Privacy Policy

Last Updated: March 27, 2026 | Compliant with Digital Personal Data Protection Act, 2023

1. Data Controller

GrahAI ("Platform", "we", "us") is operated by Rahul Dubey (Sole Proprietor), Choodasandra, Bangalore 560035, Karnataka, India. We are the data fiduciary responsible for your personal data under the Digital Personal Data Protection Act, 2023 (DPDP Act).

2. Data We Collect

Personal Information (provided by you):

  • Name, email address
  • Phone number (optional)
  • Gender (optional)
  • Date of birth, time of birth, place of birth
  • Marital status, primary concern (optional)

Payment Information:

  • Processed securely by Razorpay. We do NOT store credit/debit card numbers or banking details.
  • We retain: transaction ID, plan purchased, amount, date for our records.

Usage Data (collected automatically):

  • Pages visited, features used, time spent
  • Device type, browser, screen size
  • IP address, approximate location
  • Referral source (how you found us)

Cookies & Tracking:

  • Google Analytics (website analytics)
  • Microsoft Clarity (session recordings & heatmaps)
  • Google Ads (conversion tracking)
  • Firebase Analytics (app usage)

3. Purpose of Data Collection

We collect and process your data for:

  • Service delivery: Generate Kundli, reports, predictions, matching results
  • AI processing: Birth data is sent to Google Gemini AI to generate personalized astrological interpretations
  • Payment processing: Complete transactions via Razorpay
  • Communication: Send service-related emails (welcome, receipts, notifications)
  • Analytics: Improve platform experience, understand usage patterns
  • Advertising: Measure ad campaign effectiveness (Google Ads conversion tracking)

4. Legal Basis

We process your data based on your consent as defined under the DPDP Act, 2023. By creating an account or using our services, you consent to the collection and processing described in this policy. You may withdraw consent at any time (see Section 8).

5. Data Sharing

We share your data with the following third parties, solely for the purposes described:

Service ProviderPurposeData Shared
Firebase (Google Cloud)Data storage, authenticationAll account data
Google Gemini AIAI prediction generationBirth details, questions
RazorpayPayment processingEmail, name, amount
ResendEmail deliveryEmail, name
Google AnalyticsWebsite analyticsUsage data, device info
Microsoft ClaritySession analyticsUsage patterns, clicks
Google AdsConversion trackingConversion events

We do NOT sell your personal data to third parties.

6. Data Retention

  • Active accounts: Data retained while your account exists
  • Inactive accounts: Data purged after 3 years of inactivity
  • Payment records: Retained for 8 years (tax/legal compliance)
  • Analytics data: Aggregated and anonymized after 26 months

7. Cross-Border Data Transfer

Your data may be processed on Google Cloud and other service provider servers located outside India (primarily United States and Singapore). Under the DPDP Act, 2023, cross-border transfers are permitted unless the Indian government restricts transfers to specific countries. As of the date of this policy, no such restrictions apply to our service providers.

8. Your Rights (DPDP Act, 2023)

As a data principal, you have the right to:

  • Access: Request a summary of your personal data we hold
  • Correction: Request correction of inaccurate or incomplete data
  • Erasure: Request deletion of your account and all personal data
  • Withdraw consent: Withdraw consent for data processing at any time
  • Nominate: Nominate a person to exercise your rights in case of death or incapacity
  • Grievance: File a complaint with our Grievance Officer

To exercise any of these rights, email: grievance@grahai.com

9. Data Deletion

You may request deletion of your account and all associated personal data by emailing grievance@grahai.com. Data deletion will be processed within 30 days of verified request. Note: we may retain payment records as required by tax law.

10. Data Security

We implement industry-standard security measures including: HTTPS encryption for all data transmission, Firebase Security Rules for database access control, secure authentication via Firebase Auth, and regular security reviews. However, no method of electronic transmission or storage is 100% secure.

11. Children's Privacy

GrahAI is intended for users aged 18 and above. We do not knowingly collect personal data from individuals under 18 years of age. If we become aware of such collection, we will promptly delete the data.

12. Cookies

We use cookies and similar technologies for analytics, advertising measurement, and platform functionality. You can manage cookie preferences through your browser settings. Disabling cookies may affect certain platform features.

13. Data Breach Notification

In the event of a personal data breach, we will notify the Data Protection Board of India and affected users within 72 hours of becoming aware of the breach, as required by the DPDP Act, 2023.

14. Grievance Officer

Name: Rahul Dubey

Email: grievance@grahai.com

Address: Choodasandra, Bangalore 560035, Karnataka, India

Complaints will be acknowledged within 24 hours and resolved within 15 days.

15. Changes to This Policy

We may update this Privacy Policy periodically. Changes will be posted on this page with an updated "Last Updated" date. We encourage you to review this policy regularly.

16. Contact

For questions about this Privacy Policy: support@grahai.com