అమలులోకి వచ్చే తేదీ: 2026-10-05
వెర్షన్: v6.3 మునుపటి వెర్షన్: v6.2
v6.3 మార్పుల సారాంశం: అందుబాటులో ఉన్న Android English dictationకు OS speech processing, పంపే ముందు transcript editing వివరాలను జోడిస్తుంది; purchase-support మరియు store financial-event recordsకు వేర్వేరు retentionను వివరిస్తుంది. 2026-10-05 నుంచి అమల్లోకి వస్తుంది; v6.2ను భర్తీ చేస్తుంది. v6.1 మార్పుల సారాంశం: Android మరియు iOS Appలో city నిర్ణయించడానికి optional privacy-minimised flowను జోడించాం. Save చేసిన లేదా ఎంచుకున్న cityకి ప్రాధాన్యం ఉంటుంది. City లేకపోతే ఒక cookie-free request trusted Cloudflare edge headers ద్వారా validated nearby cityని సూచించవచ్చు; అది దొరకకపోతే Ujjainను స్పష్టమైన defaultగా చూపుతాం. Use my current location నొక్కినప్పుడు మాత్రమే App ఒకసారి approximate foreground locationను కోరుతుంది (iOSలో When In Use), పంపే ముందు దాదాపు 5 km నగర పరిమాణ ప్రాంతానికి తగ్గిస్తుంది, raw fixను తొలగిస్తుంది. Precise/background location లేదా location history నిల్వ చేయము.
v6 మార్పుల సారాంశం: పూర్తి Hindi publicationను మరియు ప్రస్తుత చట్టానికి సంబంధించిన clarificationను జోడిస్తుంది. DPDP Actలోని ప్రధాన processing, obligation మరియు Data Principal rights provisions (sections 3–17), అలాగే Rules 3 మరియు 5–16, 13 May 2027న అమలులోకి వస్తాయి; Data Protection Board ఇప్పటికే స్థాపించబడింది. ఆ provisions అమలులోకి వచ్చే వరకు వర్తించే dutiesలో Information Technology Act, 2000 మరియు SPDI Rules, 2011 ఉంటాయి. Astroyana ఇప్పటికే పేర్కొన్న controlsను contractual service commitmentsగా అందిస్తుంది. వినియోగదారు ఫిర్యాదు acknowledgement గడువు 72 గంటల నుంచి 48 గంటలకు తగ్గుతుంది. ఈ revision కొత్త privacy-minimised server-side Yana weekly aggregate counter మరియు optional paid Yana voice unlockను కూడా వెల్లడిస్తుంది. Aggregate వల్ల user-level analytics record, individual profiling, offer tracking లేదా Android capability చేరదు. §5Bలో వివరించిన narrow voice processing కోసం మాత్రమే §7లో Google Cloud Text-to-Speechను జోడించాం.
v6.2 change-log: Yana calculation packet, Android Google Play credit/report purchases, optional notifications వివరాలను సరిచేస్తుంది. 2026-10-03 నుంచి అమలులో; v6.1 స్థానంలో ఉంటుంది.
1. మేమెవరం
Operator మరియు భవిష్యత్తు Data Fiduciary:
- Operator: SNAZZYWORKS నిర్వహించే సేవా బ్రాండ్ Astroyana
- GSTIN: 27HXGPD1259E1ZL
- Registered / principal address: Ground Floor, Tejaswani Hsg Society, DP Road, Baner, Pune - 411045, Maharashtra, India
- General contact: [email protected]
- Customer care / grievance phone: +91 83903 38556
- Website: https://astroyana.com
- Android app: Google Playలో "Astroyana", application identifier
com.astroyana.app, publisher SNAZZYWORKS
1.1 గోప్యత మరియు ఫిర్యాదు contact
- Name: Mahesh Dhaifule
- Designation: Grievance Officer & Data Protection Lead
- Email: [email protected]
- Phone: +91 83903 38556
- Postal address: Ground Floor, Tejaswani Hsg Society, DP Road, Baner, Pune - 411045, Maharashtra, India
- Consumer-grievance timeline: 48 గంటల లోపు acknowledgement; ఒక నెలలో redressal
- Other privacy requests: సాధారణంగా 30 రోజుల లోపు substantive response; వర్తించే GDPR period §16లో ఉంది
DPDP Act §§8(10), 13 మరియు Rule 14, 13 May 2027న అమలులోకి వచ్చినప్పుడు, తరువాతి policy replacementను పేర్కొనకపోతే ఈ contact statutory contactగా పనిచేస్తుంది.
2. పరిధి
మీరు కింది చర్యలు చేసినప్పుడు process అయ్యే personal dataకు ఈ Policy వర్తిస్తుంది:
- astroyana.com లేదా astroyana.inను సందర్శించడం
- Astroyana Android appను ఉపయోగించడం
- ఉచిత లేదా paid report లేదా calculatorను కోరడం
- Account సృష్టించడం లేదా web magic link / app OTP ద్వారా sign in చేయడం
- AI జ్యోతిష్కుడు Yanaను ఉపయోగించడం
- Feature enable చేసినప్పుడు Family Vaultలో మరో adultను save చేయడం
- Web checkout ద్వారా కొనుగోలు చేయడం లేదా supportతో communicate చేయడం
మేము ఇప్పుడే అందించే controls, భవిష్యత్తు DPDP rights, మరియు EU, EEA, UK usersకు అదనపు GDPR / UK GDPR సమాచారాన్ని కూడా ఇది వివరిస్తుంది (§16).
