Privacy
Privacy Policy
What jothi.sh collects, why, who else sees it, how long it is kept, and exactly how to get it back or destroy it. The same policy covers the website and the iOS and Android apps.
Last updated: · Version 1.2
1. Who we are, and how to reach us
jothi.sh ("we", "us") is a Vedic astrology service — panchāṅga, birth charts, compatibility, muhūrta and an AI advisor — operated by [[LEGAL ENTITY OR PROPRIETOR NAME — owner to supply]], [[REGISTERED ADDRESS — owner to supply]].
For anything about your data — access, correction, export, erasure, or a complaint — write to [[PRIVACY & SUPPORT EMAIL — owner to supply]]. Grievances in India may be addressed to our grievance contact: [[GRIEVANCE OFFICER NAME AND EMAIL — owner to supply]]. We are the controller of the personal data described here.
Please note the address the app sends mail from (no-reply@mail.jothi.sh, or no-reply@send.semm.ai on our staging site) is not monitored. Use the address above.
2. What this policy covers
One document set covers every way you use jothi.sh: the website, the iOS app and the Android app. They are the same product talking to the same server, so they collect the same things. Where a platform differs — advertising identifiers, app-store billing — it is called out.
This policy is written to be read alongside our Terms & Conditions, which govern the service itself.
3. What we collect, and why
We collect the following, and nothing else:
- Birth details — date, time and place of birth (converted to coordinates and a time zone), plus a label you choose and an optional relationship role. This is the entire input to every calculation. There is no name field for a birth profile: we never ask for one. The label is free text you type, so please do not type a name into it if you would rather we did not hold one.
- Your account — your email address, and nothing more if you sign in with a one-time code. If you sign in with Google or Apple we additionally store the display name and avatar image URL that provider returns, together with the provider's stable identifier for you.
- Your questions to the advisor — the text you type, the answer produced, and the transcript of the conversation. The transcript is saved automatically as you talk, encrypted, so that you can pick the conversation up again; we do not wait for you to ask. You can see the list and delete any of them under Privacy & AI in Preferences.
- Technical and usage data — your IP address, browser or app user-agent, request timings, error status codes and anonymous counters for which screens are reached. IP addresses are used for rate limiting and abuse prevention and are held for at most an hour as part of a counter key; they are not stored alongside your identity or your chart.
- Notification preferences — if you turn on a daily digest or browser push: the push endpoint and the ECDH transport keys your browser generates (or your email), your time zone, preferred hour and language. The app offers no way to turn these on today, so unless you have arranged it with us directly, we hold none of this for you.
- Payment records — if you ever buy a plan: which plan, when, and the reference the payment provider gives us. Card, UPI and bank details never reach our servers.
- Developer API keys — if you create one, we store the name you gave it, a hash of the key (never the key itself) and when it was created and last used, so it can be rate-limited and revoked. No birth data is stored with API requests.
- Advisor feedback you submit — see section 7; it is the one place your question text is stored in the clear.
4. Our legal bases
Under the GDPR (and the equivalent notions in India's DPDP Act) we rely on:
- Contract — to run your account, compute the charts you ask for, and deliver what you paid for.
- Consent — for birth details, for saving a profile about another person, for notifications, and for personalised advertising. You can withdraw any of these at any time; withdrawing does not undo processing already done.
- Legitimate interests — keeping the service up and affordable (rate limits, abuse prevention, aggregate analytics, error diagnostics). We keep this minimal and PII-free by design.
- Legal obligation — tax and accounting records for payments, where the law requires them.
5. How your birth data is protected
- Signed out, nothing leaves your device. The calculation engine runs in your browser as well as on our server, so a chart, panchāṅga or muhūrta computed while you are signed out is computed on your device and saved only in that browser's local storage. It reaches us only if you use the AI advisor or download a PDF report, both of which require an account.
- Saved profiles are encrypted individually. Each profile gets its own random AES-256-GCM key, which encrypts the birth payload; that key is itself stored only in wrapped form, under a key derived from a server secret. Your account identifier is bound into the encryption, so a row copied to another account cannot be decrypted at all.
- Deleting really deletes. Deleting a profile destroys its unique key and leaves an empty tombstone row. Because the key is the only copy, the ciphertext — including in backups — becomes permanently unreadable. The same applies to saved advisor conversations.
- Identity is kept apart from data. Profiles are keyed by an opaque identifier. Reading the database reveals labels and opaque ids and nothing else.
- Operational logs are PII-free. Telemetry passes through a redaction filter and records only route names, durations, status codes and coarse topic categories — never your question, your birth details or your email.
