only for Significant Data Fiduciaries, which we are not). The Grievance Officer above performs that function.

2. Data Inventory: every data element, in one table

"Device" means your browser or phone, under your control. "Server" means our application server and database hosted on Amazon Lightsail in Mumbai, India. "Transient" means the data passes through memory to do the job and is not written to disk. Lawful basis is stated for the DPDP Act (consent, or a "legitimate use" under s.7) and, where you are in the EU/UK, for the GDPR.

Data elementPurposeLawful basis / consent typeWhere it is storedRetentionWho can access it
Email addressCreate and secure your account; sign-in and verification; legal and service notices; supportConsent at sign-up; performance of the Terms (GDPR 6(1)(b))Firebase Authentication (Google); Server accounts databaseUntil you delete your account (removed from our database immediately; Firebase removes it from live and backup systems within 180 days)You; the operator (support and customer list); Firebase
Display nameAddress you in the app and in emailsConsent at sign-upFirebase Authentication; Server accounts databaseSame as emailYou; operator; Firebase
Firebase user ID (UID)Link your account to its profiles, consents, entitlements and purchases; RevenueCat app-user ID; reference in Razorpay order notesPerformance of the TermsServer accounts database; RevenueCat; Razorpay order notesReplaced by a keyed pseudonymous hash on deletion; the hash is purged after 30 daysYou (in export); operator; RevenueCat; Razorpay
Birth date, birth time, birth place, gender, profile nameCompute your chart, dashas, transits, Panchang, compatibility and numerology; sync profiles across your devices if you chooseExplicit consent (may reveal religious or philosophical beliefs; GDPR Art. 9(2)(a))Device (always); Server accounts database only for profiles you explicitly syncDevice: until you delete the profile or clear data. Server: until you delete the profile or your account (immediate)You; operator (database administration only); AI providers transiently when you ask Samay
Coordinates, time zone, verified place (derived from the birth place)Chart computationSame as birth dataWith the profile (device / server)Same as birth data. The place text is sent transiently to a geocoding provider (Section 3) and is not retained by us in any cache or logSame as birth data; geocoding provider transiently
Chart outputs (planet positions, houses, dashas, yogas, scores, reports)Show you the result you asked for; generate PDF reportsPerformance of the TermsComputed transiently on the server; kept on your device. A generated PDF report is held on the server for up to 24 hours so you can download itDevice: until cleared. Server PDF: 24 hours, or immediately on account deletionYou; operator (file storage, no PII in filenames)
Chat messages to Samay and its answersGenerate the answer you asked forExplicit AI-processing consent (separate switch; withdrawable in Settings)Device only (your browser or app storage keeps recent chat history). Sent transiently to the AI providers in Section 3. Not stored on our server and not written to our logs.Device: until you clear it (the web app keeps the most recent messages per profile). Server: noneYou; AI providers transiently under their retention terms (Section 3)
Facts Samay remembers (short notes such as a stated preference, situation or goal, extracted from a finished chat)So you need not repeat context in later chatsConsent (only when signed in; anonymous chats are never remembered)Server accounts database (max 50 notes per account, each under 400 characters)Until you delete the note (individually or all) or delete your account (immediate)You (view and delete in Settings); operator; the AI provider sees them transiently as part of your prompt
Voice recordings (only if you tap the microphone)Convert speech to textExplicit AI-processing consent plus your actionNowhere. Audio is held in memory and streamed to Groq's Whisper transcription API; only the text comes backNone; the audio is never written to disk by usGroq transiently
Uploaded files (PDF, up to 10 MB)Extract text so you can ask about itPerformance of the Terms; your actionNowhere. Parsed in memory in an isolated process; up to 5,000 characters of text are returned to youNone; nothing is written to disk and there is no file libraryNobody after the request completes
