Pi Consultants, LLC · Legal

Privacy Policy

Effective 29 August 2026Vedic Phala · Android · us.piconsultants.phalaContact: support@vedicphala.com

This policy describes what data Vedic Phala handles, why, and what choices you have. We designed the app to work without an account — you can create and read charts anonymously, and your birth data never leaves your device in a readable form.

1 · Data you provide

Birth details. When you create a chart, you enter a name or label, date of birth, time of birth, and birth place. For family members or other people you add, the same details. This is the core personal data the app processes.

Account email. Only if you choose to sign in with Google to enable cross-device sync, subscription restore, or the optional daily email digest. We receive your verified email address from Google; we never receive your Google password.

Questions you type in Ask Phala. The wording you send to the chat, and the recent turns of that conversation, so the assistant can follow what you are asking. See section 6: what you type is sent as written, so avoid typing your birth date, time, or place there — the app already has them and deliberately does not send them.

Photos and video you take or choose. Sky Photo uses your camera to take a picture of people with their birth star in the background, and Sky-Eye can record a short video clip of the sky. Sky-Eye also has a screen-recording button for capturing your own walk-through of the app; it starts only through Android's own screen-capture consent dialog, records no audio, and the resulting video is saved to your gallery like any other clip. You can also set a reference photo for a saved chart so the app can tell who is who in a family shot. Sky Photos and video clips never leave your device — we do not upload them, we cannot see them, and there is no copy of them on our servers. Reference photos you attach to a saved chart are different: if you sync (Plus only), a reference photo is encrypted on your device and backed up the same way your chart data is (see section 4) — the server stores only the encrypted result and cannot read it, but a copy does now leave your device when sync is on. This changed 2026-08-24 with the addition of encrypted chart-photo sync; before that date reference photos stayed device-only.

  • Photos and video clips you capture with Sky Photo or Sky-Eye are saved to your own device gallery, in Phala albums, exactly like any other photo or video you capture. They are yours; delete them the way you delete any photo.
  • Video clips are recorded by the app's own in-app camera. Sound is recorded only if you allow the microphone — the app asks the first time you record, and if you decline, the clip records picture-only. The microphone is used solely while you are recording a clip you started; it is never on in the background, and the audio exists only inside your clip, on your device. The Sky-Eye screen recorder remains silent — it captures the screen, never sound.
  • Reference photos for a chart are deliberately excluded from the chart file itself, so that when you share or export a chart, nobody's face travels with it — this holds whether or not sync is on.
  • Contact import. When adding a family member, you can pick them from your phone's contacts instead of typing their details. The system picker hands the app read access to only the one contact you chose — no separate permission is needed for their name or photo. If you also allow contacts access, the app can additionally read that contact's birthday and prefer their WhatsApp profile photo when available. We never read, search, or store anything about your other contacts.
  • If you choose to share a Sky Photo or video clip, the app hands it to Android's normal share sheet and you pick where it goes. From that point the file is governed by whichever app or service you sent it to, not by us.
  • To place each person's star path above the right head — and, while you record a video clip, to keep the drawn sky above the tallest head as people move — the app detects where faces are in a Sky Photo, on your device, using Google ML Kit. By default it finds only the position of a face; it does not recognise or identify anyone, and builds no faceprint.
  • Optional face matching (off until you turn it on). If you give explicit permission when asked, the app additionally compares faces in your new photos and clips with each chart's reference photo, so it can suggest which family member is which. To do this it computes a numeric face signature on your device, in memory, for the moment of the comparison. These signatures are never stored beyond that moment, never synced, and never sent anywhere — the comparison exists only on your phone, and its result is only a suggestion your own choice always overrides. Decline, and no face signature is ever computed; you can also simply not set reference photos.
  • The app reads a photo's orientation tag so pictures appear the right way up. It does not read, add, or transmit location data in your photos.

2 · Data collected automatically

Approximate device location. The app requests coarse location (city-level accuracy, foreground only) to anchor the panchang — the almanac that shows sunrise, sunset, and Rahu Kala — and the sky view to where you are. You are asked for permission first, and both screens work without it. The coordinate is stored only on your device and is used there in the calculation; it is never transmitted to any server. The app never requests precise or background location.

Where the birth-place map opens. The picker centers on the last place you chose, or on the approximate location already held on your device for the almanac. Nothing is sent anywhere to work that out, and wherever it opens, only the place you pick is used for your chart.

Birth-place and time-zone lookup. When you search for or select a birth place, the place name you typed is sent to Google Maps Platform (the Geocoding service) to resolve it to coordinates, and the selected coordinates are sent to its Time Zone service to find the birth time zone. Only the typed text and the resulting coordinates are sent; no device location is used for these lookups.

Anonymous identifier. On first launch, a random account ID is issued by Supabase (our backend provider). It contains no name, email, or device data and is used solely to associate your encrypted chart backups with your device.

