విషయానికి వెళ్లండి

చట్టపరమైన సమాచారం

గోప్యతా విధానం

అమలులోకి వచ్చే తేదీ: 2026-10-05

వెర్షన్: v6.3 మునుపటి వెర్షన్: v6.2

v6.3 మార్పుల సారాంశం: అందుబాటులో ఉన్న Android English dictationకు OS speech processing, పంపే ముందు transcript editing వివరాలను జోడిస్తుంది; purchase-support మరియు store financial-event recordsకు వేర్వేరు retentionను వివరిస్తుంది. 2026-10-05 నుంచి అమల్లోకి వస్తుంది; v6.2ను భర్తీ చేస్తుంది. v6.1 మార్పుల సారాంశం: Android మరియు iOS Appలో city నిర్ణయించడానికి optional privacy-minimised flowను జోడించాం. Save చేసిన లేదా ఎంచుకున్న cityకి ప్రాధాన్యం ఉంటుంది. City లేకపోతే ఒక cookie-free request trusted Cloudflare edge headers ద్వారా validated nearby cityని సూచించవచ్చు; అది దొరకకపోతే Ujjainను స్పష్టమైన defaultగా చూపుతాం. Use my current location నొక్కినప్పుడు మాత్రమే App ఒకసారి approximate foreground locationను కోరుతుంది (iOSలో When In Use), పంపే ముందు దాదాపు 5 km నగర పరిమాణ ప్రాంతానికి తగ్గిస్తుంది, raw fixను తొలగిస్తుంది. Precise/background location లేదా location history నిల్వ చేయము.

v6 మార్పుల సారాంశం: పూర్తి Hindi publicationను మరియు ప్రస్తుత చట్టానికి సంబంధించిన clarificationను జోడిస్తుంది. DPDP Actలోని ప్రధాన processing, obligation మరియు Data Principal rights provisions (sections 3–17), అలాగే Rules 3 మరియు 5–16, 13 May 2027న అమలులోకి వస్తాయి; Data Protection Board ఇప్పటికే స్థాపించబడింది. ఆ provisions అమలులోకి వచ్చే వరకు వర్తించే dutiesలో Information Technology Act, 2000 మరియు SPDI Rules, 2011 ఉంటాయి. Astroyana ఇప్పటికే పేర్కొన్న controlsను contractual service commitmentsగా అందిస్తుంది. వినియోగదారు ఫిర్యాదు acknowledgement గడువు 72 గంటల నుంచి 48 గంటలకు తగ్గుతుంది. ఈ revision కొత్త privacy-minimised server-side Yana weekly aggregate counter మరియు optional paid Yana voice unlockను కూడా వెల్లడిస్తుంది. Aggregate వల్ల user-level analytics record, individual profiling, offer tracking లేదా Android capability చేరదు. §5Bలో వివరించిన narrow voice processing కోసం మాత్రమే §7లో Google Cloud Text-to-Speechను జోడించాం.

v6.2 change-log: Yana calculation packet, Android Google Play credit/report purchases, optional notifications వివరాలను సరిచేస్తుంది. 2026-10-03 నుంచి అమలులో; v6.1 స్థానంలో ఉంటుంది.


1. మేమెవరం

Operator మరియు భవిష్యత్తు Data Fiduciary:

  • Operator: SNAZZYWORKS నిర్వహించే సేవా బ్రాండ్ Astroyana
  • GSTIN: 27HXGPD1259E1ZL
  • Registered / principal address: Ground Floor, Tejaswani Hsg Society, DP Road, Baner, Pune - 411045, Maharashtra, India
  • General contact: [email protected]
  • Customer care / grievance phone: +91 83903 38556
  • Website: https://astroyana.com
  • Android app: Google Playలో "Astroyana", application identifier com.astroyana.app, publisher SNAZZYWORKS

1.1 గోప్యత మరియు ఫిర్యాదు contact

  • Name: Mahesh Dhaifule
  • Designation: Grievance Officer & Data Protection Lead
  • Email: [email protected]
  • Phone: +91 83903 38556
  • Postal address: Ground Floor, Tejaswani Hsg Society, DP Road, Baner, Pune - 411045, Maharashtra, India
  • Consumer-grievance timeline: 48 గంటల లోపు acknowledgement; ఒక నెలలో redressal
  • Other privacy requests: సాధారణంగా 30 రోజుల లోపు substantive response; వర్తించే GDPR period §16లో ఉంది

DPDP Act §§8(10), 13 మరియు Rule 14, 13 May 2027న అమలులోకి వచ్చినప్పుడు, తరువాతి policy replacementను పేర్కొనకపోతే ఈ contact statutory contactగా పనిచేస్తుంది.


2. పరిధి

మీరు కింది చర్యలు చేసినప్పుడు process అయ్యే personal dataకు ఈ Policy వర్తిస్తుంది:

  • astroyana.com లేదా astroyana.inను సందర్శించడం
  • Astroyana Android appను ఉపయోగించడం
  • ఉచిత లేదా paid report లేదా calculatorను కోరడం
  • Account సృష్టించడం లేదా web magic link / app OTP ద్వారా sign in చేయడం
  • AI జ్యోతిష్కుడు Yanaను ఉపయోగించడం
  • Feature enable చేసినప్పుడు Family Vaultలో మరో adultను save చేయడం
  • Web checkout ద్వారా కొనుగోలు చేయడం లేదా supportతో communicate చేయడం

మేము ఇప్పుడే అందించే controls, భవిష్యత్తు DPDP rights, మరియు EU, EEA, UK usersకు అదనపు GDPR / UK GDPR సమాచారాన్ని కూడా ఇది వివరిస్తుంది (§16).

Third-party sites, ఇంకా engage చేయని భవిష్యత్తు astrologers లేదా contractors, లేదా వేరే సోదర బ్రాండ్ Rudrakshakavachకు ఇది వర్తించదు.


3. మేము process చేసే personal data

ఎంచుకున్న service మరియు దాని securityకి అవసరమైన మేరకే collectionను పరిమితం చేస్తాము.

