Protected observatory archive
Privacy Policy
Policy contents
1. Scope and effective date
This policy applies to the Cosmic Quest Android app (com.cosmicquest.android) and cosmicquest.in from 2026-08-28.
2. Who controls the data
Cosmic Quest (proposed Cosmic Quest LLP; registration pending), trading as Cosmic Quest, operates from Bommanahalli PO, Bengaluru, Karnataka, India. Organisation status: Proposed limited liability partnership (registration pending). Registration: Not yet issued; LLP registration is pending.
3. Core privacy approach
Core chart calculations are local by default. Online data processing occurs only for the cloud or connected feature identified below.
4. Data that remains on-device
- Core astrology: name
- Core astrology: birth date
- Core astrology: birth time
- Core astrology: birth place
- Core astrology: coordinates
- Core astrology: timezone
- Core astrology: chart/settings/results
- Mission signal: step count
- Mission signal: sleep sessions
5. Data collected or stored for online features
| Feature | Data | Purpose |
|---|---|---|
| Optional online account | Firebase UID, provider, email or phone when supplied, anonymous identity, session metadata | Authentication and session security |
| Cloud restore | encrypted profile backup ciphertext, backup metadata | Restore on another device |
| AI guidance | messages, minimum chart context, usage counters, provider request metadata | Generate response and enforce limits |
| Product measurement | consent-gated product events, app/device pseudonymous identifiers | Product analytics |
| Reliability | stack traces, device/app state, native crash diagnostics, possible pseudonymous installation ID | Diagnose crashes |
| Optional server notifications | FCM registration token, notification preferences, installation/account link | Deliver requested notifications |
| Astrologer marketplace | session records, chat messages, reviews, reports, block records | Run chat consultations and safety workflows |
| Provider onboarding | application, identity/compliance documents, provider images, payout records | Verify and administer providers |
| Research platform | profile, posts, messages, spaces, courses, submissions, publications, reputation, consent grants, donated charts, access audit | Community, education, publication and consent-scoped research |
| Paid access and CosmicCash | purchase token submitted for verification, token hash/encrypted server material, entitlements, subscription status, wallet ledger, referral code/rewards | Verify purchases, grant access, prevent replay/fraud, operate rewards |
| Physical store | order, amount/status, shipping contact/address, fulfilment events, tax/accounting record | Order preparation, support, accounting, and future fulfilment |
| Security and safety | App Check signals, server logs, audit events, moderation/safety cases, deleted-account tombstone references | Prevent abuse, audit sensitive operations, enforce safety |
6. Account and authentication data
Firebase UID, provider, email or phone when supplied, anonymous identity, session metadata.
7. Birth, chart and astrology data
local by default; optional backup/donation paths separate. Optional backup and research donation are separate choices.
8. Device permissions and sensor data
| Permission | Use | Control |
|---|---|---|
| CAMERA | Vastu/Trail AR and user-chosen synchronicity capture; video consultations are disabled | Deny permission or leave feature |
| RECORD_AUDIO | Audio/video consultation capability declared but disabled in the current release | Deny permission or leave feature |
| ACCESS_COARSE_LOCATION | Birthplace prefill, question moment, trails | Deny and enter place manually |
| ACCESS_FINE_LOCATION | Precise birthplace, sky and AR/trails | Choose approximate/deny |
| READ_CALENDAR | Life Archive calendar import | Deny/skip import |
| READ_MEDIA_IMAGES | Life Archive media import | Deny/skip import |
| READ_MEDIA_AUDIO | Life Archive audio import | Deny/skip import |
| READ_EXTERNAL_STORAGE | Legacy Android media import through API 32 | Deny/skip |
| POST_NOTIFICATIONS | Panchanga, mission, trail, consultation and FCM notifications | OS/app notification controls |
| RECEIVE_BOOT_COMPLETED | Restore user-scheduled local reminders | Disable reminders |
| health.READ_STEPS | Optional Health Connect mission signal (full flavor) | Health Connect permission manager |
| health.READ_SLEEP | Optional Health Connect mission signal (full flavor) | Health Connect permission manager |
9. Health Connect data
Optional mission progress signal. No durable storage verified in audited provider.
10. Analytics, diagnostics and crash reporting
Analytics default: disabled. Crash reporting: Enabled in release builds through Firebase Crashlytics; disabled in debug and offline builds. Crashlytics retains covered diagnostics for 90 days before removal begins.
11. Notifications and FCM tokens
Token and registration mappings are removed within 30 days after unregister or account deletion.
12. AI features and provider processing
Active providers: OpenAI API (gpt-4o-mini). Messages and minimum feature context are processed to answer the request.
13. Marketplace, consultation and KYC data
RTC providers: None in the current release. KYC providers: Google Firebase Storage with manual review by Cosmic Quest. Recording: No; consultation recording is disabled and no RTC provider is configured.
