Skip to content

Privacy Policy

What we collect, why, and how to delete it. Birth data stays yours.

Last updated: 2026-09-14

This Privacy Policy explains what MyPanditji collects about you, why we collect it, who we share it with, how long we keep it, and the choices you have. It covers the MyPanditji website (mypanditji.io), the iOS and Android apps, and the Panditji WhatsApp service. Please read it together with our Terms of Service, Cookie Policy and Disclaimer.

1. Who we are

MyPanditji is operated by Grupo Sineva Inc., a Delaware corporation (“MyPanditji”, “we”, “us”). Under India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) we are the data fiduciary for the personal data described here; under the EU and UK GDPR we are the controller.

Mailing address: MyPanditji (Grupo Sineva Inc.), 1000 Main St, Houston, TX, United States

Email: support@mypanditji.io

Grievance Officer (India): Grievance Officer, MyPanditji — support@mypanditji.io (see section 20)

2. What this policy covers

This policy applies whenever you use MyPanditji — as a signed-in member, as a guest without an account, as a newsletter subscriber, or by messaging Panditji on WhatsApp. It also covers the emails, push notifications and WhatsApp messages we send you.

It does not cover the services of other companies you reach through MyPanditji — for example the Apple App Store, Google Play, WhatsApp, or a website we link to. Those companies have their own privacy policies.

3. Information you give us

Most of what we hold, you typed, chose or uploaded yourself:

a) Account and contact detailsWhen you sign up we collect your name, your email address and/or WhatsApp phone number, and the language you prefer. Sign-in normally works with a one-time code sent to WhatsApp or email; if you choose to set a password, our authentication provider (Supabase) stores only a salted hash of it — we never see it. You may add a profile photo (avatar); avatars are stored in a bucket whose files can be viewed by anyone who has the link, so they can appear beside your community posts.

b) Birth detailsTo compute a Vedic chart we need your date of birth, time of birth, place of birth and gender. When you type a place name we look it up (section 8) and store the place’s name, coordinates and time zone. We also store chart preferences such as the ayanamsa and horoscope system you choose. Birth details are the heart of the Service: every reading, horoscope, dasha and compatibility report is calculated from them.

c) Family and friends’ chartsYou can save the birth details of other people to read their charts and compare compatibility. Before saving a new person you must confirm that you have their permission to store their birth details on MyPanditji; you are responsible for that permission. A chart saved for someone under 18 is treated with extra care: readings about a minor are limited to soft, supportive guidance, with no marriage timing and no fixed predictions (section 14).

d) PhotosIf you use palm reading, face reading or Vastu, you may take or upload photos of your palms, your face or a room. Palm and face photos are sensitive personal data. We ask for your explicit permission before any photo is sent to an AI provider (section 7). A copy of each reading photo is kept in a private, owner-only storage bucket so that the reading can be shown again in your history. The “scan a QR code with your phone” hand-off uploads the photo the same way, and the hand-off link itself expires after 15 minutes.

e) Questions, conversations and readingsWe store the questions you ask Panditji and the replies you receive, in every chat mode — Normal, Deep Research, Max Council, Prediction, Vastu — and in the feature chats (tarot, numerology, dreams, remedies, palm, face and others). If you use Verify Your Pandit, we store the transcript you paste so that it can be graded. Your conversations and saved readings are kept so that you can return to them; deleting your account removes them all (section 11).

f) VoiceIf you tap the microphone to dictate a question, the audio clip is sent to a speech-to-text model (Google Gemini) and transcribed; the clip is discarded as soon as the text comes back and is never kept. If you start a voice call with Panditji (a Max feature), your voice is streamed to ElevenLabs, which turns speech into text and text into speech while our AI answers; your name and a short summary of your chart are shared with the call so that Panditji can answer in context.

g) Journal, practices and streakJournal entries, moods, saved readings, daily practices and your streak are stored with your account so that we can show them back to you and grant streak rewards.

h) CommunityIf you post, comment, upvote or report in the Community, we store what you posted, when, and the identity mode you chose — your real name, a display name, or anonymous. Posts are visible to other people (section 17).

i) PaymentsPurchases are made through the Apple App Store or Google Play (managed for us by RevenueCat) or through Stripe on the web. We receive confirmation of what you bought, when, for how much, the status of your subscription or credits, and an identifier that lets us match the purchase to your account. We never receive or store your full card number.