3.1 మీరు ఇచ్చే data

CategoryExamples మరియు purpose
Account మరియు profileEmail; optional name మరియు phone; locale, tradition మరియు communication preferences. Authentication, account management, personalisation మరియు విడిగా opt-in చేసిన communications కోసం ఉపయోగిస్తాము.
Birth-chart inputsName, birth date, time మరియు place/coordinates. Chart లేదా reportను calculate చేయడానికి. Saved account chartsకు §11 వర్తిస్తుంది; anonymous chart snapshot accountలో write చేయబడదు.
Calculator inputsTool ఆధారంగా: name, birth date/time/place, coordinates, gender, మరియు matching కోసం ఇద్దరు adults వివరాలు. Android calculators email/phoneను అడగవు లేదా పంపవు. Separate functional consent తరువాత మాత్రమే website lead store అవుతుంది.
Family VaultFeature enable అయినప్పుడు మాత్రమే మరో adult name/nickname, relationship, birth details మరియు మీ consent attestation (§5A). ఆ వ్యక్తి email లేదా phoneను collect చేయము.
Communicationshello@, grievance@ లేదా supportకు messages; support subject/body; Yana responseను report చేసినప్పుడు optional reason మరియు answer excerpt. Support, grievances మరియు moderation కోసం.
Payments మరియు taxభారత web checkoutలో card/UPI credentialsను Razorpay స్వీకరిస్తుంది; international option ఉన్నప్పుడు మాత్రమే Stripe. మాకు full credentials కాకుండా limited transaction references, status, amount మరియు method metadata వస్తాయి. Optional B2B checkout tax invoice కోసం GSTIN మరియు legal nameను collect చేస్తుంది. Androidలో Google Play Billing ద్వారా in-app credit మరియు report purchases అందుబాటులో ఉన్నాయి. Shared walletలో credits జోడించే లేదా report fulfil చేసే ముందు Astroyana server ప్రతి purchaseను verify చేస్తుంది. Paymentను Google Play process చేస్తుంది; Astroyanaకు పూర్తి card లేదా bank credentials అందవు.
Yana questionsAnswerను generate చేయడానికి మరియు enable చేసినప్పుడు retain చేయడానికి, question మరియు §5Bలోని mode-specific context.

Android purchases and notifications. Google Play Billing in-app credit and report paymentsను process చేస్తుంది; fulfilmentకు ముందు Astroyana server purchase evidenceను verify చేస్తుంది. Optional reminders మరియు report-ready notificationsకు మీ action మరియు OS permission అవసరం; delivery కోసం Astroyana Expo push token మరియు installation/build metadataను Expo Push Serviceకు పంపుతుంది.

3.2 స్వయంచాలకంగా generate అయ్యే data

CategoryExamples మరియు purpose
Request metadataSecurity/audit tablesలో one-way SHA-256-hashed IP, browser లేదా app user-agent/version, OS మరియు timestamps; security, rate limiting, abuse control మరియు debugging కోసం.
Login మరియు computation eventsSign-in method, endpoint, time, outcome, duration, cache-hit మరియు signed-in account ID. Calculator request body, birth data, name, email, phone లేదా Yana question text ఉండవు.
First-party product analytics (web)Fixed page/tool/button events, query లేని path, referrer/campaign, coarse device/browser/OS, country, per-tab ID, signed in అయితే account ID, మరియు hashed IP. Free text, birth data, Yana question లేదా full URL ఉండవు. On-page opt-out ఈ pipelineను ఆపుతుంది. మేము third-party analytics serviceను load చేయము.
AuthenticationBrowser లేదా app native cookie storeలో host-only HttpOnly Secure session cookie.
CAPTCHAWeb formsలో transient Cloudflare Turnstile token; మేము store చేయము.
Birthplace query textExplicit Search/Enter లేదా field resolution తరువాత మాత్రమే city/place stringను మా /api/geocode proxy ద్వారా Nominatimకు పంపుతాము. Search-as-you-type autocomplete లేదు; మీ IP Nominatim నుంచి దాచబడుతుంది. Application search-history rowను సృష్టించము; సాధారణ infrastructure records request URLను process చేయవచ్చు.

Server-side Yana weekly aggregate analytics. పైన ఉన్న first-party web analyticsకు వేరుగా, ఈ feature enable చేసినప్పుడు computation engineకు చేరి completed అయిన requestsను మాత్రమే server లెక్కిస్తుంది. IST week (సోమవారం నుంచి), Engine response-domain enum, channel (web లేదా whatsapp) మరియు outcome (answer, degraded లేదా redirect) ప్రతి combinationకు ఒక counterను ఉంచుతుంది. Aggregateలో ఈ నాలుగు dimensions మరియు count మాత్రమే ఉంటాయి. Account, user, conversation లేదా request identifier, question లేదా answer text, birth/chart data, IP address, device/campaign data లేదా event timestamp ఉండవు.

ఈ weekly totalsను Yanaను మెరుగుపరచడానికి మరియు aggregate astrology-product demandను పరిశీలించడానికి మాత్రమే ఉపయోగిస్తాము. Targeting, individual profiling, purchase attribution లేదా cross-session journeys కోసం ఉపయోగించము. Analyst results 10 కంటే తక్కువ turns ఉన్న cellsను చూపవు; వాటిని తిరిగి లెక్కించగల totalను కూడా ప్రచురించవు. Counterను accountతో తిరిగి అనుసంధానించలేము కాబట్టి account deletion తర్వాత కూడా అది ఉంటుంది; individual export లేదా erasureలో చేర్చలేము. ఈ server-side aggregate first-party web analyticsకు వేరు; browser opt-out దీనికి వర్తించదు.

