iAstroGuru

Your information, with care

Privacy policy & data notice

What we collect, why we use it and the choices you have. Last updated: 4 October 2026.

Who this notice covers

This notice covers visitors, account holders and people whose details they add with permission. We collect data for the service, not public profiles. Birth profiles, charts and reports are private to the account. The operator/controller and Grievance Officer are listed below; missing details must be published before paid launch.

What we collect — notice at collection

  • Account identifiers: name and verified email from Google; or, with email-code sign-in, the email address whose emailed code you entered; or, when enabled, verified phone number and account identifier from Supabase phone sign-in. We never receive your Google password. Phone accounts store the number through an internal, undeliverable email-shaped identifier; it is not a real email address.
  • Birth profiles: supplied name, date and time of birth, time confidence, place, latitude/longitude, time zone and chosen astrology system, for you or people who give permission.
  • Charts and reports: calculation snapshots, engine version, calculated chart details, reading content and status, report preparations, linked partner profiles and generation/error attempt records.
  • Purchases: order ID, product, amount/currency, payment status, Razorpay order/payment/event references, signature verification, payment-event evidence and paid access entitlements. We do not store card numbers, CVV or banking passwords.
  • Consent and service records: consent type, version and time; reading-request identifiers, input hashes, status and timing; and the report launch waitlist you join.
  • Security and operations: hashed session identifiers and expiry, email sign-in codes stored only as hashes (purpose: sign-in; kept 10 minutes or until used), rate-limit counters using hashed IP addresses, phone numbers or email addresses, and owner security/admin logs. When AI is enabled, a usage record notes the purpose, report/profile references and usage.
  • Browser preferences and temporary details: cookies, localStorage and sessionStorage listed below. Messages and replies you send to support are also held in the support inbox.

We do not normally request a postal address, government ID, medical records or financial history. Necessary business billing address/GSTIN collection is a planned invoice feature. CRM notes and automatic email history are also planned; their notice and export/removal controls will be added when activated.

Purposes & lawful bases

  • Account access, chart calculation, saved readings, purchased reports and service emails: performing your request or contract (contract under EU/UK GDPR); in India, informed consent where required.
  • Optional marketing: separate, withdrawable consent; not active today.
  • Security, fraud prevention, rate limits, error checks and limited AI spend accounting: legitimate interests in a safe, reliable service under GDPR, balanced against your privacy; the applicable permitted basis in India.
  • Tax, accounting and legally necessary payment evidence: legal obligation. We retain only what that purpose requires.

Without required details we may be unable to provide the relevant service. Readings do not make employment, insurance, lending or other decisions with legal or similarly significant effects on you.

Free tools & AI writing

Charts are calculated on our server by the iAstroGuru Engine, not sent to an outside astrology API. Free calculator tools, including Vedic/Western, Chinese zodiac, numerology and tarot, never use AI. Using a tool alone does not create a saved birth profile; details carried into the saving form may remain temporarily in that tab.

Readings and reports may be written with the help of AI from calculated chart facts, and then reviewed by our quality checks. For this, details are sent to AI service providers located outside India (for example, in the United States). For the free reading the AI provider receives chart facts only (ascendant, Moon, planets, yogas, doshas and current dasha periods), not your name, birth date, time or place. For a paid report it receives the calculated chart details, which include the profile’s name and birth details and, for matching, the other person’s relevant details. The notice below follows the current setting.

The current writing setting could not be verified. We cannot confirm whether AI-assisted writing is enabled right now. Check again later or ask support; see your report for the writing mode actually used.

We use business services from AI providers whose terms state that data sent to them is not used to train their AI by default, and we do not opt customer birth data into training. This is not a promise of zero retention: security, abuse-monitoring and legal retention can apply. A list of providers is available on request at support@iastroguru.com.

Providers & recipients

  • Cloudflare: planned public hosting, D1 database and security; R2 storage for private PDFs is a future feature. Before launch, development also runs locally with protected backups.
  • Google: Google sign-in when chosen; Supabase and its SMS providers: phone-code delivery and verification when phone sign-in is enabled.
  • Razorpay and relevant payment/banking providers: payments and refunds. We receive payment evidence, not card data.
  • AI service providers (located outside India, for example in the United States): help writing readings, reports, question answers and Customer Care chat when enabled as described above.
  • Zoho: planned Zoho Mail inbox for support@iastroguru.com. An email delivery provider for automatic emails (planned Zoho ZeptoMail; not active yet). When email sign-in is on, ZeptoMail delivers your sign-in code to your address.

Providers receive information needed for their role. Processing on our behalf requires appropriate contractual terms; payment and identity providers may also act as independent controllers for their own obligations. Records may be disclosed in response to valid legal demands. A full list of providers is available on request at support@iastroguru.com.

