Esha Privacy Policy
Effective: 19 August 2026 App: Esha Operator (Data Fiduciary under DPDP 2023): Solo individual (not a company). Operator legal name: Phanidhar Rao Madduri (sole proprietor), India. Operator country of residence: India. Primary regulatory framework: India Digital Personal Data Protection Act, 2023 (DPDP). Service area: Esha is not offered to individuals in the EU/EEA, the United Kingdom, or Switzerland — account creation from those regions is blocked (see §11). For California residents, the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA) applies to the extent its thresholds and provisions are applicable to the operator. Privacy contact (grievance redressal under DPDP §8(10) and §13; Data Protection Officer equivalent): privacy@askesha.com (operator-monitored mailbox; replies issued from this address within the SLAs in §17). Esha has not been notified as a Significant Data Fiduciary under DPDP §10; a designated DPO is a §10 obligation for notified fiduciaries, and we provide one voluntarily.
Where DPDP enforcement stands (honest framing): the DPDP Act received assent on 11 August 2023, and the DPDP Rules, 2025 were notified on 14 November 2025. Under the phased commencement (Rule 1 of the Rules and the corresponding Act notifications), the substantive obligations — notice, consent, security safeguards, breach notification, children's data, and data-principal rights — come into force eighteen months after publication, i.e. around May 2027. Until then, the legally operative Indian data-protection floor is the IT Act, 2000 (§43A) and the SPDI Rules, 2011. This policy states DPDP-aligned commitments now, voluntarily and ahead of that date, and we treat them as binding promises by the operator rather than as descriptions of currently mandatory law.
Public account-deletion page: https://askesha.com/delete-account
1. Plain-English summary
| Topic | Plain meaning |
|---|---|
| Who runs Esha | A solo individual, not a company. |
| What we collect | Account: email + hashed password, an optional signup-attribution label, and your optional account-level AI-features decision and version. Newsletter, only if separately requested: email, signup-source label, double-opt-in confirmation, and unsubscribe status. Chart: name, birth date, birth time, birth place, latitude, longitude, timezone, and encrypted chart-derived Blueprint prose, which is displayed only while current AI consent is granted. Chat: your messages and AI replies; the web app can temporarily keep one pending outgoing message in per-tab browser storage so a reload safely resumes the same turn. Activity: streaks, subscription tier, daily AI usage. Purchases: report orders and subscription billing events. |
| What we do not collect | Phone numbers, contacts, photos, microphone or camera input, current GPS location, health-app data, payment-card numbers, government IDs, biometric data, browsing history outside Esha. |
| Why we use AI providers | OpenAI generates astrology readings and chat replies. Google Gemini independently checks messages and draft replies for regulated or crisis content before release. |
| Selling your data | We do not. |
| Ads / third-party analytics SDKs | Esha does not run ads. Esha does not use any tracking-based analytics SDK (no Mixpanel, Amplitude, Firebase Analytics, PostHog, or Google Analytics). We use Vercel Web Analytics — cookieless, first-party, aggregate page metrics only, no cross-site tracking, no advertising use. See §6. |
| First-party usage telemetry | Esha collects first-party usage telemetry events (screen views, feature opens, paywall interactions) linked to your user ID. This data improves product quality and is NEVER sold or shared with third-party analytics platforms. It is OFF unless you turn it on. The signup form asks you outright, with Yes and No equally easy and neither pre-selected, and stores only the answer you give; if you sign up with Google or Apple, Esha asks you the same question once when you first open the app. You can change your answer anytime in Profile → Privacy. See §3 for the schema. |
| Your control | You can export everything we hold about you, delete a profile, or delete your entire account from inside the app at any time. |
| Minimum age | 18. Single global floor that satisfies India DPDP 2023 §2(f)/§9(1) (children defined as under-18 requiring verifiable parental consent), GDPR Art. 8 (highest member-state digital-consent ceiling is 16), and the adult-targeted nature of relationship/career/health astrology content. |
This summary is informational only; the sections below control if there is any conflict.
2. Who Esha is
Esha is operated by Phanidhar Rao Madduri (sole proprietor), a solo individual based in India. References to "Esha," "we," "us," or "our" mean that operator and any service providers acting on the operator's behalf. There is no company, partnership, or limited-liability entity behind Esha at version 1.0. The operator is the Data Fiduciary under India DPDP 2023 §2(i). Esha is not offered to individuals in the EU/EEA, the UK, or Switzerland, and the operator does not designate itself a controller under those regimes; for California residents, CCPA/CPRA applies to the extent applicable.
The operator is also the named contact for grievance redressal under DPDP §8(10) and §13; complaints under DPDP and CCPA "right to know / delete / opt-out" requests all reach the same address listed at the top of this document.
