Legal
Privacy Policy
Last updated 9 August 2026 · Applies to vrindaved.com and the Vrinda Ved mobile apps
This policy explains what personal data Vrinda Ved collects, why we collect it, who else sees it, how long we keep it, and what you can ask us to do with it. It is written to satisfy India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) and, for users in Europe and the United Kingdom, the GDPR.
For the purposes of the DPDP Act, Hardevi Hardasani is the Data Fiduciary and you are the Data Principal. Under the GDPR we are the controller.
The short version. To draw your chart we need your date, time and place of birth. That is unusually sensitive information, so: we never sell it, we never use it for advertising, we do not use your data to train AI models, and we delete it when you delete your account. The rest of this page is the detail behind those four promises.
1. What we collect
Information you give us
- Account details — your name, and an email address and/or mobile number depending on how you sign in. If you use Google sign-in, we receive your name, email address and profile picture from Google.
- Birth details — your date of birth, time of birth (and whether it is known), and place of birth, which we convert into latitude, longitude and timezone in order to compute your chart. This is the core of the Service and cannot be omitted.
- Birth details of other people — if you use compatibility features, the name and birth details you enter for a partner or family member. See clause 6.
- Your questions and conversations — the messages you send in chat, the readings generated in reply, and any rating or feedback you give on them.
- Preferences — chart style, notification settings and similar choices.
- Correspondence — what you send us by email or through support.
Information we generate or collect automatically
- Computed astrological data — charts, dashas, yogas, transits and compatibility scores derived from your birth details.
- Usage records — which features you use, how many questions you have used against your allowance, and timestamps. We use this to enforce plan limits and to understand what to improve.
- Payment records — a history of your transactions: amount, currency, plan, provider and a provider reference. We never receive or store your card number, UPI ID or bank credentials.
- Technical data — IP address, browser and device type, and error diagnostics, used for security, rate limiting and debugging.
Sensitive data, and a note on inference
Birth details are not classified as “special category” data under the GDPR in themselves, but we recognise that a person’s exact time and place of birth is intimate, permanent and unchangeable — you cannot rotate it like a password. We also recognise that what you ask the Service can reveal a great deal: questions about illness, fertility, money trouble or a relationship breakdown are, in substance, sensitive. We therefore apply the same care to your questions as to your birth data, and we do not profile you or infer health, sexual orientation, religious belief or political opinion for any purpose beyond answering the question you actually asked.
2. Why we process it, and on what basis
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and secure your account | Account details, technical data | Performance of a contract; consent (DPDP s.6) |
| Compute charts and generate readings | Birth details, questions | Performance of a contract; consent |
| Compatibility analysis | Your birth details and those you enter for another person | Consent — yours, and the other person’s, which you confirm you have |
| Take payment and manage subscriptions | Account details, payment records | Performance of a contract; legal obligation (tax records) |
| Enforce plan allowances and the one-time free trial | Usage records, hashed email/phone fingerprint | Legitimate interest in preventing abuse |
| Security, rate limiting, fraud prevention | Technical data, usage records | Legitimate interest; legal obligation |
| Fix bugs and improve the Service | Error diagnostics, aggregated usage | Legitimate interest |
| Service emails (receipts, renewal and security notices) | Account details | Performance of a contract |
We do not run behavioural advertising and we do not sell personal data to anyone, in any sense of the word “sell”.
3. How AI providers are involved
Readings and chat replies are generated by large language models operated by third parties. When you ask a question, we send the model the astrological context it needs — your computed chart, the relevant planetary positions, and your question — so that it can answer.
- We send the computed chart rather than your raw birth record where the calculation has already been done, and we do not send your email address, phone number or payment details to any model provider.
- Your name may appear where it makes the reading read naturally.
- Your data is not used to train any AI model. We use these providers under commercial API terms that exclude training on customer inputs and outputs. Providers may retain inputs briefly for abuse monitoring under their own policies.
4. Who else processes your data
We use the service providers below. Each acts as a processor on our instructions, under a contract that requires confidentiality and appropriate security, except where noted.
| Provider | What it does | Where |
|---|---|---|
| Supabase | Database, authentication and file storage — holds your account and birth details | Singapore / EU |
| Google Cloud Platform (Cloud Run, Firebase Hosting) | Application hosting and content delivery | Mumbai, India (asia-south1) and global edge |
| Anthropic (via an API gateway) | Generates chart interpretations, readings and chat replies | United States |
| Google (Gemini API) | Generates daily readings and computes text embeddings for scripture search | United States |
| Message Central | Delivers one-time passcodes by SMS when you sign in with a phone number | India |
| Razorpay Software Private Limited | Processes payments made in Indian Rupees | India |
| Creem | Merchant of Record for payments made in currencies other than INR | European Union / United States |
| Upstash | Rate limiting and short-lived caching | Global edge |
| Sentry | Error monitoring and diagnostics | United States / European Union |
Creem acts as Merchant of Record for payments outside India, which makes it an independent controller of the transaction data for that sale, not merely our processor. Our Indian payment processor is likewise an independent controller of the payment instrument data it collects from you directly.
We will also disclose data where we are legally required to, or to establish or defend a legal claim.
If the business is ever sold or merged, your data may transfer to the acquirer. We will tell you before that happens and the acquirer will be bound by this policy until they publish their own.
5. International transfers
The Service is hosted in Mumbai, India. Some providers above process data outside India, including in the United States and the European Union. Where data leaves the UK or EEA we rely on the European Commission’s Standard Contractual Clauses or an adequacy decision. The DPDP Act permits transfer to any country not specifically restricted by the Government of India, and we monitor that list.
