Privacy Policy
1. Summary
- Offline-first by design. Your birth details, charts and settings are stored on your device in an encrypted database. You can use the core app without any account.
- Cloud data exists only for features you choose: sign-in, encrypted backup, subscriptions, AI conversations, the astrologer marketplace, the research community, wallet and referrals.
- We never store raw purchase tokens — only SHA-256 hashes for fraud prevention.
- You can delete your account in the app or at cosmicquest.in/delete-account. Deletion removes your cloud data comprehensively; the narrow, documented exceptions are listed in section 10.
2. Who is responsible
3. Data that stays on your device
The following is stored locally in an SQLCipher-encrypted database, with the key held in your device's hardware-backed keystore. It never leaves your device unless you explicitly enable a cloud feature that uses it:
- Birth profiles: name, birth date, time, place, coordinates and timezone.
- Saved charts, compatibility analyses and calculation results.
- Calculation settings (ayanamsha, house system, node mode, zodiac mode), language and display preferences.
- Tarot readings and journals (local-only in the current release).
- Downloaded content packs and ephemeris data.
Uninstalling the app, or using the in-app "clear local data" controls, removes this local data. Cloud account deletion deliberately does not wipe your device — the app remains usable offline afterwards.
4. Data stored in the cloud (only if you sign in)
Online mode is optional. If you create an account (including anonymous sign-in), the following categories exist server-side, scoped to your account:
| Category | What it contains | Why |
|---|---|---|
| Account | Firebase Authentication identity: sign-in provider, email or phone if you used one, anonymous ID otherwise | Sign-in, session security |
| Entitlements & billing events | Which features your purchases unlocked; immutable audit events; SHA-256 purchase-token hashes (never raw tokens) | Delivering what you paid for; fraud prevention |
| Encrypted backup | Your profile backup as ciphertext you key with a recovery phrase; we cannot read it | Restore on a new device |
| AI conversations | Messages you exchange with AI features and usage counters | Providing the feature, enforcing plan limits |
| Marketplace | Consultation sessions and messages with astrologers; if you apply as an astrologer: application, KYC documents, profile imagery | Running consultations; verifying professionals |
| Store orders | Order, payment status and fulfilment records; contact and shipping details you provide | Fulfilling physical orders; tax/audit law |
| Wallet & referrals | CosmicCash balances, ledger entries, referral codes and reward events | Operating the wallet and referral programme |
| Research community | Your research profile, posts, messages, spaces, course enrolments, submissions, publications, and consent-scoped chart-data donations with their access-audit trail | Running the research platform with auditable consent |
| Operational security | Crash reports, App Check and abuse-prevention signals, server logs | Keeping the service working and safe |
5. Device permissions
- Location (optional): used on-device to compute your local Panchanga and to point the Night Sky. Not uploaded as a location history.
- Camera (optional): used live for Vastu AR overlays; frames are processed on-device and not recorded.
- Motion sensors: compass/gyroscope orient the Live Sky and Vastu compass on-device.
- Notifications (optional): Panchanga and reminder alerts you schedule.
6. AI features
AI conversations are processed server-side. Your messages and the minimum chart context needed to answer are sent to our AI provider to generate responses; usage counters enforce plan limits. Do not include information you don't want processed. AI output is guidance, not a guarantee — the app's content style avoids fatalistic claims by policy.
7. Payments and billing
Purchases and subscriptions are processed by Google Play. We never see your card or bank details. Our servers verify purchases with the Google Play Developer API and store only entitlement records and hashed purchase tokens. Managing or cancelling a subscription happens in Google Play subscriptions — deleting your Cosmic Quest account does not cancel Play billing (see section 10).
8. Service providers
- Google Firebase (Authentication, Firestore, Cloud Storage, Cloud Functions, Remote Config, App Check, Crashlytics) — cloud infrastructure.
- Google Play — app distribution and billing.
- AI model provider(s) — pending confirmation, see section 6.
9. Retention
- Account-scoped cloud data: kept while your account exists; removed or unlinked on deletion as described in section 10.
- Billing and order records: retained as required by tax and accounting law, with contact details stripped on account deletion. Pending owner confirmation: the exact statutory retention period must be stated here after legal review.
- Security/audit logs: retained for fraud and abuse prevention; identity references become unlinkable after account deletion.
- Encrypted backups: deleted with your account, and can be deleted earlier in-app.
10. Account deletion — exactly what happens
Request deletion in the app (Account → Danger Zone → Delete account) or at cosmicquest.in/delete-account. The pipeline is idempotent and resumable; you can watch its status. It:
- Deletes your user document tree (entitlements, backups, wallet mirrors, AI history, tarot sync data), astrologer profile and KYC files, research profile, reputation records, connections, blocks, donated chart records and their consent grants, community memberships, enrolments, challenge entries, referral codes, and every Cloud Storage object under your account prefixes.
- Unlinks (pseudonymises) records that must outlive the account: published research and reviews keep their content with authorship replaced by a non-identifying marker; billing/tax order records keep amounts but lose your contact details; purchase-token hashes stay bound to a tombstone value so a used token can never credit another account.
- Retains, with a documented basis: server-only security audit trails and moderation/safety cases (abuse patterns must survive deletion); these are inaccessible to other users and become unlinkable to you once profile data is gone.
- Finally deletes your sign-in account itself. If that last step fails, the status says so honestly and a retry completes it — we never report success while your account still exists.
Deletion does not: cancel Google Play subscription billing (do that in Play subscriptions), or wipe the app's local data on your device (offline use keeps working; clear local data separately in the app if you want that too).
Anonymous accounts can be deleted the same way from inside the app.
11. Your rights
Depending on your jurisdiction (including under India's Digital Personal Data Protection Act), you may have rights to access, correct, export, and erase your personal data, to withdraw consent, to nominate, and to grieve. In practice:
- Access/export: use the in-app export tools before deleting.
- Correction: edit profiles and settings directly in the app.
- Erasure: section 10.
- Consent withdrawal: research chart-donation consent is revocable in-app and cuts off dataset access immediately.
- Grievance: contact channel in section 16.
12. Children
13. Security
Local data is encrypted with SQLCipher; keys live in the Android Keystore. Transport is TLS. Cloud access is constrained by Firebase security rules that deny cross-account reads and client writes to server-owned records; purchases are verified server-side; premium content is delivered through short-lived signed URLs. No system is unbreakable — we do not promise absolute security, we reduce what an attacker could gain.
14. Where data is processed
Cloud services run on Google Cloud with primary processing in the
asia-south1 (Mumbai) region. Some Google services may process data in other
regions under Google's data-processing terms.
15. Changes
We will post changes here with a new version number and effective date. Material changes will be announced in the app before they take effect.