14. Community, courses and research data
Profiles and consents are deleted within 30 days; surviving published content is unlinked and chart-donation access is revoked immediately.
15. Research chart donations and consent
Research donation is optional and consent-scoped. The applicable retention and withdrawal behavior appears in the schedule below.
16. Payments, subscriptions, wallet and referrals
Payment providers: Google Play Billing for digital purchases. Google Play subscription cancellation remains a separate user action.
17. Store orders, shipping and tax records
Fulfilment providers: None in the current release. Statutory records follow the verified schedule below.
18. Service providers and processors
| Provider | Status | Data |
|---|---|---|
| google-firebase | VERIFIED_ACTIVE | account_auth, encrypted_backup, ai_conversation, analytics, crash_diagnostics, notification_installation, consultation_marketplace, provider_kyc, research_community, billing_wallet_referral, store_order, security_abuse |
| google-play | VERIFIED_ACTIVE | billing_wallet_referral |
| android-health-connect | VERIFIED_OPTIONAL | health_connect |
| ai-provider | OWNER_VERIFIED | ai_conversation |
| rtc-media-provider | NOT_USED_IN_CURRENT_RELEASE | consultation_marketplace |
| kyc-verification-provider | OWNER_VERIFIED | provider_kyc |
| payment-provider | OWNER_VERIFIED | billing_wallet_referral, store_order |
| fulfilment-provider | NOT_USED_IN_CURRENT_RELEASE | store_order |
19. Purpose and applicable processing basis
| Feature | Purpose | Basis |
|---|---|---|
| Core astrology | Calculate and save charts | User-requested core function |
| Optional online account | Authentication and session security | User-requested account and service security |
| Cloud restore | Restore on another device | Explicit user action to provide cloud restore |
| AI guidance | Generate response and enforce limits | User-requested optional AI feature |
| Product measurement | Product analytics | User consent, which can be withdrawn in settings |
| Reliability | Diagnose crashes | Service reliability and security |
| Optional server notifications | Deliver requested notifications | Notification permission and feature choice |
| Mission signal | Optional mission progress signal | Explicit Health Connect permission |
| Astrologer marketplace | Run chat consultations and safety workflows | User-requested optional consultation service and safety obligations |
| Provider onboarding | Verify and administer providers | Provider application, compliance, fraud prevention, and contractual steps |
| Research platform | Community, education, publication and consent-scoped research | Explicit donation, participation, or publication action |
| Paid access and CosmicCash | Verify purchases, grant access, prevent replay/fraud, operate rewards | Performance of the chosen purchase, fraud prevention, and legal obligations |
| Physical store | Order preparation, support, accounting, and future fulfilment | User-requested order preparation and legal obligations |
| Security and safety | Prevent abuse, audit sensitive operations, enforce safety | Service security, fraud prevention, safety, and legal obligations |
20. Data sharing and disclosures
Sharing is limited to the processors and recipients mapped above, user-directed publication, and disclosures required by verified law.
21. International or other-region processing
Functions: asia-south1 (Mumbai, India); Firestore: asia-south1 (Mumbai, India); Storage: US-EAST1 (primary Firebase Storage bucket), asia-south1 (Cloud Functions build and source buckets).
22. Retention schedule
| Category | Trigger or period | Deletion | Exception |
|---|---|---|---|
| local_birth_chart | Until user deletes local profile/app data | Local delete/clear/uninstall; cloud deletion does not wipe device | None verified beyond the stated trigger |
| account_auth | authentication: Until account deletion; the Firebase Authentication record is deleted at the end of the deletion pipeline within 30 days. | Deletion pipeline removes the Authentication account within 30 days after mandatory data tasks | None verified beyond the stated trigger |
| encrypted_backup | encryptedBackups: Until the user deletes the backup or account; deletion is completed within 30 days and recovery copies expire with the stated 7-day provider windows. | Storage prefix deleted within 30 days by the account-deletion pipeline; 7-day soft-delete recovery window applies | None verified beyond the stated trigger |
| ai_conversation | aiConversations: Until the user deletes the conversation or account; Cosmic Quest copies are deleted within 30 days. OpenAI may retain API inputs and outputs for up to 30 days for service and abuse monitoring unless law requires longer. | Firestore history is deleted within 30 days; OpenAI API inputs and outputs may be retained for up to 30 days | Firestore history is deleted within 30 days; OpenAI API inputs and outputs may be retained for up to 30 days |
| analytics | analytics: Disabled by default. If the user opts in, account-linked deletion requests are processed within 30 days where supported; Google Analytics event-level retention uses Google's available 2-month minimum for standard properties. | Collection stops when consent is withdrawn; linked deletion requests are submitted where supported and provider retention applies | None verified beyond the stated trigger |
| crash_diagnostics | crashReports: Firebase Crashlytics retains crash diagnostics for 90 days before removal from live and backup systems begins. | Crashlytics retains covered diagnostics for 90 days before removal begins | Crashlytics retains covered diagnostics for 90 days before removal begins |
