Privacy and your data.
Last updated: 9 May 2026
This policy describes how Astron collects, uses, and stores your personal data, and explains your rights under India’s Digital Personal Data Protection Act 2023 (DPDP Act).
[[COMPANY LEGAL NAME]] is the data fiduciary (data controller) responsible for the personal data described in this policy, registered at [[REGISTERED ADDRESS]]. Contact: [[SUPPORT EMAIL]].
Data we collect
We collect the following categories of personal data:
- Birth details — date, time, and place of birth. Required to compute a KP chart. Stored encrypted at rest.
- Email address — used for magic-link authentication and transactional communications (purchase receipts, answer delivery).
- Question text — the questions you ask through the Platform. Stored to enable answer history and to improve question classification accuracy.
- Payment metadata — Stripe stores your card and billing data. We receive only a Stripe payment intent ID and a purchase record (amount, currency, timestamp). We do not store card numbers.
- Session data — a magic-link session token with a 30-day expiry. Stored as a secure httpOnly cookie.
- Usage data — anonymous page-view counts and feature interaction data used to understand platform usage patterns. If you accept analytics, this is measured with Google Analytics and the Meta Pixel (see § 03).
Why we collect it
We use your data only for the following purposes:
Who we share your data with
We share personal data only with the following third parties, and only to the minimum extent required:
- Stripe — payment processing. Stripe receives your email address and payment details. Stripe’s own Privacy Policy governs their use of your data.
- Swiss Ephemeris — the ephemeris library used to compute planetary positions. This library runs locally on our servers. No data is sent to a third party for chart computation.
- Meta Platforms (Facebook / Instagram) — only if you accept analytics in the cookie banner. We use the Meta Pixel in your browser and Meta’s Conversions API from our server to measure which of our ads lead people to the site. Meta receives the page address without its query string, the event (for example “free report generated” or “checkout started” with the price), a random event ID, your IP address and browser type, Meta’s own cookie IDs (
_fbp,_fbc), and, if you are signed in, your email address and account ID in hashed (SHA-256) form. We never send your birth details, name, questions, or report content. If you decline, none of this is sent.
Outside of Stripe, Swiss Ephemeris, and — only if you accept analytics — Google Analytics and Meta as described above, we do not sell, rent, or share your personal data with advertisers, data brokers, or any third party for marketing purposes. We never send birth details, names, or question/report content to any analytics or advertising provider. You can withdraw analytics consent at any time — see “Cookie settings” in the footer.
Your rights under DPDP Act 2023
Under India’s Digital Personal Data Protection Act 2023, you have the following rights regarding your personal data:
How to exercise your rights
Most data rights can be exercised directly through your account dashboard at /account, which provides options to:
- Download an export of all your personal data
- Request deletion of your account and all associated data
- Correct your birth details, email, or other account information
For requests that cannot be completed through the dashboard, contact our Grievance Officer at [[SUPPORT EMAIL]]. We will respond within 30 days.
Our current Grievance Officer: [[NAME]] ([[EMAIL]]).
Data retention
We retain your personal data for as long as your account is active or as needed to provide the service. Specifically:
- Birth details and question history: retained until you request deletion
- Payment records: retained for 7 years to meet accounting obligations
- Session tokens: expire after 30 days and are purged from the database
- Shared answer links: expire after 30 days if not renewed
On account deletion, all personal data is removed within 30 days, except payment records that must be retained for legal compliance. Retained payment records contain no birth details or question content.
Cookies
We use one essential cookie: an httpOnly session cookie that stores your authentication token after you complete magic-link sign-in. This cookie is required for the authenticated experience. It is not used for tracking or advertising.
If you accept analytics, Google Analytics and the Meta Pixel set their own cookies (_ga, _fbp, _fbc) to measure visits and which ads work. If you decline, neither is loaded and no such cookies are set. You can change your decision at any time using “Cookie settings” in the footer.