Privacy Policy

Version 0.9 (draft) · Prepared 28 July 2026 · Applies to the Cosmic Quest Android app (com.cosmicquest.android) and cosmicquest.in

Draft status. This policy describes the app's actual, code-verified data behaviour, but it has not yet completed legal review, and the controller identity and grievance contact below are pending owner confirmation. It must not be treated as final until this banner is removed.

1. Summary

2. Who is responsible

Pending owner confirmation: legal entity name, registered address and Grievance Officer details (required under India's DPDP framework) have not been finalised. This policy cannot take effect until they are published here.

3. Data that stays on your device

The following is stored locally in an SQLCipher-encrypted database, with the key held in your device's hardware-backed keystore. It never leaves your device unless you explicitly enable a cloud feature that uses it:

Uninstalling the app, or using the in-app "clear local data" controls, removes this local data. Cloud account deletion deliberately does not wipe your device — the app remains usable offline afterwards.

4. Data stored in the cloud (only if you sign in)

Online mode is optional. If you create an account (including anonymous sign-in), the following categories exist server-side, scoped to your account:

CategoryWhat it containsWhy
AccountFirebase Authentication identity: sign-in provider, email or phone if you used one, anonymous ID otherwiseSign-in, session security
Entitlements & billing eventsWhich features your purchases unlocked; immutable audit events; SHA-256 purchase-token hashes (never raw tokens) Delivering what you paid for; fraud prevention
Encrypted backupYour profile backup as ciphertext you key with a recovery phrase; we cannot read itRestore on a new device
AI conversationsMessages you exchange with AI features and usage countersProviding the feature, enforcing plan limits
MarketplaceConsultation sessions and messages with astrologers; if you apply as an astrologer: application, KYC documents, profile imagery Running consultations; verifying professionals
Store ordersOrder, payment status and fulfilment records; contact and shipping details you provideFulfilling physical orders; tax/audit law
Wallet & referralsCosmicCash balances, ledger entries, referral codes and reward eventsOperating the wallet and referral programme
Research communityYour research profile, posts, messages, spaces, course enrolments, submissions, publications, and consent-scoped chart-data donations with their access-audit trailRunning the research platform with auditable consent
Operational securityCrash reports, App Check and abuse-prevention signals, server logsKeeping the service working and safe
Research chart donations are governed by explicit, revocable consent grants; every access to a donated chart is recorded in an audit log you benefit from. Public research profiles never expose email, phone, birth date or exact birth time — the security rules forbid it.

5. Device permissions

6. AI features

AI conversations are processed server-side. Your messages and the minimum chart context needed to answer are sent to our AI provider to generate responses; usage counters enforce plan limits. Do not include information you don't want processed. AI output is guidance, not a guarantee — the app's content style avoids fatalistic claims by policy.

Pending owner confirmation: the named AI model provider(s) and their data-retention terms must be listed here before this policy is final.

7. Payments and billing

Purchases and subscriptions are processed by Google Play. We never see your card or bank details. Our servers verify purchases with the Google Play Developer API and store only entitlement records and hashed purchase tokens. Managing or cancelling a subscription happens in Google Play subscriptions — deleting your Cosmic Quest account does not cancel Play billing (see section 10).

8. Service providers

9. Retention

10. Account deletion — exactly what happens

Request deletion in the app (Account → Danger Zone → Delete account) or at cosmicquest.in/delete-account. The pipeline is idempotent and resumable; you can watch its status. It:

Deletion does not: cancel Google Play subscription billing (do that in Play subscriptions), or wipe the app's local data on your device (offline use keeps working; clear local data separately in the app if you want that too).

Anonymous accounts can be deleted the same way from inside the app.

11. Your rights

Depending on your jurisdiction (including under India's Digital Personal Data Protection Act), you may have rights to access, correct, export, and erase your personal data, to withdraw consent, to nominate, and to grieve. In practice:

12. Children

Pending owner decision: the minimum age for using Cosmic Quest and the verification approach (DPDP requires verifiable parental consent for children) must be decided and stated here before this policy is final.

13. Security

Local data is encrypted with SQLCipher; keys live in the Android Keystore. Transport is TLS. Cloud access is constrained by Firebase security rules that deny cross-account reads and client writes to server-owned records; purchases are verified server-side; premium content is delivered through short-lived signed URLs. No system is unbreakable — we do not promise absolute security, we reduce what an attacker could gain.

14. Where data is processed

Cloud services run on Google Cloud with primary processing in the asia-south1 (Mumbai) region. Some Google services may process data in other regions under Google's data-processing terms.

15. Changes

We will post changes here with a new version number and effective date. Material changes will be announced in the app before they take effect.

16. Contact

Pending owner confirmation: the verified privacy/grievance mailbox and the Grievance Officer's name will be published here. Until then, support requests flow through the app's existing support channel and the Play Store listing contact.