| notification_installation | notificationTokens: Until notifications are disabled, the installation is unregistered, or the account is deleted; removal is completed within 30 days. | Token and registration mappings are removed within 30 days after unregister or account deletion | None verified beyond the stated trigger |
| health_connect | No durable storage verified in audited provider | Revoke permission or delete the source record in Health Connect | None verified beyond the stated trigger |
| consultation_marketplace | marketplaceMessages: Until the consultation/account is deleted; deletion or pseudonymisation is completed within 30 days unless a dispute, safety case, payment record, or legal hold applies. consultationRecords: Until the consultation/account is deleted; deletion or pseudonymisation is completed within 30 days unless a dispute, safety case, payment record, or legal hold applies. | Deletion or pseudonymisation is completed within 30 days unless a dispute, safety, payment, or legal exception applies | None verified beyond the stated trigger |
| provider_kyc | KycRecords: Until the provider application or relationship ends; deletion is completed within 30 days unless identity, payout, fraud, dispute, or legal-retention duties require longer. | Storage prefixes are deleted within 30 days unless identity, payout, fraud, dispute, or legal duties require longer | None verified beyond the stated trigger |
| research_community | researchCommunity: Until the user deletes the content/account; deletion or pseudonymisation is completed within 30 days. Public research already published may remain without account-identifying authorship. donatedChartData: Until consent is withdrawn or the account is deleted; access is revoked immediately and deletion is completed within 30 days, except already aggregated or de-identified research results. | Profiles and consents are deleted within 30 days; surviving published content is unlinked and chart-donation access is revoked immediately | Profiles and consents are deleted within 30 days; surviving published content is unlinked and chart-donation access is revoked immediately |
| billing_wallet_referral | billingEntitlements: For the subscription or entitlement lifecycle; account linkage is removed within 30 days after deletion, subject to tax, accounting, fraud, refund, and dispute records. purchaseTokenHashes: Account linkage is removed within 30 days after deletion; irreversible anti-replay hashes may remain without profile data to prevent duplicate credit and fraud. | Account linkage is removed within 30 days; irreversible anti-replay hashes and legally required transaction records may remain | None verified beyond the stated trigger |
| store_order | storeOrders: No physical-goods payment or fulfilment provider is active. If an order record exists, account linkage is removed within 30 days; a minimised transaction record may remain for tax, accounting, refund, and dispute duties. shippingDetails: Deleted or stripped from retained order records within 30 days after fulfilment or account deletion unless an active delivery, return, dispute, or legal obligation requires temporary retention. taxAccountingRecords: When GST recordkeeping applies, 72 months from the due date of the annual return, or longer where a proceeding or investigation requires it; retained records are minimised and pseudonymised where possible. | Shipping identity is stripped within 30 days; minimised transaction records follow the verified statutory schedule | None verified beyond the stated trigger |
| security_abuse | securityLogs: 30 days from collection unless needed for an active security investigation, fraud prevention, dispute, or legal obligation; retained records are access-restricted and account references are pseudonymised on deletion. moderationSafetyCases: Reviewed after 30 days and retained only while needed for an active safety, abuse, dispute, or legal purpose; account references are pseudonymised on deletion where possible. deletedAccountTombstones: Account-linked deletion status is retained for up to 30 days; irreversible anti-replay or security markers may remain without profile data. | Ordinary logs follow 30-day retention; active cases and pseudonymised anti-replay or audit records may remain for the documented exception | Ordinary logs follow 30-day retention; active cases and pseudonymised anti-replay or audit records may remain for the documented exception |
23. Security
Cosmic Quest uses platform access controls, transport encryption, Firebase Security Rules, App Check where configured, and deletion audit state. No system can guarantee absolute security.
24. Account deletion and processor deletion
Use the app or the external deletion route. The retention table distinguishes deletion, unlinking, exceptions and processor behavior.
25. Access, correction, erasure, withdrawal and grievance rights
Contact contact@cosmicquest.in for rights requests and Email contact@cosmicquest.in with the subject Privacy or Grievance for grievances. Identity verification may be required.
26. Children and minimum age
Minimum age: 18 years. Cosmic Quest is for adults and does not permit accounts or services for anyone under 18. Parental-consent implementation: Not applicable because users under 18 are not permitted.
27. Changes to this policy
Material changes will update the version, date and change log and will be communicated through an appropriate product channel.
28. Contact and grievance process
Sourik Ganguly, Director
contact@cosmicquest.in
Sourik Ganguly, Cosmic Quest, Bommanahalli PO, Bengaluru, Karnataka, India
Change log
Version 1.0 — initial owner-approved publication, reviewed by Sourik Ganguly (Director).