Privacy Policy & Data Protection

Your cosmic journey is protected by enterprise-grade security and transparent data practices. We follow the GDPR, UK GDPR, CCPA/CPRA, India's DPDP Act 2023, PIPEDA and Australia's Privacy Act, and we say plainly what we do and do not do.

Version 1.2 · Effective: 2026-09-08|Last Updated: 2026-09-08

Select Your Region for Specific Information(Currently viewing: Global)

1. Data Controller & Contact Information

Company Information

Company Name: JyoLing LLC (operating AstraFlow)

Incorporated in: Texas, United States

Registration Number: Available on request

Address: 1833 Auburn Dr, Carrollton, TX 75007, USA

Privacy Contact

Email: privacy@astraflow.app

We handle privacy questions and requests by email only. We aim to acknowledge every message within 48 hours.

Regional Representatives

We have not appointed a representative or grievance officer in the EU, the UK, India, Australia, China or any other region. Wherever you are, contact us at privacy@astraflow.app and we will handle your request under the rules that apply to you.

2. Information We Collect

2.1 Information You Provide Directly

Account Registration:

  • Full name (required for personalized readings)
  • Email address (primary communication)
  • Phone number (optional; used only if you ask us to contact you)
  • Password - held by Amazon Cognito, our sign-in provider; we never see or store it. Or Google sign-in, if you choose it.

Astrological Profile Data:

  • Birth date (essential for planetary calculations)
  • Birth time (precision affects house calculations)
  • Birth location (latitude/longitude for accurate charts)
  • Current location (for real-time transit calculations)

Sathi journal (with your separate consent - see 2.4):

  • What you write to Sathi
  • Habits you choose to work on, and aims you state
  • The name you ask Sathi to call you

Optional Information:

  • Profile photo (from Google sign-in, if you use it)
  • Spiritual/religious preference (for contextual insights)
  • Language preference
  • Time zone settings

2.2 Information Collected Automatically

Device Information:

  • Device type (mobile/tablet/desktop)
  • Operating system and version
  • Browser type and version
  • Screen resolution and orientation
  • Device identifiers (for session management)
  • Mobile app version (if applicable)

Usage Data:

  • Pages visited and features used
  • Click patterns and scroll depth
  • Session duration and frequency
  • Referral source (how you found us)
  • Search queries within the platform
  • Error logs and crash reports

Network Information:

  • IP address (for security and routing)
  • Approximate location (city/region level)
  • Internet service provider
  • Connection type (WiFi/cellular)

2.3 Information from Third Parties

Payment Processors (Stripe):

  • Transaction status and ID
  • Subscription status
  • Payment method type (not full details)
  • Billing country

Social Media (if you connect accounts):

  • Basic profile information
  • Email (for account linking)
  • Profile photo

Analytics Providers:

None. Usage events go to our own tracker on our own servers. We do not use Google Analytics, Firebase, Facebook Pixel, Amplitude or any other third-party analytics or advertising service.

2.4 Sathi Journal (only with your consent)

Sathi is a reflective journaling companion. Nothing in this section happens unless you have turned on Sathi memory & insights - a separate, explicit consent, available from age 16, that you can withdraw at any time in Settings → Privacy. Sathi is not therapy, not medical care and not a crisis service.

What we keep when it is on:

  • What you write to Sathi, and Sathi's replies, per session
  • A short record of each session (themes, a mood score, anything you said you are working on or aiming for)
  • Derived signals: mood, habit observations and aims, each stamped with the sky at that moment (Moon nakshatra, tara, dasha period, tithi) so patterns can be read against your chart
  • A running state of what you are working on, so the next session can pick up where you left off

What happens when you turn it off: processing stops immediately, and the records and derived signals above are removed within 30 days. Your chart and the rest of your account are unaffected.

Sensitive content: what people write in a journal can reveal health, beliefs, relationships or other sensitive matters. That is exactly why this consent is separate and explicit, why it is never shared, sold or used for advertising, and why we never use it to make automated decisions with legal or similar effects about you.

3. Legal Basis for Processing (GDPR/UK GDPR)

We process your data based on:

Contract Performance: To provide astrological services you've subscribed to

Legitimate Interests: To improve our services, ensure security, prevent fraud

Consent: For marketing communications, cookies, special categories of data

Legal Obligation: Tax records, compliance with court orders

Vital Interests: In rare cases of safety concerns

Purpose Limitation

We only use your data for:

  • Generating accurate astrological readings
  • Personalizing your cosmic insights
  • Processing payments and subscriptions
  • Providing customer support
  • Improving our algorithms and services
  • Legal compliance and fraud prevention
  • Marketing (with consent only)

4. How We Use Your Information

4.1 Core Service Delivery

Astrological Calculations:

  • Generate natal charts using Swiss Ephemeris
  • Calculate planetary transits and progressions
  • Determine Mahadasha/Antardasha periods
  • Create compatibility analyses
  • Generate timing recommendations

4.2 AI and Machine Learning

Which models: we use large language models from Anthropic (Claude) and, for some features, OpenAI, Google and xAI, through their business APIs - never their consumer chat products. Which model serves which feature can change; the list of providers will not change without an update to this policy.

What the AI layer receives:

  • Positions and timings derived from your birth chart (signs, nakshatras, dasha periods, house placements) and the current sky
  • For Sathi: your message, recent context from that conversation, the name you asked Sathi to call you (which may be your first name), and - with Sathi memory on - a short summary of what you are working on
  • For readings: the question or feature you asked for

What it never receives: your email, phone number, exact birth place or coordinates, payment details, account identifiers or IP address. Our systems pass an internal reference, not your identity.

