Trust & transparency

Privacy Policy

Last updated: 2026-08-04. Written by a person, not a boilerplate generator.

The short version

We keep your birth details to compute your chart. We keep your email if you sign in with Google. We use Google Analytics + Microsoft Clarity to see anonymous usage patterns. We use free-tier LLM providers (Groq, Cerebras, Together, OpenAI) to generate readings — your birth details and question text are sent to them per query. We don't sell anything, we don't run ads, we don't email you unless you subscribe. You can delete your data any time by contacting us.

What we collect and why

Birth details (name, date, time, place)
Required to compute your Vedic birth chart. Stored in an HMAC-signed browser cookie (24-hour rolling TTL) so you don't re-enter them on every visit. If you sign in with Google we also mirror them to server-side storage so they persist across devices. You can clear them via /account or by clearing your browser cookies.
Google sign-in identity (email, name, Google user ID)
Only if you click "Sign in with Google". Used to persist your saved charts + reading history across devices. We don't have your Google password (Google handles auth). We don't request or receive Gmail contents, calendar, or drive access — just profile basics.
Question text you type into /ask
Sent to one of our LLM providers (see next section) along with your chart data to generate an answer. Cached on our server for ~14 days so re-asking the same question doesn't re-charge the quota. Never used to train any model on our behalf.
Anonymous usage analytics
Google Analytics 4 (GA4) and Microsoft Clarity track page views, feature clicks, and (Clarity only) session replays without personal data — no birth details, no email, no question text. Used to understand which features people actually use so we can improve them. You can opt out via your browser's Do Not Track setting or a tracker-blocking extension; the site works fine without either.
Cookies
One HMAC-signed session cookie (birth details + language + Google sign-in state). One quota-tracking cookie for the daily 3-free-questions /ask limit. GA4 sets its own cookies (_ga, _gid). Clarity sets one too (_clck, _clsk). No advertising cookies. No cross-site tracking.

Third parties we send data to

LLM providers (chart-reading generation): your birth chart summary + question text are sent per query to whichever of these has capacity available: Groq (groq.com), Cerebras (cerebras.ai), Together AI (together.xyz), Mistral (mistral.ai), or OpenAI (openai.com). Each request is stateless and none of these providers uses our data to train their models (per their API terms). Chart summaries include placements — they do NOT include your name.

Google (sign-in + analytics): if you sign in, Google verifies your identity to us via OAuth. Google Analytics 4 receives anonymous page-view and event data.

Microsoft Clarity (session replay): anonymized session recordings so we can see where users get stuck. Does NOT capture form input values (birth details typed into the Kundli form are masked before capture).

Google Cloud (hosting): the app runs on Google Cloud Run in the Asia South 1 (Mumbai) region. Application logs (not personal data) are stored in Google Cloud Logging.

We do NOT share your data with any other party. We do NOT sell data. We do NOT run advertising.

How long we keep data

Your rights (India DPDP Act 2023 + general good practice)

Children's data

Shubh Bhagya is not directed at children under 18. If a parent submits a child's birth details for a Kundli reading, that data is treated identically to adult data. Please don't have a child under 18 create an account.

Security

Session cookies are HMAC-signed with a server-side secret so they can't be tampered with client-side. All traffic is HTTPS. Google OAuth tokens are validated per Google's published public keys. We're a small operation — we take reasonable steps but can't guarantee absolute security against a determined attacker; you should treat your birth details the same way you'd treat any personal record you enter online.

Changes to this policy

If we materially change data practices, we'll update the "Last updated" date at the top and — for signed-in users — surface a notice on /account next time you visit. Immaterial fixes (typos, clarifications) will happen silently.

Contact

Questions or concerns? Email mahajananuj07@gmail.com. Human replies, usually within 48 hours.


This policy is written to be readable and honest, not to satisfy any specific legal framework. It reflects our actual practice. If you're a lawyer reviewing this on behalf of a user or regulator and something reads ambiguously, please write to us at the address above — we'll clarify or amend.