3.3 Android local data

App phoneలో పరిమిత app-private stateను ఉంచుతుంది:

  • Native cookie store: secure server session cookie
  • SecureStore: account ID/email marker, theme, Yana consent markers, మరియు గరిష్ఠంగా 24 గంటల question-only pre-auth Yana draft
  • App-private SQLite: saved city మరియు దాని source (manual, network estimate లేదా approximate device location), manually వెతికిన గరిష్ఠంగా ఎనిమిది recent cities, చిన్న public Panchang cache. Network/device path coarse city centroid మాత్రమే ఉంచుతుంది; raw fix లేదా location history కాదు; స్పష్టమైన Ujjain fallback save చేయబడదు
  • తొలగించే వరకు, app data clear/uninstall అయ్యే వరకు లేదా sign-out purge చేసే వరకు account-scoped report PDFs
  • Android share sheetకు అందించేంత సమయం మాత్రమే data-export cache file; తరువాత best-effort deletion

Android backup disabled. Sign-out server-session expiryని కోరుతుంది; local account state, Yana draft/consent, query cache మరియు downloaded reportsను clear చేస్తుంది. మీరు ఉద్దేశపూర్వకంగా save లేదా share చేసిన copyని Android మరియు destination నియంత్రిస్తాయి.

3.4 మేము collect లేదా use చేయని data

Advertising లేదా cross-app tracking SDKsను ఉపయోగించము; camera లేదా precise/background/continuous GPS dataను collect చేయము; personal dataను అమ్మము; birth data నుంచి predictive marketing segments సృష్టించము; Appలో engine/payment secretను embed చేయము. Optional location button ఒక approximate foreground fixను మాత్రమే వాడుతుంది; permission నిరాకరిస్తే మళ్లీ మళ్లీ అడగదు, city search అందుబాటులో ఉంటుంది. App astroyana.comను call చేస్తుంది; report short-lived authorised HTTPS redirect ద్వారా Cloudflare R2కు వెళ్లవచ్చు. App computation engineను నేరుగా ఎప్పుడూ contact చేయదు.


4. Legal మరియు service bases

ఇక్కడ పేర్కొన్న DPDP provisions 13 May 2027న అమలులోకి వస్తాయి. అప్పటి వరకు కూడా Astroyana వర్తించే ప్రస్తుత చట్టం — అవసరమైన చోట IT Act §43A మరియు SPDI Rules — contractual promises మరియు consumer lawను పాటించాలి.

4.1 Consent మరియు మీరు కోరే actions

Family Vault, Yana, marketing మరియు reminders సహా ఒక feature కోరినప్పుడు explicit consentను record చేస్తాము. Recordలో scope, wording/version, time మరియు అందుబాటులో ఉన్న request metadata ఉండవచ్చు. Required attestation record చేయలేకపోతే Family Vault saving fail closed అవుతుంది.

Calculator submit చేయడం, మీ chartను save చేయడం, sign-in కోరడం, report download చేయడం, payment, export లేదా delete చేయడం కూడా ఆ actionకు అవసరమైన dataను process చేయమనే instruction. అది unrelated marketing consentను సూచించదు. Feature-specific consentను దాని controlsలో లేదా [email protected] ద్వారా withdraw చేయవచ్చు; ముందుగా జరిగిన lawful processing చెల్లుబాటును అది రద్దు చేయదు.

4.2 Contract, law మరియు security

కోరిన లేదా కొనుగోలు చేసిన serviceను అందించడానికి, tax recordsను ఉంచడానికి, binding legal demandకు సమాధానం ఇవ్వడానికి మరియు serviceను రక్షించడానికి అవసరమైన dataను process చేస్తాము. DPDP commencement తరువాత, facts listed categoryకు సరిపోతేనే §7 "certain legitimate use"పై ఆధారపడతాము. "Fraud prevention"ను free-standing §7 categoryగా పరిగణించము; marketing లేదా unrelated profilingకు §7ను ఉపయోగించము.

4.3 Authentication

  • Magic link (web): 24 గంటలు valid, single-use
  • One-time code (app): 10 నిమిషాలు valid అయ్యే 6-digit code, single-use

రెండూ ఒకే server-side session మరియు host-only cookieని సృష్టిస్తాయి (§13).


5. Birth data మరియు reports

Birth date, time మరియు place అత్యంత identifying సమాచారం; అందువల్ల అదనపు safeguards ఉంటాయి.

5.1 Stored encryption మరియు transport

PostgreSQL storageకు ముందు birth columnsను AES-256-GCMతో at rest encrypt చేస్తాము. Deployment key Hostinger KVM2 VPSలోని Coolify environment variablesలో విడిగా ఉంటుంది; source controlలో commit చేయబడదు. ఇదే application-level encryption saved people birth data మరియు stored Yana textకు వర్తిస్తుంది.

Client నుంచి Cloudflare ద్వారా originకు connections TLS 1.2 లేదా higher మరియు Full (Strict) modeను ఉపయోగిస్తాయి. Origin-to-PostgreSQL container hop ప్రస్తుతం TLS-enabled కాదు; రెండూ ఒకే Mumbai host మరియు private non-public container networkలో ఉంటాయి. Sensitive columns database storageకు ముందే application-encryptedగా ఉంటాయి.

5.2 Decryption boundary

Birth data report computation, Yanaకు అవసరమైన chart findingsను రూపొందించడం లేదా మీ export కోసం memoryలో decrypt అవుతుంది. Raw natal date/time/place Yana structured calculation packetలో ఉండవు. Numerology కోసం ఇచ్చిన name/current name మరియు optional date of birth Astroyana serverలో ఉపయోగిస్తారు; §5B ప్రకారం providerకు raw inputsకు బదులుగా వాటి నుండి వచ్చిన findings వెళ్తాయి. మీరు వ్రాసిన question, history, clarificationలో personal details ఉండవచ్చు. Decrypted fields application logs మరియు transactional/marketing emailsలో ఉండవు. Error telemetryలో PII scrubbing ఉంటుంది; అది user data copy కాదు.