If Esha later becomes operated by a legal entity, an acquirer, or a successor, this Privacy Policy will be updated and you will be notified before that change takes effect.
3. What we collect
We collect only what we need to run the product. Each row below maps to a real storage location in our database or with a named processor; nothing on this list is hypothetical.
| Category | Specific fields | Where it lives |
|---|---|---|
| Account | Email address; hashed password (bcrypt); subscription tier (free / pro / premium); account creation timestamp; optional signup-attribution label; current AI-features consent state, notice version, and decision timestamp. | users table |
| AI consent audit | Immutable records of each AI-features grant, decline, and withdrawal, including the notice version and timestamp. | user_consents table |
| Newsletter subscription (optional and separate from an Esha account) | Email address; a short SOURCE label identifying the Esha page where you subscribed; double-opt-in request and confirmation timestamps/status; unsubscribe or suppression status. No name or birth details. Consent is not complete until you confirm through the email Brevo sends. Newsletter and product-account consent are separate. | Brevo list esha-weekly (not the Esha product database) |
| Report purchases | Order ID (Razorpay), SKU, amount, order status (created/paid/refunded/disputed), timestamps, an optional partner referral code, and optional tool/variant labels recording which of our free tools (and which A/B copy variant) led to the purchase. Never your card number (Razorpay handles card data under PCI-DSS). | report_purchases table |
| Subscription billing-lifecycle events | An append-only log of subscription billing events: event type (e.g. trial authorized, charged, cancelled, refunded), gateway subscription/plan identifiers, charge amount, tier/status before and after, timestamp. Contains no name, email, or content — only your numeric user ID and gateway identifiers. Kept for legal/accounting compliance (see §7). | subscription_events table |
| Age confirmation at registration | Date of birth used solely to enforce the minimum-age rule. Validated server-side and not persisted to the account record. If you exit the app between registration and the chart-onboarding step, the value is held briefly in your device's secure storage (iOS Keychain / Android Keystore — never plaintext on disk) so the onboarding flow can resume; it is cleared on completion or on logout. | Validated in transit; transiently held in device secure storage if onboarding is paused |
| Birth profile(s) | Profile name; birth date; birth time; birth place text; latitude; longitude; timezone; the computed astrological chart | profiles table |
| Chat | Each message you send; each AI reply; session ID; profile ID; timestamp | chat_messages table |
| Pending web-chat recovery | At most one frozen outgoing message, chart/session IDs, an opaque logical-turn UUID, and start timestamp. No auth token or AI/provider reply is stored in this record. It exists only to reconcile the same admitted turn after a same-tab reload. | Your browser's per-tab sessionStorage on app.askesha.com |
| Life Blueprint prose (current AI features consent only) | AI-written area headlines and bodies derived from the deterministic chart Blueprint; exact render fingerprint/model/version; queue status and timestamps; error class only on failure. The prose checkpoint is AES-GCM encrypted with row/column-bound authenticated data. Raw prompts are not stored. | blueprint_prose_jobs table |
| Auto-extracted life events | Tags such as "career change," "relationship," "loss," extracted from your chat content using keyword rules to give the AI relevant context for future replies | life_events table |
| Conversation summaries (cross-session memory) | Per-conversation summaries generated AFTER a session ends: top topics, emotional tone, decisions you reached, follow-up hooks for next time, and a short prose summary. Used so Esha can pick up where you left off in your next conversation rather than starting cold. Up to the last 3 of these summaries are loaded as context when you next chat. | conversation_digests table |
| Streak | Current streak, longest streak, last check-in date, total check-ins | user_streaks table |
| Rate-limit state | Number of questions asked today, number of compatibility checks today | rate_limits table |
| Daily content cache | Daily insight, daily card, and daily digest payloads, keyed by profile and date | daily_insight_cache, daily_card_cache, daily_digest_cache |
| Family-plan slots | Slot ID, member user ID (if filled), action history | family_slot_changes |
| AI usage logs | Per-call token counts (prompt, completion, total), endpoint, tier, model, timestamp | token_usage_logs table |
| Chat-quality evaluation (on while usage telemetry is on) | A copy of your question and Esha's reply, plus computed quality signals (reply length, jargon flags, voice-drift summary, safety verdict), captured only while usage telemetry is enabled (off unless you chose it — the signup form asks outright, nothing is pre-selected; change your answer anytime in Profile → Privacy). Used solely by the operator to measure and improve answer quality; never shared with third parties; deleted when you delete your account. | ai_response_evals table |
| Crash & error diagnostics | Stack traces and request metadata, sent to Sentry only if Sentry is enabled for the deployment. We do not send your chat content or birth data to Sentry. | Third-party (Sentry) |
We do not collect: phone numbers, contact lists, photos, microphone or camera input, current GPS location, Apple Health or Google Fit data, browsing history outside Esha, payment-card numbers, government IDs, or biometric data.
