Legal

Dasha Privacy Notice

Effective date: 2026-03-06 ยท Consent version: 2026-03-07a

This notice explains how Kiwi Agents processes data for Dasha. The service is designed around data minimization: we keep user state in the browser session where possible and limit operator analytics to privacy-preserving operational metadata.

Back to App Terms of Use

1. Data We Process

On-Device Data

  • saved profiles, chart state, chat history, downloaded reports, and preferences stored in your browser or, in the mobile app, on your device;
  • browser-session data is intended to disappear when the session ends; mobile-app data persists on your device until you delete it or use the in-app Clear Data control.

Optional Account Data (only if you register)

  • your email address and a Firebase Authentication identifier;
  • birth profiles you explicitly choose to import for cross-device sync, and nothing uploads automatically;
  • consent records, feature-usage counters, and subscription entitlement state;
  • if you purchase a subscription, transaction metadata from the app store and our subscription processor (we never see your card details).

Request Data Processed for Service Delivery

  • birth details, chart inputs, compatibility inputs, uploaded file bytes, and request parameters needed to calculate and return the result you asked for;
  • generated reports, readings, and chart outputs created in response to your request.

Operator Analytics

  • consented event records such as page views, chart calculations, coarse chat topic labels, model names, timestamps, feature usage counts, and request success/failure metadata;
  • a coarse device type (for example mobile or desktop, broad operating-system and browser family) and a rotating pseudonymous session identifier, used only to measure reliability, retention, and where the experience can be improved, never a precise device fingerprint;
  • we do not store raw chat prompts, precise location, your raw device identifiers or IP address, or publicly list user-uploaded files, as analytics content;
  • separately from analytics, and only when you are signed in, Dasha saves short factual notes drawn from what you tell it so you need not repeat yourself. Those notes are described in section 1a, are visible to you, and can be deleted individually or all at once.

1a. Voice, Memory, and Notifications

These three features involve data the rest of this policy does not otherwise describe. All three are optional. None of them operate unless you use them.

Voice input

  • If you tap the microphone and speak, the recording is sent to our transcription provider and converted to text.
  • We do not keep the audio. It exists only for the length of that request. Only the resulting text reaches the conversation, where you can edit or delete it before sending.
  • The microphone is accessed only while you are recording, and is released if you leave the screen.
  • If you never use voice input, no audio is ever captured or transmitted.

What Dasha remembers

  • When you are signed in, Dasha may save short factual notes from your conversations, such as a stated preference, an ongoing situation, or a goal, so later answers do not require you to repeat context.
  • These notes are limited in number and length, belong to your account alone, and are never combined with, compared against, or shared with another person's.
  • You can view every saved note and delete any or all of them in the app. Deleting your account deletes them with it.
  • If you are not signed in, nothing is remembered between conversations.

Push notifications

  • Nothing is sent unless you switch notifications on. There is no default and no promotional messaging.
  • Switching them on registers a device token that tells the notification service which device to reach. It is stored against your account and removed when you switch notifications off, sign out, or delete your account.
  • You choose which kinds you receive, and can set quiet hours during which nothing arrives.

2. Why We Use Data

  • to calculate natal charts, transits, compatibility results, reports, and daily guidance;
  • to process uploaded files during the active request;
  • to operate, secure, rate-limit, debug, and monitor the product;
  • to maintain operator analytics about feature usage and service reliability without relying on raw-content storage;
  • to investigate abuse, fraud, safety incidents, or legal requests where reasonably necessary.

3. Consent and Lawful Basis

We rely on your consent for the product data practices presented before use and on operational necessity to process the specific request you submit. If you do not agree, do not use the service.

If you submit another person's data, you represent that you have lawful authority and any consent required for that submission.

4. Storage Model and Retention

  • without an account, profiles, chat history, and preferences stay in your browser and are never sent to us as stored records;
  • with an account, we hold your account identity, any profiles you choose to sync, your entitlements, your notification preferences, and the facts Dasha has remembered about you;
  • operator analytics are retained for approximately 365 days unless a shorter or longer period is needed for security or legal handling;
  • uploads are processed for the active request and are not intended to persist as a shared library of user documents;
  • service providers and infrastructure logs may hold technical request records for their own operational windows;
  • account data (identity, imported profiles, consents, entitlements) is kept until you delete your account; deletion removes it promptly, keeping only a minimal pseudonymous deletion record and any transaction records the law requires us to retain;
  • we take periodic operational backups of server data, which age out on a short rolling window.