Third-party sites, ఇంకా engage చేయని భవిష్యత్తు astrologers లేదా contractors, లేదా వేరే సోదర బ్రాండ్ Rudrakshakavachకు ఇది వర్తించదు.
3. మేము process చేసే personal data
ఎంచుకున్న service మరియు దాని securityకి అవసరమైన మేరకే collectionను పరిమితం చేస్తాము.
3.1 మీరు ఇచ్చే data
| Category | Examples మరియు purpose |
|---|---|
| Account మరియు profile | Email; optional name మరియు phone; locale, tradition మరియు communication preferences. Authentication, account management, personalisation మరియు విడిగా opt-in చేసిన communications కోసం ఉపయోగిస్తాము. |
| Birth-chart inputs | Name, birth date, time మరియు place/coordinates. Chart లేదా reportను calculate చేయడానికి. Saved account chartsకు §11 వర్తిస్తుంది; anonymous chart snapshot accountలో write చేయబడదు. |
| Calculator inputs | Tool ఆధారంగా: name, birth date/time/place, coordinates, gender, మరియు matching కోసం ఇద్దరు adults వివరాలు. Android calculators email/phoneను అడగవు లేదా పంపవు. Separate functional consent తరువాత మాత్రమే website lead store అవుతుంది. |
| Family Vault | Feature enable అయినప్పుడు మాత్రమే మరో adult name/nickname, relationship, birth details మరియు మీ consent attestation (§5A). ఆ వ్యక్తి email లేదా phoneను collect చేయము. |
| Communications | hello@, grievance@ లేదా supportకు messages; support subject/body; Yana responseను report చేసినప్పుడు optional reason మరియు answer excerpt. Support, grievances మరియు moderation కోసం. |
| Payments మరియు tax | భారత web checkoutలో card/UPI credentialsను Razorpay స్వీకరిస్తుంది; international option ఉన్నప్పుడు మాత్రమే Stripe. మాకు full credentials కాకుండా limited transaction references, status, amount మరియు method metadata వస్తాయి. Optional B2B checkout tax invoice కోసం GSTIN మరియు legal nameను collect చేస్తుంది. Androidలో Google Play Billing ద్వారా in-app credit మరియు report purchases అందుబాటులో ఉన్నాయి. Shared walletలో credits జోడించే లేదా report fulfil చేసే ముందు Astroyana server ప్రతి purchaseను verify చేస్తుంది. Paymentను Google Play process చేస్తుంది; Astroyanaకు పూర్తి card లేదా bank credentials అందవు. |
| Yana questions | Answerను generate చేయడానికి మరియు enable చేసినప్పుడు retain చేయడానికి, question మరియు §5Bలోని mode-specific context. |
Android purchases and notifications. Google Play Billing in-app credit and report paymentsను process చేస్తుంది; fulfilmentకు ముందు Astroyana server purchase evidenceను verify చేస్తుంది. Optional reminders మరియు report-ready notificationsకు మీ action మరియు OS permission అవసరం; delivery కోసం Astroyana Expo push token మరియు installation/build metadataను Expo Push Serviceకు పంపుతుంది.
3.2 స్వయంచాలకంగా generate అయ్యే data
| Category | Examples మరియు purpose |
|---|---|
| Request metadata | Security/audit tablesలో one-way SHA-256-hashed IP, browser లేదా app user-agent/version, OS మరియు timestamps; security, rate limiting, abuse control మరియు debugging కోసం. |
| Login మరియు computation events | Sign-in method, endpoint, time, outcome, duration, cache-hit మరియు signed-in account ID. Calculator request body, birth data, name, email, phone లేదా Yana question text ఉండవు. |
| First-party product analytics (web) | Fixed page/tool/button events, query లేని path, referrer/campaign, coarse device/browser/OS, country, per-tab ID, signed in అయితే account ID, మరియు hashed IP. Free text, birth data, Yana question లేదా full URL ఉండవు. On-page opt-out ఈ pipelineను ఆపుతుంది. మేము third-party analytics serviceను load చేయము. |
| Authentication | Browser లేదా app native cookie storeలో host-only HttpOnly Secure session cookie. |
| CAPTCHA | Web formsలో transient Cloudflare Turnstile token; మేము store చేయము. |
| Birthplace query text | Explicit Search/Enter లేదా field resolution తరువాత మాత్రమే city/place stringను మా /api/geocode proxy ద్వారా Nominatimకు పంపుతాము. Search-as-you-type autocomplete లేదు; మీ IP Nominatim నుంచి దాచబడుతుంది. Application search-history rowను సృష్టించము; సాధారణ infrastructure records request URLను process చేయవచ్చు. |
Server-side Yana weekly aggregate analytics. పైన ఉన్న first-party web
analyticsకు వేరుగా, ఈ feature enable చేసినప్పుడు computation engineకు చేరి
completed అయిన requestsను మాత్రమే server లెక్కిస్తుంది. IST week (సోమవారం నుంచి),
Engine response-domain enum, channel (web లేదా whatsapp) మరియు outcome
(answer, degraded లేదా redirect) ప్రతి combinationకు ఒక counterను ఉంచుతుంది.
