← Back to Karma Karyam
Privacy Policy
Last updated: 20 May 2026
Karma Karyam ("we", "our", or "the app") is operated as an independent project. We treat your birth chart as sacred personal information and we treat your data with the same care. This policy explains what we collect, why we collect it, and what control you have.
1. What we collect
We collect only what we need to deliver the service. Concretely:
Account information
- Your email address (required to sign in).
- Your display name (optional; defaults to the part of your email before the "@").
- The OAuth provider you used to sign in (e.g. Google), if applicable.
Birth and chart information
- Your date of birth, time of birth, and place of birth (only what you choose to enter).
- Your uploaded Kundali PDF, processed only to extract planetary positions (Rashi, Nakshatra, Lagna, current Dasha, planetary placements). The PDF text is stored encrypted at rest in our database.
- Your derived chart fields (Rashi, Nakshatra, Lagna, Dasha) used to personalise guidance.
Activity data
- Questions you ask the AI Oracle and the responses generated.
- Daily quota usage (so we can enforce the free/premium limits).
- Your reminders, mantra completions, and sankalpa entries.
- Push-notification endpoints (web push) or FCM tokens (Android), only if you opt in to remedy reminders.
Payment information
- For web subscriptions, payment is processed by Stripe. We store only the customer ID and subscription ID, never card numbers.
- For Android subscriptions, payment is processed by Google Play. We store only the purchase token and order ID returned by Google.
Sankalpa donation proof emails
When you tap "Send proof + commit", your email client opens a pre-filled message addressed to the operator's contact mailbox. Sending the email is at your discretion. The mailbox is monitored only to provide service-related responses; we do not share its contents.
2. Why we collect it
- To provide the service: show you your chart, give personalised AI guidance, deliver reminders, run your subscription.
- To enforce rate limits and quotas: the free / premium tier caps are enforced server-side using your daily and lifetime counters.
- To detect abuse: short-window rate limiting prevents anyone from running up our AI bill.
- To comply with legal obligations (e.g. tax records of payments, audit trails for fraud disputes).
We do not sell your data. We do not use your chart for advertising. We do not profile you for third-party marketing.
3. Who we share it with
Your data passes through a small set of service providers ("processors"), each used for a single specific purpose:
- Supabase, managed Postgres + authentication. Stores your profile, chart, and activity.
- Netlify, application hosting and serverless functions. Sees requests in transit; does not store your data.
- Stripe, payment processing for web subscriptions.
- Google Play Billing, payment processing for Android subscriptions.
- Groq, Google (Gemini), NVIDIA, and OpenRouter, large language model providers. When you ask the Oracle, the text of your question (with chart context) is sent to one of these providers to generate the response. We choose based on availability; we do not send your name or email along with the request.
- Upstash, Redis used for short-window rate limiting (your user ID is the rate-limit key; no other data stored).
- Firebase Cloud Messaging, only if you opt in to Android push; used to deliver remedy reminders.
None of these providers are authorised to use your data for their own purposes. Each operates under a data processing agreement.
4. How long we keep it
- Profile, chart, and reminders: kept while your account is active.
- Question history: kept for 12 months, then anonymised for service improvement.
- Payment records: kept for 7 years as required by tax law.
- On account deletion: we erase all personal data within 30 days (typically immediately). Payment-record retention obligations may keep an anonymised receipt for accounting.
5. Your rights and choices
You have the right to:
- Access the data we hold about you (use "Profile → Manage subscription" or contact us).
- Correct inaccurate data (edit your profile or upload a new Kundali).
- Delete your account and all associated data: Profile → Delete my account permanently. This is irreversible.
- Cancel your subscription at any time:
- Web subscription → Profile → Manage subscription (opens Stripe portal).
- Android subscription → Google Play Store → Subscriptions → Karma Karyam → Cancel.
- Withdraw consent for push notifications at any time in your device settings.
- Export your data on request.
If you are in the EU/UK, you may also lodge a complaint with your local data protection authority.
6. Security
All traffic between your device and our servers uses HTTPS. Your chart data is encrypted at rest. Service-role keys are stored in Netlify's encrypted environment store and never exposed to the browser. Auth tokens are JWTs scoped to your user ID.
No system is perfectly secure. If we ever experience a breach affecting your data, we will notify you within 72 hours.
7. Children
Karma Karyam is intended for adults (18+). We do not knowingly collect data from children under 18. If you believe a minor has signed up, contact us and we will delete the account.
8. Changes to this policy
We may update this policy occasionally. Material changes will be announced in-app and via email if you have an account. The "Last updated" date at the top reflects the most recent revision.
Privacy questions, data export requests, or anything else: privacy@karmakaryam.app
For account-deletion requests, the in-app button (Profile → Delete my account permanently) is the fastest path. Email is a fallback.