Device push token (only if you turn notifications on)Deliver the notifications you choseConsent (opt-in; off by default)Server accounts database; Firebase Cloud MessagingUntil you turn notifications off, sign out, or delete your account (immediate)Operator; Firebase
Notification preferences, quiet hours, time zoneSend only what you chose, when you allowConsentServer accounts databaseUntil changed or account deleted (immediate)You; operator
Purchase and entitlement metadata (plan, status, period end, RevenueCat event IDs and payload hashes, Razorpay order ID, payment ID, customer ID)Grant and verify Premium; prevent replayed or duplicate payments; tax and accounting recordsPerformance of the Terms; legal obligation (tax law)Server accounts database; RevenueCat; Razorpay; Apple / Google hold the actual transactionEntitlement records deleted with your account. Payment-event records are kept for as long as tax law requires but are unlinked from your identity on deletion. We never receive or store card, UPI or bank details.You (in export); operator; RevenueCat; Razorpay; Apple; Google
Consent records (version accepted, time accepted; AI-consent grant time)Prove which version of the Terms and this policy you accepted (DPDP s.6, GDPR 7(1))Legal obligation; performance of the TermsServer accounts database (signed-in users); device (all users); anonymous web acceptances also produce one pseudonymous analytics eventUntil account deletion; analytics copy per the analytics retention belowYou (in export); operator
Usage counters (how many AI answers, reports or profiles you used in the current window)Enforce free-tier and fair-use limitsPerformance of the TermsServer accounts databaseRolling window; deleted with your accountYou (in export); operator
Analytics events (event type, timestamp, path, coarse device type / OS family / browser family, whitelisted properties such as feature name, model name, success/failure, length bucket of a question, never the question)Measure reliability, retention and which features are usedConsent (no event is recorded unless the request carries an accepted, current consent version)Server analytics database and a rotating event log file365 days, then deleted automaticallyOperator (admin dashboard behind authentication)
Pseudonymous visitor key and session key (salted one-way hashes of a random ID your device generates)Count distinct visitors and sessions without identifying youConsent (as above)Server analytics store365 daysOperator
IP addressDeliver the service (TLS); rate limiting; blocking abuseLegitimate use: security and service delivery (DPDP s.7; GDPR 6(1)(f))Transient in-memory rate-limit windows (minutes); operating-system access logs on the server. Never stored in analytics and never joined to your accountRate-limit windows: minutes. Access logs: rolling, not more than 30 days. Firebase separately logs sign-in IPs for a few weeksOperator; hosting provider; Firebase (sign-in)
User agent (browser / app identification string)Serve the right content; coarse device statisticsLegitimate useParsed transiently into coarse buckets (for example "mobile / android / chrome"); the raw string is not stored in analytics; may appear in access logsAccess logs: not more than 30 daysOperator
Answer feedback (thumbs up/down, model name, lengths)Improve SamayConsent (your action)Server file30 daysOperator
Daily-guidance cache (profile name, date of birth, the day's generated text)Avoid calling the AI again for the same day's guidancePerformance of the TermsServer cache directoryCleared at every server restart or deploymentOperator
Weekly and monthly outlook cache (the generated outlook text for a calendar window, filed under a one-way hash of the birth details; no name and no birth data are written)Avoid calling the AI again for the same outlook windowPerformance of the TermsServer cache directoryUntil the operator clears the cache directory; the entry cannot be linked to you without the birth details that produced itOperator
Emails you send us (support, grievances, rights requests)Answer you; keep a record of the requestPerformance of the Terms; legal obligation (grievance records)Received through Amazon SES and forwarded to our Google mailboxAs long as needed to resolve the matter and to evidence that we did, then deletedOperator
Error reports (if error monitoring is enabled)Detect crashes and bugsLegitimate useSentry, configured with personal data sending disabled, no request bodies and no local variablesPer Sentry's retention (90 days by default)Operator; Sentry