5.3 PDF storage

PDFsను Cloudflare R2 at rest encrypt చేస్తుంది. Download short-lived, single-use bearer grantను ఉపయోగిస్తుంది. PostgreSQL దాని SHA-256 hash మరియు atomic redemptionను మాత్రమే store చేస్తుంది. Raw grant bounded POST bodyలో submit చేసే వరకు URL fragmentలో ఉంటుంది; successful redemption bounded HTTPS redirectను R2కు return చేస్తుంది.

Account ఉన్నంత కాలం birth data ఉంటుంది. Account deletion మరియు backup handling §9 మరియు §11లో ఉన్నాయి.


5A. Family Vault

Family Vault server-feature-gated. Disabledగా ఉన్నప్పుడు peopleను save చేయడం లేదా read చేయడం జరగదు. Enabledగా ఉన్నప్పుడు reading కోసం మరో adult name/nickname, relationship మరియు birth detailsను save చేయవచ్చు. Details AES-256-GCM encrypted. వారి email లేదా phoneను collect చేయము.

ఆ adult permission ఇచ్చారని మీరు confirm చేయాలి. Consent scope saved_person_attestation, version saved-person-v2 కింద wording, date మరియు అందుబాటులో ఉన్న request/device detailsను record చేస్తాము. Shared web మరియు Android validators 18 కంటే తక్కువ వయస్సు ఉన్న ఎవరినైనా reject చేస్తాయి; Family Vaultలో parent లేదా guardian minor path లేదు.

ఆ వ్యక్తి 18 సంవత్సరాల లోపు ఉన్నప్పుడు పాత నమోదు సృష్టించబడితే, అది తొలగించడానికి మాత్రమే కనిపించే జాబితా నమోదుగా ఉంటుంది. దాన్ని తెరవడం, మార్చడం, export చేయడం లేదా readingలో ఉపయోగించడం సాధ్యం కాదు; తరువాత 18 సంవత్సరాలు నిండినా పాత attestation మళ్లీ చెల్లుబాటు కాదు. దాన్ని తొలగించి, ఆ వ్యక్తికి 18 సంవత్సరాలు నిండి permission ఇచ్చిన తర్వాత మాత్రమే మళ్లీ జోడించవచ్చు.

పరిమితి లేని saved adultను మీరు delete చేసే వరకు లేదా account delete అయ్యే వరకు ఉంచుతాము; అది మీ exportలో కనిపిస్తుంది. Account deletionలో ప్రతి నమోదు తొలగుతుంది. వారు నేరుగా మమ్మల్ని contact చేస్తే, verify చేసి detailsను తొలగించవచ్చు. Requested readings కోసం మాత్రమే ఆ detailsను ఉపయోగిస్తాము; ఎప్పుడూ అమ్మము లేదా external model trainingలో opt in చేయము.


5B. Yana, AI జ్యోతిష్కుడు

Yana server feature flag ద్వారా నియంత్రించబడుతుంది. Enabled అయినప్పుడు external language serviceకు మీ question, ఇటీవల సంబంధిత conversation context (మునుపటి questions మరియు answers), clarification question మరియు answer, అలాగే ఎంచుకున్న modeకు అవసరమైన computed findings ఉన్న structured calculation packet పంపబడతాయి. ఆ packetలో raw birth records, account identifiers లేదా account details ఉండవు. Dates మరియు placementsతో సహా derived chart లేదా calculation findings ఉండవచ్చు.

Numerology కోసం మీరు ఇచ్చిన name/current name మరియు optional date of birthను Astroyana server reading లెక్కించడానికి ఉపయోగిస్తుంది. Raw inputs బదులుగా వాటి నుండి వచ్చిన findingsను external language serviceకు పంపుతుంది. మీరు వ్రాసిన question, history మరియు clarification textగా పంపబడతాయి; వాటిలోని personal details కూడా share కావచ్చు. Service స్పష్టమైన email, phone మరియు account identifiersను తొలగిస్తుంది, కానీ ప్రతి personal detailను గుర్తించి తొలగించదు. Account email, phone మరియు payment dataను account fieldsగా పంపము.

Astroyana conversationsను model trainingలో opt in చేయదు. Anthropic standard commercial-API terms ప్రకారం input/outputను defaultగా generative models train చేయడానికి ఉపయోగించరు; Usage Policy enforce చేయడానికి లేదా law పాటించడానికి ఎక్కువ కాలం retain చేసే materialకు లోబడి, సాధారణంగా 30 రోజుల లోపు backend నుంచి delete చేస్తారు. Astroyana విడిగా encrypted conversation textను 180 రోజులు ఉంచుతుంది. ఒకటి లేదా అన్ని conversationsను delete చేయవచ్చు; export మరియు account deletion వాటిని include చేస్తాయి. Wallet ledgerలో chat text ఉండదు.

పూర్తయిన answerకు private audio సృష్టించేందుకు ఒక existing whole creditను విడిగా spend చేయవచ్చు. కేవలం normalised final answer text మరియు fixed locale/versioned voice configuration మాత్రమే server-to-server Google Cloud Text-to-Speechకు పంపుతాము. ఈ feature కోసం question, birth/chart data, account identity, conversation history, payment data లేదా arbitrary client textను Googleకు పంపము. explicit unlock తరువాతే generation మొదలవుతుంది. Cloud Text-to-Speech stateless, resourceless అని మరియు customer text లేదా generated audioను log చేయదని Google చెబుతుంది. పూర్తయిన private audio source answer ఉన్నంతకాలం Cloudflare R2లో, అదే conversation/account deletion controls మరియు 180 రోజుల retentionకు లోబడి ఉంటుంది. దానికి కొద్దిగా మించిన R2 lifecycle rule failsafe మాత్రమే, primary erasure కాదు. De-identified character, request, cost, time totals accounting/control windowకు user, answer, audio లేదా conversation content link లేకుండా ఉండవచ్చు.

Answersలో "Calculated by Ganaka, voiced by Yana" disclosure ఉంటుంది. అవి informational మాత్రమే; professional advice లేదా legally significant automated decision కావు.


