1. Scope and effective date

This policy applies to the Cosmic Quest Android app (com.cosmicquest.android) and cosmicquest.in from 2026-08-28.

2. Who controls the data

Cosmic Quest (proposed Cosmic Quest LLP; registration pending), trading as Cosmic Quest, operates from Bommanahalli PO, Bengaluru, Karnataka, India. Organisation status: Proposed limited liability partnership (registration pending). Registration: Not yet issued; LLP registration is pending.

3. Core privacy approach

Core chart calculations are local by default. Online data processing occurs only for the cloud or connected feature identified below.

4. Data that remains on-device

5. Data collected or stored for online features

FeatureDataPurpose
Optional online accountFirebase UID, provider, email or phone when supplied, anonymous identity, session metadataAuthentication and session security
Cloud restoreencrypted profile backup ciphertext, backup metadataRestore on another device
AI guidancemessages, minimum chart context, usage counters, provider request metadataGenerate response and enforce limits
Product measurementconsent-gated product events, app/device pseudonymous identifiersProduct analytics
Reliabilitystack traces, device/app state, native crash diagnostics, possible pseudonymous installation IDDiagnose crashes
Optional server notificationsFCM registration token, notification preferences, installation/account linkDeliver requested notifications
Astrologer marketplacesession records, chat messages, reviews, reports, block recordsRun chat consultations and safety workflows
Provider onboardingapplication, identity/compliance documents, provider images, payout recordsVerify and administer providers
Research platformprofile, posts, messages, spaces, courses, submissions, publications, reputation, consent grants, donated charts, access auditCommunity, education, publication and consent-scoped research
Paid access and CosmicCashpurchase token submitted for verification, token hash/encrypted server material, entitlements, subscription status, wallet ledger, referral code/rewardsVerify purchases, grant access, prevent replay/fraud, operate rewards
Physical storeorder, amount/status, shipping contact/address, fulfilment events, tax/accounting recordOrder preparation, support, accounting, and future fulfilment
Security and safetyApp Check signals, server logs, audit events, moderation/safety cases, deleted-account tombstone referencesPrevent abuse, audit sensitive operations, enforce safety

6. Account and authentication data

Firebase UID, provider, email or phone when supplied, anonymous identity, session metadata.

7. Birth, chart and astrology data

local by default; optional backup/donation paths separate. Optional backup and research donation are separate choices.

8. Device permissions and sensor data

PermissionUseControl
CAMERAVastu/Trail AR and user-chosen synchronicity capture; video consultations are disabledDeny permission or leave feature
RECORD_AUDIOAudio/video consultation capability declared but disabled in the current releaseDeny permission or leave feature
ACCESS_COARSE_LOCATIONBirthplace prefill, question moment, trailsDeny and enter place manually
ACCESS_FINE_LOCATIONPrecise birthplace, sky and AR/trailsChoose approximate/deny
READ_CALENDARLife Archive calendar importDeny/skip import
READ_MEDIA_IMAGESLife Archive media importDeny/skip import
READ_MEDIA_AUDIOLife Archive audio importDeny/skip import
READ_EXTERNAL_STORAGELegacy Android media import through API 32Deny/skip
POST_NOTIFICATIONSPanchanga, mission, trail, consultation and FCM notificationsOS/app notification controls
RECEIVE_BOOT_COMPLETEDRestore user-scheduled local remindersDisable reminders
health.READ_STEPSOptional Health Connect mission signal (full flavor)Health Connect permission manager
health.READ_SLEEPOptional Health Connect mission signal (full flavor)Health Connect permission manager

9. Health Connect data

Optional mission progress signal. No durable storage verified in audited provider.

10. Analytics, diagnostics and crash reporting

Analytics default: disabled. Crash reporting: Enabled in release builds through Firebase Crashlytics; disabled in debug and offline builds. Crashlytics retains covered diagnostics for 90 days before removal begins.

11. Notifications and FCM tokens

Token and registration mappings are removed within 30 days after unregister or account deletion.

12. AI features and provider processing

Active providers: OpenAI API (gpt-4o-mini). Messages and minimum feature context are processed to answer the request.

13. Marketplace, consultation and KYC data

RTC providers: None in the current release. KYC providers: Google Firebase Storage with manual review by Cosmic Quest. Recording: No; consultation recording is disabled and no RTC provider is configured.

14. Community, courses and research data

Profiles and consents are deleted within 30 days; surviving published content is unlinked and chart-donation access is revoked immediately.

15. Research chart donations and consent

Research donation is optional and consent-scoped. The applicable retention and withdrawal behavior appears in the schedule below.