j) Support, grievances and feedbackWhen you write to support@mypanditji.io, report a post, appeal a decision or send a grievance, we keep the correspondence so that we can respond and keep a record of how it was resolved.

k) Referral codes and the clipboardWhen you share your referral code or enter someone else’s, we record who referred whom so that rewards can be granted. On the mobile sign-up screen the app may check your clipboard once for a MyPanditji referral code so that you do not have to type it; nothing else on the clipboard is read or stored.

l) Newsletter and daily-horoscope emailsIf you subscribe from the website without an account, we store your email address and the sign you chose so that we can send the daily horoscope and newsletter until you unsubscribe.

4. Information we collect automatically

Some information is recorded by the software as you use it:

a) Product analyticsWe use PostHog to understand which features are used and whether they complete — for example “a tarot reading was started” or “a kundli was generated”. In the mobile app these events are keyed to a random device identifier that is not your name, account or birth details, and that identifier is reset when you sign out. The text of your questions and readings, your contact details, your birth details and your photos are never sent to analytics. Analytics runs only with your consent in the EEA/UK and can be turned off anywhere in Settings → Privacy & data (section 12).

b) Error and crash reportsWhen something breaks on the website or in our server functions, an error report — the error message, a stack trace, the function that failed and, where available, your user ID — is sent to Sentry so that we can fix it. On the website this loads only with analytics consent. The mobile app does not currently send crash reports to a third party.

c) Website measurement and advertising analyticsOn the website only, and only with the same consent as analytics, we load Google Analytics 4 (page and event counts), Microsoft Clarity (anonymised session replays and heatmaps; the text you type is masked before anything is recorded) and the Meta Pixel (which of our own Instagram and Facebook ad campaigns brought you here). Separately, when you create an account, reach the guest message limit, or complete a purchase, our server reports that single event to Meta’s Conversions API with your email address or phone number hashed (SHA-256), so that Meta can attribute it to our own advertising. Your birth details, chats, photos and readings are never included. We do not run third-party advertising inside the app or the website, and we do not allow other ad networks to place cookies.

d) Device and app informationDevice type, operating system, app version, language, time zone and screen size; on mobile, a push notification token if you allow notifications. We use your time zone to decide which consent rules apply to you, to compute the day’s Panchang, and to send morning notifications at the right hour.

e) How you found usOn the website we record the first way you arrived — the referring site, the landing page and any campaign tags in the link (utm_*). This stays in your browser until you sign up and is then attached to your account so that we know which campaigns work.

f) Logs and usage recordsOur infrastructure keeps short-lived request logs (IP address, timestamps and request metadata) for security, abuse prevention and debugging. For every AI request we record which model was used, how many tokens it consumed and what it cost us — never the content — to enforce fair-use limits and control spending.

g) Interest topicsFrom the questions you ask we may derive a simple profile of the topics you are interested in (for example career, relationships or health) so that MyPanditji can show you more relevant content. Messages about crisis, legal, medical or similarly sensitive matters are filtered out before this profile is built. The profile is never used to make a decision with legal or similarly significant effect on you, and it is deleted with your account.

h) Cookies and local storageThe website uses cookies and browser storage to keep you signed in, remember your preferences and cache the day’s horoscope. The full list is in our Cookie Policy. The mobile app sets no cookies.

5. How we use your information

We use your information to:

Calculate your Kundli, divisional charts, dashas, transits, Panchang, Muhurat, horoscopes and compatibility reports.

Generate AI readings and answer your questions in every chat mode and feature.

Create and manage your account, and keep your family and friends’ charts, journal, practices and streak.

Process subscriptions, trials, credits, referrals and rewards, and prevent fraud and abuse.

Send the notifications, emails and WhatsApp messages you have asked for (section 13).

Run the Community, moderate content and act on reports.

Understand how the product is used, fix errors and improve features.

Measure our own advertising and learn which campaigns brought you here.

Enforce our Terms, keep the Service secure and comply with the law.

Respond to your questions, requests and grievances.

Our team may review your conversations with Panditji for quality and support — for example to check that an answer was accurate, or to help with a request you have sent us. Such reviews are limited to staff with admin access, and every time a conversation is opened for review we record who opened it and when.

6. Our legal bases

Where the EU or UK GDPR applies, we rely on:

Contract — everything needed to provide the Service you signed up for, including calculating charts and generating readings.