Aggregateలో ఈ నాలుగు dimensions మరియు count మాత్రమే ఉంటాయి. Account, user,
conversation లేదా request identifier, question లేదా answer text, birth/chart
data, IP address, device/campaign data లేదా event timestamp ఉండవు.
ఈ weekly totalsను Yanaను మెరుగుపరచడానికి మరియు aggregate astrology-product demandను పరిశీలించడానికి మాత్రమే ఉపయోగిస్తాము. Targeting, individual profiling, purchase attribution లేదా cross-session journeys కోసం ఉపయోగించము. Analyst results 10 కంటే తక్కువ turns ఉన్న cellsను చూపవు; వాటిని తిరిగి లెక్కించగల totalను కూడా ప్రచురించవు. Counterను accountతో తిరిగి అనుసంధానించలేము కాబట్టి account deletion తర్వాత కూడా అది ఉంటుంది; individual export లేదా erasureలో చేర్చలేము. ఈ server-side aggregate first-party web analyticsకు వేరు; browser opt-out దీనికి వర్తించదు.
3.3 Android local data
App phoneలో పరిమిత app-private stateను ఉంచుతుంది:
- Native cookie store: secure server session cookie
- SecureStore: account ID/email marker, theme, Yana consent markers, మరియు గరిష్ఠంగా 24 గంటల question-only pre-auth Yana draft
- App-private SQLite: saved city మరియు దాని source (manual, network estimate లేదా approximate device location), manually వెతికిన గరిష్ఠంగా ఎనిమిది recent cities, చిన్న public Panchang cache. Network/device path coarse city centroid మాత్రమే ఉంచుతుంది; raw fix లేదా location history కాదు; స్పష్టమైన Ujjain fallback save చేయబడదు
- తొలగించే వరకు, app data clear/uninstall అయ్యే వరకు లేదా sign-out purge చేసే వరకు account-scoped report PDFs
- Android share sheetకు అందించేంత సమయం మాత్రమే data-export cache file; తరువాత best-effort deletion
Android backup disabled. Sign-out server-session expiryని కోరుతుంది; local account state, Yana draft/consent, query cache మరియు downloaded reportsను clear చేస్తుంది. మీరు ఉద్దేశపూర్వకంగా save లేదా share చేసిన copyని Android మరియు destination నియంత్రిస్తాయి.
3.4 మేము collect లేదా use చేయని data
Advertising లేదా cross-app tracking SDKsను ఉపయోగించము; camera లేదా precise/background/continuous GPS dataను collect చేయము; personal dataను అమ్మము; birth data నుంచి predictive marketing segments సృష్టించము; Appలో engine/payment secretను embed చేయము. Optional location button ఒక approximate foreground fixను మాత్రమే వాడుతుంది; permission నిరాకరిస్తే మళ్లీ మళ్లీ అడగదు, city search అందుబాటులో ఉంటుంది. App astroyana.comను call చేస్తుంది; report short-lived authorised HTTPS redirect ద్వారా Cloudflare R2కు వెళ్లవచ్చు. App computation engineను నేరుగా ఎప్పుడూ contact చేయదు.
4. Legal మరియు service bases
ఇక్కడ పేర్కొన్న DPDP provisions 13 May 2027న అమలులోకి వస్తాయి. అప్పటి వరకు కూడా Astroyana వర్తించే ప్రస్తుత చట్టం — అవసరమైన చోట IT Act §43A మరియు SPDI Rules — contractual promises మరియు consumer lawను పాటించాలి.
4.1 Consent మరియు మీరు కోరే actions
Family Vault, Yana, marketing మరియు reminders సహా ఒక feature కోరినప్పుడు explicit consentను record చేస్తాము. Recordలో scope, wording/version, time మరియు అందుబాటులో ఉన్న request metadata ఉండవచ్చు. Required attestation record చేయలేకపోతే Family Vault saving fail closed అవుతుంది.
Calculator submit చేయడం, మీ chartను save చేయడం, sign-in కోరడం, report download చేయడం, payment, export లేదా delete చేయడం కూడా ఆ actionకు అవసరమైన dataను process చేయమనే instruction. అది unrelated marketing consentను సూచించదు. Feature-specific consentను దాని controlsలో లేదా [email protected] ద్వారా withdraw చేయవచ్చు; ముందుగా జరిగిన lawful processing చెల్లుబాటును అది రద్దు చేయదు.
4.2 Contract, law మరియు security
కోరిన లేదా కొనుగోలు చేసిన serviceను అందించడానికి, tax recordsను ఉంచడానికి, binding legal demandకు సమాధానం ఇవ్వడానికి మరియు serviceను రక్షించడానికి అవసరమైన dataను process చేస్తాము. DPDP commencement తరువాత, facts listed categoryకు సరిపోతేనే §7 "certain legitimate use"పై ఆధారపడతాము. "Fraud prevention"ను free-standing §7 categoryగా పరిగణించము; marketing లేదా unrelated profilingకు §7ను ఉపయోగించము.
4.3 Authentication
- Magic link (web): 24 గంటలు valid, single-use
- One-time code (app): 10 నిమిషాలు valid అయ్యే 6-digit code, single-use
రెండూ ఒకే server-side session మరియు host-only cookieని సృష్టిస్తాయి (§13).