6. When your data goes to an AI
Almost nothing in jothi.sh involves AI. Charts, the panchāṅga, compatibility, muhūrta, the personal-day heatmap and every calculation behind them are produced by our own deterministic engine, which computes and does not guess. Exactly three features send anything to a third-party AI: the Advisor, the written lifetime prediction inside a full report, and the one-line daily note at the top of the home screen.
The first two happen only when you ask for them. The daily note does not. If you are signed in and have a saved chart, it is written when the home screen loads, without you pressing anything — so it is the AI request you are most likely to make without noticing. You can turn it off: see the end of this section.
What we send is a compact block of computed facts derived from the birth details — planetary positions, houses, daśā periods with dates, current transits, and similar — plus, for the advisor, your question (up to 1,000 characters) and up to eight previous turns of that conversation. That block carries no name, no email and no account identifier. It does carry the profile label you chose, so again: please do not put a name in the label.
This is sent over HTTPS to an AI gateway operated at dev.token.semm.ai, which forwards it to DeepSeek models (DeepSeek-V4-Flash for the app; a higher-quality variant for direct API calls). The model is instructed only to narrate the facts we supply — it does not compute your chart.
If you would rather no AI saw anything: do not use the advisor and do not generate a written lifetime prediction, and set the daily note to "Computed only" under Privacy & AI in Preferences. That switch stops the request being made at all. The card stays where it is and still shows your day — the same figures, computed on your own device — it simply is not written up by a model. Nothing else in the product changes.
7. Who else processes your data
We do not sell personal data, ever, and we do not share it for anyone else's marketing. We do use the service providers below. Each is bound by its contract with us to protect your data to at least the standard described in this policy and to process it only on our instructions.
- Cloudflare — hosting, database, object storage, aggregate analytics (Workers Analytics Engine) and outbound email. Effectively everything we store lives here.
- The semm.ai AI gateway and DeepSeek — advisor answers and written predictions, as described in section 6.
- Komoot (Photon) — when you type a place name that is not in our built-in city list, your browser sends the typed text to
photon.komoot.ioto find it. That request carries the text you typed and your IP address, and nothing else. Time-zone lookup happens offline on your device. - Google Fonts — every page loads typefaces from
fonts.googleapis.comandfonts.gstatic.com, which discloses your IP address and browser to Google on each page view, including before you sign in. - Your browser or device vendor's push service (for example Google's FCM or Apple's APNs) — only if you turn on push notifications.
- Google AdSense and Google AdMob — only on the free tier, and only where advertising is switched on. See section 8.
- Razorpay and Stripe — only if you buy a plan; they receive your email address and the amount. They are the ones handling your card or UPI details, not us.
- Zoho CRM — account lifecycle records only: your email, a display name, which sign-in method you used, dated notes such as "signed up" or "generated a report", and — if you buy a plan — which plan you bought and the amount, the same commercial facts the payment provider already holds. No birth data, chart, question or answer is ever sent to it. While this connection is switched off, nothing about you is sent or queued for it. When it is on, deleting your account also deletes the records there — including the queue of updates waiting to be sent, which holds your email address.
- Advisor feedback and model improvement. If you press 👍 or 👎 on an advisor answer, we store your question, that answer, and the computed chart facts that produced it — in the clear, filed under a one-way hash of your account id rather than your email. We use this to find bad answers and to improve our models, including as training examples. Deleting your account deletes these records. One honest limitation: if we have already converted a record into a training example, that copy carries no link back to you and cannot be found again. If you would rather not contribute, do not use the feedback buttons.
- We also hold a small research library of the birth and death dates of well-known public figures, drawn from published sources and Wikidata, used only internally to test the accuracy of our timing calculations. It contains no user data.
8. Advertising
jothi.sh has an ad-supported free tier. Paid plans carry no advertising at all — that is what you are paying for. Advertising is currently switched off everywhere; this section describes what happens when it is on.
- Your birth data is never used for advertising. Not your chart, not your questions, not your saved profiles, not your birth place. This is enforced in code: the advertising modules cannot read any of it.
- Ads are non-personalised unless you opt in. No advertising code loads at all until you have answered the consent question, and dismissing that question without answering leaves advertising off. If you decline, ads still appear but are not personalised.
- What the ad networks see regardless — Google receives your IP address, your device or browser information, and which page the ad is on, as any ad network does.
- Rewarded ads. Watching an optional ad can grant one extra advisor question. The grant only happens when Google's advertising servers send us a cryptographically signed confirmation that you actually watched it, capped at three per day.