5C. Android app

App server-backed. Identity, money, credits, saved charts మరియు report authority astroyana.comలో ఉంటాయి. Appలో engine credential లేదు.

  • OTP sign-in Siteతో అదే server sessionను ఏర్పరుస్తుంది.
  • Session 5 నిమిషాల కంటే తక్కువ వయస్సులో ఉండేలా fresh OTP re-authentication తరువాత in-app export మరియు deletion అందుబాటులో ఉంటాయి.
  • Androidలో Google Play Billing ద్వారా in-app credit మరియు report purchases అందుబాటులో ఉన్నాయి. Shared walletలో credits జోడించే లేదా report fulfil చేసే ముందు Astroyana server ప్రతి purchaseను verify చేస్తుంది. Paymentను Google Play process చేస్తుంది; Astroyanaకు పూర్తి card లేదా bank credentials అందవు.
  • App settingsలో optional reminders మరియు report-ready notificationsను enable చేయవచ్చు. మీ స్పష్టమైన action మరియు OS notification permission అవసరం. App Expo push token మరియు installation/build metadataను Astroyanaకు పంపుతుంది; Expo Push Service notificationను device platformకు relay చేస్తుంది.
  • ఈ features కోసం App Google Play Billing మరియు notification librariesను కలిగి ఉంది. Advertising, cross-app tracking, device-attestation లేదా mobile crash-reporting SDK లేదు.
  • Store Data Safety declarations birth/astrology data, third-party AI processing మరియు deletionను conservativeగా cover చేస్తాయి.

Androidలో optional English dictationను ఉపయోగించడానికి microphoneను స్పష్టంగా నొక్కి OS permission ఇవ్వాలి. Dictation ఉపయోగించకుండా మీరు టైప్ చేయవచ్చు, రాసినదాన్ని సవరించవచ్చు లేదా తొలగించవచ్చు. ఎంచుకున్న OS speech-recognition service మీ మాటలను deviceలో లేదా తన network ద్వారా process చేస్తుంది; ఆ service processing మరియు retention దాని provider privacy policy, settingsకు లోబడి ఉంటాయి. ఇది §5Bలోని paid answer audioకు వేరు. Astroyana raw audioను స్వీకరించదు లేదా నిల్వ చేయదు. Transcriptను సవరించవచ్చు; మీరు Sendను ఎంచుకున్నప్పుడే అది Astroyanaకు పంపబడుతుంది.

6. Uses

ఎంచుకున్న serviceను అందించడం, authenticate చేయడం, usersకు support ఇవ్వడం మరియు grievancesను పరిష్కరించడం, పరిమిత first-party web analytics మరియు operational events run చేయడం, performance/security monitor చేయడం, abuse నివారించడం, law/tax duties పాటించడం కోసం dataను ఉపయోగిస్తాము.

Separate opt-in లేకుండా marketing చేయము; dataను sell/rent చేయము; unrelated profiles సృష్టించము; birth data, saved-person data లేదా Yana conversationsను external model trainingలో opt in చేయము.


7. Processors

ProviderPurpose మరియు dataLocation
CloudflareDNS/CDN/WAF, Turnstile మరియు private R2 storage; request metadata, encrypted PDFs, private Yana WAV audio, pseudonymous user/answer/generation UUID object-key identifiers, Turnstile IP. మొదటి city-less App requestలో coherent edge headers advisory city estimate ఇవ్వవచ్చు; server దాన్ని store చేయదు లేదా identity, security, entitlement, payment కోసం వాడదుUS / global edge
Zoho / ZeptoMailTransactional email మరియు mailboxes; address, recipient name మరియు మీరు పంపే messagesChennai, India
HostingerOrigin VPS మరియు stored service dataMumbai, India
SentryScrubbed web error traces మరియు bounded diagnostics; Android SDK లేదుUnited States
OpenStreetMap Foundation / Nominatimమా proxy ద్వారా explicitly submitted city/place search మరియు optional దాదాపు 5 km foreground-location area reverse lookup; generic User-Agent, account ID లేదా user IP లేవుEurope
RazorpayIndian web payment credentials మరియు transaction processing; మాకు limited references వస్తాయిIndia
Stripeఅందించినప్పుడు international paymentUS / global
Anthropic, PBCYana question మరియు mode-specific §5B contextUnited States
Google Cloud Text-to-Speechexplicit voice unlockపై కేవలం normalised final Yana answer text మరియు fixed locale/versioned voice configurationGlobal infrastructure

Provider processing వర్తించే service/data termsకు లోబడి ఉంటుంది. ప్రతి provider విడిగా negotiated agreementపై sign చేసిందని ఈ table claim చేయదు. Materially new processor లేదా data useను జోడించే ముందు Policyని update చేస్తాము.

ఈ featuresకు processors: Android in-app credit and report payment మరియు purchase verification కోసం Google Play; optional notification relay కోసం Expo Push Service; మరియు §5Bలో వివరించిన Yana question, recent relevant conversation/clarification text, mode-specific structured calculation findings కోసం Anthropic, PBC. Yana packetలో raw birth records లేదా account fields ఉండవు; user textలో personal details ఉండవచ్చు.


8. International transfers

Cloudflare, Sentry, Stripe, Anthropic మరియు Google Cloud వర్తించే transfer terms కింద, అవసరమైన చోట Standard Contractual Clausesతో, data minimisation మరియు encryptionతో India బయట process చేయవచ్చు. Zoho మరియు Hostinger పేర్కొన్న India locationsను ఉపయోగిస్తాయి. DPDP Act §16 కింద India ఒక countryని restrict చేస్తే, ఆ provision మరియు restriction వర్తించినప్పుడు పాటిస్తాము.

Google Play మరియు Expo Push Service §§5C, 7లో వివరించిన Android purchase లేదా notification సమాచారాన్ని తమ వర్తించే transfer terms ప్రకారం India వెలుపల కూడా process చేయవచ్చు.


9. మీ controls మరియు rights

Astroyana ఈ controlsను ఇప్పుడే service commitmentsగా అందిస్తుంది; పేర్కొన్న DPDP rights 13 May 2027న అమలులోకి వస్తాయి.