5. Birth data మరియు reports
Birth date, time మరియు place అత్యంత identifying సమాచారం; అందువల్ల అదనపు safeguards ఉంటాయి.
5.1 Stored encryption మరియు transport
PostgreSQL storageకు ముందు birth columnsను AES-256-GCMతో at rest encrypt చేస్తాము. Deployment key Hostinger KVM2 VPSలోని Coolify environment variablesలో విడిగా ఉంటుంది; source controlలో commit చేయబడదు. ఇదే application-level encryption saved people birth data మరియు stored Yana textకు వర్తిస్తుంది.
Client నుంచి Cloudflare ద్వారా originకు connections TLS 1.2 లేదా higher మరియు Full (Strict) modeను ఉపయోగిస్తాయి. Origin-to-PostgreSQL container hop ప్రస్తుతం TLS-enabled కాదు; రెండూ ఒకే Mumbai host మరియు private non-public container networkలో ఉంటాయి. Sensitive columns database storageకు ముందే application-encryptedగా ఉంటాయి.
5.2 Decryption boundary
Birth data report computation, Yanaకు అవసరమైన chart findingsను రూపొందించడం లేదా మీ export కోసం memoryలో decrypt అవుతుంది. Raw natal date/time/place Yana structured calculation packetలో ఉండవు. Numerology కోసం ఇచ్చిన name/current name మరియు optional date of birth Astroyana serverలో ఉపయోగిస్తారు; §5B ప్రకారం providerకు raw inputsకు బదులుగా వాటి నుండి వచ్చిన findings వెళ్తాయి. మీరు వ్రాసిన question, history, clarificationలో personal details ఉండవచ్చు. Decrypted fields application logs మరియు transactional/marketing emailsలో ఉండవు. Error telemetryలో PII scrubbing ఉంటుంది; అది user data copy కాదు.
5.3 PDF storage
PDFsను Cloudflare R2 at rest encrypt చేస్తుంది. Download short-lived, single-use bearer grantను ఉపయోగిస్తుంది. PostgreSQL దాని SHA-256 hash మరియు atomic redemptionను మాత్రమే store చేస్తుంది. Raw grant bounded POST bodyలో submit చేసే వరకు URL fragmentలో ఉంటుంది; successful redemption bounded HTTPS redirectను R2కు return చేస్తుంది.
Account ఉన్నంత కాలం birth data ఉంటుంది. Account deletion మరియు backup handling §9 మరియు §11లో ఉన్నాయి.
5A. Family Vault
Family Vault server-feature-gated. Disabledగా ఉన్నప్పుడు peopleను save చేయడం లేదా read చేయడం జరగదు. Enabledగా ఉన్నప్పుడు reading కోసం మరో adult name/nickname, relationship మరియు birth detailsను save చేయవచ్చు. Details AES-256-GCM encrypted. వారి email లేదా phoneను collect చేయము.
ఆ adult permission ఇచ్చారని మీరు confirm చేయాలి. Consent scope saved_person_attestation, version saved-person-v2 కింద wording, date మరియు అందుబాటులో ఉన్న request/device detailsను record చేస్తాము. Shared web మరియు Android validators 18 కంటే తక్కువ వయస్సు ఉన్న ఎవరినైనా reject చేస్తాయి; Family Vaultలో parent లేదా guardian minor path లేదు.
ఆ వ్యక్తి 18 సంవత్సరాల లోపు ఉన్నప్పుడు పాత నమోదు సృష్టించబడితే, అది తొలగించడానికి మాత్రమే కనిపించే జాబితా నమోదుగా ఉంటుంది. దాన్ని తెరవడం, మార్చడం, export చేయడం లేదా readingలో ఉపయోగించడం సాధ్యం కాదు; తరువాత 18 సంవత్సరాలు నిండినా పాత attestation మళ్లీ చెల్లుబాటు కాదు. దాన్ని తొలగించి, ఆ వ్యక్తికి 18 సంవత్సరాలు నిండి permission ఇచ్చిన తర్వాత మాత్రమే మళ్లీ జోడించవచ్చు.
పరిమితి లేని saved adultను మీరు delete చేసే వరకు లేదా account delete అయ్యే వరకు ఉంచుతాము; అది మీ exportలో కనిపిస్తుంది. Account deletionలో ప్రతి నమోదు తొలగుతుంది. వారు నేరుగా మమ్మల్ని contact చేస్తే, verify చేసి detailsను తొలగించవచ్చు. Requested readings కోసం మాత్రమే ఆ detailsను ఉపయోగిస్తాము; ఎప్పుడూ అమ్మము లేదా external model trainingలో opt in చేయము.
5B. Yana, AI జ్యోతిష్కుడు
Yana server feature flag ద్వారా నియంత్రించబడుతుంది. Enabled అయినప్పుడు external language serviceకు మీ question, ఇటీవల సంబంధిత conversation context (మునుపటి questions మరియు answers), clarification question మరియు answer, అలాగే ఎంచుకున్న modeకు అవసరమైన computed findings ఉన్న structured calculation packet పంపబడతాయి. ఆ packetలో raw birth records, account identifiers లేదా account details ఉండవు. Dates మరియు placementsతో సహా derived chart లేదా calculation findings ఉండవచ్చు.
