B1Who we are & scope
- This Privacy Policy explains how Nishant Chauhan, an individual sole proprietor based in India ("we", "us", the "Developer"), collects, uses, shares, and protects your personal data when you use the Ravitra mobile app.
- For the purposes of the India Digital Personal Data Protection Act, 2023 (DPDP Act) we act as a Data Fiduciary; for the EU/UK GDPR we act as a data controller.
- This policy covers all users worldwide. Additional region-specific rights (India, EU/EEA, UK, California) are described in B10.
- Contact / grievance channel for all privacy matters: support@ravitra.com (see B13).
B2What data we collect
We collect only what we need to run the App. Categories:
- Account & authentication data
- When you sign in with Google: your email address and Google account identifier.
- A display name you provide when setting up your profile — required to create your account and personalize your experience.
- Gender (optional) — you may optionally tell us the gender for a chart (your own, or a second person in a compatibility match). It is optional (you can choose "prefer not to say"), and we use it only to inflect the wording and voice of your readings (for example, correct grammatical gender in the generated text). We do not use it for advertising or share it for advertising.
- Sensitive birth details (core input — treated as sensitive)
- Your date of birth, exact time of birth, and place of birth (city label plus latitude/longitude of the place you select).
- We treat these as sensitive personal data: combined they are precise, identifying, and can be adjacent to inferences about your beliefs. They are encrypted at rest (AES-256-GCM), place of birth included.
- Astrology data we generate from your birth details
- Natal and divisional charts, dashas, horoscopes, predictions, forecasts, Janma Patrika reports, and Kundli Milan (compatibility) results. If you run a compatibility match, the second person's birth details you enter are processed to compute the match; you must have that person's permission to enter them (Terms A8), and their details are protected, and deleted with your account, the same way as your own.
- AI chat content
- The free-text messages you send in the AI chat, and a distilled "user memory" (a short summary of facts you've shared to give continuity across chats).
- Payment / subscription metadata
- Your Google Play purchase token, subscription plan, and status. We do NOT collect or store your card, bank, or other payment-instrument details — Google Play processes all payments.
- Approximate location (optional — off unless you ask for it)
- The App has an optional "refresh location" feature on the Home screen. If you tap it and grant the device permission, the App takes a one-time reading of your approximate current location (latitude/longitude of your current city) so it can compute daily timings (muhurta) for where you are right now.
- This is entirely optional and user-initiated. It is not continuous or background tracking — we do not follow your movements. The reading is stored on your device and sent to our server only to return your daily timings; it is not shared with third parties and not used for advertising. You can decline or revoke the location permission at any time in your device settings, and the App still works (you can also set your city manually).
- Device & technical data
- A push-notification token (Firebase Cloud Messaging) if you enable notifications.
- Usage and diagnostic analytics via Google Firebase Analytics and Firebase Crashlytics in the mobile app: aggregated app-usage/interaction events (to understand which features are used and keep the App reliable) and crash reports (which may include device/OS type, app version, and a diagnostic stack trace) so we can find and fix problems.
- What we do NOT do (stated for clarity, and true):
- We do not sell your personal data, and we do not use it for cross-context behavioral advertising or ad-tracking. The App contains no third-party advertising SDKs and no ad networks, and we do not build advertising profiles. Firebase Analytics is used only for our own product analytics and diagnostics, not to target ads to you.
- We do not track your location continuously or in the background — the only location data we ever use is the birth place you enter and the one-time, optional current-city reading described above.
- We do not use website cookies (the App is not a website); there is no ad or tracking-cookie layer. Firebase may use device/installation identifiers to provide the analytics and crash-reporting functions described above.
B3How we collect it
- Directly from you — when you create an account, enter birth details, chat, or configure preferences.
- Automatically — a device push token (if you enable notifications), usage/ diagnostic analytics and crash reports (Firebase Analytics + Crashlytics) when the App runs, and, only if you tap the optional "refresh location" affordance and grant permission, a one-time approximate current-location reading.
- From third parties — your email from Google Sign-In; subscription status from Google Play.
