Privacy Policy.
What we collect, why we collect it, how long we keep it, and the rights you have over your data — written for humans, structured for compliance.
We collect your birth details to compute charts and your email to run your account. We do not sell your data. We do not train third-party AI on your private conversations without your opt-in. You can export or delete everything from Settings → Account, anytime.
- Who this policy applies to
- Personal data we collect
- Why we collect it (purposes)
- Legal basis under DPDP Act
- How we share data
- International transfers
- How long we keep it
- Security
- Your rights as Data Principal
- Children
- Cookies & trackers
- AI training & your data
- Data breach notifications
- Changes to this policy
- Contact
01Who this policy applies to
This Privacy Policy ("Policy") applies to all personal data that Hey Gaargi ("Hey Gaargi", "we") processes about you when you use our mobile application, website, or any related service (collectively, the "Service"). For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDP Act"), we are the Data Fiduciary and you are the Data Principal.
This Policy supplements, and forms part of, our Terms of Service.
02Personal data we collect
We collect personal data in three ways: data you give us, data generated when you use the Service, and data we receive from third parties.
2.1 Data you give us
| Category | What it includes |
|---|---|
| Account identifiers | Name, email address, mobile number (verified by OTP), country, preferred language. |
| Astrological inputs | Date of birth, time of birth, place of birth (city + country, used to derive coordinates and timezone). |
| Profile (optional) | Gender, photograph, marital status, relationship details, profession — only if you choose to add them. |
| Conversations | The questions you ask Gaargi and the answers we generate, stored on our servers until you delete them. |
| Payment data | Billing name, billing address, GSTIN (optional), tokenised payment method. We do not store your full card number, UPI VPA, or net-banking credentials. |
| Communications | Emails, support tickets, survey responses, content of feedback you send us. |
2.2 Data we generate when you use the Service
- Device & technical — IP address, device model, OS version, app version, crash logs, language and timezone.
- Usage — features visited, buttons tapped, time spent, in-app errors. We use a self-hosted analytics stack (PostHog on AWS Mumbai) — no third-party analytics SDKs in production builds.
- Computed astrological data — birth charts, daśā tables, transit calendars derived from your inputs.
- Diagnostics — performance metrics, anonymised model latency, error reports.
2.3 Data we receive from third parties
- Payment processors (Cashfree) confirm payment success/failure and provide tokenised payment methods for future purchases.
- Sign-in providers (Google, Apple) provide your verified email and name only if you choose to sign in with them.
- Place lookup (OpenStreetMap Nominatim, self-hosted) returns coordinates for the city you enter.
03Why we collect it (purposes)
| Purpose | What we use |
|---|---|
| Provide the core service | Account identifiers, astrological inputs, conversations |
| Authenticate & secure your account | Email/mobile, device, IP address |
| Process payments & issue invoices | Payment data, billing address, GSTIN |
| Customer support | Communications, account identifiers |
| Improve the service (aggregated, anonymous) | Usage analytics, diagnostics |
| Send transactional emails (receipts, renewals) | Email address |
| Send marketing emails — only with opt-in | Email address, preferences |
| Legal compliance & fraud prevention | Transaction records, IP, device fingerprint |
04Legal basis under the DPDP Act
Under Section 4 of the DPDP Act, we process your personal data on one of two bases:
- Consent (Section 6) — for processing that requires you to opt in (e.g., marketing emails, optional profile fields, voice features). Consent is requested in clear, plain language and can be withdrawn at any time.
- Certain legitimate uses (Section 7) — for processing strictly necessary to provide the Service you requested, fulfil legal obligations, respond to medical emergencies, or comply with a court order or judicial decree.
05How we share data
We share personal data only with Data Processors (vendors processing on our behalf, under contract) and only as needed to operate the Service. Our active processor list:
| Processor | Purpose & location |
|---|---|
| Amazon Web Services (AWS) | Hosting & storage · Mumbai (ap-south-1) |
| Cashfree Payments India Pvt. Ltd. | Payment processing · India |
| OpenAI / Anthropic (AI inference) | Model inference for chat responses. Conversations are sent without your name or contact details and are processed under zero-retention agreements. |
We do not sell your personal data. We do not share it with advertisers or data brokers. We may disclose it to law-enforcement or regulatory authorities only when required by valid legal process under Indian law.
06International transfers
Your data is primarily stored in India (AWS Mumbai). Where a processor operates outside India (e.g., OpenAI, Anthropic), we transfer the minimum data necessary under standard contractual clauses and the conditions in Section 16 of the DPDP Act. As of the date of this Policy, the Central Government has not restricted transfers to any country; we will update this section if that changes.
07How long we keep it
| Data | Retention |
|---|---|
| Active account data (charts, conversations) | Until you delete the account. |
| Deleted account — backups | Purged from production within 7 days; from backups within 90 days. |
| Tax invoices & transaction records | 8 years (Section 36 of the CGST Act, 2017; Section 44AA of the Income-Tax Act, 1961). |
| Support tickets | 3 years after resolution. |
| Server & access logs | 180 days, then deleted. |
| Marketing preferences (unsubscribed) | Retained as a suppression record for 5 years. |
08Security
We use industry-standard safeguards including TLS 1.3 in transit, AES-256 encryption at rest, hashed and salted passwords (Argon2id), role-based access control, mandatory two-factor authentication for all staff, quarterly third-party penetration testing, and a documented incident-response plan. Despite these measures, no internet service can be 100% secure — you accept this residual risk by using the Service.
09Your rights as a Data Principal
Under Sections 11–14 of the DPDP Act, you have the right to:
- Access — request a summary of the personal data we hold about you and how it is processed;
- Correction — request that we correct inaccurate or update incomplete data;
- Erasure — request deletion of your personal data, subject to legal retention obligations;
- Withdraw consent — withdraw consent for any consent-based processing, with effect on future processing;
- Nominate — nominate another individual to exercise your rights in the event of your death or incapacity;
- Grievance redressal — file a complaint with our Grievance Officer (see Grievance Redressal) or, if unresolved, with the Data Protection Board of India.
Most rights can be exercised directly from Settings → Privacy. You can also email privacy@heygaargi.com. We respond within 30 days as required by the DPDP Act.
10Children
Hey Gaargi is intended for users aged 18 and above. For users between 13 and 18, we require verifiable parental consent before processing personal data, in accordance with Section 9 of the DPDP Act. We do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. Users under 13 are not permitted on the Service.
11Cookies and trackers
Our website uses a minimal set of essential cookies and one self-hosted analytics cookie. We do not run third-party advertising trackers. Full details are at Cookie Policy.
12AI training and your data
We use third-party large language models to power Gaargi's responses. Conversations sent to these providers are processed under zero-retention agreements: providers do not store our prompts, do not train their models on them, and do not use them for any purpose other than returning a single response to us. We do not use the contents of your private conversations to train our own models without explicit opt-in. If you opt in to "Help improve Gaargi" under Settings → Privacy, anonymised, redacted excerpts may be used for evaluation; you can revoke this at any time.
13Data breach notifications
In the event of a personal data breach affecting your information, we will notify the Data Protection Board of India and affected users without undue delay, in accordance with Section 8(6) of the DPDP Act. Notifications will include the nature of the breach, the data affected, mitigation steps, and contact details for queries.
14Changes to this policy
We may update this Policy when our practice or the law changes. Material changes will be notified by email and via an in-app notice at least 30 days in advance. The "Last revised" date at the top of this document is the source of truth.
15Contact
For any privacy-related question, write to our Data Protection Officer at dpo@heygaargi.com. For formal complaints, see Grievance Redressal.