Numerology కోసం మీరు ఇచ్చిన name/current name మరియు optional date of birthను Astroyana server reading లెక్కించడానికి ఉపయోగిస్తుంది. Raw inputs బదులుగా వాటి నుండి వచ్చిన findingsను external language serviceకు పంపుతుంది. మీరు వ్రాసిన question, history మరియు clarification textగా పంపబడతాయి; వాటిలోని personal details కూడా share కావచ్చు. Service స్పష్టమైన email, phone మరియు account identifiersను తొలగిస్తుంది, కానీ ప్రతి personal detailను గుర్తించి తొలగించదు. Account email, phone మరియు payment dataను account fieldsగా పంపము.
Astroyana conversationsను model trainingలో opt in చేయదు. Anthropic standard commercial-API terms ప్రకారం input/outputను defaultగా generative models train చేయడానికి ఉపయోగించరు; Usage Policy enforce చేయడానికి లేదా law పాటించడానికి ఎక్కువ కాలం retain చేసే materialకు లోబడి, సాధారణంగా 30 రోజుల లోపు backend నుంచి delete చేస్తారు. Astroyana విడిగా encrypted conversation textను 180 రోజులు ఉంచుతుంది. ఒకటి లేదా అన్ని conversationsను delete చేయవచ్చు; export మరియు account deletion వాటిని include చేస్తాయి. Wallet ledgerలో chat text ఉండదు.
పూర్తయిన answerకు private audio సృష్టించేందుకు ఒక existing whole creditను విడిగా spend చేయవచ్చు. కేవలం normalised final answer text మరియు fixed locale/versioned voice configuration మాత్రమే server-to-server Google Cloud Text-to-Speechకు పంపుతాము. ఈ feature కోసం question, birth/chart data, account identity, conversation history, payment data లేదా arbitrary client textను Googleకు పంపము. explicit unlock తరువాతే generation మొదలవుతుంది. Cloud Text-to-Speech stateless, resourceless అని మరియు customer text లేదా generated audioను log చేయదని Google చెబుతుంది. పూర్తయిన private audio source answer ఉన్నంతకాలం Cloudflare R2లో, అదే conversation/account deletion controls మరియు 180 రోజుల retentionకు లోబడి ఉంటుంది. దానికి కొద్దిగా మించిన R2 lifecycle rule failsafe మాత్రమే, primary erasure కాదు. De-identified character, request, cost, time totals accounting/control windowకు user, answer, audio లేదా conversation content link లేకుండా ఉండవచ్చు.
Answersలో "Calculated by Ganaka, voiced by Yana" disclosure ఉంటుంది. అవి informational మాత్రమే; professional advice లేదా legally significant automated decision కావు.
5C. Android app
App server-backed. Identity, money, credits, saved charts మరియు report authority astroyana.comలో ఉంటాయి. Appలో engine credential లేదు.
- OTP sign-in Siteతో అదే server sessionను ఏర్పరుస్తుంది.
- Session 5 నిమిషాల కంటే తక్కువ వయస్సులో ఉండేలా fresh OTP re-authentication తరువాత in-app export మరియు deletion అందుబాటులో ఉంటాయి.
- Androidలో Google Play Billing ద్వారా in-app credit మరియు report purchases అందుబాటులో ఉన్నాయి. Shared walletలో credits జోడించే లేదా report fulfil చేసే ముందు Astroyana server ప్రతి purchaseను verify చేస్తుంది. Paymentను Google Play process చేస్తుంది; Astroyanaకు పూర్తి card లేదా bank credentials అందవు.
- App settingsలో optional reminders మరియు report-ready notificationsను enable చేయవచ్చు. మీ స్పష్టమైన action మరియు OS notification permission అవసరం. App Expo push token మరియు installation/build metadataను Astroyanaకు పంపుతుంది; Expo Push Service notificationను device platformకు relay చేస్తుంది.
- ఈ features కోసం App Google Play Billing మరియు notification librariesను కలిగి ఉంది. Advertising, cross-app tracking, device-attestation లేదా mobile crash-reporting SDK లేదు.
- Store Data Safety declarations birth/astrology data, third-party AI processing మరియు deletionను conservativeగా cover చేస్తాయి.
Androidలో optional English dictationను ఉపయోగించడానికి microphoneను స్పష్టంగా నొక్కి OS permission ఇవ్వాలి. Dictation ఉపయోగించకుండా మీరు టైప్ చేయవచ్చు, రాసినదాన్ని సవరించవచ్చు లేదా తొలగించవచ్చు. ఎంచుకున్న OS speech-recognition service మీ మాటలను deviceలో లేదా తన network ద్వారా process చేస్తుంది; ఆ service processing మరియు retention దాని provider privacy policy, settingsకు లోబడి ఉంటాయి. ఇది §5Bలోని paid answer audioకు వేరు. Astroyana raw audioను స్వీకరించదు లేదా నిల్వ చేయదు. Transcriptను సవరించవచ్చు; మీరు Sendను ఎంచుకున్నప్పుడే అది Astroyanaకు పంపబడుతుంది.
6. Uses
ఎంచుకున్న serviceను అందించడం, authenticate చేయడం, usersకు support ఇవ్వడం మరియు grievancesను పరిష్కరించడం, పరిమిత first-party web analytics మరియు operational events run చేయడం, performance/security monitor చేయడం, abuse నివారించడం, law/tax duties పాటించడం కోసం dataను ఉపయోగిస్తాము.
