Privacy Policy
Effective August 13, 2026
Acharya is built by people who believe a birth chart is one of the most personal artifacts you can hand over. This policy explains what we collect, what we don't, and what we do with what we keep.
What we collect
Birth particulars
Name, date of birth, time of birth, and place of birth — for you and any family member you choose to add. We need these to cast a chart. Without them, Acharya can't read anything. When you add someone else's birth details — a family member, or a prospective match in Kundli Milan — you confirm you're doing so with their knowledge and consent (or, for your own child, as their parent or guardian). When you type a birth place into the place picker, the search text is sent to Open‑Meteo, a geocoding service, to resolve coordinates and timezone.
Conversation history
The questions you ask Acharya and the readings Acharya returns. We store this so you can revisit past conversations and so Acharya can remember context within your account.
Prediction feedback
When you mark whether a prediction played out (or didn't), we record that. This is how Acharya learns to be more accurate for you over time.
Account information
The email address and authentication identifier from your sign‑in. On the web you sign in with a one‑time email link or with Google; in the iOS app, with Sign in with Apple. We only receive the minimal identity your provider shares — for example, with Sign in with Apple we never see your full Apple ID.
Technical telemetry
Crash reports, performance metrics, and aggregate usage signals that help us fix bugs and improve the app. No conversation content is included.
So we can tell how many people actually use Acharya, we record which days your account used the service and which platform you used (iOS, Android, or web) — one record per day, not a log of what you looked at. We do not record the pages or screens you visit, we do not build a behavioural profile, and we do not use this for advertising. It is the same aggregate counting a shop does when it counts customers through the door.
What we don't collect
- We do not collect your contacts, calendar, photos, or location unless you explicitly grant permission for a feature that needs it (e.g., a future panchang‑aware calendar feature).
- We do not run third‑party advertising trackers.
- We do not sell, rent, or share your data with marketing partners. Period.
How we use what we keep
- To read your chart — birth particulars are passed to our astrological computation engine.
- To answer your questions — your chart and conversation context are sent to our AI provider (currently Anthropic) under commercial terms that prohibit them from using your data to train their models.
- To improve Acharya — aggregate, de‑identified signals (e.g., which kinds of questions are common, which features get used) inform product decisions. Your individual content is not used for model training.
- To recalibrate predictions — your prediction feedback informs how confidently Acharya makes claims to you. With your consent, anonymized feedback may contribute to cohort‑level calibration (the long‑run "Acharya Codex" project) — and you can opt out at any time.
Where data lives
Charts and conversation history are stored in a Postgres database we operate on infrastructure in the United States. Authentication is handled via your sign‑in provider (a one‑time email link, Google, or Apple). AI requests are sent to Anthropic under commercial terms that prohibit them from using your prompts to train their models.
How we protect your data
- Encrypted in transit — every connection between your device and Acharya, and between our own services, uses TLS. Your questions and birth details are never readable on the wire.
- Encrypted at rest — the databases that hold your charts, conversations, and feedback are encrypted at the storage layer (AES‑256, managed by our database provider).
- No passwords — sign‑in is a one‑time email link, Google, or Apple. There is no Acharya password to steal or reuse.
- Payment details never touch our servers — payments are processed by Razorpay, a PCI‑DSS certified payment processor. We store only a payment reference and its status, never your card or bank details.
- Least access — production credentials are held in environment configuration, not code, and administrative surfaces require separate keys. A small number of authorized Acharya personnel can access production data, and only to operate, support, and debug the service. Astrologers on our panel see a client's birth details only for consultations booked with them — never your private conversations with Acharya.
One honest note: Acharya is not "end‑to‑end encrypted" — our systems must read your question to compute your chart and compose a reading. What we promise instead is narrower and true: your data is encrypted in transit and at rest, only used to serve you, and never sold or used for advertising.