We do not collect: precise location, contacts, photos, health data, biometric data, government IDs, payment card numbers, advertising identifiers, or anything from other apps on your device.

3. Sub-processors: who receives data, where, and why

Each provider below is a Data Processor acting on our instructions, receives only what its job needs, and is bound by its own published terms, linked here. We review this list when we change a provider and update the policy before the change takes effect.

ProviderCountryPurposeData sharedTheir retentionTheir privacy terms
Amazon Web Services (Lightsail) India (Mumbai) Hosting the application server, databases and nightly backups. Everything stored server-side (Section 2). Under our control; see Section 4. Privacy terms
Groq (GroqCloud) USA AI text generation for Samay chat, guidance, and reports. Also transcribes voice recordings into text when you use voice input. Birth details, computed chart, remembered facts, your message; voice audio for transcription. Not retained by default; may be logged for up to 30 days only to troubleshoot errors or investigate abuse; not used for training. Privacy terms
Amazon Web Services (Bedrock) India (Mumbai, ap-south-1) Text embeddings for grounding classical-text search: converts your question into a numeric vector so the answer can be matched against classical sources. Nothing is retained by us from this step. The text of your question. Zero data retention: inputs and outputs are not stored, logged or shared with model providers. Privacy terms
Google Gemini API USA Fallback AI text generation when Groq is unavailable. Birth details, computed chart, remembered facts, your message. Processed under the paid Gemini API terms; not used to improve Google products. Privacy terms
Firebase Authentication and Cloud Messaging (Google) USA / outside India Sign-in, and delivery of push notifications if you turn them on. Email, display name, sign-in identifier and sign-in IP logs; push token. Sign-in IP logs a few weeks; user records until we delete the user, then removed from live and backup systems within 180 days. Privacy terms
Resend USA Delivers account emails (verification, password reset) sent by Firebase Authentication. Your email address and the message. Only as long as necessary to deliver and log the message, under Resend's policy. Privacy terms
Amazon Web Services (SES inbound email) and Google (Gmail) India / USA Receives emails you send to our support and privacy addresses and forwards them to our mailbox. Your email address and what you write to us. Until the matter is resolved and evidenced. Privacy terms
Google Maps Platform (Geocoding) USA / outside India Turns a birth place into coordinates and a time zone. The birth-place text only (never who it belongs to). Per Google's API terms; we keep no query cache. Privacy terms
Nominatim (OpenStreetMap Foundation) and ArcGIS (Esri) Outside India Fallback geocoding when Google Maps is unavailable. The birth-place text only. Per their published policies; we keep no query cache. Privacy terms
Apple (App Store) USA Billing for subscriptions bought in the iOS app. Handled entirely by Apple under your Apple ID; we receive entitlement state only. Per Apple's policy. Privacy terms
Google Play USA Billing for subscriptions bought in the Android app. Handled entirely by Google under your Google account; we receive entitlement state only. Per Google's policy. Privacy terms
RevenueCat USA Tracks subscription state for purchases made in the mobile app. The purchase itself is handled by Apple or Google. Your account ID (Firebase UID), Apple receipt or Google purchase token, device type. Until we delete your customer record on account deletion. Privacy terms
Razorpay India Processes payments made on the website. Payment details you enter into Razorpay's own checkout; from us, a plan name and account ID only. As required of a regulated payment aggregator under RBI rules. Privacy terms
Sentry (only if error monitoring is enabled) USA Crash and error reports. Error type and stack trace; personal data sending, request bodies and local variables are disabled. Per Sentry's policy (90 days by default). Privacy terms

AI processing in detail

AI features send your birth details, the chart data computed from them, any facts Samay remembers, and the message you type to Groq (GroqCloud), Amazon Web Services (Bedrock), and, when Groq is unavailable, the Google Gemini API, only to generate the answer you asked for. These providers act as processors on our behalf and do not use the data to train their models under their API terms. You give explicit consent in the app before the first AI request and can withdraw it at any time in Settings, after which no further AI requests are made. No AI output is medical, legal, or financial advice.

  • Groq states that by default it does not retain inference inputs or outputs, that it may temporarily log them for up to 30 days only to troubleshoot errors or investigate abuse, and that its systems are in the United States.
  • Amazon Bedrock operates a zero-data-retention model for the embedding call we make (used only when classical-text grounding is enabled): inputs are not stored, not logged and not shared with model providers. The call is made in the Mumbai (ap-south-1) region.
  • Google Gemini API is our fallback only. We use it under the paid API terms, under which Google does not use prompts or responses to improve its products.
  • We may add, remove or switch AI providers. The list above is kept current and a material change will be presented for re-consent in the app.

Transfers outside India

Groq, Google (Firebase, Gemini, Maps), RevenueCat, Apple, Resend and Sentry process data in the United States or other countries outside India. Hosting (Lightsail), Bedrock and Razorpay are in India. The DPDP Act permits transfer to any country the Central Government has not restricted; we will not transfer data to a restricted country. For EU/UK users see Section 13.