Separate opt-in లేకుండా marketing చేయము; dataను sell/rent చేయము; unrelated profiles సృష్టించము; birth data, saved-person data లేదా Yana conversationsను external model trainingలో opt in చేయము.
7. Processors
| Provider | Purpose మరియు data | Location |
|---|---|---|
| Cloudflare | DNS/CDN/WAF, Turnstile మరియు private R2 storage; request metadata, encrypted PDFs, private Yana WAV audio, pseudonymous user/answer/generation UUID object-key identifiers, Turnstile IP. మొదటి city-less App requestలో coherent edge headers advisory city estimate ఇవ్వవచ్చు; server దాన్ని store చేయదు లేదా identity, security, entitlement, payment కోసం వాడదు | US / global edge |
| Zoho / ZeptoMail | Transactional email మరియు mailboxes; address, recipient name మరియు మీరు పంపే messages | Chennai, India |
| Hostinger | Origin VPS మరియు stored service data | Mumbai, India |
| Sentry | Scrubbed web error traces మరియు bounded diagnostics; Android SDK లేదు | United States |
| OpenStreetMap Foundation / Nominatim | మా proxy ద్వారా explicitly submitted city/place search మరియు optional దాదాపు 5 km foreground-location area reverse lookup; generic User-Agent, account ID లేదా user IP లేవు | Europe |
| Razorpay | Indian web payment credentials మరియు transaction processing; మాకు limited references వస్తాయి | India |
| Stripe | అందించినప్పుడు international payment | US / global |
| Anthropic, PBC | Yana question మరియు mode-specific §5B context | United States |
| Google Cloud Text-to-Speech | explicit voice unlockపై కేవలం normalised final Yana answer text మరియు fixed locale/versioned voice configuration | Global infrastructure |
Provider processing వర్తించే service/data termsకు లోబడి ఉంటుంది. ప్రతి provider విడిగా negotiated agreementపై sign చేసిందని ఈ table claim చేయదు. Materially new processor లేదా data useను జోడించే ముందు Policyని update చేస్తాము.
ఈ featuresకు processors: Android in-app credit and report payment మరియు purchase verification కోసం Google Play; optional notification relay కోసం Expo Push Service; మరియు §5Bలో వివరించిన Yana question, recent relevant conversation/clarification text, mode-specific structured calculation findings కోసం Anthropic, PBC. Yana packetలో raw birth records లేదా account fields ఉండవు; user textలో personal details ఉండవచ్చు.
8. International transfers
Cloudflare, Sentry, Stripe, Anthropic మరియు Google Cloud వర్తించే transfer terms కింద, అవసరమైన చోట Standard Contractual Clausesతో, data minimisation మరియు encryptionతో India బయట process చేయవచ్చు. Zoho మరియు Hostinger పేర్కొన్న India locationsను ఉపయోగిస్తాయి. DPDP Act §16 కింద India ఒక countryని restrict చేస్తే, ఆ provision మరియు restriction వర్తించినప్పుడు పాటిస్తాము.
Google Play మరియు Expo Push Service §§5C, 7లో వివరించిన Android purchase లేదా notification సమాచారాన్ని తమ వర్తించే transfer terms ప్రకారం India వెలుపల కూడా process చేయవచ్చు.
9. మీ controls మరియు rights
Astroyana ఈ controlsను ఇప్పుడే service commitmentsగా అందిస్తుంది; పేర్కొన్న DPDP rights 13 May 2027న అమలులోకి వస్తాయి.
9.1 Access మరియు export
https://astroyana.com/account/export లేదా Appను ఉపయోగించండి. JSONలో decrypted birth data, saved people మరియు Yana conversations ఉంటాయి; 24 గంటలకు ఒక్కసారి మాత్రమే; 5 నిమిషాల లోపు authenticate చేసిన session అవసరం. Accessible encrypted email exportను [email protected] నుంచి కోరవచ్చు.
9.2 Correction మరియు erasure
Account/App controlsలో profile dataను correct చేయండి లేదా మాకు email పంపండి. Fresh OTP verification తరువాత account deletion pageలో లేదా Appలో accountను delete చేయండి.
ఖాతా తొలగింపు మొదలైన వెంటనే ఖాతా నిలిపివేయబడుతుంది; తరువాత 30 రోజుల పునరుద్ధరణ ఉపశమన గడువు ఉంటుంది. ఆ తరువాత రోజువారీ శాశ్వత తొలగింపు ప్రక్రియ వినియోగదారు నమోదు, జనన సమాచార భాగాలు, Family Vault మరియు సమ్మతి నమోదులు, Yana పాఠ్యం, ఖాతాతో అనుసంధానమైన R2 నివేదిక నిల్వ విభాగాలు, సమ్మతి అనుమతులు, సెషన్లు, వినియోగదారుతో అనుసంధానమైన ప్రవేశం/వెబ్/గణన ఘటనలను తొలగిస్తుంది.