Sensitive data, treated as sensitive
Using an astrology service can itself reveal something personal — your spiritual leanings. Some optional features (like chart verification) may ask about past life events, including health‑adjacent facts you choose to share. We treat all of this as sensitive data: we collect it only when it is strictly necessary to provide the reading you asked for, we never sell it or share it for advertising under any circumstances, and features that ask more personal questions are opt‑in and clearly framed before you answer. You can decline or skip any question, and delete what you've shared at any time.
How long we keep it
We keep your data for as long as your account exists, because a janam patri is a living record — the value of Acharya is precisely that your chart, readings, and verified predictions accumulate over years. When you delete your account (or a family member's profile), the associated data is removed from active databases within 30 days and ages out of backups within 90. We don't keep what you've deleted.
Our service providers
A small set of providers process data on our behalf, each under terms limiting use to providing their service to us: Anthropic (AI readings — prohibited from training on your data), Neon (database), Render and Vercel (hosting), Cloudflare (network), Upstash (caching), Resend and SendGrid (transactional email — sign‑in links, booking confirmations, reminders, and the daily digest if you opt in; each receives your email address and the message content), Razorpay (payments), Open‑Meteo (birth‑place lookup), Sentry (error monitoring — no conversation content), Apple (sign‑in, and push notification delivery — see below), and Google (sign‑in; and calendar invites when you book a live sitting — the invite carries your name, email, and the sitting topic). We'll update this list if it changes.
Push notifications
If you turn on notifications, your device registers a push token with Apple's Push Notification service (APNs), and we store that token so we can reach your device. When we send you a notification — a transit alert, a sitting reminder, your daily pulse — the text of that notification passes through Apple's servers to reach your phone. That text can name a planet, a house, or a sitting you have booked, so treat notification content as visible to Apple in transit. Apple does not receive your chart, your conversations, or your birth details. Turning notifications off in your device settings stops this entirely, and deleting your account deletes the stored tokens.
Your rights
- Access — you can request an export of everything we hold on you.
- Deletion — you can delete your account from inside the app. Charts, conversations, and feedback are removed from active databases within 30 days; backups age out within 90.
- Correction — birth particulars can be edited at any time inside the app.
- Opt‑out of calibration — your prediction feedback can be excluded from the cohort‑level calibration loop.
To exercise any of these rights, use the Data & Privacy controls in your account, or email [email protected] — we respond to verified requests within 45 days (usually much faster).
Children
Acharya is intended for adults; you must be 18 or older to create an account. We do not knowingly allow anyone under 18 to create their own account, and we do not knowingly collect data directly from a child.
Parents and guardians may add a child's birth details to their own family patri. Because a child's data is treated as sensitive under India's Digital Personal Data Protection Act, this is gated, not merely disclosed: when you mark a profile as a child, Acharya will not save it until you affirmatively confirm that you are that child's parent or legal guardian and that you consent on their behalf. We record who gave that confirmation and when, so the consent is demonstrable. The same gate applies whether you add the child through the app or by asking Acharya to add them in conversation — there is no path that skips it.
For any profile marked as a child, we additionally commit that we will not:
- use their data for behavioural monitoring, profiling, or targeted advertising of any kind;
- provide marriage, romance, or other adult readings — readings are limited to age‑appropriate topics such as character, strengths, education, and wellbeing;
- make their data available to anyone outside the account holder and, where a sitting is booked about them, the panel Acharya conducting it.
You can delete a child's profile and all associated data at any time from inside the app, and doing so removes it on the same schedule as any other deletion.
Changes to this policy
If we make a material change, we'll surface it inside the app and email you. The effective date above is updated whenever the policy is revised. When you accept the Terms and this policy, we record the date and the policy version you accepted, so your consent is verifiable.
Grievance Officer
Under India's Digital Personal Data Protection Act, 2023 (§13), we publish a named officer to answer grievances about how your data is handled. If you are not satisfied with our response, you may escalate to the Data Protection Board of India.
Ajay Sharma
Grievance Officer, Grahrishi Technologies (OPC) Limited
[email protected]
Write with "Grievance" in the subject line. We acknowledge within 7 days and respond substantively within 30.
Contact
Questions, concerns, or requests: [email protected].