4. Retention and deletion schedule

DataKept untilHow it is deleted
Account identity (email, name, UID), synced profiles, consents, entitlement state, usage counters, remembered facts, push tokens, notification preferences, web-subscription record, pending PDF reportsYou delete your accountDeleted immediately by the deletion request; your Firebase identity is deleted; your RevenueCat customer record is deleted
Deletion tombstone (a keyed hash proving deletion happened; no email, no name)30 days after deletionPurged automatically by a background job
Payment-event records (Razorpay / RevenueCat event IDs and payload hashes)As long as tax and accounting law requiresUnlinked from your identity on deletion; contain no card data
Chat history, AI answersOn your device until you clear itNever stored on our server. Groq: not retained by default (≤30 days if logged for abuse or troubleshooting). Bedrock: zero retention. Gemini: processed transiently under the paid API terms
Voice audio, uploaded filesDuration of the requestNever written to disk
Generated PDF reports24 hoursPurged automatically; purged immediately on account deletion
Analytics events and pseudonymous keys365 daysPurged automatically from the durable store and the event log
Answer feedback30 daysPurged automatically
Daily-guidance cacheNext server restart or deploymentCleared at startup
Weekly and monthly outlook cache (generated text under a one-way hash; no name, no birth data)Until the operator clears the cache directoryDeleted by the operator; not linkable to a person
Server access logs (IP, user agent, path)Not more than 30 daysRotated by the operating system
Server backups (nightly archive of the databases)The 14 most recent nightly backups are keptOlder archives are deleted automatically, so deleted data disappears from backups within 14 days. Backups are used only for disaster recovery and are never used to restore an individual's deleted data
Firebase Authentication copiesUntil we delete your userGoogle removes them from live and backup systems within 180 days
Support emailsUntil the matter is resolved and evidencedDeleted from the mailbox

Under DPDP Act s.8(7) we erase personal data when you withdraw consent or when its purpose is served, whichever is earlier, unless a law requires us to keep it. Under s.8(8) we cause our processors to do the same.

5. Consent Ledger: what we record when you accept, and how you withdraw

What is recorded

  • Signed-in users: the consent version you accepted (for this edition, 2026-09-13a) and the date and time you accepted it, stored against your account. Nothing else: no IP address, no device details.
  • All users: the accepted version is stored on your device so the app does not ask again until the version changes.
  • Web acceptances without an account: one pseudonymous analytics event recording the version and that you confirmed you are over 18, under the salted visitor key described in Section 2. It is not linked to an email or an IP address.
  • AI processing: the date and time you allowed AI processing is stored on your device (shown as "Allowed on …" in Settings). Requests to AI features carry the current consent version; without it, no AI request is made.
  • Age: we record that you confirmed you are at least 18 (or that your parent or guardian consented). We do not collect your date of birth for this purpose.

How to withdraw

  • AI processing: Settings → AI processing → turn off. No further AI requests are sent from that moment. Turning it back on is a fresh consent.
  • Notifications: Settings → Notifications → turn off. The push token is removed.
  • Remembered facts: Settings → What Samay remembers → delete any or all.
  • Profile sync: delete a synced profile in the app; it is removed from the server.
  • Everything: Settings → Account → Delete account (app) or Account → Delete account (web). See Section 10.
  • Local data: the Clear Data control (app) or clearing site data (browser) removes what is on your device.

Withdrawing consent is as easy as giving it, as DPDP Act s.6(4) requires, and never needs an email to us. Withdrawal does not affect the lawfulness of processing before it.

6. Purposes and lawful bases, in one list

PurposeDPDP Act basisGDPR / UK GDPR basis (EU/UK users)
Computing charts, dashas, transits, compatibility, numerology, Panchang and reports from birth dataExplicit consent (s.6)Art. 6(1)(a) consent and Art. 9(2)(a) explicit consent
Generating AI answers and remembering facts you tell SamayExplicit consent, separately given (s.6)Art. 6(1)(a) and 9(2)(a)
Creating and operating your account; syncing profiles; notifications you turn onConsent (s.6)Art. 6(1)(b) contract; Art. 6(1)(a) for notifications
Selling and verifying subscriptions; preventing duplicate or fraudulent paymentsConsent; legitimate use for the specified purpose (s.7(a))Art. 6(1)(b) contract; 6(1)(c) legal obligation (tax)
Security, rate limiting, abuse prevention, debuggingLegitimate use (s.7)Art. 6(1)(f) legitimate interests
Product analyticsConsent (s.6)Art. 6(1)(a) consent
Responding to rights requests, grievances and legal processLegitimate use; legal obligation (s.7)Art. 6(1)(c)

We do not use your data for advertising, profiling for marketing, selling, or any purpose not listed here. We do not make automated decisions that have legal or similarly significant effects on you.