శాశ్వత తొలగింపు సమయంలో చెల్లింపు వివాదం లేదా ఖాతాల సరిపోల్చే ప్రక్రియ కొనసాగుతుంటే, మొత్తం తొలగింపు తుది సరిపోలిక పూర్తయ్యే వరకు వాయిదా పడుతుంది. తుది సరిపోలిక తరువాత ప్రక్రియ మళ్లీ మొదలై ఖాతాతో అనుసంధానమైన ఆ నివేదిక నిల్వ విభాగాలు మరియు వ్యక్తిగత సమాచారాన్ని తొలగిస్తుంది. ఈ వాయిదా PDFలకు చట్టపరమైన నిలుపుదల మినహాయింపును కల్పించదు: వేరే నివేదిక నిల్వ ప్రక్రియ ఉచిత PDFలను సరిగ్గా 90 రోజులకు, చెల్లింపు PDFలను సరిగ్గా 365 రోజులకు తొలగిస్తుంది.
Law లేదా security అవసరమైనదాన్ని మాత్రమే retain చేస్తాము: creation తరువాత ఒక సంవత్సరం వరకు audit entries, account linkను NULLగా set చేస్తాము; statutory period (సాధారణంగా 7 సంవత్సరాలు) వరకు anonymised tax amounts/fields; free text redacted చేసిన support/refund records. Encrypted backupsను 30 రోజుల లోపు purge చేస్తాము.
9.3 Grievance మరియు nomination
Grievanceను [email protected]కు పంపండి. వినియోగదారు grievanceను 48 గంటల లోపు acknowledge చేసి, ఒక నెలలో redress చేయడానికి ప్రయత్నిస్తాము. 13 May 2027 నుంచి eligible unresolved DPDP grievanceను Data Protection Board of Indiaకు escalate చేయవచ్చు.
Death/incapacity సందర్భంలో future DPDP rightsను exercise చేయడానికి, వారి contact మరియు notarised authorityతో ఒక personను nominate చేయవచ్చు.
10. పిల్లలు
Accounts మరియు Android 18 లేదా ఎక్కువ వయస్సు వారికి. Android Family Vault minorsను block చేస్తుంది. Website report form ప్రస్తుతం parent/guardian attestationను accept చేయవచ్చు; కానీ దాన్ని DPDP Rule 10 identity/age verificationగా మేము చూపము. 13 May 2027కు ముందు compliant verifiable parental consentను deploy చేస్తాము లేదా ప్రతి minor pathwayను disable చేస్తాము. పిల్లలను profile చేయము, behaviourally monitor చేయము లేదా adsతో target చేయము.
Suspected child dataను [email protected]కు report చేయండి. Specific law retentionను కోరితే తప్ప processingను suspend చేసి delete చేస్తాము; investigate చేసి 7 రోజులలో respond చేస్తాము.
11. Retention summary
| Data | Retention |
|---|---|
| Account మరియు encrypted birth data | Active account + 30-day deletion grace, తరువాత hard delete |
| Family Vault person/consent | తొలగించే వరకు లేదా account deletion వరకు |
| Yana text | 180 రోజులు; user ముందే delete చేయవచ్చు |
| Private Yana voice audio | source answer ఉన్నంతవరకు; దానితో erase, 181-day R2 failsafeతో |
| Google Cloud Text-to-Speech customer content | Google Cloud TTS data-use documentation ప్రకారం logged కాదు |
| De-identified Yana voice spend/usage totals | accounting/provider-spend control window; user, text లేదా audio link లేదు |
| Anthropic API copy | Documented exceptionsకు లోబడి సాధారణంగా 30 రోజుల వరకు |
| Chat text లేని wallet ledger | Account lifetime |
| Free / paid PDFs | 90 / 365 రోజులు |
| Audit logs | Creation నుంచి 1 సంవత్సరం |
| Session | 30-day rolling max-age |
| Magic link / OTP | 24 గంటలు / 10 నిమిషాలు, single-use |
| Login, computation మరియు first-party web events | గరిష్ఠంగా 365 రోజులు; hard deleteలో user-linked rows erase అవుతాయి |
| Android Yana draft | గరిష్ఠంగా 24 గంటలు |
| Android city/Panchang cache | Prune లేదా app data removal వరకు app-private |
| Android report/export file | Sign-out/app removal వరకు report; share తరువాత export best-effort deletion |
| Tax invoice / optional B2B GSTIN మరియు name | 7 సంవత్సరాలు; deletionలో order identifiers anonymise అవుతాయి |
Purchase-support operational records, verified final resolution తర్వాత 180 రోజులు గడిచేలోపు reviewed deletionకు అర్హం కావు. అర్హత రావడం ఆటోమేటిక్ deletion కాదు; deletionకు నిర్ణీత గడువు లేదు. Store financial-event records సంబంధిత భారత ఆర్థిక సంవత్సరం ముగిసిన తర్వాత కనీసం 8 సంవత్సరాలు నిల్వ ఉంటాయి; తరువాతి statutory deadlines, unresolved refunds/recovery మరియు legal holds దీనిని పొడిగించవచ్చు. Orders, purchases, credits, reports మరియు invoicesకు వేర్వేరు lifecycle, legal retention ఉంటాయి; ఈ operational process వాటిని delete చేయదు.
12. Security మరియు breach response
Controlsలో AES-256-GCM sensitive-column encryption; R2 encryption; client నుంచి Cloudflare ద్వారా originకు TLS; passwordless authentication; host-only HttpOnly cookies; rate limits; Turnstile; Coolify secret storage; gitleaks; bounded audit logs; HIGH+ dependency scanning; encrypted backups; documented incident runbook ఉన్నాయి.