We do not use third-party advertising SDKs, or any analytics SDK that tracks you individually or across sites. We use Vercel Web Analytics — cookieless, first-party, aggregate page metrics only; see §6.
First-party usage telemetry (server-side analytics): Esha collects a curated allowlist of telemetry events — for example, today_screen_viewed, pillar_opened, chat_message_sent, paywall_viewed, subscription_purchase_initiated — linked to your user_id. The full allowlist lives in backend/main.py under TELEMETRY_EVENT_ALLOWLIST and is also visible to App Store / Google Play reviewers on request. The data is used to (a) measure feature adoption, (b) detect breakages (e.g. a screen that nobody can open), (c) inform product decisions. It is NEVER sold, NEVER shared with any third-party analytics service, and is silently dropped for users who switch it off via Profile → Privacy. During the beta the default for NEW accounts is on, disclosed at the point of signup; switching it off stops collection immediately. Accounts created before 17 August 2026 keep their earlier default (off unless they opted in). See §10 (Retention) for storage duration.
4. Why we use it (purpose limitation)
| Purpose | Data used |
|---|---|
| Calculate your astrological chart | Birth date, birth time, birth place, latitude, longitude, timezone |
| Generate AI chat responses (current AI features consent only) | Your message; recent chat history (up to ten messages); chart context; current dasha context; system prompts |
| Generate optional Life Blueprint prose (current AI features consent only) | Bounded, chart-derived Blueprint verdict facts for each available life area. With consent off or withdrawn, Esha returns the deterministic structured Blueprint and does not enqueue, attach, or transmit AI prose. |
| Generate optional personalised reading prose (current AI features consent only) | Bounded chart-derived placements, verdicts, witnesses, and current timing facts used to phrase pillar, daily, and forecast interpretations. With consent off or withdrawn, Esha serves deterministic engine facts and makes no provider request. |
| Measure and improve answer quality (while usage telemetry is on) | A copy of your question + reply + computed quality signals — recorded only while usage telemetry is enabled (off unless you chose it at signup — you are asked outright and nothing is pre-selected). You can change your answer anytime in Profile → Privacy; collection stops immediately. |
| Maintain conversational continuity across sessions (personalization) | Auto-extracted life-event tags from your chat content; conversation summaries from your previous sessions (top topics, emotional tone, decisions, follow-up hooks) — so Esha can pick up where you left off and reference what you've talked about before. Lawful basis: contract performance (Art. 6(1)(b) GDPR / DPDP §7(a)) — these features are core to the product you signed up for; you can opt out by deleting your account. |
| Personalize daily content | Birth profile + current date. Deterministic daily facts do not require AI consent; optional AI-written wording does. |
| Enforce minimum-age policy | Your confirmation that you are 18 or older at registration (a yes/no attestation — we do not collect a date of birth purely to age-gate) |
| Operate accounts and sessions | Email, hashed password, JWT |
| Apply rate limits and per-user daily AI-cost limits | rate_limits table + token_usage_logs table |
| Operate subscriptions | Subscription tier + free-trial timestamp; billing receipts handled by Apple, Google, and RevenueCat (mobile) and by Razorpay for web subscriptions on app.askesha.com |
| Detect crisis prompts and route to safe responses | Your message text matched against keyword patterns; no detection metadata is sent to third parties |
| Diagnose crashes | Sentry crash reports (only if Sentry is enabled) |
| Respond to your privacy or support request | Your contact email and the contents of your request |
| Send Esha Weekly, only after separate double opt-in | Newsletter email, source label, consent status, and suppression/unsubscribe status. Lawful basis: your consent; you may withdraw it at any time through the unsubscribe link. |
| Measure which of our own pages and campaigns lead to signups and purchases (acquisition measurement / service improvement) | The signup-attribution label captured at registration; tool/variant labels on report purchases; subscription billing-lifecycle events — all first-party, all aggregate in use (the operator's weekly report reads counts, never individual browsing). This is an account field disclosed at signup via this policy, not usage telemetry — the §3 telemetry setting is separate — see §3 for its default and off switch. |
One account-level AI choice
Esha has one optional account-level AI features decision. If you allow AI, it covers the purposes itemised before you decide: OpenAI-written Life Blueprint and personalised-reading prose (including optional daily and forecast wording), OpenAI Chat answers, and Google Gemini safety checks for Chat. If you continue without AI, deterministic chart facts remain available and no AI request is made. A changed notice is treated as no current consent until you decide again. You may withdraw at any time in Profile.