7. Children

  • You must be at least 18 years old to use the Service. Under the DPDP Act, anyone under 18 is a child.
  • If you are 13 to 17, you may use the Service only where local law allows and only with the verifiable consent of your parent or lawful guardian (DPDP Act s.9(1)); the parent or guardian must contact us at privacy@dasha-astro.com so that we can verify their identity and record their consent before the account is used.
  • We do not, for any user, and will not, for a child, undertake tracking, behavioural monitoring or targeted advertising (s.9(3)), and we do not process a child's data in any way likely to harm their wellbeing (s.9(2)). We do not profile children.
  • Nobody under 13 may use the Service. We do not knowingly collect data from children under 13 (COPPA). If we learn that we have, we delete it and the account.
  • If you enter a child's birth details as a profile, you confirm you are that child's parent or lawful guardian.

8. Security practices

  • Encryption in transit: all traffic between your device and our server, and between our server and every processor, uses HTTPS/TLS. HTTP Strict Transport Security (HSTS) is enabled on our domain.
  • Hardened responses: a strict Content-Security-Policy that names every host the app may talk to, no-store caching for all account and API routes, and standard protections against framing, MIME sniffing and referrer leakage.
  • Secrets: all credentials and API keys live in environment configuration, never in code or the app; the server refuses to start in production with default or weak secrets.
  • Least privilege: each processor receives only the fields it needs (for example Razorpay receives a plan name and an account ID, not your email; geocoders receive a place name, not who it belongs to).
  • No card data: payments are entered into Apple, Google or Razorpay's own checkout; we never see or store card, UPI or bank details.
  • Pseudonymised analytics: no IP address, no raw device identifiers, no question text.
  • Isolation: uploaded files are parsed in memory in a resource-limited separate process and never stored.
  • Access control: the admin dashboard is behind authentication with rate-limited login; account deletion requires a recent sign-in (within 5 minutes) and export requires a signed-in session; rate limits apply per account and per IP.
  • Backups: nightly, kept for 14 days, on the server and optionally in a private cloud bucket in the same account, used only for disaster recovery.
  • Sole operator: only the operator has administrative access. There are no employees, contractors or resellers with access to personal data.
  • No system is perfectly secure. Do not enter information whose exposure would cause you serious harm, and do not enter other people's data unless you are entitled to.

Personal data breach notification

  • If a breach affects your personal data we will inform you without undue delay and in any event within 72 hours of becoming aware, through your account email or the app, describing what happened, the likely consequences, what we have done, what you can do, and whom to contact (DPDP Rules, 2025, Rule 7(1)).
  • We will intimate the Data Protection Board of India without delay and file the detailed report within 72 hours as the Act (s.8(6)) and Rules require, and, for EU/UK users where applicable, the relevant supervisory authority within 72 hours (GDPR Art. 33).

9. Your rights and how to exercise them

Rights under the Digital Personal Data Protection Act, 2023 (all users)

  • Access (s.11): a summary of the personal data we process about you, how we process it, and the identities of every Data Fiduciary and Processor we have shared it with. Section 2 and Section 3 of this policy are that summary; the export in Section 10 gives you the data itself.
  • Correction, completion, updating and erasure (s.12): edit profiles, remembered facts and your name directly in the app; ask us for anything else; delete your account to erase everything we are not legally required to keep.
  • Withdraw consent (s.6(4)): Section 5.
  • Grievance redressal (s.13): write to the Grievance Officer. You must give us the chance to resolve a grievance before approaching the Board.
  • Nominate (s.14): name a person who may exercise these rights if you die or become incapacitated. Email us their name and contact details from your account address.
  • Complain to the Data Protection Board of India (s.13(3), s.18) if we do not resolve your grievance.

Request procedure and service levels

  1. Self-service first: export, correction, consent withdrawal and deletion are all available in Settings / Account without contacting us.
  2. Otherwise email privacy@dasha-astro.com from the email address on your account. Say which right you are exercising and what you want.
  3. Identity verification: to protect you we act only on requests we can tie to the account. Writing from the account email is normally enough; if not, we may ask you to confirm a code sent to that address or to sign in. We never ask for your password.
  4. Acknowledgement within 7 days; resolution within 30 days of a verified request (one month under GDPR, extendable by two months for complex requests with notice). Grievances under the IT Rules are acknowledged within 24 hours and resolved within 15 days.
  5. No fee, unless a request is manifestly unfounded or excessive, in which case we may decline and explain why.
  6. Refusals are given in writing with reasons and with the route to complain.