Customer Care

Customer Care shows your orders, reports, saved profiles, preparations and consent records only to your account. Service requests are saved as CRM notes and queued support emails. Conversations are private, visible in the owner CRM and deleted after 180 days. Chats, notes and email history are included in your export and reading-data removal controls.

AI chat depends on the owner switch and monthly budget. When enabled, the text you type and the last six conversation turns go to an AI service provider located outside India. The AI is not given database access, birth details or payment records; fixed account-scoped actions run on the server. Avoid typing sensitive details. Astrology and unrelated topics are refused. Buttons and human service support remain available without AI.

Open Customer Care

Service & marketing emails

Customer Care uses support@iastroguru.com; at launch reports and automatic customer emails will use guru@iastroguru.com. Transactional receipts, report delivery and security emails need no additional marketing consent. Marketing is not active; if introduced, it requires a separate opt-in and an unsubscribe option in each email. Phone-only accounts cannot receive email until a real address is securely added.

Cookies & device storage

There are no advertising trackers or analytics cookies. After a review on 2 October 2026 we keep strictly necessary storage only: for sign-in and security, and for choices you make yourself (language, theme, chart style, city) or results you ask for (today’s tarot card). On the public site we use a cookieless analytics service that counts page views without identifying you or setting cookies. So no consent banner is needed. An automatic layout value and a lasting tarot identifier were removed. Any non-essential storage would require a consent banner and a refusal option before it is set.

  • iastroguru_session: HttpOnly sign-in cookie, 30 days; only a hashed form of it is stored in the database. Secure on public HTTPS, SameSite=Lax.
  • iastroguru_oauth: HttpOnly Google sign-in security/PKCE cookie, up to 10 minutes; cleared on return.
  • iastroguru-lang: English/Hindi choice, one year.
  • localStorage: iastroguru-intro (when the opening scene last played, so it does not repeat), iastroguru-preferences (answer language and Hindi style you chose while signed out), iastroguru-theme (theme you chose), iastroguru-chart-style (chart style you chose), iastroguru-panchang-city (city you chose), iastroguru-tarot-day (today’s date and card, set when you ask for it, so it stays the same until tomorrow; replaced the next day). No identifiers; these may remain until you clear browser data.
  • sessionStorage: iastroguru-motion-paused (motion choice), iastroguru-pending-birth and iastroguru-pending-match (birth/matching details before saving), checkout:… (payment request identifier to avoid duplicate charges). These last for the tab session; carried birth details are removed after successful saving.
  • The owner has a separate HttpOnly admin-session cookie; it is not public customer sign-in. The Razorpay payment window may use its own security technologies.

You can clear cookies and storage in your browser; this may sign you out or reset choices but does not delete server reports. Any new storage is reviewed for necessity and added to this list before it is used.

ICO guidance on cookies and similar technologies.

Ask iAstroGuru: questions & payment

We save your selected birth profile, question, language, status, quoted price, payment state (held, charged, released or refunded), any discount code used, answer and AI usage record privately in your account. Questions are checked before payment; rejected questions and failed answers are not charged. Each follow-up is a new question.

For the first check, an AI service provider located outside India receives only the question. To help write the answer, an AI service provider receives the question and calculated chart facts (placements, dashas, transits, yogas and doshas), excluding the profile name, birthplace, birth date and birth time. Any private details you type in the question are sent as part of it.

Questions and answers stay until you delete them. Deleting a question, its profile or all reading data removes the associated questions and answers. Order, payment, discount and tax evidence, without the question text, remains for the applicable accounting period. Your export includes questions, answers, orders and discount-code uses. AI usage accounting follows the 730-day schedule below.

How long we keep it

Saved birth profiles, charts, preparations and readings stay until you delete them; there is no automatic inactivity deletion today. Removing all reading data clears request input hashes and report references, but keeps account-linked reading-request timing and status for a while for quota protection.

An automatic clean-up applies this schedule every day in small batches: expired sign-in sessions, phone and email codes, rate-limit counters and export locks after they expire; reading-request records after 90 days; abandoned (unpaid) checkouts after 30 days; Customer Care conversations after 180 days; sent automatic emails after 180 days (for bounced addresses only the address and status stay, so we do not send to them again, not the message); waitlist entries after 365 days; admin/security logs and AI usage records after 730 days (2 years). Consent records, including withdrawn ones, stay with the account as evidence. Paid or refunded orders and their payment evidence are never removed by this clean-up. Contact support for review and erasure of records no longer needed.

Orders, payment and tax records must be kept for the period required by applicable law — for example, 8 years where company accounting law applies; disputes or investigations can require longer. GST has its own retention rules. These are never deleted automatically; they will be reviewed by hand once the period ends.