16. Payments, subscriptions, wallet and referrals

Payment providers: Google Play Billing for digital purchases. Google Play subscription cancellation remains a separate user action.

17. Store orders, shipping and tax records

Fulfilment providers: None in the current release. Statutory records follow the verified schedule below.

18. Service providers and processors

ProviderStatusData
google-firebaseVERIFIED_ACTIVEaccount_auth, encrypted_backup, ai_conversation, analytics, crash_diagnostics, notification_installation, consultation_marketplace, provider_kyc, research_community, billing_wallet_referral, store_order, security_abuse
google-playVERIFIED_ACTIVEbilling_wallet_referral
android-health-connectVERIFIED_OPTIONALhealth_connect
ai-providerOWNER_VERIFIEDai_conversation
rtc-media-providerNOT_USED_IN_CURRENT_RELEASEconsultation_marketplace
kyc-verification-providerOWNER_VERIFIEDprovider_kyc
payment-providerOWNER_VERIFIEDbilling_wallet_referral, store_order
fulfilment-providerNOT_USED_IN_CURRENT_RELEASEstore_order

19. Purpose and applicable processing basis

FeaturePurposeBasis
Core astrologyCalculate and save chartsUser-requested core function
Optional online accountAuthentication and session securityUser-requested account and service security
Cloud restoreRestore on another deviceExplicit user action to provide cloud restore
AI guidanceGenerate response and enforce limitsUser-requested optional AI feature
Product measurementProduct analyticsUser consent, which can be withdrawn in settings
ReliabilityDiagnose crashesService reliability and security
Optional server notificationsDeliver requested notificationsNotification permission and feature choice
Mission signalOptional mission progress signalExplicit Health Connect permission
Astrologer marketplaceRun chat consultations and safety workflowsUser-requested optional consultation service and safety obligations
Provider onboardingVerify and administer providersProvider application, compliance, fraud prevention, and contractual steps
Research platformCommunity, education, publication and consent-scoped researchExplicit donation, participation, or publication action
Paid access and CosmicCashVerify purchases, grant access, prevent replay/fraud, operate rewardsPerformance of the chosen purchase, fraud prevention, and legal obligations
Physical storeOrder preparation, support, accounting, and future fulfilmentUser-requested order preparation and legal obligations
Security and safetyPrevent abuse, audit sensitive operations, enforce safetyService security, fraud prevention, safety, and legal obligations

20. Data sharing and disclosures

Sharing is limited to the processors and recipients mapped above, user-directed publication, and disclosures required by verified law.

21. International or other-region processing

Functions: asia-south1 (Mumbai, India); Firestore: asia-south1 (Mumbai, India); Storage: US-EAST1 (primary Firebase Storage bucket), asia-south1 (Cloud Functions build and source buckets).