9.1 Access మరియు export

https://astroyana.com/account/export లేదా Appను ఉపయోగించండి. JSONలో decrypted birth data, saved people మరియు Yana conversations ఉంటాయి; 24 గంటలకు ఒక్కసారి మాత్రమే; 5 నిమిషాల లోపు authenticate చేసిన session అవసరం. Accessible encrypted email exportను [email protected] నుంచి కోరవచ్చు.

9.2 Correction మరియు erasure

Account/App controlsలో profile dataను correct చేయండి లేదా మాకు email పంపండి. Fresh OTP verification తరువాత account deletion pageలో లేదా Appలో accountను delete చేయండి.

ఖాతా తొలగింపు మొదలైన వెంటనే ఖాతా నిలిపివేయబడుతుంది; తరువాత 30 రోజుల పునరుద్ధరణ ఉపశమన గడువు ఉంటుంది. ఆ తరువాత రోజువారీ శాశ్వత తొలగింపు ప్రక్రియ వినియోగదారు నమోదు, జనన సమాచార భాగాలు, Family Vault మరియు సమ్మతి నమోదులు, Yana పాఠ్యం, ఖాతాతో అనుసంధానమైన R2 నివేదిక నిల్వ విభాగాలు, సమ్మతి అనుమతులు, సెషన్లు, వినియోగదారుతో అనుసంధానమైన ప్రవేశం/వెబ్/గణన ఘటనలను తొలగిస్తుంది.

శాశ్వత తొలగింపు సమయంలో చెల్లింపు వివాదం లేదా ఖాతాల సరిపోల్చే ప్రక్రియ కొనసాగుతుంటే, మొత్తం తొలగింపు తుది సరిపోలిక పూర్తయ్యే వరకు వాయిదా పడుతుంది. తుది సరిపోలిక తరువాత ప్రక్రియ మళ్లీ మొదలై ఖాతాతో అనుసంధానమైన ఆ నివేదిక నిల్వ విభాగాలు మరియు వ్యక్తిగత సమాచారాన్ని తొలగిస్తుంది. ఈ వాయిదా PDFలకు చట్టపరమైన నిలుపుదల మినహాయింపును కల్పించదు: వేరే నివేదిక నిల్వ ప్రక్రియ ఉచిత PDFలను సరిగ్గా 90 రోజులకు, చెల్లింపు PDFలను సరిగ్గా 365 రోజులకు తొలగిస్తుంది.

Law లేదా security అవసరమైనదాన్ని మాత్రమే retain చేస్తాము: creation తరువాత ఒక సంవత్సరం వరకు audit entries, account linkను NULLగా set చేస్తాము; statutory period (సాధారణంగా 7 సంవత్సరాలు) వరకు anonymised tax amounts/fields; free text redacted చేసిన support/refund records. Encrypted backupsను 30 రోజుల లోపు purge చేస్తాము.

9.3 Grievance మరియు nomination

Grievanceను [email protected]కు పంపండి. వినియోగదారు grievanceను 48 గంటల లోపు acknowledge చేసి, ఒక నెలలో redress చేయడానికి ప్రయత్నిస్తాము. 13 May 2027 నుంచి eligible unresolved DPDP grievanceను Data Protection Board of Indiaకు escalate చేయవచ్చు.

Death/incapacity సందర్భంలో future DPDP rightsను exercise చేయడానికి, వారి contact మరియు notarised authorityతో ఒక personను nominate చేయవచ్చు.


10. పిల్లలు

Accounts మరియు Android 18 లేదా ఎక్కువ వయస్సు వారికి. Android Family Vault minorsను block చేస్తుంది. Website report form ప్రస్తుతం parent/guardian attestationను accept చేయవచ్చు; కానీ దాన్ని DPDP Rule 10 identity/age verificationగా మేము చూపము. 13 May 2027కు ముందు compliant verifiable parental consentను deploy చేస్తాము లేదా ప్రతి minor pathwayను disable చేస్తాము. పిల్లలను profile చేయము, behaviourally monitor చేయము లేదా adsతో target చేయము.

Suspected child dataను [email protected]కు report చేయండి. Specific law retentionను కోరితే తప్ప processingను suspend చేసి delete చేస్తాము; investigate చేసి 7 రోజులలో respond చేస్తాము.


11. Retention summary

DataRetention
Account మరియు encrypted birth dataActive account + 30-day deletion grace, తరువాత hard delete
Family Vault person/consentతొలగించే వరకు లేదా account deletion వరకు
Yana text180 రోజులు; user ముందే delete చేయవచ్చు
Private Yana voice audiosource answer ఉన్నంతవరకు; దానితో erase, 181-day R2 failsafeతో
Google Cloud Text-to-Speech customer contentGoogle Cloud TTS data-use documentation ప్రకారం logged కాదు
De-identified Yana voice spend/usage totalsaccounting/provider-spend control window; user, text లేదా audio link లేదు
Anthropic API copyDocumented exceptionsకు లోబడి సాధారణంగా 30 రోజుల వరకు
Chat text లేని wallet ledgerAccount lifetime
Free / paid PDFs90 / 365 రోజులు
Audit logsCreation నుంచి 1 సంవత్సరం
Session30-day rolling max-age
Magic link / OTP24 గంటలు / 10 నిమిషాలు, single-use
Login, computation మరియు first-party web eventsగరిష్ఠంగా 365 రోజులు; hard deleteలో user-linked rows erase అవుతాయి
Android Yana draftగరిష్ఠంగా 24 గంటలు
Android city/Panchang cachePrune లేదా app data removal వరకు app-private
Android report/export fileSign-out/app removal వరకు report; share తరువాత export best-effort deletion
Tax invoice / optional B2B GSTIN మరియు name7 సంవత్సరాలు; deletionలో order identifiers anonymise అవుతాయి

Purchase-support operational records, verified final resolution తర్వాత 180 రోజులు గడిచేలోపు reviewed deletionకు అర్హం కావు. అర్హత రావడం ఆటోమేటిక్ deletion కాదు; deletionకు నిర్ణీత గడువు లేదు. Store financial-event records సంబంధిత భారత ఆర్థిక సంవత్సరం ముగిసిన తర్వాత కనీసం 8 సంవత్సరాలు నిల్వ ఉంటాయి; తరువాతి statutory deadlines, unresolved refunds/recovery మరియు legal holds దీనిని పొడిగించవచ్చు. Orders, purchases, credits, reports మరియు invoicesకు వేర్వేరు lifecycle, legal retention ఉంటాయి; ఈ operational process వాటిని delete చేయదు.