Consent — sending your birth details, questions and photos to AI providers; processing palm and face photos; analytics, session replay and advertising measurement in the EEA/UK; marketing emails; connecting Google Calendar or your device calendar. You can withdraw consent at any time (section 11).

Legitimate interests — securing the Service, preventing abuse, measuring our own campaigns, understanding usage and improving features, where these do not override your rights.

Legal obligation — keeping records we are required to keep and responding to lawful requests.

Where India’s DPDP Act applies, we process your personal data on the basis of the consent you give when you sign up and when you approve AI processing, and for the legitimate uses the Act allows — for example when you voluntarily provide data for a stated purpose, or when we must comply with the law. Each consent request is specific, and consent can be withdrawn as easily as it was given.

AI PROCESSING

7. AI processing — what is sent, and to whom

Every reading MyPanditji produces is written by an AI model. To produce one we send the AI provider:

the questions you ask and the messages in that conversation;

your date, time and place of birth and the chart we calculated from them — or those of the family member or friend you selected;

any photo you chose to upload for a palm, face or Vastu reading;

relevant passages from our library of classical texts, and any context you added (for example a pasted transcript for Verify Your Pandit).

The AI providers we use are Google (Vertex AI — Gemini models), OpenAI and Anthropic. Different modes and features use different models, and if one provider fails we fall back to another. Each provider processes the data solely to return your reading, does not use it to train its models, and is bound by contract to protect it. Where a feature needs fresh information from the web, the provider may run a web search on our behalf using your question.

We ask for your explicit permission before anything is sent — in the app, on a dedicated consent screen before your first reading. You can withdraw that permission at any time in Settings → Privacy & data; readings then stop until you turn it back on. Readings are interpretive: they reflect a tradition, not proof, and they are not medical, legal, financial or psychological advice (see our Disclaimer).

8. Who we share your information with

We share personal data only with the companies that help us run the Service, each under a contract that limits what they may do with it:

a) Hosting, database, authentication and storageSupabase, which runs on Amazon Web Services infrastructure, hosts our database, authentication, file storage and server functions. Everything in your account lives here, protected by row-level security so that only you can read your rows.

b) Astronomical calculationsOur own astro engine, hosted on Fly.io, receives the date, time and coordinates of birth — never a name — and returns planetary positions. Where possible we calculate on your device or reuse a cached result instead.

c) AI providersGoogle (Vertex AI), OpenAI and Anthropic, as described in section 7. Google Gemini also transcribes voice notes, and ElevenLabs powers voice calls with Panditji.

d) Google servicesGoogle Places looks up the birth place you type. If you choose to sync festivals or muhurats to Google Calendar on the website, Google receives the events you add and tells us which account is connected; the access token stays in your browser and we never store it. In the mobile app, festivals you choose are written to your device’s calendar app with its permission.

e) PaymentsThe Apple App Store and Google Play process in-app purchases; RevenueCat manages those subscriptions and tells us what you are entitled to. Stripe processes web payments, in Indian Rupees. Each handles your payment details under its own privacy policy.

f) Messaging and notificationsResend sends our emails (daily horoscope, transit alerts, newsletter, product and offer emails). Meta’s WhatsApp Business Platform carries messages between you and Panditji on WhatsApp, including login codes. Expo’s push service, Firebase Cloud Messaging (Android), the Apple Push Notification service (iOS) and your browser’s push service deliver push notifications.

g) Analytics and measurementPostHog (product analytics), Sentry (error reports), Google Analytics 4, Microsoft Clarity and Meta (Pixel and Conversions API), exactly as described in section 4 and nothing more.

h) Other peopleCommunity posts are visible to other users under the identity mode you chose. A reading you share by link can be opened by anyone who has the link until it expires or you revoke it. Saving a family member’s chart does not give that person access to your account.

i) Legal, safety and business transfersWe may disclose personal data when the law requires it, to respond to a valid legal request, to protect the rights, safety or property of MyPanditji or others, or to a successor if MyPanditji is acquired or merged — in which case this policy continues to apply.

j) What we never doWe do not sell your personal data, and we do not share it with data brokers or advertising networks. Our providers act on our instructions under data-processing agreements and may not use your data for their own purposes.