10. Data export and account deletion

Export

  • App: Settings → Account → Export data. Web: Account → Export data. You must be signed in.
  • You receive a JSON file (named dasha-astro-account-export-YYYYMMDD.json) containing your account identity, every consent record, every synced profile, your entitlement state and history, usage counters, and payment-event processing metadata. It states explicitly that raw provider records are excluded and that we hold no payment card data.
  • Data that lives only on your device (chat history, local charts, preferences) is already yours; the Clear Data control lists it.

Deletion

  • App: Settings → Account → Delete account. Web: Account → Delete account. A recent sign-in (within 5 minutes) is required.
  • Immediately: your email, name and identity are removed; profiles, consents, entitlements, usage counters, remembered facts, push tokens, notification preferences, web-subscription record and pending PDF reports are deleted; your Firebase Authentication user and your RevenueCat customer record are deleted.
  • Within 30 days: the pseudonymous deletion tombstone is purged by a background job.
  • Within 14 days: the last nightly backup containing your data ages out.
  • Kept: payment-event records required by tax law, unlinked from you; pseudonymous analytics that were never linked to you.
  • Deleting your account does not cancel an Apple or Google subscription; cancel it in the store.
  • Full details: how account deletion works.

11. Cookies and local storage

  • No third-party cookies, no advertising cookies, no trackers, no fingerprinting.
  • Cookies we set: dasha-consent-<version> (records that you accepted the current consent version; 365 days). The operator's own admin login uses dasha_admin_session; it is never set for users.
  • Local storage on your device (web app and mobile app), all strictly necessary to run the app:
    • dasha_consent, dasha.aiConsent.v1 — your consent choices and when you made them; dasha_consent_required_version, dasha_consent_synced — which consent version the server currently asks for and whether your acceptance has been recorded against your account;
    • dasha_account_entry_seen, dasha_account_guest_mode — whether you have seen the sign-in screen and whether you chose to continue as a guest;
    • astro_profile, astro_saved_profiles_v1, astro_chart_v1, dasha_profile_client_ids_v1 — your profiles and current chart;
    • astro_chat_v1 — recent chat history with Samay;
    • astro_chart_style_v1, astro_theme, dasha.language, dasha.answerMode — display preferences;
    • dasha_report_job_v1 — the ID of a PDF report you asked for;
    • dasha_visitor_id, dasha_session_id — random IDs used only to hash the pseudonymous analytics keys in Section 2.
  • Session storage: your Firebase sign-in token is held in session storage (cleared when the tab closes), never in local storage.
  • IndexedDB: the Firebase SDK keeps its own authentication state there.
  • Third-party checkout: if you pay on the website, Razorpay's checkout runs in its own frame and may set its own cookies and load its own analytics under Razorpay's privacy policy, for the duration of the payment. If you sign in with Google, Google sets its own cookies under Google's policy.
  • Clear all of this with the in-app Clear Data control, or by clearing site data in your browser.

12. Sharing and disclosure

  • We share personal data only with the processors in Section 3, only for the purposes stated.
  • We do not sell personal data, do not share it for advertising, and do not give it to data brokers.
  • We may disclose data where the law requires (for example a valid order from a court or authority in India), or where reasonably necessary to protect users, investigate abuse or fraud, or defend legal claims; we will disclose only what is required and, where lawful, tell you.
  • If the Service is transferred to a company we form or to a successor operator, your data moves with it under this policy; you will be notified and may delete your account before the transfer.