22. Retention schedule

CategoryTrigger or periodDeletionException
local_birth_chartUntil user deletes local profile/app dataLocal delete/clear/uninstall; cloud deletion does not wipe deviceNone verified beyond the stated trigger
account_authauthentication: Until account deletion; the Firebase Authentication record is deleted at the end of the deletion pipeline within 30 days.Deletion pipeline removes the Authentication account within 30 days after mandatory data tasksNone verified beyond the stated trigger
encrypted_backupencryptedBackups: Until the user deletes the backup or account; deletion is completed within 30 days and recovery copies expire with the stated 7-day provider windows.Storage prefix deleted within 30 days by the account-deletion pipeline; 7-day soft-delete recovery window appliesNone verified beyond the stated trigger
ai_conversationaiConversations: Until the user deletes the conversation or account; Cosmic Quest copies are deleted within 30 days. OpenAI may retain API inputs and outputs for up to 30 days for service and abuse monitoring unless law requires longer.Firestore history is deleted within 30 days; OpenAI API inputs and outputs may be retained for up to 30 daysFirestore history is deleted within 30 days; OpenAI API inputs and outputs may be retained for up to 30 days
analyticsanalytics: Disabled by default. If the user opts in, account-linked deletion requests are processed within 30 days where supported; Google Analytics event-level retention uses Google's available 2-month minimum for standard properties.Collection stops when consent is withdrawn; linked deletion requests are submitted where supported and provider retention appliesNone verified beyond the stated trigger
crash_diagnosticscrashReports: Firebase Crashlytics retains crash diagnostics for 90 days before removal from live and backup systems begins.Crashlytics retains covered diagnostics for 90 days before removal beginsCrashlytics retains covered diagnostics for 90 days before removal begins
notification_installationnotificationTokens: Until notifications are disabled, the installation is unregistered, or the account is deleted; removal is completed within 30 days.Token and registration mappings are removed within 30 days after unregister or account deletionNone verified beyond the stated trigger
health_connectNo durable storage verified in audited providerRevoke permission or delete the source record in Health ConnectNone verified beyond the stated trigger
consultation_marketplacemarketplaceMessages: Until the consultation/account is deleted; deletion or pseudonymisation is completed within 30 days unless a dispute, safety case, payment record, or legal hold applies. consultationRecords: Until the consultation/account is deleted; deletion or pseudonymisation is completed within 30 days unless a dispute, safety case, payment record, or legal hold applies.Deletion or pseudonymisation is completed within 30 days unless a dispute, safety, payment, or legal exception appliesNone verified beyond the stated trigger
provider_kycKycRecords: Until the provider application or relationship ends; deletion is completed within 30 days unless identity, payout, fraud, dispute, or legal-retention duties require longer.Storage prefixes are deleted within 30 days unless identity, payout, fraud, dispute, or legal duties require longerNone verified beyond the stated trigger
research_communityresearchCommunity: Until the user deletes the content/account; deletion or pseudonymisation is completed within 30 days. Public research already published may remain without account-identifying authorship. donatedChartData: Until consent is withdrawn or the account is deleted; access is revoked immediately and deletion is completed within 30 days, except already aggregated or de-identified research results.Profiles and consents are deleted within 30 days; surviving published content is unlinked and chart-donation access is revoked immediatelyProfiles and consents are deleted within 30 days; surviving published content is unlinked and chart-donation access is revoked immediately
billing_wallet_referralbillingEntitlements: For the subscription or entitlement lifecycle; account linkage is removed within 30 days after deletion, subject to tax, accounting, fraud, refund, and dispute records. purchaseTokenHashes: Account linkage is removed within 30 days after deletion; irreversible anti-replay hashes may remain without profile data to prevent duplicate credit and fraud.Account linkage is removed within 30 days; irreversible anti-replay hashes and legally required transaction records may remainNone verified beyond the stated trigger
store_orderstoreOrders: No physical-goods payment or fulfilment provider is active. If an order record exists, account linkage is removed within 30 days; a minimised transaction record may remain for tax, accounting, refund, and dispute duties. shippingDetails: Deleted or stripped from retained order records within 30 days after fulfilment or account deletion unless an active delivery, return, dispute, or legal obligation requires temporary retention. taxAccountingRecords: When GST recordkeeping applies, 72 months from the due date of the annual return, or longer where a proceeding or investigation requires it; retained records are minimised and pseudonymised where possible.Shipping identity is stripped within 30 days; minimised transaction records follow the verified statutory scheduleNone verified beyond the stated trigger
security_abusesecurityLogs: 30 days from collection unless needed for an active security investigation, fraud prevention, dispute, or legal obligation; retained records are access-restricted and account references are pseudonymised on deletion. moderationSafetyCases: Reviewed after 30 days and retained only while needed for an active safety, abuse, dispute, or legal purpose; account references are pseudonymised on deletion where possible. deletedAccountTombstones: Account-linked deletion status is retained for up to 30 days; irreversible anti-replay or security markers may remain without profile data.Ordinary logs follow 30-day retention; active cases and pseudonymised anti-replay or audit records may remain for the documented exceptionOrdinary logs follow 30-day retention; active cases and pseudonymised anti-replay or audit records may remain for the documented exception

23. Security

Cosmic Quest uses platform access controls, transport encryption, Firebase Security Rules, App Check where configured, and deletion audit state. No system can guarantee absolute security.

24. Account deletion and processor deletion

Use the app or the external deletion route. The retention table distinguishes deletion, unlinking, exceptions and processor behavior.

25. Access, correction, erasure, withdrawal and grievance rights

Contact contact@cosmicquest.in for rights requests and Email contact@cosmicquest.in with the subject Privacy or Grievance for grievances. Identity verification may be required.

26. Children and minimum age

Minimum age: 18 years. Cosmic Quest is for adults and does not permit accounts or services for anyone under 18. Parental-consent implementation: Not applicable because users under 18 are not permitted.

27. Changes to this policy

Material changes will update the version, date and change log and will be communicated through an appropriate product channel.

28. Contact and grievance process

Sourik Ganguly, Director
contact@cosmicquest.in
Sourik Ganguly, Cosmic Quest, Bommanahalli PO, Bengaluru, Karnataka, India

Change log

Version 1.0 — initial owner-approved publication, reviewed by Sourik Ganguly (Director).