9. International transfers

MyPanditji is operated from the United States, and our providers process data in the United States, in India (for example some Google Cloud processing in Mumbai) and in other countries where they operate. Wherever your data goes, it stays protected by this policy and by our contracts with those providers. For transfers out of the EEA or UK we rely on the Standard Contractual Clauses (with the UK Addendum) approved for that purpose. India’s DPDP Act permits transfers outside India except to countries the Government restricts; we will comply with any such restriction.

10. How long we keep your information

We keep personal data only as long as we need it for the purposes above:

Account, birth details, saved charts, conversations, journal, readings and preferences — for as long as your account exists. When you delete your account we remove them from our live systems immediately and complete deletion, including from backups, within 30 days.

Guest sessions — a guest who has not signed up and has been inactive for 7 days is deleted automatically, together with the conversation.

Reading photos — kept privately with the reading, and deleted with your account.

Voice notes — deleted as soon as they are transcribed.

QR hand-off sessions — expire 15 minutes after they are created.

Shared reading links — expire after 30 days by default, or earlier if you revoke them.

Purchase and billing records — for as long as tax and accounting law requires after your account closes.

Support, grievance and moderation records — up to three years after the matter is closed, so that we can show how it was handled.

Analytics — held in aggregate; the random device identifier is reset when you sign out.

Logs — short-lived operational logs are rotated automatically.

We may keep anonymised or aggregated data, which cannot identify you, indefinitely.

11. Your rights and choices

Wherever you live, you can:

a) See and export your dataSettings → Your data → Export gives you a copy of your profile, charts, conversations, journal, readings and preferences — as a PDF in the app, and as JSON or PDF on the website. You can also ask us by email.

b) Correct itUpdate your name, contact details, language and preferences in Settings, and your birth details from your profile or chart page.

c) Delete itSettings → Your data → Delete everything removes your account and all of its data. On WhatsApp, reply DELETE to the Panditji number. Or email support@mypanditji.io. Deletion is irreversible.

d) Withdraw consentAI processing: Settings → Privacy & data. Analytics: the same screen, or the consent controls on the website. Notifications: Settings → Notifications, or your device settings. Marketing email: the unsubscribe link in any email. WhatsApp: reply STOP. Google Calendar: disconnect from the calendar page or from your Google account. Withdrawing consent does not affect processing that already happened lawfully.

e) Object, restrict or portIf the GDPR applies to you, you can object to processing based on legitimate interests (including any direct marketing), ask us to restrict processing while a dispute is resolved, and receive your data in a machine-readable format.

f) Nominate someoneIf the DPDP Act applies to you, you can nominate a person to exercise these rights for you in the event of your death or incapacity. Write to us to record a nomination.

g) ComplainYou can complain to our Grievance Officer (section 20), to the Data Protection Board of India, to your EEA data-protection authority, or to the UK Information Commissioner’s Office.

h) How we handle requestsWe may need to verify that you are the account holder before acting — usually by asking you to write from the email address or WhatsApp number on the account. We answer within 30 days, or sooner where the law requires. Requests are free unless they are repetitive or manifestly unfounded.

12. Cookies, analytics and consent

The website uses strictly-necessary cookies (sign-in session, guest identifier, daily cache), preference storage (language, theme) and — with consent — analytics and advertising-measurement cookies. If you are in the EEA or UK we show a consent banner and load nothing non-essential until you accept; you can change your mind at any time from Settings → Privacy & data. Elsewhere, analytics is on unless you turn it off, which you can do on the same screen, on the website and in the app. The mobile app sets no cookies; its analytics follow the same consent rules. The full list of cookies and storage keys is in our Cookie Policy.

13. Notifications, emails and WhatsApp messages

Service messages — one-time login codes, receipts, security alerts and notices about changes to these terms — are part of the Service and are sent for as long as you have an account.

Everything else is your choice:

Push notifications (daily horoscope, transit alerts, streak reminders, family birthdays, community replies) are sent only if you allow notifications on your device, and each topic can be switched off in Settings → Notifications.

Emails (daily horoscope, transit alerts, newsletter, product news and offers) carry an unsubscribe link. Product and offer emails go only to people who have signed up or subscribed.

WhatsApp messages from Panditji are sent only if you started a WhatsApp conversation with us or opted in. We send at most one promotional message a day; reply STOP at any time and they end immediately.

We do not give your phone number or email address to other companies for their marketing.