13. Additional information for users in the EU, EEA and UK (GDPR / UK GDPR)

  • Controller: Shrey Soni (Kiwi Agents), Shahdol, Madhya Pradesh, India. Contact: privacy@dasha-astro.com.
  • Lawful bases: Section 6. Birth data used for astrology is treated as special-category data (religious or philosophical beliefs, Art. 9) and processed only with your explicit consent (Art. 9(2)(a)).
  • Representative: we have not appointed a representative under Art. 27 because our processing of EU/UK residents' data is occasional, is not large-scale, and is unlikely to result in a risk to your rights (Art. 27(2)(a)). If that changes we will appoint one and update this policy.
  • International transfers: India has no adequacy decision. Transfers to processors in the USA rely on the Standard Contractual Clauses included in those processors' data-processing agreements (AWS, Google, Groq, RevenueCat, Resend, Sentry). The transfer from you to us in India is necessary to perform the contract you asked for (Art. 49(1)(b)) and is also covered by your explicit consent after being informed here that India lacks an adequacy decision and that Indian law may allow government access under conditions different from EU law (Art. 49(1)(a)). You may withdraw that consent by deleting your account.
  • Your rights: access (Art. 15), rectification (16), erasure (17), restriction (18), portability (20; the export in Section 10 is machine-readable JSON), objection (21, including to processing based on legitimate interests), withdrawal of consent (7(3)), and the right not to be subject to solely automated decisions with legal or similarly significant effects (22; we make none).
  • Complaints: you may lodge a complaint with your national supervisory authority (EU) or the Information Commissioner's Office (UK), but we would welcome the chance to resolve it first.
  • Retention: Section 4. Recipients: Section 3. Whether provision is mandatory: birth data is required to compute a chart; an email is required for an account; everything else is optional.

14. Information for California residents (CCPA/CPRA)

  • We are below every threshold that makes a "business" subject to the CCPA (annual revenue, number of California consumers, revenue from selling data). We nevertheless state, for clarity: we do not sell or share personal information, we do not use it for cross-context behavioural advertising, and we do not use or disclose sensitive personal information for any purpose other than providing the service you asked for.
  • The rights to know, delete, correct and to data portability described in Section 9 and Section 10 are available to you on the same terms as everyone else, and we will not discriminate against you for exercising them.
  • Categories collected (in CCPA terms): identifiers; account and commercial information; internet activity (our own analytics only); inferences drawn for astrological interpretation; and, in the sense of Cal. Civ. Code §1798.140(ae), sensitive personal information limited to data revealing religious or philosophical beliefs via birth data and messages you choose to send.

15. How this maps to the Apple and Google privacy labels

Store categoryCollected?Linked to you?Used for tracking?Detail
Contact info (email, name)Yes, if you create an accountYesNoSection 2
User content (birth data, profiles, messages, remembered facts)YesYes for synced profiles and remembered facts; messages are not stored by usNoSection 2, 3
Identifiers (user ID)YesYesNoFirebase UID
Purchases (purchase history)YesYesNoEntitlement metadata only; no card data
Usage data (product interaction)Yes, with consentNo (pseudonymous)NoAnalytics, 365 days
Diagnostics (crash data)Only if error monitoring is enabledNoNoSentry with PII disabled
Sensitive info (birth data, because it is used for astrology and may reveal religious or philosophical beliefs, Section 2 and Section 14)Yes, with explicit consentYes for synced profilesNoApp functionality only; the same birth data as the user-content row above
Location, contacts, health, financial info, browsing history, search history, photos, audio (stored)No——Voice audio is transcribed transiently and never stored; the birth place is text you type, not your device location
Data shared with third partiesYes: AI providers (Groq, Google Gemini, AWS Bedrock) for app functionality; Firebase, RevenueCat, Razorpay, geocoders as processors—NoSection 3
Tracking (App Tracking Transparency)None. We do not track you across apps or websites and do not use the advertising identifier.

Data is encrypted in transit; you can request deletion in the app (Google Play Data safety "data deletion" requirement) and at /account/deletion.

16. Changes to this policy

  • We update this policy when the software, a provider or the law changes. Every version carries an effective date and a consent version at the top.
  • Material changes (a new category of data, a new purpose, a new AI provider, a longer retention period) are presented for re-consent in the app before they apply to you. Non-material changes take effect on publication.
  • The version you accepted and when is kept as described in Section 5.

17. Contact

Grievance Officer and privacy contact: Shrey Soni, privacy@dasha-astro.com · Support: support@dasha-astro.com · Data Fiduciary: Shrey Soni (Kiwi Agents), Shahdol, Madhya Pradesh, India.

Data Protection Board of India: established under s.18 of the Digital Personal Data Protection Act, 2023; complaint channels are published by the Board and the Ministry of Electronics and Information Technology.

Version 2026-09-13a · Effective 2026-09-13