Privacy Policy
1. Introduction
ZodiacReads ("we", "us", "our") operates the web application located at app.zodiacreads.com and a companion Android mobile application (together, the "Service"), which generate Vedic astrology birth charts, divisional charts, dasha timelines, numerology readings, and related interpretive content. Your account and data are shared across both — signing up or in through either the website or the Android app gives you access to the same account.
This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the rights you have over your data. By creating an account or using the Service, you agree to the practices described in this policy.
This policy is intended to comply with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), India's Digital Personal Data Protection Act (DPDPA, 2023), and other applicable privacy laws.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Name (display name, optional)
- Email address (used as your login identifier and for account-related notifications)
- Password (stored only as a salted bcrypt hash — we never see or store your plaintext password)
- Google account identifier, name, and email, only if you choose to sign in with Google (see Section 6)
2.2 Birth Chart Data
To generate astrology readings, we collect the following birth details that you provide voluntarily:
- Full name (or any label) for each chart
- Date of birth
- Time of birth
- Place of birth (city / locality), which we convert to latitude and longitude for chart calculation
- Gender (used only for KUA number calculation in numerology and salutation; treated as optional)
You may also save additional charts for family members, friends, or clients. You are responsible for obtaining their consent before entering their information into the Service.
2.3 Computed Astrological Data
We store the chart calculations derived from your birth data, including planetary longitudes, ascendant degree, lagna sign, vimshottari dasha tree, detected yogas, and divisional chart placements. This data is treated with the same protection as your raw birth details.
2.4 Usage and Technical Information
When you interact with the Service, we automatically collect:
- IP address (used for rate limiting and abuse prevention)
- Browser type and version, operating system
- Referring URL, pages visited, and timestamps
- Device identifiers required for session management
- Push notification token (Android app only) — if you have the Android app installed, we store a Firebase Cloud Messaging device token linked to your account so we can deliver notifications (e.g. daily Panchang, festival reminders). This token identifies your device for notification delivery only; it is not used for advertising or shared with advertisers.
2.5 Location Data (Android App Only)
The Android app requests approximate location permission (Android's ACCESS_COARSE_LOCATION — city-block level, not precise GPS). This is separate from the web app, which only uses the city you type in (see Section 2.2) and never accesses device location.
- What it's used for: computing your daily Panchang, sunrise/sunset, Rahu Kaal, Choghadiya, and determining your timezone so notifications are timed correctly for your location.
- How it's obtained: your device's last-known location. Your coordinates are reverse-geocoded into a city name for display purposes only.
- Where it's processed: entirely on your device. Your location is never sent to or stored on our servers — the calculations run locally in the app.
- Third parties involved: reverse-geocoding your coordinates into a city name uses Android's built-in Geocoder (Google) and, in some cases, OpenStreetMap's Nominatim service — both receive only the coordinates needed to look up a place name, not your account information.
- Fallback: if you deny the permission or a location fix isn't available, the app defaults to Mumbai's coordinates so Panchang-related features still work.
- Your control: you can deny or revoke this permission at any time from your device's Android system settings.
2.6 Information We Do Not Collect
We do not collect financial information, government IDs, or biometric data. We do not access precise/GPS-level location, contacts, camera, microphone, or storage on your device.
3. How We Use Your Information
- To create and manage your account and authenticate your sessions
- To compute and display your astrological charts, dashas, yogas, and other interpretive content
- To save and retrieve charts you choose to persist in your account
- To send transactional emails (password reset, security alerts, important service notices)
- To monitor, debug, secure, and improve the Service
- To enforce our Terms of Service and prevent fraudulent or abusive use
- To comply with legal obligations
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
4. Legal Basis for Processing
4.1 European Economic Area (GDPR)
If you are located in the European Economic Area, our legal bases are:
- Performance of a contract — to provide the Service you signed up for
- Consent — for any optional features you enable (e.g. saving charts, marketing communications)
- Legitimate interest — for security, fraud prevention, and product improvement
- Legal obligation — when required by law
4.2 India (Digital Personal Data Protection Act, 2023)
If you are a Data Principal located in India, our processing is based on:
- Consent — the primary basis for processing your personal data. Consent is collected at account creation and, separately, for any optional processing (such as marketing emails) that is not necessary to provide the core Service. You may withdraw consent at any time (see Section 10), and withdrawal is as easy as giving it.
- Certain legitimate uses specified under the Act — for example, where you have voluntarily provided data for a specified purpose (such as saving a chart) and have not indicated you do not consent to its use, or where processing is necessary to respond to a medical emergency, or to comply with a legal obligation or court order.
The DPDP Act does not recognise "legitimate interest" as a standalone lawful basis in the way GDPR does. For Data Principals in India, we do not rely on legitimate interest as a basis for processing — only on consent or a specified legitimate use under the Act.
5. How We Share Information
We share personal information only with the following categories of recipients, under contractual confidentiality obligations:
- Hosting and infrastructure providers — Vercel (application hosting) and MongoDB Atlas (database hosting). These providers store your data on our behalf and do not access it for their own purposes.
- Email delivery providers — used to send transactional emails (e.g. password reset).
- Geocoding services — on the web app, when you type a city we send the city name to a third-party geocoding API (OpenStreetMap Nominatim) to obtain latitude and longitude. On the Android app, when using location-based Panchang features, your coordinates are sent to Android's built-in Geocoder (Google) and, in some cases, OpenStreetMap Nominatim, to look up a place name (see Section 2.5). In both directions, we do not send your name, email, or other identifying information with these requests.