Self-service reading removal does not erase the account, consents, waitlist or payment evidence. Protected backups may retain copies after deletion; there is no fixed backup retention schedule yet. Provider logs/backups follow their policies.

Withdrawal & your controls

Use account privacy controls to export saved information or remove reading data. To correct birth details, create a new reading from the saved profile and remove the old report separately. Send requests for account closure, other erasure, access or correction to support@iastroguru.com. There is no automatic full-account closure button today.

Withdraw consent by writing to support@iastroguru.com. Withdrawal does not invalidate earlier lawful processing. Withdrawing permission for required data can prevent the relevant service, while legally required records may remain.

India: DPDP rights & grievances

Under the Digital Personal Data Protection Act 2023 and Rules 2025, where applicable, rights include information/access, correction, updating, erasure and grievance redressal. You may nominate someone to exercise your rights in case of death or incapacity. Contact our Grievance Officer; if unresolved, you may complain to the Data Protection Board of India through the applicable process.

The Act and Rules have phased commencement; not all provisions are in force on 2 October 2026. You can request the service controls described here now; statutory rights apply according to their commencement. Official Rules and enforcement timeline.

EU/UK: GDPR rights & international transfers

Where GDPR applies, request access, correction, erasure, restriction, portability, objection to legitimate-interest processing and withdrawal of consent. We normally respond within one month and explain any lawful extension. You may complain to your local supervisory authority or the UK ICO.

Providers may process data in India, the US or other countries; we do not promise one-country residency. Applicable EU/UK safeguards may include adequacy decisions, providers’ Standard Contractual Clauses (SCCs) and a required UK addendum/IDTA. Appropriate agreements and transfer assessments must be completed before public launch; this notice alone does not establish they are in place. Ask support for the relevant safeguards. Any required EU/UK representative must be assessed and appointed before launch into those markets.

Cloudflare DPA ·GDPR.

California: CCPA/CPRA notice

We do not sell or share personal information for cross-context behavioural advertising. The collection notice above lists identifiers, contact/profile details, commercial/payment records, internet/device activity and chart-derived interpretations/inferences. Birthplace coordinates are not your current device GPS location. Any sensitive information is used only for requested services, security or legal requirements.

Where CCPA/CPRA applies, rights include knowing/access, correction, deletion, opting out of sale/sharing and limiting certain sensitive-information uses, without discrimination. Send requests to support@iastroguru.com. Proportionate identity verification is required; authorised agents can request with evidence of authority. We normally respond within 45 days and explain any lawful extension.

Official California privacy rights.

Children’s data

Accounts are for adults 18+. The service is not directed to children under 13 and we do not knowingly collect data directly from them (COPPA). Before saving birth details for a child under 18, the parent or lawful guardian gives explicit consent and provides their own birth year, which must indicate an age of at least 18. These voluntarily provided age details support the Rule 10 route. We record the consent purpose, version, parent’s account ID, child’s profile ID, declared birth year and timestamp.

Withdraw consent by deleting the child’s profile from My readings; this removes the associated details and readings and stops their further use. We do not market to, track, behaviourally monitor or target advertising at children; their details are excluded from CRM tags and marketing segments.

Security, breach notification & changes

Safeguards include public HTTPS, account-scoped access, HttpOnly sessions and payment verification. No system guarantees complete security. If a personal-data breach occurs, we will investigate, contain it and take protective steps. We will notify affected people without undue delay in plain language about what happened, affected data, protective steps and help, and notify authorities within applicable deadlines.

Where GDPR requires authority notification, the deadline is 72 hours from awareness; individual notification follows its risk threshold. Under the applicable DPDP process, initial notification to affected people/the Board is without delay and detailed Board notification is normally within 72 hours. Requirements depend on the applicable law and commencement.

We will update this notice for material data-use changes and obtain fresh consent where required. Report security or privacy concerns to the support email.

Operator & Grievance Officer

The seller of this service and controller of your personal data (Data Fiduciary in India):

Legal name
Shiv Shakti Software Solutions (sole proprietorship of Mohan Minda; Udyam registered), trading as iAstroGuru
Location
New Delhi, India (full postal address for legal notices on request by email)
Contact
support@iastroguru.com
Grievance Officer name
Mohan Minda (proprietor)
Grievance Officer email
support@iastroguru.com

Support and privacy requests: support@iastroguru.com. We will acknowledge complaints within 48 hours and resolve consumer grievances within one month of receipt, or sooner where applicable law requires.

Related policies & language

English is the governing text. Every policy is available in English and Hindi.

English privacy notice · हिंदी गोपनीयता सूचना