Last updated: May 29, 2026
This Privacy Policy describes how Astroniq ("Astroniq", "we", "us") collects, uses, stores, and shares personal information of users ("you") of the Astroniq website, mobile-installable PWA, and related services (collectively, the "Service"). By using Astroniq, you agree to the practices described here. If you don't agree, please don't use the Service.
1. The short version
- We collect birth data (date, time, place) you give us during onboarding - without it, we can't compute your chart.
- We collect account data (email or phone) so you can sign back in.
- We collect chat history so you can pick up where you left off.
- We collect technical data (device, IP, error reports) only as needed to run the Service.
- We never sell your data to third parties.
- We never train public AI models on your chat or birth data.
- You can export or delete everything from the Me tab.
2. Information we collect
We collect the following categories of personal information. "Personal information" includes anything that identifies you directly or could reasonably be linked back to you.
- Account information. Your email address or phone number (used for sign-in). Optionally: your display name.
- Birth data. Your date of birth, time of birth (if known), birth place (latitude / longitude / timezone offset), and the certainty level you set for your birth time. We need this to compute your Vedic birth chart.
- Home location. Latitude / longitude / timezone for where you currently live. Used to compute "today" surfaces (panchang, muhurta windows).
- People records. The birth data of people you save in the People tab to run compatibility against. You're the data controller for that information - see "People you save" below.
- Chat content. Messages you send to Astroniq and the AI replies you receive. Stored against your account so you can revisit threads.
- Usage analytics. Internal product telemetry on which features you use and how often. Aggregated, no third-party trackers, PII scrubbed.
- Technical data. Device type, browser user-agent, IP address, error logs (Sentry). Used to debug failures and detect abuse.
- Payment metadata. Subscription status, plan tier, billing dates, invoice records. We never see your card number - those go straight to our payment processors (see section 5).
- Push subscriptions. If you opt in to push notifications, your browser's push-subscription token + a device label.
3. How we use your information
We use your information only to:
- Provide the Service (compute charts, answer questions, deliver readings).
- Maintain your account and session.
- Process payments and manage subscriptions.
- Send transactional emails (sign-in links, payment receipts, security notices).
- Send push notifications you've opted into.
- Debug technical failures and detect abuse.
- Comply with legal obligations (tax, anti-fraud, lawful requests).
We do not use your information for:
- Selling to data brokers or marketing networks.
- Training public AI models on your chat or birth data.
- Advertising you elsewhere (we don't ship third-party ad pixels or remarketing tags).
- Sharing with matrimony, dating, or insurance services unless you explicitly opt in to a future feature that requires it.
4. Legal basis for processing
For users in India (DPDP Act 2023), our lawful basis is primarily your consent - given when you create an account and accept this policy. For payment processing and security, we additionally rely on legitimate use as defined by the Act.
For users in the EU / UK, our lawful bases under GDPR are:
- Consent (Article 6(1)(a)) for chart computation, marketing emails (if you opt in), and push.
- Contract (Article 6(1)(b)) for account management, subscription billing, and Service delivery.
- Legitimate interests (Article 6(1)(f)) for fraud detection, security, and product improvement.
- Legal obligation (Article 6(1)(c)) for tax records and responses to lawful requests.
5. Third-party services we use
We rely on a small number of trusted third parties to operate the Service. Each is bound by a data-processing agreement and is contractually prohibited from selling or mining your data.
- LLM providers (Google Gemini, Groq). Process your chat messages to generate replies. Enterprise terms prohibit training on API inputs.
- Payment processors (Razorpay, Stripe). Process payments. They see your card details; we don't. Both are PCI-DSS Level 1 certified.
- Authentication (Google OAuth, email magic-link). Used at sign-in. We retain only the resulting account identifier, not the OAuth/magic-link tokens.
- Push delivery (FCM, Apple Push). Routes push notifications when you've opted in.
- Email delivery (Resend or equivalent). Sends transactional emails (sign-in links, receipts).
- Error monitoring (Sentry). Captures JavaScript errors and backend exceptions. PII is scrubbed from event payloads via `beforeSend` filters.
- Hosting (AWS / Vercel / equivalent). Stores user data encrypted at rest, in regions chosen for latency to our users.
6. Data retention
We retain your information for as long as your account is active. If you delete your account, we delete personal information within 30 days, with these exceptions:
- Financial records (invoices, payment transactions): retained for as long as required by tax law, typically 7 years in India.
- Anonymised aggregates (e.g. "how many users sent a chat message yesterday") may be retained indefinitely.
- Backups may include your data for up to 35 days after deletion, after which they're overwritten.
7. Your rights
You have the following rights with respect to your data:
- Access. Request a copy of the personal information we hold about you.
- Correction. Update inaccurate information - most fields are self-editable from the Me tab.
- Deletion. Delete your account at any time from the Me tab. This is a self-serve, irreversible action.
- Portability. Export your data in a machine-readable format. Email astroniq.app@gmail.com if you need this and we'll send it within 30 days.
- Withdraw consent. Opt out of push notifications, marketing emails, or future research participation from the Me tab.
- Lodge a complaint. If you're in India, you may complain to the Data Protection Board. If you're in the EU/UK, you may complain to your local supervisory authority.
8. People you save (compatibility)
When you save someone else's birth data on the People tab (e.g. a partner, parent, friend), you are the data controller for that information, and Astroniq is your processor. You confirm that you have permission from that person - or a legitimate basis - to enter their data into our Service.
People records are scoped to your account. They are not visible to other Astroniq users, are not used to make independent profiles, and are deleted when you delete the record or your account.
9. Children
Astroniq is not directed to anyone under the age of 13. We don't knowingly collect information from children. If you believe a child has provided us information, email astroniq.app@gmail.com and we'll delete it.
10. International transfers
Our servers and processors may be located outside your country of residence. By using the Service, you consent to your data being processed in those locations. We rely on standard contractual clauses (SCCs) where required.
11. Security
We protect your data with HTTPS encryption in transit, encryption at rest, HttpOnly + SameSite session cookies, and quarterly secret rotation. Full technical details at /security. No system is perfectly secure - if we ever experience a breach affecting your data, we'll notify you without undue delay.
12. Changes to this policy
We may update this policy from time to time. If we make a material change, we'll notify you by email and via an in-app banner before the change takes effect. Continued use of the Service after the change constitutes acceptance.
13. Contact
For privacy questions, data requests, or to exercise your rights, email astroniq.app@gmail.com. Our Grievance Officer (per India DPDP / IT Rules) can be reached at the same address.
Entity: Astroniq
Registered address: Chandigarh, India