B4How and why we use your data, and our legal bases
| Purpose | Data used | Legal basis (GDPR) / DPDP note |
|---|---|---|
| Create and manage your account; sign you in | Email, account IDs | Contract (GDPR Art. 6(1)(b)); DPDP: necessary for the service you requested |
| Compute charts, dashas, horoscopes, forecasts, Patrika, Kundli Milan | Birth details + generated astrology data | Explicit consent for sensitive birth data (GDPR Art. 9(2)(a)); performance of the service. DPDP: consent obtained at onboarding |
| Provide the AI chat and AI-narrated readings | Chat messages, user memory, derived birth facts | Consent + contract; sensitive data processed on your explicit consent |
| Inflect the wording and voice of your readings (correct grammatical gender) | Optional gender you provide for a chart | Consent (optional field; you may choose "prefer not to say"); DPDP: consent |
| Provide, verify, and manage your paid subscription | Purchase token, subscription status | Contract; plus legal obligation for retaining transaction records |
| Show daily timings (muhurta) for your current city | Optional one-time approximate location | Consent (you tap "refresh location" and grant the OS permission); DPDP: consent |
| Send push notifications (daily guidance + billing/transactional) | Push token, notification preferences | Consent for daily-guidance pushes; contract/legitimate interest for transactional billing notices |
| Understand feature usage; keep the App reliable; find and fix crashes | Firebase Analytics usage events, Crashlytics crash/diagnostic data, account IDs | Legitimate interests (GDPR Art. 6(1)(f)) and, for users in the European Economic Area or the United Kingdom, consent where required by local law; DPDP "legitimate uses" / security |
| Keep the App secure, prevent abuse, debug errors | Technical/diagnostic data, account IDs | Legitimate interests (GDPR Art. 6(1)(f)); DPDP "legitimate uses" / security |
| Comply with law; establish, exercise, or defend legal claims | Billing records, minimal account data | Legal obligation and legitimate interests |
- Withdrawing consent. Where we rely on consent, you can withdraw it at any time (see B10). Withdrawal does not affect processing already carried out, and may mean we can no longer provide astrology features that depend on your birth details.
- If you choose not to provide data. You are never obliged to give us your data, but some of it is necessary to provide the Service: without an email we cannot create your account, and without your birth details we cannot compute charts, readings, or any other astrology feature. Chat is always optional.
- No automated decisions with legal or similar effects. The App generates automated astrological content (including AI chat), but we do not use your data to make automated decisions that produce legal effects or similarly significantly affect you (GDPR Art. 22) — no scoring, credit, insurance, or eligibility decisions of any kind.
- No profiling for advertising. We do not profile you for advertising or marketing purposes; personalization is limited to the astrology content you asked for.
B5AI processing disclosure (Anthropic)
- Ravitra's AI chat and AI-narrated readings are generated by a third-party AI provider, Anthropic (the Claude API), acting as our processor / sub-processor.
- What is sent: the text of your chat messages and astrology facts derived from your birth details (needed to produce a relevant response). Anthropic's servers process this to generate the reply.
- Training: under the applicable commercial API terms, your inputs and outputs are not used to train Anthropic's models — Anthropic does not use data sent through its commercial API to train its models by default, under its Commercial Terms of Service and Data Processing Addendum.
- Cross-border: this processing may occur outside India (see B8).
- AI output is automated and may be inaccurate — see the Terms, section A4.