Using your chart to tailor AI-written reflective content is a form of profiling. It does not make automated decisions that produce legal or similarly significant effects.
5. AI processing — what OpenAI and Google Gemini see
Esha uses OpenAI to generate chat responses and structured interpretations. Esha also uses Google Gemini as a separate safety processor to classify the current request and screen the draft reply before it is shown.
When you chat with Esha, we send OpenAI:
- Your message
- Up to ten recent prior messages from the same conversation
- Up to three short summaries of your previous conversations (top topics, emotional tone, decisions, follow-up hooks, prose summary) — so Esha can pick up where you left off rather than starting cold
- Auto-extracted life-event tags relevant to your profile (career change, relationship, loss, etc.)
- A compact, redacted snapshot of your chart (planetary placements, current dasha, the houses relevant to your question)
- A system prompt that instructs the model how to behave
- A response contract requiring the model to ground its reply in your chart
When the current AI features consent is granted and Blueprint prose is requested, Esha may asynchronously send OpenAI a bounded chart-derived verdict for each available Blueprint area (for example, the area label, support/challenge band, confidence, cited chart witnesses, and permitted plain-language meanings) to write its headline and body. This worker does not send your email, password, profile name, raw birth date/time/place, chat history, or stored conversation summaries. Consent is checked again immediately before every provider request; withdrawing it blocks the next request, although a request already in flight cannot be recalled. Its response is discarded and cannot become visible or be checkpointed.
For other personalised readings, Esha may send OpenAI a bounded subset of the same derived chart facts, including relevant placements, verdicts, witnesses, and current timing facts, to phrase pillar, daily, or forecast prose. These requests do not add your email, password, profile name, raw birth details, or Chat history. Without current AI consent, Esha uses deterministic engine facts and does not send this reading request.
What we do not send to OpenAI:
- Your email address
- Your password (it is hashed and never leaves our database)
- Numeric strength scores from internal calculations (these are redacted before transmission)
- Crash diagnostics
OpenAI processes these inputs to produce a reply and may retain limited request metadata for safety, abuse prevention, and reliability under its own privacy terms. We do not control OpenAI's infrastructure.
For each chat safety check, we send Google Gemini only:
- Your current message
- A selected, bounded portion of your recent user and assistant messages needed to understand references
- The draft reply for the final pre-release safety check
- Safety instructions and a structured response contract
We do not add your email address, password, stored birth details, chart snapshot, planetary evidence, internal profile identifiers, or stored conversation summaries to Google safety requests. The selected conversation portion can include prior assistant replies when they are needed to understand your current message. Information you type in a message is included in that message. Google is used for safety classification, not to write your astrology reading. Esha uses the paid Gemini API. Under Google's paid-service terms, prompts and responses are not used to improve Google's products, although Google may log them for a limited period for abuse prevention, security, and legal compliance. We do not opt chat data into feedback datasets or model-improvement sharing.
Two important properties of how we use the model:
- Output validation. Every AI reply passes through an automated safety layer before you see it. Replies that would name a specific date for marriage, childbirth, death, or disease are blocked and replaced with a safe response that frames life timing as windows and tendencies. This reduces, but does not eliminate, AI mistakes.
- Layered refusals. Requests for medical diagnosis, legal advice, financial advice, the date of someone's death, or harm to another person are designed to be refused before they reach the model. Questions about life timing such as marriage or children are answered as windows or tendencies rather than dates. No automated safety layer is perfect; treat every reply as reflection, not instruction.
You should not submit information to Esha that you do not want processed by an AI provider.