6. When you enter someone else’s birth details
Compatibility features require a second person’s details. When you enter them you are confirming that you have that person’s consent. Under the DPDP Act and the GDPR the responsibility for having a lawful basis to share another person’s data sits with you.
The Service is built to analyse the relationship between two charts and will decline to produce a standalone personal reading about someone who is not the account holder. If a person learns that their birth details are stored in someone else’s account and wants them removed, they can write to privacy@vrindaved.com and we will delete them.
Where our compatibility engine learns from patterns across many readings, it does so only from de-identified data from which individuals cannot be recovered.
7. How long we keep things
| Data | Retention |
|---|---|
| Account, birth details, charts, saved partners | Until you delete your account |
| Chat history and readings | Until you delete them, or until account deletion |
| Payment and tax records | 8 years, as required by Indian tax law — this survives account deletion |
| Free-trial fingerprint (irreversible hash) | Indefinitely — it is what makes the trial one-per-person |
| Security and rate-limit logs | Up to 180 days |
| Error diagnostics | Up to 90 days |
| Backups | Purged on the normal backup rotation, up to 30 days after deletion |
8. Your rights
Under the DPDP Act you have the right to:
- Access — a summary of the personal data we process about you and who we have shared it with;
- Correction and completion — to have inaccurate or incomplete data fixed;
- Erasure — to have your data deleted where we no longer need it for the purpose you gave it for, or for a legal obligation;
- Grievance redressal — to complain to us first, and then to the Data Protection Board of India;
- Nominate — to name another person to exercise these rights on your behalf if you die or become incapacitated.
If the GDPR or UK GDPR applies to you, you additionally have the right to data portability, to object to processing based on legitimate interests, to restrict processing, and to complain to your national supervisory authority.
Withdrawing consent. You can withdraw consent at any time by deleting your account. Because birth details are the entire input to the Service, withdrawing consent to process them means the Service can no longer function for you. Withdrawal does not affect processing already carried out.
To exercise any of these rights, write to privacy@vrindaved.com from the address on your account, or use the account deletion option in your profile. We respond within 30 days and will not charge you. We may ask you to verify your identity — we will not disclose someone’s chart to a person who merely claims to be them.
9. Cookies and similar technologies
We keep this deliberately minimal. We use no advertising cookies and no third-party tracking cookies, which is why you are not being shown a consent banner.
| Cookie | Purpose | Lifetime |
|---|---|---|
__session | Strictly necessary. Holds your sign-in session so you stay logged in. | Until you sign out or it expires |
| Local storage | Strictly necessary. Remembers interface preferences such as chart style and theme. | Until you clear it |
Strictly necessary cookies do not require consent under the GDPR’s ePrivacy rules. If we ever add analytics or advertising technology, we will ask for your consent first and update this section.
10. How we protect your data
- All traffic is encrypted in transit with TLS; data is encrypted at rest by our hosting providers.
- Your conversations carry a second layer on top of that. The messages you send, the readings generated in reply, and any question you rate are encrypted with AES-256 before they are stored, using a key the database itself never holds. Anyone who obtained a copy of the database — a stolen backup, a leaked credential — would find unreadable ciphertext rather than your conversations.
- To be plain about the limit of that: your conversations are processed on our servers in readable form, because answering a question requires reading it. The encryption above protects what is stored, not the moment of answering.
- Database access is enforced per-user at the row level, so one account cannot read another’s chart even if application code is at fault.
- Sign-in uses one-time passcodes or Google — we do not store passwords you have chosen.
- Secrets and API keys are held in a managed secret store, not in code.
- Access to production data is limited to those who need it. Reading stored conversation content takes a separate tool that records who ran it, when, whose data was read, and a written reason.
No system is perfectly secure. If a personal data breach occurs, we will notify the Data Protection Board of India and every affected user as required by the DPDP Rules, and — where the GDPR applies — the relevant supervisory authority within 72 hours.
11. Children
The Service is for adults aged 18 and over. We do not knowingly process the personal data of a child. Under the DPDP Act, processing a child’s data requires verifiable parental consent and prohibits tracking and behavioural advertising directed at children; rather than attempt this, we simply do not serve under-18s. If you believe a child has given us data, write to privacy@vrindaved.com and we will delete it.
12. Grievance Officer and escalation
If you have a concern about how we handle your data, contact our Grievance Officer first:
Hardevi Hardasani, Proprietor
Vrinda Ved, 311, Vaibhav Apartments, Sethi Colony, Jaipur, Rajasthan 302004, India
hardevi@vrindaved.com
We acknowledge within 48 hours and aim to resolve within 15 days. If you are not satisfied, you may complain to the Data Protection Board of India, or — if you are in the EU or UK — to your national data protection authority.
13. Changes to this policy
We will update this page when our practices change, and change the “last updated” date above. If a change materially affects your rights, we will notify you by email or in the app at least 30 days before it takes effect.
14. Contact
Hardevi Hardasani (Proprietor, Vrinda Ved)
311, Vaibhav Apartments, Sethi Colony, Jaipur, Rajasthan 302004, India
privacy@vrindaved.com
See also our Terms of Service and Disclaimer.
© 2026 Vrinda Ved. All rights reserved.
Vrinda Ved is a commercial trade name and a sole proprietorship venture owned and operated legally by Hardevi Hardasani.