12. Security మరియు breach response

Controlsలో AES-256-GCM sensitive-column encryption; R2 encryption; client నుంచి Cloudflare ద్వారా originకు TLS; passwordless authentication; host-only HttpOnly cookies; rate limits; Turnstile; Coolify secret storage; gitleaks; bounded audit logs; HIGH+ dependency scanning; encrypted backups; documented incident runbook ఉన్నాయి.

Same-host private database మరియు internal engine hopsను end-to-end TLSగా వివరించము. Quarterly restore procedure ఉంది; కానీ మొదటి full isolated live restore ఇంకా పూర్తి కాలేదు; verified live restore readiness ఉందని claim చేయము.

అవసరమైనప్పుడు affected individualsకు delay లేకుండా notify చేస్తాము. వర్తించే DPDP commencement తరువాత Boardకు initial intimation delay లేకుండా, అది మరింత సమయం అనుమతించకపోతే further particulars 72 గంటల్లో అందిస్తాము.


13. Cookies మరియు browser storage

CookiePurposeDuration
__Host-astroyana.session-tokenAuthentication30 రోజులు, rolling
__Host-astroyana.csrf-tokenCSRF protectionSession
__Host-astroyana.callback-urlMagic-link redirectSession
__Host-astroyana.pkce-code-verifierPKCE verification15 నిమిషాలు

ఇవి strictly necessary. Advertising లేదా third-party tracking cookie, cross-site profiling ఉపయోగించము. First-party analytics temporary per-tab browser-storage ID మరియు published opt-outను ఉపయోగిస్తుంది. వర్తించే చట్టం non-essential storageకు prior consent కోరినప్పుడు, analytics client consent-gatedగా ఉండాలి లేదా disabled కావాలి; opt-outనే consentగా పరిగణించము.


14. Policy changes

కొత్త versionను Privacy Policy pageలో publish చేసి, దాని hashను policy_versionsలో record చేస్తాము. Material expansionకు ముందు advance email notice ఇస్తాము; అవసరమైనప్పుడు fresh acceptance కోరుతాము; అమలులోకి రాకముందు deletionకు అవకాశం ఇస్తాము. Previous versionsను [email protected] నుంచి పొందవచ్చు.


15. Contact

Privacy rights మరియు grievances కోసం [email protected], general questions కోసం [email protected]ను ఉపయోగించండి. Contact details మరియు response times §1.1లో ఉన్నాయి. Data Protection Board ఉంది; సంబంధిత complaint provisions 13 May 2027న అమలులోకి వస్తాయి; filing route అందుబాటులో వచ్చినప్పుడు publish చేస్తాము.


16. EU / EEA / UK users

ఈ usersకు SNAZZYWORKS controller. Serviceను calculate/deliver చేయడం లేదా web paymentకు processing contractపై ఆధారపడుతుంది (GDPR Art. 6(1)(b)); optional Family Vault, Yana personalisation మరియు communications consentపై (Art. 6(1)(a)); proportionate security/operations మరియు aggregate analytics legitimate interestsపై (Art. 6(1)(f)); tax retention legal obligationపై (Art. 6(1)(c)) ఆధారపడతాయి.

Lawకు లోబడి, access, rectify, erase, restrict, port, object, consent withdraw చేయవచ్చు; legal లేదా similarly significant effect కలిగించే solely automated decisionsను avoid చేయవచ్చు. Astrological/Yana outputకు అటువంటి effect లేదు. ఒక నెలలో answer చేస్తాము; complexity ఉంటే noticeతో రెండు నెలలు extend చేయవచ్చు. UK ICO సహా మీ local supervisory authorityకు complaint చేయవచ్చు. International transfers §8లోని safeguardsను ఉపయోగిస్తాయి.


17. App connection summary

App astroyana.comను call చేస్తుంది. Report redemption server-authorised HTTPS R2 redirectను follow చేయవచ్చు. Private Yana voice మాత్రం short-lived, single-purpose header tokenతో Astroyana same-origin endpoint ద్వారా stream అవుతుంది; Appకు direct R2 URL ఇవ్వము. Identity, credits, purchases, saved charts మరియు report access server-authoritativeగా ఉంటాయి. App §3.3లోని పరిమిత local stateను మాత్రమే store చేస్తుంది. ఇందులో advertising, cross-app tracking, device-attestation లేదా mobile crash-reporting SDK లేదు. Android credit and report purchases Google Play Billingను ఉపయోగిస్తాయి. Optional reminders, report-ready notifications user action మరియు OS permission తరువాత అందుబాటులో ఉంటాయి; App Expo push token, installation/build metadataను Expo Push Service ద్వారా పంపుతుంది.

Appendix A: Legal references


Appendix B: Document control

FieldValue
Document titleగోప్యతా విధానం — Astroyana
Versionv6.2
స్థితిActive
Effective from2026-10-03
Supersedesv6.1

DOCUMENT ముగిసింది.

