Who we are
Vedic Rishi Astro Solutions Pvt Ltd, trading as AstrologyAPI, provides the services at AstrologyAPI.com. In this Policy, “we”, “us” and “our” refer to that company.
Our registered office is D-3/60, SVP Nagar, Versova MHADA, Andheri-West, Mumbai - 400053, Maharashtra, India. For privacy questions or requests, email mail@astrologyapi.com or write to this address, marking your correspondence “Privacy”.
Scope and our role
This Policy explains how we handle personal information for our website, accounts, billing, sales, support and other activities whose purposes we determine.
We also process information submitted through customers' applications to deliver API, report, image and conversational services. Where we do so solely on a customer's documented instructions, we act as a processor, or as a subprocessor where the customer itself acts as a processor. The customer's privacy notice and the applicable service agreement, including any executed Data Processing Agreement, govern that relationship.
If you use a customer's website or application, contact that operator about its own collection and use of your information. This Policy does not cover its independent systems or replace its privacy notice.
Information we handle
| Category | Examples and sources |
|---|---|
| Account information | Your name, email address, login and account identifiers, and information you or your account administrator provide when using the account. |
| Billing and transactions | Billing name and address, tax details where supplied, purchases, subscription information and payment status associated with your account. |
| Communications | Information you choose to include in emails, sales enquiries, support conversations and feedback. |
| Website and usage information | Browser and device information, page interactions, identifiers and information associated with cookies, analytics and support tools. JSON API records retain API identity and success/failure status, not submitted user details. |
| Service inputs and outputs | Depending on the feature: birth details, location or coordinates, names or profile identifiers, palm or face images or image URLs, floor plans, questions, conversation context, generated readings and reports. These may come from you or from a customer's application. |
Please provide only what is necessary. Free-text questions, images and floor plans can contain information beyond the fields a service asks for. Avoid including unrelated individuals, identity documents, account secrets or unnecessary sensitive information.
Why we use information
We use account and business information to provide and administer accounts, manage subscriptions and payments, respond to requests and support customers. We use website and operational information to understand website use, troubleshoot services and protect against misuse. We also use relevant information to comply with legal obligations and establish, exercise or defend legal claims.
For processing to which the GDPR or UK GDPR applies, the basis depends on the activity and relationship:
- Contract: information necessary to provide the services you request as an individual contracting with us, or to take steps at your request before entering a contract.
- Legitimate interests: administering business customer relationships, responding to business enquiries, securing services and addressing legal claims, subject to the applicable assessment of your rights and interests.
- Legal obligations: records and disclosures required by applicable law, including relevant tax and accounting requirements.
- Consent: activities for which applicable law requires consent. You may withdraw consent without affecting processing that was lawful before withdrawal.
These bases for our own activities do not give us permission to use customer-submitted service data for unrelated purposes. Customers are responsible for establishing the lawful basis for the processing they instruct us to perform. Contact us to ask about the basis for a particular activity, object to relevant processing or withdraw consent.
Information needed to create an account, process a payment or run a requested feature must be supplied for that activity to work. Optional information in enquiries or feedback is your choice. A product's required inputs are described in its interface or API documentation.
API, report and AI data
For JSON APIs, we do not retain submitted user details. We retain which API was called and whether it succeeded or failed.
Generated PDF reports are kept for three months and can be deleted earlier on request. AI chat, palm, face and Vastu data are permanently deleted after approximately thirty days, including originals and backups held by AstrologyAPI. The thirty-day period is approximate rather than a fixed deletion deadline.
We never train models on user data. Our AI services use multiple providers, mainly OpenAI and Gemini. We prohibit providers from using customer data for their own evaluation. Provider-specific retention, safety monitoring, human review and model-use arrangements are separate from this statement about our own training practices.
Read the storage and deletion page and AI & image data notice for more detail. Identifiers, generated interpretations and image-derived information can still be personal data when they relate to an identifiable individual.
Who receives information
We use providers that support cloud infrastructure, hosting, storage, AI processing, website analytics, communications, customer support and payment processing. They receive information relevant to their function. Our service provider overview describes the principal infrastructure and AI providers; our Cookie Policy describes website technologies.
A provider's role depends on the service and relationship. A provider processing customer data on our behalf is different from a payment service, website tool or independent integration acting under its own applicable terms. Your signed DPA identifies the subprocessors authorised for its covered processing.
We may disclose relevant information to meet a legal requirement, respond to a lawful request or address a dispute or protection of rights, subject to applicable restrictions. Information you send to or store in a separate customer application or third-party AI client is also handled by that operator under its own notice.
Locations and international processing
We use AWS and Google Cloud infrastructure in India and US regions, Cloudflare for DNS and website hosting, and Cloudflare R2 and Amazon S3 for storage. This describes our infrastructure at an overall level. It does not establish exclusive residency for every product, backup, provider or remote-access activity.
If you need service-specific processing locations or international-transfer safeguards, contact us before submitting affected data. Required contractual safeguards must be agreed for the relevant transfer; this notice does not itself execute standard contractual clauses or a transfer agreement. A server location alone does not determine the complete transfer arrangements.
Retention
Product retention periods are set out on our storage and deletion page. Account information is used for the account relationship; after closure, any remaining retention is tied to outstanding transactions, applicable recordkeeping duties or the establishment, exercise or defence of legal claims. Billing records follow relevant tax, accounting and dispute requirements. Support correspondence is retained according to the issue, its resolution and any continuing contractual or legal need.
These business records are distinct from submitted JSON API user details and from the PDF and AI product retention cycles. Contact us about retention of a specific record or to request deletion. Copies downloaded or independently held by customers and other recipients are subject to their own controls.
Cookies and similar technologies
Our website uses cookies for login, local storage for appearance preferences, Google analytics and tag-management scripts, and Intercom for support. The Cookie Policy explains these uses and available browser and provider controls. Browser controls do not change our responsibilities under applicable law.
Your rights and requests
Depending on the law and circumstances, you may have rights to access or receive a copy of personal data, correct it, request deletion or restriction, object to processing, receive portable data, withdraw consent and complain to a competent data protection authority. You may object to processing for direct marketing, including related profiling, at any time.
Email mail@astrologyapi.com with your request and information sufficient to locate the relevant account or record. We may request proportionate information to verify identity or authority. Do not send identity documents or API secrets unless specifically requested through an appropriate route.
We respond within the time required by applicable law. Where the GDPR applies, this is ordinarily one month; permitted extensions for complex or numerous requests require notice and reasons within the first month. Requests are generally free, subject to the limited exceptions allowed by applicable law. We will explain any restriction, fee or refusal that applies.
If the request concerns data processed for a customer, we may direct you to that customer and assist it under the applicable agreement and law. You may complain to the authority competent for you, including an EU supervisory authority or the UK Information Commissioner's Office where the relevant law applies.
Information about other people
Customers must have authority and a lawful basis for information they submit about others, including any required parent or guardian authorisation for children's information. Submit only data needed for the service and consider additional restrictions on sensitive information and images. These customer responsibilities do not remove our own legal obligations.
Astrology and AI outputs may be inaccurate. They should not be treated as medical diagnosis, professional advice or a reliable basis for decisions that significantly affect a person's rights or opportunities. Customers remain responsible for how they present and use outputs in their applications.
Security and changes
See our Security page for integration precautions and how to contact us about an incident or request security information. No method of transmission or storage eliminates all risk.
We may update this Policy to reflect changes in our services or applicable requirements. The version published on this page describes the relevant practices. An update does not itself authorise processing that requires a separate lawful basis, consent or contractual instruction.