5. Service Providers and Transfers

Answering your request means sending parts of it to the providers below. They are named rather than described, because a list that says "providers configured for the deployment" tells you nothing you can act on. Each receives only what its job requires.

ProviderWhat it doesWhere
Amazon Web Services Hosting, databases, and backups (Mumbai region). India
Amazon Bedrock (AWS) Converts your question into a numeric vector so the answer can be grounded in classical texts. The question text is sent; nothing is retained by us from this step. India
Google (Gemini) Generates the readings and guidance you request. Outside India
Groq Transcribes voice recordings into text when you use voice input. Used only when you choose to speak. Outside India
Firebase (Google) Sign-in, and delivery of push notifications if you turn them on. Outside India
Google Maps Platform Turns a birth place into coordinates and a time zone. Outside India
Razorpay Processes payments made on the website. India
RevenueCat Tracks subscription state for purchases made in the mobile app. The purchase itself is handled by Apple or Google. Outside India

Providers outside India process data under their own terms and safeguards. Where a transfer leaves India, it happens because it is necessary to deliver the feature you asked for.

If you create an account, sign-in is provided by Firebase Authentication (Google). If you purchase a subscription in the mobile app, billing is processed by the Apple App Store or Google Play, and RevenueCat processes purchase state on our behalf. If you purchase a subscription on our website, payment is processed by Razorpay. In all cases we receive entitlement and transaction metadata only, never your payment card details.

We do not sell personal data. We may disclose data when reasonably necessary to comply with law, protect users, investigate abuse, or defend legal rights.

6. Security Measures

  • admin analytics are protected behind admin authentication;
  • API responses are configured with security headers and no-store caching for sensitive routes;
  • public saved-profile APIs are disabled and uploads are handled ephemerally.

No online system is risk-free. Do not submit information that would create unacceptable harm if compromised, and avoid sensitive third-party data unless you have a clear lawful basis to provide it.

7. Your Choices and Requests

  • you may stop using the service if you do not accept these data rules;
  • you may clear the current browser session using the in-app session reset control;
  • in the mobile app, the Clear Data control removes locally stored app data from your device;
  • if you registered, you can export your account data or delete the account yourself from the Account panel (web) or Settings (app). See how account deletion works;
  • app-store subscriptions are cancelled in your Apple or Google subscription settings. Deleting the account does not cancel an active store subscription;
  • website premium purchases via Razorpay are one-time payments for a fixed period. They do not auto-renew, and paid time stays active until the period ends;
  • you may contact us for access, deletion, or privacy questions, subject to identity verification, technical limits, and applicable law.

8. Your Rights, and How to Complain

If you are in India, the Digital Personal Data Protection Act, 2023 gives you rights over your personal data, and Kiwi Agents is the data fiduciary responsible for honouring them. If you are in a jurisdiction with comparable law, such as the UK or the European Union, we apply the same handling rather than maintaining a weaker path for you.

  • Access. Ask what personal data we hold about you and who we have shared it with.
  • Correction and completion. Ask us to correct anything inaccurate or fill in anything incomplete. Birth details, profiles, and remembered notes can also be edited directly in the app.
  • Erasure. Ask us to delete your data. Deleting your account does this, keeping only a minimal pseudonymous record that the deletion happened, plus any transaction record the law requires us to keep.
  • Withdraw consent. Withdraw it as easily as you gave it. Turning off notifications, deleting remembered notes, or deleting your account each withdraw consent for that processing, and none of them require you to contact us.
  • Nominate. Nominate another person to exercise these rights on your behalf if you are unable to.
  • Grievance redressal. Raise a complaint with us first, using the details below. If we do not resolve it, you may escalate to the Data Protection Board of India.

Write to our Grievance Officer at privacy@kiwiagents.com. We aim to respond within 30 days. Please write from the email address on your account, or include enough detail for us to find your records without exposing them to somebody else.

9. Contact

Privacy and data requests: privacy@kiwiagents.com