6. Third-party services we actually use
| Provider | Role | Data potentially processed |
|---|---|---|
| OpenAI | AI inference for Chat, Blueprint prose, and optional personalised reading, daily, and forecast wording | Prompt, bounded derived chart facts, and for Chat only, bounded recent context; technical metadata |
| Google Gemini API (paid service) | Independent request and draft-response safety classification | Current message, selected bounded recent user and assistant messages, draft reply, safety instructions, technical usage metadata. Esha does not add stored birth or chart data. |
| Railway | Hosting (US region) for the API server and Postgres database | All stored data, request logs, technical metadata |
| Apple App Store / Google Play | App distribution and in-app purchases | Subscription / purchase metadata under their own terms |
| RevenueCat | Subscription orchestration across Apple and Google billing | App user ID, product IDs, entitlement state, receipt metadata |
| Razorpay | Payment processing for subscriptions purchased on the web app (app.askesha.com) | Payment / subscription metadata, transaction identifiers, and the billing details you enter at checkout. We do not see or store your full card number; Razorpay handles card data under PCI-DSS. |
| Brevo (Sendinblue SAS) — transactional and opt-in newsletter email (operator-configured email provider; EU-based, sends over its API or hosted form) | Sends account-verification, security, password-reset, rights-request, and (if ever needed) breach-notice emails; stores separately double-opted-in Esha Weekly subscribers and sends the newsletter when it launches | Your email address, email content, and — for Esha Weekly only — signup-source label, double-opt-in status/timestamps, and unsubscribe or suppression status. No birth details. |
Sentry (only if SENTRY_DSN is configured for the deployment) | Crash and error reporting | Stack traces, request metadata. No chat content. No birth data. |
| Expo Push (Apple APNs / Google FCM) | Push notifications for daily content | Device push token; notification body |
| Vercel Web Analytics | Aggregate traffic metrics (page views, top pages) for the marketing site and the web app | Cookieless, first-party, aggregate page metrics, no cross-site tracking, no advertising use. No personal identifiers are collected. |
| Vercel Speed Insights (marketing site, askesha.com, only) | Aggregate page-performance metrics (Core Web Vitals) | Cookieless, first-party, aggregate performance metrics only. No personal identifiers are collected. |
| OpenStreetMap Nominatim (OpenStreetMap Foundation) | Geocoding — converting a birth place you type into map coordinates | The place-name text only (e.g. "Pune, India"), sent from our server. Never your name, birth date, or birth time; your own IP address is not exposed to OpenStreetMap (our server makes the request). Used by both the app's chart creation and the free tools; processed under OpenStreetMap's usage policy. |
We do not use Mixpanel, Amplitude, Firebase Analytics, PostHog, Google Analytics, or any other tracking-based analytics SDK. We do not embed advertising SDKs of any kind. If we add any of these in the future, this Privacy Policy will be updated and you will be notified in-app before the change takes effect.
7. Data retention
| Data | How long we keep it |
|---|---|
| Account, birth profiles, chat history, life events, conversation summaries, streak, daily caches | Until you delete the chat, profile, or account, or until your account is suspended for abuse. Withdrawing AI consent does not automatically delete existing Chat history; provider-written daily caches are cleared and deterministic daily facts can be rebuilt. |
| Encrypted AI-written Blueprint and pillar prose | Until AI-consent withdrawal, profile/account deletion, or another applicable lifecycle event. It is neither displayed nor sent to an AI provider without current consent. Withdrawal clears stored prose and partial checkpoints; a content-free in-flight fence is deleted after its lease safely expires. |
| Pending web-chat recovery record | Until the assistant result is safely stored, the turn receives a terminal error, you log out, or the tab/browser session closes. Records older than 24 hours are discarded the next time the app reads them. It is local to that browser tab and is not retained in server backups. |
Chat-quality evaluation rows (ai_response_evals) | Deleted with your account; not retained after deletion completes. |
| Hashed password | Until account deletion |
AI usage logs (token_usage_logs) | Up to 24 months for cost accounting, abuse detection, and fraud prevention. We may retain aggregated, non-identifiable totals longer. |
Report purchase records (report_purchases) | Deleted with your account. Razorpay retains the corresponding payment records under its own terms; those gateway records are the accounting record of the transaction. |
Subscription billing-lifecycle events (subscription_events) | Retained after account deletion for legal and accounting compliance (DPDP 2023 §8(4) — retention necessary for compliance with law; Indian tax/financial record-keeping). These rows carry no name, email, or content — only your numeric user ID, gateway identifiers, amounts, and tier/status transitions. |
| Crash diagnostics in Sentry (if enabled) | Per Sentry's default retention; typically 30–90 days |
| Backups | Standard Postgres backup cycle; deletion from backups can lag the live system by up to 30 days |
| Family-plan slot change history | Up to 24 months for abuse prevention |
| Newsletter subscription in Brevo | Until you unsubscribe or ask us to erase it. Brevo may retain the minimum suppression record needed to ensure we do not email an unsubscribed address again. This record is separate from any Esha account. |
When you delete your account, every row tied to your user_id in the tables listed in Section 3 is removed in a single database transaction, except backup snapshots which roll off naturally, aggregated cost totals where required for fraud and accounting purposes, and subscription billing-lifecycle events (subscription_events), which are retained for legal/accounting compliance as stated in the retention table above and §9.