- Changing your mind. Personalised advertising is a control under Privacy & AI in Preferences, and you can switch it back at any time — withdrawing is exactly as easy as giving it, which is what the law requires and what we would want anyway. The choice lives on your device, so clearing your browser or app storage also resets it and we will ask again.
9. How long we keep things
- Saved profiles — until you delete them, or delete your account.
- Saved advisor conversations — saved automatically as you talk, then kept until you delete them under Privacy & AI in Preferences, or delete your account.
- Sign-in sessions — 30 days, then automatically removed. One-time email codes expire in 10 minutes.
- Advisor answers (cache) — up to 24 hours. Written lifetime predictions (cache) — up to 30 days. The daily note (cache) — to the end of that day. All three are stored against your account and are deleted when you delete it.
- Report PDFs — cached in object storage so a repeat download is instant, and kept until you delete your account, which removes them. Each PDF contains the full computed chart.
- Operational telemetry — 30 days.
- Advisor feedback — until you delete your account, subject to the limitation in section 7.
- Notification subscriptions — until you unsubscribe, or 30 days after your browser tells us the subscription is dead.
- Payment records — removed when you delete your account, except where tax law requires us to keep a record.
- The tamper-evidence log. We keep an append-only, hash-chained log of profile actions — the fact that a profile with a given opaque id was created or deleted, and when. It holds no birth details, no email and no location, and it survives account deletion, because a chain with a hole in it can no longer prove it has not been tampered with. This is the one exception to "deleting your account removes everything", and we would rather state it than let you discover it.
10. Your rights, and exactly where to exercise them
You have the right to access, correct, export, and erase your personal data, to restrict or object to processing, and to withdraw consent. We honour these for everyone, wherever you are. You will never be charged or treated differently for using them.
- See and correct — your saved profiles are on the home screen; open one and edit it.
- Export everything — "Export my data" on the home screen or in Preferences downloads all your profiles as a file.
- Delete one chart — the delete control on that profile destroys its encryption key immediately.
- Delete one conversation — the list under Privacy & AI in Preferences. Deleting destroys that conversation's own key, exactly as for a chart.
- Delete your whole account — "Delete account" on the home screen or in Preferences. It works the same in the apps and on the website. There is also a public page at /delete-account for when you cannot sign in.
- Withdraw consent — the automatic daily AI note and personalised advertising each have a control under Privacy & AI in Preferences, and either can be switched back as easily as it was switched on. For everything else, delete the relevant data. Notifications are not something the app can turn on yet, so there is nothing to withdraw there.
- Complain — write to us first at [[PRIVACY & SUPPORT EMAIL — owner to supply]]. If we do not resolve it, you may complain to your data-protection supervisory authority in the EU or UK, or to the Data Protection Board of India.
11. Children and minors
jothi.sh is for adults. You must be old enough to enter a contract where you live — generally 18 — to hold an account.
People do save charts for children, and the honest position is this: when the birth date you enter indicates the person is under 18, we ask you to confirm that you are their parent or legal guardian, or that you have a guardian's consent. That confirmation is a declaration by you; we do not independently verify it, and we do not knowingly collect data directly from children.
We do not build advertising profiles of children and we never use birth data for advertising at all. You can destroy a minor's profile at any time using the same one-click erasure as any other profile.
If you believe a child's data has been given to us without a guardian's consent, write to [[PRIVACY & SUPPORT EMAIL — owner to supply]] and we will delete it.
12. Where your data goes
We are operated from India and our infrastructure is global. Your data is processed on Cloudflare's worldwide network and by the providers named in section 7, which means it may be handled in countries other than your own, including outside the EEA, the UK and India.
Where personal data leaves the EEA or the UK we rely on our providers' standard contractual clauses and equivalent safeguards. Birth details travel only as ciphertext, or as the compact computed block described in section 6.
13. What is stored on your device
We use no advertising or tracking cookies, and no analytics cookies. What we do store in your browser's local storage — or, in the apps, in the platform's own preferences store so that the operating system cannot silently discard it — is:
- your saved birth profiles and which one is active;
- your display and calculation preferences, language, theme and country;
- your advertising choice;
- in the apps only, your sign-in token;
- a short-lived copy of your sign-in state, to avoid re-asking the server on every page.
14. Changes to this policy
If we change this policy in a way that materially affects you, we will say so in the app and update the version and date at the top. Continuing to use jothi.sh after that means you accept the updated policy. Previous versions are available on request.