Same-host private database మరియు internal engine hopsను end-to-end TLSగా వివరించము. Quarterly restore procedure ఉంది; కానీ మొదటి full isolated live restore ఇంకా పూర్తి కాలేదు; verified live restore readiness ఉందని claim చేయము.
అవసరమైనప్పుడు affected individualsకు delay లేకుండా notify చేస్తాము. వర్తించే DPDP commencement తరువాత Boardకు initial intimation delay లేకుండా, అది మరింత సమయం అనుమతించకపోతే further particulars 72 గంటల్లో అందిస్తాము.
13. Cookies మరియు browser storage
| Cookie | Purpose | Duration |
|---|---|---|
__Host-astroyana.session-token | Authentication | 30 రోజులు, rolling |
__Host-astroyana.csrf-token | CSRF protection | Session |
__Host-astroyana.callback-url | Magic-link redirect | Session |
__Host-astroyana.pkce-code-verifier | PKCE verification | 15 నిమిషాలు |
ఇవి strictly necessary. Advertising లేదా third-party tracking cookie, cross-site profiling ఉపయోగించము. First-party analytics temporary per-tab browser-storage ID మరియు published opt-outను ఉపయోగిస్తుంది. వర్తించే చట్టం non-essential storageకు prior consent కోరినప్పుడు, analytics client consent-gatedగా ఉండాలి లేదా disabled కావాలి; opt-outనే consentగా పరిగణించము.
14. Policy changes
కొత్త versionను Privacy Policy pageలో publish చేసి, దాని hashను policy_versionsలో record చేస్తాము. Material expansionకు ముందు advance email notice ఇస్తాము; అవసరమైనప్పుడు fresh acceptance కోరుతాము; అమలులోకి రాకముందు deletionకు అవకాశం ఇస్తాము. Previous versionsను [email protected] నుంచి పొందవచ్చు.
15. Contact
Privacy rights మరియు grievances కోసం [email protected], general questions కోసం [email protected]ను ఉపయోగించండి. Contact details మరియు response times §1.1లో ఉన్నాయి. Data Protection Board ఉంది; సంబంధిత complaint provisions 13 May 2027న అమలులోకి వస్తాయి; filing route అందుబాటులో వచ్చినప్పుడు publish చేస్తాము.
16. EU / EEA / UK users
ఈ usersకు SNAZZYWORKS controller. Serviceను calculate/deliver చేయడం లేదా web paymentకు processing contractపై ఆధారపడుతుంది (GDPR Art. 6(1)(b)); optional Family Vault, Yana personalisation మరియు communications consentపై (Art. 6(1)(a)); proportionate security/operations మరియు aggregate analytics legitimate interestsపై (Art. 6(1)(f)); tax retention legal obligationపై (Art. 6(1)(c)) ఆధారపడతాయి.
Lawకు లోబడి, access, rectify, erase, restrict, port, object, consent withdraw చేయవచ్చు; legal లేదా similarly significant effect కలిగించే solely automated decisionsను avoid చేయవచ్చు. Astrological/Yana outputకు అటువంటి effect లేదు. ఒక నెలలో answer చేస్తాము; complexity ఉంటే noticeతో రెండు నెలలు extend చేయవచ్చు. UK ICO సహా మీ local supervisory authorityకు complaint చేయవచ్చు. International transfers §8లోని safeguardsను ఉపయోగిస్తాయి.
17. App connection summary
App astroyana.comను call చేస్తుంది. Report redemption server-authorised HTTPS R2 redirectను follow చేయవచ్చు. Private Yana voice మాత్రం short-lived, single-purpose header tokenతో Astroyana same-origin endpoint ద్వారా stream అవుతుంది; Appకు direct R2 URL ఇవ్వము. Identity, credits, purchases, saved charts మరియు report access server-authoritativeగా ఉంటాయి. App §3.3లోని పరిమిత local stateను మాత్రమే store చేస్తుంది. ఇందులో advertising, cross-app tracking, device-attestation లేదా mobile crash-reporting SDK లేదు. Android credit and report purchases Google Play Billingను ఉపయోగిస్తాయి. Optional reminders, report-ready notifications user action మరియు OS permission తరువాత అందుబాటులో ఉంటాయి; App Expo push token, installation/build metadataను Expo Push Service ద్వారా పంపుతుంది.
Appendix A: Legal references
- DPDP Act 2023 — https://www.indiacode.nic.in/indiacode/handle/123456789/22037?view_type=browse
- DPDP Rules 2025 మరియు commencement — https://www.meity.gov.in/documents/act-and-policies/digital-personal-data-protection-rules-2025-gDOxUjMtQWa
- IT Act 2000 §43A మరియు SPDI Rules 2011 — India Code
- Consumer Protection Act 2019 మరియు E-Commerce Rules 2020 — India Code / Department of Consumer Affairs
- GDPR / UK GDPR — Regulation (EU) 2016/679 మరియు UK data-protection law
Appendix B: Document control
| Field | Value |
|---|---|
| Document title | గోప్యతా విధానం — Astroyana |
| Version | v6.2 |
| స్థితి | Active |
| Effective from | 2026-10-03 |
| Supersedes | v6.1 |
DOCUMENT ముగిసింది.