B6Who we share data with — sub-processors & third parties
We do not sell your personal data and do not share it for advertising. We share data with service providers ("sub-processors") strictly to run the App, under contractual data-protection terms:
| Sub-processor | Role | Data involved |
|---|---|---|
| Supabase | Database (Postgres), authentication, file/report storage | Account data, encrypted birth details, generated astrology data, chat, reports |
| Google Cloud Platform (Cloud Run, region asia-south1 / India) | Application hosting / compute | All processing transits our GCP backend |
| Anthropic (Claude API) | AI generation for chat & readings | Chat text + derived birth facts (see B5) |
| Google — Sign-In | Google account authentication | Email, Google account ID |
| Google — Play Billing | Payment processing & subscriptions | Purchase token, subscription status (Google holds payment details; we don't) |
| Firebase Cloud Messaging (Google) | Push notification delivery | Push token |
| Firebase Analytics (Google) | Product usage/interaction analytics (mobile app) | App-usage events, device/installation identifiers |
| Firebase Crashlytics (Google) | Crash reporting (mobile app) | Crash reports, device/OS type, app version, stack traces |
| OpenStreetMap / Nominatim | Birth-place / city geocoding lookup (fallback search) | The place name you type when searching for a birth place |
- We may also disclose data if required by law, to respond to lawful requests, or to protect our rights, users, or the public — limited to what is necessary.
- If the App is ever transferred to a new owner or business entity, we will disclose that and honor this policy or give you notice.
B7Data retention
We keep personal data only as long as needed for the purpose it was collected, then delete or anonymize it:
- Birth details, charts, reports, predictions, profile: kept while your account is active; erased when you delete your account (in-app Delete account).
- AI chat messages: kept for 30 days on a rolling basis, then automatically deleted. The distilled "user memory" is kept while your account is active (to give chat continuity) and is deleted when you delete your account.
- Billing / transaction records: retained even after account deletion. When you delete your account we permanently erase your personal and astrological data (birth details, charts, predictions, chat). However, we retain records of your transactions and subscription history (payment/subscription identifiers — not your chart or chat content) for as long as required to meet our legal, tax, accounting, and audit obligations and to establish, exercise, or defend legal claims — typically up to eight (8) years — after which they are deleted or anonymized. This retention is permitted under GDPR Art. 17(3)(b)/(e) and India's DPDP Act (retention for legal compliance / enforcement of legal rights); the right to erasure is not absolute for these records.
- Diagnostic/error logs and caches: kept for a short period for security and reliability, then rotated/deleted.
B8International data transfers
- Our database, authentication, and file storage (Supabase) are hosted in Mumbai, India (AWS ap-south-1), and our backend runs on Google Cloud in Mumbai, India (asia-south1). Some providers — including Google Firebase/Google Analytics and Anthropic — may process data outside India, including in the United States.
- AI processing (Anthropic) may occur outside India (e.g. in the United States).
- Where personal data is transferred across borders, we rely on appropriate safeguards — such as the provider's Data Processing Agreement and EU Standard Contractual Clauses (SCCs) / UK IDTA, or transfers to jurisdictions recognized as adequate — and, for Indian users, transfer only to jurisdictions permitted under the DPDP Act and its rules. We maintain Data Processing Addenda that incorporate the European Commission's Standard Contractual Clauses (SCCs) with our processors, including Anthropic, Supabase, and Google.
B9Security
- We use reasonable technical and organizational safeguards, including: encryption at rest of your sensitive birth details (AES-256-GCM), encryption in transit (HTTPS/TLS), database row-level security enforcing per-user data isolation so users can only access their own data, and access controls on our systems.
- No method of storage or transmission is 100% secure; we cannot guarantee absolute security, but we work to protect your data and will notify you and the relevant authority of a personal-data breach where required by law.
B10Your rights & how to exercise them
Depending on where you live, you have some or all of the following rights. To exercise any of them, email support@ravitra.com, or use in-app tools where available. We respond within the timeframes required by applicable law and may need to verify your identity.
- Access — get a copy of the personal data we hold about you.
- Correction / rectification — fix inaccurate or incomplete data (you can edit much of your profile and birth details in-app).
-
Deletion / erasure — delete your account and personal data in-app
(Settings → Delete account,
DELETE /v1/me— an irreversible cascade erasing your account and personal/astrological data), subject to the billing-record retention in B7. If you no longer have the App installed, you can request deletion on the web at our web account-deletion page or by emailing support@ravitra.com. - Withdraw consent — where we rely on consent (e.g. for birth-data processing, the optional current-location reading, or daily push notifications) you may withdraw it at any time. You control the location permission in your device settings, and notifications via in-app and OS settings.
