Skip to main content
Privacy Policy

Privacy Policy

Last updated: June 1, 2026

Welcome to Astra Mitra. Your privacy is of paramount importance to us. This Privacy Policy explains how Veriscribe Analytics & AI Pvt. Ltd. ("we", "us", or "our") collects, uses, discloses, and safeguards your personal data when you use our services, in strict compliance with the Digital Personal Data Protection (DPDP) Act, 2023 of India and other global standards.

Please read this policy carefully. By registering for or using Astra Mitra, you provide your explicit, unambiguous, and revocable consent to the collection and processing of your personal data as described herein.


1. Personal Data We Collect

To provide highly personalized Vedic astrological insights, birth charts (Kundli), and horoscope matching, we collect the following personal data with your direct consent:

  • Identity & Account Details: Name, email address, password, gender, marital status, and occupation.
  • Astrological Blueprints (Critical Data): Date of birth, time of birth, and place of birth. These are essential for calculating precise astronomical degrees and houses.
  • Communication Details: Phone number and metadata relating to customer support requests.

2. Purposes of Data Processing

We process your data strictly for specified, lawful purposes associated with our platform services:

  • Generating precise Vedic birth charts (Kundli) and compatibility readings.
  • Powering our interactive AI Astrologer Chat (Navi, Arya, Meera, Anand, Rishi) to answer queries.
  • Delivering daily horoscope notifications and planetary transit alerts.
  • Processing payments and managing premium subscription services.

3. Legal Basis for Processing & Consent

Under India's DPDP Act 2023, the sole legal basis for processing your personal data is your freely given, specific, informed, unconditional, and unambiguous consent. You confirm this consent by checking our consent box during signup.

Right to Withdraw Consent: You have the right to withdraw your consent at any time. Withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal. To withdraw your consent, you may delete your account.

4. Data Storage, Sharing & Transfer

Your personal data is encrypted in transit and at rest. We do not sell your personal data. We share only necessary, minimized data with trusted third-party subprocessors under strict data privacy agreements:

  • AI / LLM Providers: To respond to your chats. We redact direct identifier details where feasible.
  • Payment Gateways: To securely process transactions. We do not store full credit card details.
  • Database Hosting: Secure cloud environments in compliant locations.

4a. Cookies & Local Storage

Astra Mitra uses cookies and browser local storage for essential platform functionality. We do not use third-party tracking cookies or advertising networks. Here is exactly what is stored on your device:

  • Session Cookie (auth.js.session-token): Maintains your secure login session. Expires after 30 days of inactivity. Essential.
  • Theme Cookie: Remembers your light/dark mode preference. Purely functional.
  • Language Cookie (NEXT_LOCALE): Remembers your preferred language. Purely functional.
  • Consent Cookie (astra_mitra_cookie_consent): Records your cookie and privacy preferences. Essential for DPDP compliance.
  • Local Storage: Stores UI state such as chat avatar selection, pending messages, and toast notifications. No personal data is persisted here beyond your session.

You can manage non-essential cookie preferences at any time via the cookie consent banner or the Privacy Settings page.


5. Your Legal Rights (Data Principal Rights)

Under data protection regulations, you hold the following rights:

  • Right to Access & Summary: Access details of the personal data we hold about you.
  • Right to Correction & Update: Modify your personal profile or astrological configurations.
  • Right to Erasure (Right to be Forgotten): You have the right to have all your personal data deleted from our systems. You can trigger this instantly by navigating to your Profile Security (Danger Zone) and selecting "Delete Account".

6. Children's Data (18+ Age Restriction)

In compliance with DPDP rules governing children's data, Astra Mitra does not offer services to, or knowingly collect personal data from, individuals under the age of 18. An age validation gate is active during registration. If we learn we have collected data from a child under 18 without parental consent, we will delete it immediately.

7. Data Retention Schedule

We retain personal data only as long as necessary for the specific purpose it was collected. Below is our retention schedule per data category:

  • Account & Profile Data: Retained for the lifetime of your account. Upon deletion, erased or irreversibly anonymized within 30 days.
  • Birth Chart & Astrological Data: Retained while your account is active. Deleted alongside your account within 30 days of deletion request.
  • Chat & Consultation History: Retained while your account is active. Deleted within 30 days of account deletion.
  • Payment & Transaction Records: Retained for 7 years as required by Indian tax and financial regulations (Income Tax Act, 1961; Companies Act, 2013), even after account deletion.
  • Consent Records (Audit Log): Retained for 5 years after consent withdrawal or account deletion for legal compliance under the DPDP Act, 2023.
  • Authentication Logs & OTP Records: Retained for 90 days for security and fraud prevention.

In accordance with the DPDP Rules 2025, Rule 8, we provide 48 hours prior notice before erasing data due to account inactivity. Data in encrypted backups may take up to an additional 60 days to be fully purged.


7a. Data Breach Response Commitment

In the event of a personal data breach, Astra Mitra is committed to the following response timeline, in compliance with the DPDP Rules, 2025 (Rule 7) and CERT-In guidelines:

  • Immediate Intimation: The Data Protection Board of India (DPBI) will be notified immediately upon becoming aware of a breach.
  • Detailed Report (within 72 hours): A comprehensive incident report — including the nature of the breach, categories of affected data, number of affected Data Principals, containment measures taken, and remedial actions — will be submitted to the DPBI within 72 hours.
  • Affected User Notification (without delay): Affected Data Principals will be notified directly via email without undue delay, with clear guidance on protective measures they should take.
  • CERT-In Reporting (within 6 hours): For incidents qualifying under CERT-In guidelines, a separate notification will be filed within the mandated 6-hour window.

We maintain a documented incident response plan, conduct regular security drills, and employ AES-256 encryption for data at rest and TLS 1.3 for data in transit. Security safeguards are reviewed quarterly.

8. Grievance Redressal & Contact

If you have any questions, concerns, or grievances regarding this Privacy Policy or your personal data processing, you may reach out to our designated Grievance Officer:

Grievance Officer: Data Protection Officer

Address/Jurisdiction: Gurugram, Haryana, India

Email: contact@veriscribeanalytics.com