AGE RESTRICTION

14. Children and the 18+ rule

MyPanditji is for adults. You must be at least 18 to create an account, and we check your date of birth when you sign up. We do not knowingly collect personal data from anyone under 18; if we learn that we have, we delete it and close the account.

An adult may save the chart of a child in their family. Such charts are used only to produce gentle, supportive readings for the adult who saved them — no marriage timing, no fixed predictions — on the basis of that adult’s consent as the child’s parent or guardian. If you believe someone under 18 has given us personal data, or that a minor’s chart has been saved without a guardian’s permission, email support@mypanditji.io.

15. Security

We protect your data with encryption in transit (TLS) and at rest, row-level security in the database so that each account can read only its own rows, private storage buckets reachable only through short-lived signed links, least-privilege access for our team, secrets kept out of our code, and consent gates that stop data leaving the app until you have agreed. Palm and face photos are treated as sensitive and are never made public.

No system is perfectly secure. If a breach affects your personal data we will tell you and the relevant authority as the law requires — under the DPDP Act, that means the Data Protection Board of India and every affected user. Security researchers can report vulnerabilities under the responsible-disclosure programme on our Security page.

16. Guests, WhatsApp-only users and subscribers

You can try Panditji without an account. A guest gets an anonymous session on the device; the conversation is stored under that session so that it survives if you sign up, and is deleted after 7 days if you do not. Guest sessions have a message limit.

On WhatsApp, messaging the Panditji number creates a record of your number, the answers you give to set up your chart, and the conversation. It is covered by this policy in the same way as the app. Reply DELETE to have it removed.

Newsletter and daily-horoscope subscribers give us only an email address and a sign; unsubscribing removes you from the list.

17. Community, sharing and public content

Community posts, comments and upvotes are visible to other MyPanditji users. You choose the identity shown on each post — your real name and photo, a display name, or anonymous. We do not reveal the account behind an anonymous or display-name post to other users; even so, please avoid putting personal details into a post you want to keep private. Posts are moderated automatically and by people, other users can report them, and we may hide or remove content that breaks the Community Rules.

A reading you share by link can be opened by anyone with the link — you control who you give it to, and you can revoke it from the app.

18. Fonts, links and third-party content

Our web fonts are served from our own site. When you export a PDF on the website, the PDF loads its typefaces from Google Fonts (fonts.googleapis.com) as it is generated. Analytics and measurement scripts load from their vendors’ servers only after consent (section 12). Links to the App Store, Google Play, WhatsApp and other websites take you to services with their own policies.

19. Users in the EEA and the United Kingdom

If you are in the European Economic Area or the United Kingdom, the GDPR and UK GDPR give you the rights in section 11, on the legal bases in section 6, with transfers protected as described in section 9. You may lodge a complaint with your national supervisory authority or the UK Information Commissioner’s Office. We do not use your data for automated decisions that have legal or similarly significant effects on you.

INDIA · IT RULES 2021 · DPDP 2023

20. Users in India — the Grievance Officer and the DPDP Act

Most of our users are in India, and we follow the Information Technology Act, 2000; the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011; the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021; and the Digital Personal Data Protection Act, 2023.

Grievance Officer: Grievance Officer, MyPanditji

Email: support@mypanditji.io

Address: MyPanditji (Grupo Sineva Inc.), 1000 Main St, Houston, TX, United States

We acknowledge every grievance within 24 hours and resolve it within 15 days of receipt, as the IT Rules 2021 require. If you are not satisfied, or we do not respond in time, you may approach the Data Protection Board of India. Under the DPDP Act you also have the right to access, correct, update and erase your data, to withdraw consent, to nominate someone to act for you, and to a clear and simple explanation of how we use your data — which this policy is meant to be. Our Grievance Officer page has the full procedure.

21. Changes to this policy

When we change this policy we update the date at the top. For material changes — a new category of data, a new purpose, or a new provider that receives your data — we tell you in the app or by email at least 30 days before they take effect, and where the law requires it we ask for fresh consent. Continuing to use MyPanditji after the effective date means you accept the updated policy.

22. Contact us

Email: support@mypanditji.io (privacy requests, grievances and the Grievance Officer all reach the same inbox)

Address: MyPanditji (Grupo Sineva Inc.), 1000 Main St, Houston, TX, United States

We aim to answer privacy questions within 30 days, and grievances within the timelines in section 20.