Terms-acceptance record. The version and date you accepted our Terms of Use and Privacy Policy, kept as a record of your consent. It is stored on your device and, if you are signed in, on your account.

Usage analytics. The app sends a small set of anonymised behavioural events to PostHog (our product analytics provider). Events are limited to an explicit allowlist — feature interactions, app version, language, and astrological cohort buckets. No names, birth dates, exact coordinates, or any personally identifying information are included. Screen recordings and session replays are disabled.

Crash reports. If the app crashes, a report is sent to Sentry (our error-monitoring provider). Reports are scrubbed of personally identifying information before they leave the device.

Notification token. If you enable notifications, a push messaging token is issued by Firebase Cloud Messaging (Google) so we can deliver your daily reading to your device.

Purchase data. If you subscribe to Vedic Phala Plus, Google Play provides a purchase token we use solely to verify and activate your subscription. We do not receive or store your payment card details.

3 · How we use your data

  • To compute your birth charts and generate readings, entirely on your device.
  • To answer the questions you ask in Ask Phala (see section 6).
  • To sync your charts to your account and restore them on a new device (Plus subscribers only).
  • To deliver daily notifications and, if you opt in, a daily email reading to your verified address.
  • To verify and restore your subscription.
  • To keep a record that you accepted our Terms and when.
  • To keep the app stable through anonymised crash reporting and usage analytics.

4 · How your data is stored and protected

On your device. All birth details, chart data, and account information are stored encrypted using the Android Keystore (AES-256-GCM). No readable personal data is written to unencrypted storage.

When you sync (Plus only). Before any chart data leaves your device, it is encrypted with a key that lives only on your device (AES-256-GCM with a 96-bit random nonce). We store and transmit only the encrypted result. The server never holds your encryption key and cannot read your charts — not even we can. Only a device that holds your key, or a recovery method you set up (your recovery password, or the Google Drive backup described below), can decrypt your charts.

Recovery key backup. So that losing your device does not mean losing access to your synced charts, we keep a wrapped, encrypted copy of your encryption key on our server, protected by a recovery password you set. It is wrapped under a secret only your device (or you, via your chosen password) knows — our server cannot unwrap or read it, the same way it cannot read your chart data. This replaced a 12-word recovery phrase on 2026-08-20 — the phrase could never have recovered a purely anonymous account on a new device to begin with, so it was retired in favor of password-based recovery, which works for every signed-in Plus account.

If you link a Google account, the app can additionally store a second copy of this wrapped key in a hidden, app-only folder in your own Google Drive (Google's drive.appdata scope, which only grants access to that hidden folder, not your visible Drive files or any other file). That copy is yours — it lives in your Drive, not on our servers, and we cannot read it there either. You can delete it at any time in Google Drive's own settings (Manage apps → Vedic Phala → delete hidden app data) or by disconnecting Vedic Phala from your Google account; recovery then relies on your recovery password instead.

Device-identity recovery. If you recover your identity on a new device without using Google sign-in, our server moves your existing account data (subscription status, saved profiles, referral and usage records) from your old device session to the new one, then removes the old session. This uses only data types already described in this policy; it is a different way of reaching your existing data, not a new kind of data we collect.

In transit. All connections to external services use HTTPS. Chart data is additionally encrypted at the application layer before transmission, independent of the transport encryption.

Retention. We retain your data as long as your account is active or as required by law. You can delete all of it at any time (see section 7).

5 · Who we share your data with

We do not sell your personal data. We use the following service providers, each under their own terms and privacy policies:

Service Purpose What they receive
Supabase Account auth and chart backup Your anonymous user ID; encrypted chart blobs only — no readable birth data
Google Play App distribution and billing Purchase tokens for subscription verification
Google Maps Platform Birth-place and time-zone resolution The place name text you type and the coordinates of the place you select
Google Drive (only if you link a Google account) Backup of your wrapped recovery key, into a hidden folder in your own Drive An encrypted, unreadable copy of your recovery key — it stays in your Drive, not on our servers, and we cannot read it there
Anthropic Generates the answers in Ask Phala A results-only chart summary (see section 6) — no birth date, time, or place — your question, and the recent turns of the conversation
Firebase Cloud Messaging Push notifications A push token tied to your anonymous account
PostHog Product analytics Anonymised event data — no PII
Sentry Crash reporting PII-scrubbed crash reports
Fly.io Hosts our server: subscription receipt verification, the Ask Phala relay and question metering, account deletion, and the email relay Purchase tokens; the Ask Phala request described in section 6; the composed reading prose and your verified email address (digest feature only)

The email relay receives only the finished reading prose and your destination email address. It never receives birth dates, times, places, or chart contents.

We may disclose data if required by law or to protect the rights, safety, and integrity of the app and its users.