8. Your rights
| Right | How to use it |
|---|---|
| Access / export | Call GET /api/v1/user/export from inside the app, or email the privacy contact. We return a JSON document containing your account (including the signup-attribution label, if any), every birth profile, stored Life Blueprint prose, every chat message, every life event, every conversation summary, your streak, your daily caches, and an export timestamp. The temporary pending-chat record is local to your tab rather than our server and is therefore not part of the server export. |
| Delete a single birth profile | Use the in-app profile delete control, which calls DELETE /api/v1/profiles/{profile_id}. |
| Delete your entire account | Use the in-app account delete control, which calls DELETE /api/v1/user. You may also use the public page at https://askesha.com/delete-account or email the privacy contact. |
| Correct your data | Edit a birth profile in-app; recompute the chart if you change birth details. |
| Object to or restrict processing | Stop using the app and delete your account. |
| Withdraw consent for AI processing | Turn off AI features in Profile → Consent. This blocks new Blueprint, personalised-reading, daily/forecast, Chat, and Gemini transmissions; cancels queued prose work; and clears stored Blueprint/pillar prose, partial checkpoints, and provider-written daily caches. Existing Chat history is not automatically deleted. A provider request already in flight cannot be recalled, but its response is discarded and no later request begins after withdrawal is observed. |
| Withdraw newsletter consent | Use the unsubscribe link in any Esha Weekly email, or email the privacy contact. Unsubscribing from the newsletter does not delete an Esha account, and deleting an Esha account does not silently re-subscribe or alter the separate newsletter consent record. |
| Lodge a complaint | You may contact your local data-protection authority. We will cooperate with regulator inquiries. |
We respond to verifiable rights requests within 30 days, or sooner where required by local law. (The DPDP Rules, 2025 will allow data fiduciaries up to ninety days once in force — our 30-day commitment is deliberately stricter and is the one we hold ourselves to.) We may need to verify your identity before fulfilling sensitive requests.
9. Account deletion
You can delete your account in three ways:
- In-app: Settings → Delete account (calls
DELETE /api/v1/user). - Web:
https://askesha.com/delete-account. - Email: the privacy contact below; we will verify and delete within 30 days.
Deleting your account does not cancel a paid subscription. Subscriptions are managed by Apple, Google, or RevenueCat under their own rules. To stop being billed, cancel the subscription in your App Store or Google Play account before deleting your Esha account.
After deletion, we retain only what is strictly necessary: aggregated cost-accounting totals, fraud signals, subscription billing-lifecycle records (see §7 — retained for legal/accounting compliance; numeric IDs and gateway identifiers only, no name/email/content), and backup snapshots that roll off naturally. We do not keep your chat content or birth profiles after deletion completes.
10. Children and minors (DPDP §9 / GDPR Art. 8 / COPPA)
Esha is intended for users 18 years of age and older. The app enforces this floor at registration: to create an account you must confirm that you are 18 or older. We do not collect a full date of birth purely to age-gate — your birth date is collected later, only as the input to your astrological chart.
The 18-year floor is a single global rule that satisfies three independent regimes:
| Regime | Citation | What it requires | How Esha meets it |
|---|---|---|---|
| India DPDP 2023 | §2(f) "child" = under 18; §9(1) verifiable parental consent for processing children's personal data | Either obtain verifiable parental consent OR refuse children | Requires an explicit 18+ confirmation at registration; a user who does not confirm cannot create an account, so no self-declared child's data enters the system. |
| EU GDPR | Art. 8 sets a member-state-configurable digital-consent age between 13 and 16; highest member-state floor (DE, NL) is 16 | A digital-consent age must be set; processing of under-floor users requires parental consent | 18 > 16, so the highest GDPR member-state floor is satisfied by construction. |
| US COPPA | 15 U.S.C. §6501(1) "child" = under 13 | Requires verifiable parental consent for under-13 collection; "child-directed service" framework | 18 > 13, so the service is outside COPPA scope by construction. |
If a parent or guardian believes a person under 18 has nonetheless created an account (for example, by giving an inaccurate age confirmation), please contact the privacy address at the top of this document and we will delete the account and all associated data.
Esha does not produce content intended to be sexual, exploitative, manipulative, or upselling toward minors. The app does not give marriage, fertility, or death timing for any user — adult or otherwise.
11. International transfers
Esha is not offered to users in the European Union, the European Economic Area, the United Kingdom, or Switzerland; account creation from those regions is blocked (app-store availability, marketing, and a signup geo-fence are all scoped accordingly). The GDPR / UK-GDPR mechanisms described below are retained purely as a matter of good practice for any data that nonetheless reaches us; they are not an offer of service to, or an assumption of controller obligations for, those regions.
Esha's production servers are hosted on Railway, in the US region. If you use Esha from outside the US — including from the EU, the UK, India, or anywhere else — your data is transferred to and processed in the US.