వార్తాలేఖ, మార్కెటింగ్ ఈమెయిళ్లు

మీరు Astroyana వార్తాలేఖకు చందా తీసుకుంటే, వార్తాలేఖ (అప్పుడప్పుడు వచ్చే విశ్లేషణలు, మార్గదర్శనం, ఉత్పత్తి నవీకరణలు) పంపడం కోసం మాత్రమే మీ ఈమెయిల్ చిరునామా, భాషా ప్రాధాన్యతను సేకరిస్తాం. డిజిటల్ వ్యక్తిగత డేటా పరిరక్షణ చట్టం, 2023 ప్రకారం మీరు స్పష్టంగా, స్వచ్ఛందంగా ఇచ్చే సమ్మతే దీనికి చట్టపరమైన ఆధారం. చందా పెట్టె ముందే ఎంపిక చేసి ఉండదు; వార్తాలేఖ చందా నివేదిక కొనుగోలు లేదా గణకం వినియోగానికి వేరైనది.

మేము రెండంచెల నిర్ధారణను ఉపయోగిస్తాం. మీరు నమోదు చేసుకున్న తర్వాత నిర్ధారణ లింకును ఈమెయిల్ చేస్తాం; దాన్ని తెరిచి నిర్ధారించిన తర్వాతే చందా అమలవుతుంది. అప్పటివరకు మరే సందేశమూ పంపము. అవసరమైతే మీరు అంగీకరించిన ఖచ్చితమైన విషయాన్ని చూపేందుకు, సమ్మతి రూపాంతరం మరియు సమయాన్ని మార్పు చేయలేని రికార్డుగా ఉంచుతాం.

ప్రతి వార్తాలేఖ చివర ఉన్న ఒక-క్లిక్ లింకుతో, సైన్ ఇన్ చేయకుండా, ఎప్పుడైనా చందా రద్దు చేయవచ్చు. రద్దు చేసిన వెంటనే పంపడం ఆపి, భవిష్యత్ సందేశాలను అడ్డుకోవడానికి మీ ఎంపికను నమోదు చేస్తాం. మీరు చందాదారుగా ఉన్నంతకాలమే మీ ఈమెయిల్‌ను ఉంచుతాం; ఆ తర్వాత భవిష్యత్ సందేశాలను అడ్డుకోవడానికి అవసరమైన రద్దు రికార్డు మాత్రమే ఉంటుంది. మీ ఈమెయిల్‌ను ఎప్పుడూ విక్రయించము లేదా అద్దెకు ఇవ్వము.

ప్రథమ-పక్ష ఉత్పత్తి విశ్లేషణ

సైట్ ఎలా ఉపయోగించబడుతుందో పరిమిత ప్రథమ-పక్ష రికార్డును ఉంచుతాం; మూడో పక్ష analytics సేవను లోడ్ చేయము. పేజీ వీక్షణలు, మీరు వచ్చిన సూచన సైట్, మీ లింకులోని campaign (UTM) tags, స్థూలమైన పరికరం/browser/operating-system వర్గం, మీ network ఆధారంగా తెలిసిన దేశం (ఖచ్చితమైన ప్రదేశంగా నిల్వ చేయము), పేజీలో ఉపయోగించిన సాధనాలు, buttons వంటి కొద్దిపాటి, స్థిరమైన eventsను మాత్రమే నిల్వ చేస్తాం. మీరు టైప్ చేసే పాఠం, జనన వివరాలు లేదా పేజీల పూర్తి web addressను ఎప్పుడూ నమోదు చేయము; query strings తొలగిస్తాం. ఇది ప్రథమ-పక్ష వినియోగం మాత్రమే: ప్రకటనలకు ఉపయోగించము, ఇతర websites లేదా appsలో మిమ్మల్ని అనుసరించము, data brokersకు విక్రయించము లేదా పంచుకోము.

మీరు sign in చేసి ఉంటే, ఏదైనా సమస్య వచ్చినప్పుడు support, operations బృందం మీ వినియోగ క్రమాన్ని చూసి సహాయం చేయడానికి ఈ eventsను మీ ఖాతాతో అనుసంధానిస్తాం. Sign in చేయకపోతే అవి మీ గుర్తింపుతో అనుసంధానించబడవు. రెండు సందర్భాల్లోనూ మీ IP addressను ఒకవైపు మాత్రమే పనిచేసే SHA-256 hashగా ఉంచుతాం; అసలు IPని ఉంచము. అసలు IPని నమోదు చేసే వేరే setting, ఈ విధానాన్ని మార్చి ప్రకటించే వరకు, ఆఫ్‌లోనే ఉంటుంది; ఎప్పుడైనా దాన్ని ఆన్ చేస్తే అసలు IPలు 30 రోజుల్లో స్వయంచాలకంగా తొలగుతాయి.

ఒక సందర్శనను మరొకటి నుంచి వేరు చేయడానికి browser తాత్కాలిక storageలో ప్రతి tabకు యాదృచ్ఛిక session గుర్తింపును ఉంచుతాం. Tab మూసినప్పుడు అది తొలగుతుంది; అది cookie కాదు; ఇతర sitesలో మిమ్మల్ని అనుసరించడానికి ఉపయోగించము. దిగువ controlతో ఈ browserకు product analyticsను ఆఫ్ లేదా ఆన్ చేయవచ్చు. ఆఫ్‌లో ఉన్నప్పుడు ఈ browser నుంచి ఇకపై ఏదీ పంపము లేదా నిల్వ చేయము. ఇప్పటికే సేకరించిన eventsను గరిష్ఠంగా 365 రోజులు ఉంచి స్వయంచాలకంగా తొలగిస్తాం. ఖాతాతో అనుసంధానించిన events మీ data exportలో ఉంటాయి; ఖాతా తొలగించినప్పుడు అవీ తొలగుతాయి. సంబంధిత DPDP హక్కులు 13 మే 2027 నుంచి అమల్లోకి రావడానికి ముందే Astroyana ఈ controlsను సేవా కట్టుబాట్లుగా అందిస్తోంది. సేవను అర్థం చేసుకోవడానికి, సురక్షితంగా ఉంచడానికి, మెరుగుపరచడానికి మాత్రమే ఈ పరిమిత dataను ఉపయోగిస్తాం; opt-outతో ఎప్పుడైనా అభ్యంతరం చెప్పవచ్చు.