- Identity providers — if you choose to sign in with Google, Google handles the authentication step (see Section 6).
- Push notification delivery — if you use the Android app, we use Firebase Cloud Messaging (operated by Google) to deliver notifications to your device. Google processes your device token to route notifications; it does not receive your birth chart data.
- Legal authorities — when required by valid legal process (court order, subpoena, regulator request).
- Successor entities — in the event of a merger, acquisition, or asset sale, your data may transfer subject to this Privacy Policy.
6. Google Sign-In and Third-Party Login
If you choose to sign in with Google, we use Google's OAuth 2.0 protocol. We request the following Google scopes:
openid,email,profile— to obtain your verified email address, basic profile (name, profile picture URL), and a stable Google account identifier
We do not request or access:
- Your Google contacts, calendar, drive, photos, or any other Google services
- Permission to send email on your behalf
- Your Google password (it is never shared with us — Google handles the login directly)
The Google account information we receive is used solely to create or sign in to your ZodiacReads account. You can revoke access at any time at myaccount.google.com/permissions.
ZodiacReads's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
7. Cookies and Local Storage
We use the following kinds of client-side storage:
- Authentication cookie — a single HTTP-only, SameSite cookie containing a signed JWT that keeps you logged in. It expires when your session ends or after the configured lifetime, whichever comes first.
- sessionStorage — temporary storage in your browser used to hold the chart you are currently viewing so you can navigate between pages without recomputing it. Cleared when you close the browser tab.
- Functional preferences — small entries that remember your selected divisional chart, theme, or panel state.
We do not use third-party advertising cookies or cross-site tracking pixels.
Android app: the Android app does not use browser cookies. It stores your session token and equivalent local data securely on your device, and uses it the same way — to keep you signed in and hold the chart you're currently viewing.
8. Data Retention
We retain personal data for as long as your account is active or as needed to provide the Service. Specifically:
- Account data — retained until you delete your account.
- Saved charts — retained until you delete them or your account.
- Transactional email logs — up to 90 days for delivery diagnostics.
- Server logs — typically 30 days, longer if required for security investigations.
When you delete your account, we delete or irreversibly anonymize your personal data within 30 days, except where retention is required by law.
9. Security
We protect your data using:
- HTTPS / TLS for all traffic between your browser and our servers
- Salted bcrypt hashing for passwords (we never store plaintext passwords)
- HTTP-only, SameSite authentication cookies to mitigate XSS and CSRF
- Encryption at rest on our database provider (MongoDB Atlas)
- Principle of least privilege for internal access
- Regular dependency updates and security reviews
No system is perfectly secure. If we become aware of a data breach affecting your personal information, we will notify you and the relevant authorities as required by law.
10. Your Rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your account and associated data
- Export your data in a portable format
- Withdraw consent at any time, where processing is based on consent — withdrawal is as easy as giving it, and you can do this from your account settings or by emailing us
- Object to or restrict certain processing activities
- Lodge a complaint with your local data protection authority. If you are a Data Principal in India, this is the Data Protection Board of India, established under the DPDP Act, 2023. We encourage you to raise any concern with our Grievance Officer first (see Section 14) so we can try to resolve it directly.
To exercise any of these rights, email us at support@zodiacreads.com. We will respond within 30 days.
11. Children's Privacy
The Service is intended for use only by individuals aged 18 years or older. We do not knowingly create accounts for, or collect personal data from, anyone under 18. This applies regardless of jurisdiction, and reflects India's Digital Personal Data Protection Act, 2023, which defines a child as anyone under 18 and requires verifiable parental consent before processing a child's personal data — a consent mechanism we have not built and do not offer. Rather than process children's data under a parental-consent flow, we simply do not permit account holders under 18.
By creating an account, you confirm that you are 18 years of age or older. If we become aware that an account holder is under 18, we will suspend the account and delete the associated personal data.
This 18+ requirement applies to the account holder only. It does not prevent you from generating or saving a chart for a family member, friend, or client who is themselves under 18 (for example, a parent generating a chart for their child) — see Section 2.2 and our Terms of Service, Section 6 for your responsibilities when entering another person's birth data.
If you believe a child under 18 holds an account with us, please contact our Grievance Officer (Section 14) and we will investigate and delete the account promptly.
12. International Data Transfers
Our infrastructure providers (Vercel, MongoDB Atlas) may store and process data in regions outside your country of residence. Where personal data is transferred internationally, we rely on appropriate safeguards such as Standard Contractual Clauses approved by the European Commission.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and notify you by email or in-app notice. Your continued use of the Service after the changes take effect constitutes acceptance of the revised policy.
14. Contact Us & Grievance Officer
If you have questions about this Privacy Policy or how we handle your data, you can reach us at:
- Email: support@zodiacreads.com
- Website: zodiacreads.com
Grievance Officer (India — DPDP Act, 2023)
In accordance with the Digital Personal Data Protection Act, 2023, we have designated a Grievance Officer to address complaints and grievances from Data Principals in India:
- Name: Chetan Raje
- Email: hello@zodiacreads.com
We will acknowledge and work to resolve grievances submitted to the Grievance Officer within the timelines prescribed under the DPDP Act. If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India.
By using ZodiacReads, you acknowledge that you have read and understood this Privacy Policy.