Specific transfer mechanisms by jurisdiction:
| Source region | Mechanism | Reference |
|---|---|---|
| EU/EEA | EU Standard Contractual Clauses (Commission Decision 2021/914 of 4 June 2021, Module 1 controller-to-controller for Railway/OpenAI relationships; Module 2 controller-to-processor where the sub-processor acts on documented instructions) plus a Transfer Impact Assessment ("Schrems II" requirement); supplementary technical measures include TLS 1.2+ in transit, AES-256-GCM at rest for PII columns (AAD-bound; see §12). | GDPR Art. 46(2)(c) |
| UK | UK International Data Transfer Addendum to the EU SCCs ("UK Addendum", ICO IDTA published 21 March 2022), executed with each US-based sub-processor. | UK GDPR Art. 46; DPA 2018 §17A |
| India | DPDP 2023 §16 permits transfer to any jurisdiction except those specifically restricted by the Central Government via notification. §16 commences with the substantive DPDP core (~May 2027); as of this policy's effective date no restricted-jurisdiction list has been notified, and the US is not restricted. We will review this table if a restriction notification issues. | DPDP 2023 §16 |
| California | CCPA / CPRA does not restrict cross-border transfers per se, but requires disclosure of "categories of personal information sold or shared" — none for Esha (we do not sell). | Cal. Civ. Code §1798.100(c) |
Sub-processors listed in Section 6 transfer and process data under their own contractual safeguards. Specifically:
- OpenAI: US-based; DPA at https://openai.com/policies/data-processing-addendum executes the EU SCCs Module 2 (controller-to-processor) and UK Addendum on the operator's behalf.
- Google Gemini API: Google processes paid-service prompts and responses under its Data Processing Addendum and does not use them to improve its products. Limited abuse-prevention logging may occur under the Gemini API terms.
- Railway: US-based; provides DPA + SCCs to its customers under its Terms of Service.
- Apple App Store / Google Play / RevenueCat: US-based; each maintains its own privacy posture for billing flows that the operator does not control.
- Razorpay: India-based payment processor used for web-subscription billing on app.askesha.com. Card data is processed by Razorpay under PCI-DSS; Razorpay processes payment details under its own privacy policy (https://razorpay.com/privacy/) and the operator's merchant agreement. As an India-resident processor, Razorpay does not introduce an additional cross-border transfer for India-based users.
- Sentry (if enabled): US-based; DPA available at https://sentry.io/legal/dpa/.
- Expo Push (Apple APNs / Google FCM): Push tokens transit through Apple/Google infrastructure under their own terms.
12. Security
We use:
- TLS for all traffic in transit
- bcrypt password hashing (we never see your plaintext password after the moment you create or change it)
- JWT-based session authentication with bounded lifetimes
- Environment-isolated secrets (the JWT signing key is required to be present in production; the application will refuse to boot otherwise)
- An admin endpoint guard requiring a separate admin token in production
- Per-user daily message and AI-cost caps to prevent abuse
- An always-on, deterministic output screen that blocks AI replies naming a specific date for marriage, childbirth, death, or disease before they reach you
No system is completely secure. If we become aware of a personal-data breach affecting you, we will notify the relevant authorities and affected users within the time windows required by applicable law:
- EU / UK GDPR: the relevant supervisory authority within 72 hours of becoming aware, for qualifying breaches, and affected users without undue delay where the breach is likely to result in a high risk to their rights.
- India — DPDP Act 2023 (§8(6)) and DPDP Rules 2025 (Rule 7): every affected user is informed without delay, in plain language, with a description of the breach, its likely impact, the protective steps you can take, and a contact for help; the Data Protection Board of India receives a description of the breach without delay and updated details within 72 hours of our becoming aware (extendable only by the Board on written request). India's regime has no severity threshold, so we give intimation of each personal-data breach, not only high-risk ones. (These provisions formally commence with the substantive DPDP core — around May 2027 — and we follow them voluntarily until then.)
- India — CERT-In Directions (2022): where the breach is a reportable cyber-security incident, we report it to CERT-In within 6 hours of becoming aware.
You are responsible for the security of your device, your email account, your app-store account, and your Esha password.
13. AI accuracy and the nature of astrology
Esha is a reflective astrology product. Three things you must understand:
- AI outputs may be wrong. Even with our validation layers, AI replies may be inaccurate, incomplete, biased, outdated, or unsuitable for your situation.
- Astrology is not deterministic. Esha gives windows of activation and reflective patterns, never calendar guarantees. We screen the model's output for, and regenerate or replace, replies that claim a specific date for marriage, childbirth, death, or disease, and we refuse direct requests for the date of someone's death and for medical, legal, or financial determinations. These checks reduce but do not eliminate the risk of an over-confident reply.