- Data portability — receive certain data in a portable format (GDPR/where applicable).
- Object / restrict — object to or restrict certain processing (GDPR/where applicable).
- Grievance redressal & nomination (India DPDP) — raise a grievance with our grievance officer (B13); and nominate another individual to exercise your rights in the event of death or incapacity. If you are not satisfied with our response, you have the right to complain to the Data Protection Board of India.
- California (CCPA/CPRA) — rights to know, delete, correct, and to opt out of "sale" or "sharing." We do not sell or share your personal information as those terms are defined, and we do not process it for cross-context behavioral advertising; there is nothing to opt out of, but you may still exercise your other rights, and we will not discriminate against you for doing so. You also have the right to limit the use of sensitive personal information: we use sensitive data (your birth details) only to provide the services you request, never for other purposes, so no separate limitation step is needed. The categories of personal information we have collected in the preceding 12 months, their sources, purposes, and recipients are as described in B2–B6. You may use an authorized agent to submit a request; we will verify the request as the law allows.
- EU/EEA/UK — you also have the right to lodge a complaint with your local supervisory authority (e.g. your national Data Protection Authority, or the UK ICO).
- Other countries (including Brazil LGPD, Canada PIPEDA) — where the law of your country gives you similar rights (access, correction, deletion, withdrawal of consent, complaint to a local authority), you can exercise them through the same channels above, and nothing in this policy limits any mandatory protection of your local law.
B11Children's privacy
- Ravitra is not intended for children. You must be at least 18 years old to use the App (see Terms A2).
- We do not knowingly collect personal data from children below the applicable age. Consistent with COPPA (US), GDPR-K (EU/UK age of digital consent), and the India DPDP Act (which requires verifiable parental/guardian consent for users under 18 and bars tracking/targeted advertising of children), we do not target or profile children.
- If we learn we have collected a child's data without the required consent, we will delete it. If you believe a child has provided us data, contact support@ravitra.com.
B12Cookies, analytics & push notifications
- Cookies: the App is a mobile app, not a website, and does not use tracking or advertising cookies. Our analytics/crash SDKs may use device or installation identifiers to function (see below).
- Analytics & crash reporting: the mobile app uses Google Firebase Analytics (to understand which features are used and improve the App) and Firebase Crashlytics (to capture crash reports and fix stability problems). This is product analytics and diagnostics for our own use only — we do not run advertising, ad-targeting, or cross-app behavioral-tracking analytics, and we do not sell or share this data for advertising. Ravitra is offered to users in India and other markets and is not actively directed at individuals in the European Economic Area or the United Kingdom. Analytics and crash reporting are used to help us improve the App; if we begin actively offering the App in the EEA or UK, we will provide an in-app consent control for analytics first.
- Push notifications: if you opt in, we send (a) daily guidance notifications and (b) transactional notifications about your subscription/billing, via Firebase Cloud Messaging. You can control these with in-app notification preferences (including turning daily guidance on/off) and with your device/OS notification settings. Transactional billing notices may still be sent where necessary to service your account.
B13Grievance / Data Protection contact
- The India DPDP Act requires a reachable grievance officer, and we provide a single contact for all privacy, data-protection, and grievance matters (see the card below).
- We aim to acknowledge grievances within 2–3 business days and resolve them within the timeframe required by applicable law.
- EU/UK users may also contact us at the same email for GDPR matters. Because we do not actively offer Ravitra to, or monitor the behaviour of, individuals in the European Economic Area or the United Kingdom, we have not appointed a representative under Article 27 of the EU or UK GDPR. If you access Ravitra from the EEA or UK on your own initiative, you are responsible for compliance with your local law.
B14Changes to this policy
- We may update this Privacy Policy from time to time. Material changes will be reflected in the "Last updated" date and, where appropriate, notified in-app. Please review it periodically. Continued use after changes take effect means you accept the updated policy.
B15Effective date
- Effective date: July 26, 2026.