Privacy Policy
Last Updated: March 27, 2026 | Compliant with Digital Personal Data Protection Act, 2023
1. Data Controller
GrahAI ("Platform", "we", "us") is operated by Rahul Dubey (Sole Proprietor), Choodasandra, Bangalore 560035, Karnataka, India. We are the data fiduciary responsible for your personal data under the Digital Personal Data Protection Act, 2023 (DPDP Act).
2. Data We Collect
Personal Information (provided by you):
- Name, email address
- Phone number (optional)
- Gender (optional)
- Date of birth, time of birth, place of birth
- Marital status, primary concern (optional)
Payment Information:
- Processed securely by Razorpay. We do NOT store credit/debit card numbers or banking details.
- We retain: transaction ID, plan purchased, amount, date for our records.
Usage Data (collected automatically):
- Pages visited, features used, time spent
- Device type, browser, screen size
- IP address, approximate location
- Referral source (how you found us)
Cookies & Tracking:
- Google Analytics (website analytics)
- Microsoft Clarity (session recordings & heatmaps)
- Google Ads (conversion tracking)
- Firebase Analytics (app usage)
3. Purpose of Data Collection
We collect and process your data for:
- Service delivery: Generate Kundli, reports, predictions, matching results
- AI processing: Birth data is sent to Google Gemini AI to generate personalized astrological interpretations
- Payment processing: Complete transactions via Razorpay
- Communication: Send service-related emails (welcome, receipts, notifications)
- Analytics: Improve platform experience, understand usage patterns
- Advertising: Measure ad campaign effectiveness (Google Ads conversion tracking)
4. Legal Basis
We process your data based on your consent as defined under the DPDP Act, 2023. By creating an account or using our services, you consent to the collection and processing described in this policy. You may withdraw consent at any time (see Section 8).
5. Data Sharing
We share your data with the following third parties, solely for the purposes described:
| Service Provider | Purpose | Data Shared |
|---|---|---|
| Firebase (Google Cloud) | Data storage, authentication | All account data |
| Google Gemini AI | AI prediction generation | Birth details, questions |
| Razorpay | Payment processing | Email, name, amount |
| Resend | Email delivery | Email, name |
| Google Analytics | Website analytics | Usage data, device info |
| Microsoft Clarity | Session analytics | Usage patterns, clicks |
| Google Ads | Conversion tracking | Conversion events |
We do NOT sell your personal data to third parties.
6. Data Retention
- Active accounts: Data retained while your account exists
- Inactive accounts: Data purged after 3 years of inactivity
- Payment records: Retained for 8 years (tax/legal compliance)
- Analytics data: Aggregated and anonymized after 26 months
7. Cross-Border Data Transfer
Your data may be processed on Google Cloud and other service provider servers located outside India (primarily United States and Singapore). Under the DPDP Act, 2023, cross-border transfers are permitted unless the Indian government restricts transfers to specific countries. As of the date of this policy, no such restrictions apply to our service providers.
8. Your Rights (DPDP Act, 2023)
As a data principal, you have the right to:
- Access: Request a summary of your personal data we hold
- Correction: Request correction of inaccurate or incomplete data
- Erasure: Request deletion of your account and all personal data
- Withdraw consent: Withdraw consent for data processing at any time
- Nominate: Nominate a person to exercise your rights in case of death or incapacity
- Grievance: File a complaint with our Grievance Officer
To exercise any of these rights, email: grievance@grahai.com
9. Data Deletion
You may request deletion of your account and all associated personal data by emailing grievance@grahai.com. Data deletion will be processed within 30 days of verified request. Note: we may retain payment records as required by tax law.
10. Data Security
We implement industry-standard security measures including: HTTPS encryption for all data transmission, Firebase Security Rules for database access control, secure authentication via Firebase Auth, and regular security reviews. However, no method of electronic transmission or storage is 100% secure.
11. Children's Privacy
GrahAI is intended for users aged 18 and above. We do not knowingly collect personal data from individuals under 18 years of age. If we become aware of such collection, we will promptly delete the data.
12. Cookies
We use cookies and similar technologies for analytics, advertising measurement, and platform functionality. You can manage cookie preferences through your browser settings. Disabling cookies may affect certain platform features.
13. Data Breach Notification
In the event of a personal data breach, we will notify the Data Protection Board of India and affected users within 72 hours of becoming aware of the breach, as required by the DPDP Act, 2023.
14. Grievance Officer
Name: Rahul Dubey
Email: grievance@grahai.com
Address: Choodasandra, Bangalore 560035, Karnataka, India
Complaints will be acknowledged within 24 hours and resolved within 15 days.
15. Changes to This Policy
We may update this Privacy Policy periodically. Changes will be posted on this page with an updated "Last Updated" date. We encourage you to review this policy regularly.
16. Contact
For questions about this Privacy Policy: support@grahai.com