- Esha is not professional advice. It is not medical, legal, financial, or psychological advice. For any of those, see a licensed professional.
14. Crisis and safety
If you tell Esha you are thinking about self-harm or suicide, the app will replace the astrology reply with a crisis response that lists helplines (US 988, UK Samaritans, India Tele MANAS, and a global pointer to local emergency services). The app cannot replace emergency services. If you are in immediate danger, call your local emergency number.
We do not share crisis-detection metadata with third parties.
15. No sale, no targeted advertising
We do not sell personal data. We do not run third-party ads. We do not share birth data, chat content, or chart data with anyone for advertising purposes. If this changes, we will update this Privacy Policy and obtain any consent required by law before the change takes effect.
16. Changes to this policy
We may update this Privacy Policy. The effective date at the top of the document changes when we do. Material changes — for example, adding a new third-party processor, changing retention defaults, or starting to use data for a new purpose — will be communicated in-app, or by an email to your account address, before the change takes effect.
17. Contact
For privacy questions, rights requests, or deletion requests: privacy@askesha.com
The operator is the named contact for grievance redressal under DPDP 2023 §8(10) and §13, and the Data Protection Officer equivalent for other jurisdictions (a designated DPO is formally a Significant-Data-Fiduciary obligation under §10; Esha is not one, and provides this contact voluntarily). Verifiable rights requests will be acknowledged within 7 days and completed within the timelines required by the applicable law (typically 30 days under GDPR Art. 12(3) / DPDP 2023 §11(2); 45 days under CCPA §1798.130(a)(2)).
If you do not receive a reply within 30 days, you may contact your local data-protection authority. For India users specifically, the Data Protection Board of India — established November 2025 as a digital-first Board: complaints can be filed online through its portal, and appeals against its decisions lie to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT). For EU users, the supervisory authority of your member state of habitual residence (list at https://edpb.europa.eu/about-edpb/about-edpb/members_en). For UK users, the Information Commissioner's Office (https://ico.org.uk). For California residents, the California Privacy Protection Agency (https://cppa.ca.gov).
18. Free tools (no signup)
askesha.com/tools offers free birth-chart, kundli-matching, Mangal dosha, panchang, nakshatra, and dasha calculators that anyone can use without creating an account. These tools work differently from the rest of Esha: your birth details are computed in memory and never saved. The one exception is the birth place you type: to turn it into map coordinates, that place name alone is sent server-side to OpenStreetMap's Nominatim geocoder (see §6) — never your name, date, or time. Standard server logs (IP address, timestamp — no birth data) are kept briefly for abuse prevention, the same as any web request to our servers. No profile, chat history, or account record is created from using a free tool. If you choose to continue from a free tool into a paid report, only an opaque, short-lived draft identifier travels to checkout — never your birth date, time, place, or name in the URL or in your browser's storage; that draft expires automatically and is not linked to your identity unless you create an account. A newsletter form shown near a free tool is separate: it sends only the email address and short page-source label you submit to Brevo after you separately choose to subscribe; it never sends or saves the birth details entered in the tool.
19. Data you provide about others
Some features — adding a family member's profile, or buying a Compatibility Report for you and a partner — require you to enter someone else's birth details (name, date, time, place). When you do this:
- You confirm you have that person's permission to share their birth details with Esha for this purpose. The Compatibility Report checkout requires an explicit attestation checkbox ("I have this person's permission to use their birth details") before the purchase can proceed, and we record that you attested, and when. The same confirmation is now required on every other path that accepts another person's birth details, including the free ones — a free compatibility reading in the app, and the free kundli-matching tool on askesha.com when you continue from it towards a report — and we refuse the request without it.
- Processing basis: we rely on the permission you attest to, together with our legitimate interest in delivering the report you paid for. This basis is under review as part of our India entity setup; we will update this section if that review changes it — we do not claim more legal certainty here than we currently have.
- Minimization: for a one-time Compatibility Report, the partner's birth details are retained only long enough to generate the report and for the report link's lifetime — we do not create a separate profile or account for the partner, and we do not reuse their details for anything else. The rendered report itself shows only the partner's first name and chart placements — never their full birth date, time, or place.
- Their rights: the person whose details you entered can ask us to erase that data by contacting privacy@askesha.com (or asking you, the account holder, to request deletion on their behalf) — §8 (Your rights) and §9 (Account deletion) apply the same way to data you entered about someone else.
- Family profiles work the same way: only enter another person's birth details with their permission (or, for a minor in your care, your own authority to do so), consistent with §10.