6 · Ask Phala (the chat)

Ask Phala answers questions in plain language. Generating an answer needs a model we do not run ourselves, so this feature — and only this feature — sends chart data off your device. What it sends is deliberately narrow.

Your birth date, time, and place are never sent. Nor are your coordinates or the chart's name. That is not a promise we keep by care alone: the data structure that crosses the wire has no fields for them, and two separate steps — one on your device, one on our server — strip the name and the exact daśā dates before anything is transmitted. Automated tests fail our build if that stops being true.

What is sent is the result your device already computed:

  • the sign and degree of your Lagna, Sun, and Moon;
  • each graha's sign, house, dignity, and whether it is retrograde or combust;
  • your Janma Nakṣatra;
  • which daśā period you are in, and roughly how much of it remains — never the exact dates, because those could be used to work backwards to a birth date;
  • the current gocāra (transit) phase and any yogas found;
  • your question, the recent turns of the conversation, and your language.

Your question is sent as you wrote it. If you type your birth date, time, or place into the question, that text is sent. The app warns you before sending when it notices something that looks like birth details, and the assistant is instructed never to ask you for them. Neither replaces your own judgement about what you type.

We do not keep your conversations. Our server counts how many questions you have asked, to apply your plan's limits — nothing more. Questions and answers are not stored on our servers. Anthropic processes what it receives, under its own terms, in order to produce the answer.

One exception, and only if you ask for it. When you report inappropriate or offensive material in the chat, you can choose to send us the conversation along with your report. A complaint about something the assistant said cannot be looked into without seeing what was said. The option is off unless you turn it on, it covers only the report you are sending at that moment, and the conversation then reaches us the same way any report does. See "Suggestions and problem reports" below.

Suggestions and problem reports

The chat screen also has two buttons that reach us — the people who make the app — rather than the assistant: "Send a suggestion" and "Report a problem". They are labelled as such, and nothing you type into the chat itself is ever treated as one of these submissions.

A submission reaches us two ways, and only us: it is delivered to our support inbox by email, and it is kept as a support conversation in our database so we can answer you. It is not sent to any AI model. It contains what you typed, plus your app language, the app version, the name of the screen you came from, and a short fragment of your anonymous account identifier that lets us notice abuse of the channel — it cannot identify you.

When we answer, the reply appears in the app under Messages, and you can reply there in turn; those replies are part of the same stored conversation. If notifications are on, the app may tell you that an answer arrived — the notification never contains the answer itself, because a lock screen can be read by anyone. Deleting your account deletes these conversations with everything else.

A problem report can optionally include one screenshot of the screen you were on when you opened the chat. The screenshot is never taken or sent silently: it is shown to you in the report dialog exactly as it would be sent, it travels only if you leave the attach option on and press send, and it is discarded otherwise. We use these submissions only to fix problems and improve the app.

A problem report also carries a tick box for reporting inappropriate or offensive material in the chat. Ticking it attaches the conversation to that report, so we can see the material being reported. It is off until you tick it, it is cleared again every time the report dialog opens, and it applies to nothing but the report you send. The conversation reaches the same support inbox, is never sent to an AI model, and is used to judge the report and fix what caused it. If the conversation is long, the most recent part is what we receive.

7 · Your choices and rights

Use anonymously. You can create and read charts without signing in. No email address or account is required.

Delete all your data. The About screen in the app has a "Delete my data" option. Confirming it permanently:

  • deletes all charts and family data encrypted on your device,
  • deletes your encrypted chart backups and your account record from our servers — including the authentication record and any linked email address, and
  • signs you out and resets the app.

If the app cannot reach our server at that moment (for example, you are offline), the on-device wipe still completes and your charts are removed; contact us at support@vedicphala.com and we will finish the server-side deletion. You can also request deletion at any time by email or with the web form at vedicphala.com/delete-account.

Notifications and email. You can turn off notifications and the daily email digest at any time in the app settings.

Your legal rights. Depending on where you live, you may have the right to access, correct, delete, export, or restrict processing of your personal data, and to object to certain uses. To exercise any of these rights, contact us at support@vedicphala.com.

8 · Children

Vedic Phala is not directed to children under 13 (or under 16 where a higher age applies, such as in the EEA and UK). We do not knowingly collect personal data from children. Do not enter a child's birth details without the consent of a parent or legal guardian. If you believe a child has provided data through the app, contact us and we will delete it promptly.

9 · International transfers

Your data may be processed in countries other than the one in which you live. Where transfers require appropriate safeguards under applicable law, we ensure those safeguards are in place.

10 · Changes to this policy

We may update this policy. Material changes will be indicated by a new effective date and, where appropriate, an in-app notice.

11 · Contact

Pi Consultants, LLC
support@vedicphala.com
vedicphala.com · piconsultants.us
A postal address is available on request.

Effective 29 August 2026 · Vedic Phala