Training: we do not train models on your content. We access these providers as a business customer and do not permit them to use your inputs to train their models where the provider offers that control; providers process requests under their own API data terms.

No biometrics, no emotion recognition: we never process your face, voice, typing rhythm or any other biometric signal, and we do not infer emotion from anything except what you choose to write or self-report. AI output can be wrong, incomplete or subjective; it is guidance for reflection, not a diagnosis or a prediction.

4.3 Communication Purposes

  • Service updates and new features
  • Daily cosmic weather (Premium)
  • Payment confirmations and renewals
  • Security alerts and account changes
  • Personalized insights (with consent)
  • Educational content about astrology

4.4 Tokens and Usage Records

Paid features run on tokens. We keep a ledger of every grant (welcome tokens, subscription tokens, packs you buy), every spend (which feature, when) and every expiry, so your balance is always explainable and disputes can be resolved. The ledger is billing data and is kept with your payment records. It is never used for advertising.

5. Data Sharing and Disclosure

We DO NOT:

  • Sell your personal information to anyone
  • Share your birth details with other users
  • Use your data for user comparison features
  • Create public profiles without consent
  • Share journal entries with any third party

Limited Sharing Scenarios:

Service Providers (Data Processors):

  • Amazon Web Services - hosting, databases, storage and transactional email, US East (Ohio)
  • Stripe - payment processing (PCI compliant); we never see your full card number
  • Anthropic, OpenAI, Google, xAI - AI model providers, receiving only what section 4.2 describes
  • Google - sign-in only, if you choose to sign in with Google; it sees nothing else

We send no SMS, WhatsApp or Telegram messages and use no third-party analytics, advertising or customer-data platforms.

Legal Requirements:

  • Valid court orders or subpoenas
  • Law enforcement with proper warrants
  • Tax authorities for compliance
  • Protection of vital interests

Business Transfers:

In case of merger, acquisition, or sale, users will be notified 30 days in advance with option to delete accounts.

6. Data Retention Policy

Retention Periods

Data CategoryDetailsRetention Period
Account InformationName, email, phoneUntil account deletion + 90 days
Birth DataDate, time, locationAccount lifetime
Payment RecordsTransaction history7 years (legal requirement)
Sathi journal - what you writeSession exchanges and daily records (with your consent)Until you withdraw consent or delete your account, then removed within 30 days
Sathi journal - derived insightsMood, habit and aim signals with the sky context of the momentUntil you withdraw consent or delete your account, then removed within 30 days
Token ledgerGrants, spends, expiries per feature7 years with payment records
Consent recordsWhich version you agreed to, when, and how; withdrawalsAccount lifetime + 3 years
Usage eventsPages, journeys, feature use (our own tracker, no third-party analytics)2 years
Support TicketsCustomer communications3 years
Marketing PreferencesConsent recordsUntil withdrawn + 3 years

Deletion Process

Automatic Deletion:

  • Inactive accounts: Warning after 18 months, deletion after 2 years
  • Unverified accounts: Deleted after 30 days
  • Marketing consent: Refreshed every 12 months

Manual Deletion Rights:

  • Self-service through account settings
  • Email request to privacy@astraflow.app
  • 30-day grace period for recovery
  • Immediate deletion available on request

8. Your Privacy Rights

Universal Rights (All Users)

  • Access: Request a copy of all your personal data
  • Correction: Fix inaccurate information
  • Deletion: "Right to be forgotten"
  • Portability: Export data in JSON/CSV format
  • Objection: Opt-out of specific processing
  • Restriction: Limit how we use your data
  • Withdraw Consent: Change permissions anytime

US Residents - CCPA Rights

  • Right to know what personal information is collected
  • Right to know if information is sold or disclosed
  • Right to opt-out of sale (we don't sell data)
  • Right to non-discrimination
  • Private right of action for data breaches

California Residents: Additional rights under CPRA effective 2023

EU Residents - GDPR Rights

  • Right to lodge complaint with supervisory authority
  • Right to withdraw consent without affecting lawfulness
  • Right to object to automated decision-making
  • Right to be informed about profiling
  • Data breach notification within 72 hours

Data Protection Authority: You may contact your local DPA

UK Residents - UK GDPR Rights

  • Right to be informed about data collection
  • Right of access to your personal data
  • Right to rectification of inaccurate data
  • Right to erasure ('right to be forgotten')
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • Rights related to automated decision making

UK Supervisory Authority: Information Commissioner's Office (ICO)

Indian Residents - DPDP Act 2023

  • Right to access and correction
  • Right to erasure
  • Right to grievance redressal
  • Right to nominate digital data nominee
  • Parental consent for under 18

Grievance Officer Response: Within 15 days

Australian Residents - Privacy Act 1988

  • Access to personal information
  • Correction of inaccurate data
  • Complaint to OAIC
  • Notification of data breaches
  • Cross-border disclosure restrictions

Chinese Residents - PIPL

  • Separate consent for sensitive data
  • Right to know processing rules
  • Right to refuse automated decisions
  • Data localization requirements
  • Cross-border transfer assessment

Note: Chinese users' data is processed in compliance with PIPL. Separate consent required for international transfer.

Consent, and how to change it

Two kinds of agreement sit behind your account. When you signed up you accepted the Terms of Service and this Privacy Policy (a specific version of each - Settings → Privacy shows which). Separately, Sathi memory & insights is an explicit opt-in that you can turn on or off there at any time; turning it off stops processing at once and removes the derived data within 30 days. We keep a record of every grant and withdrawal (version, date, method) so we can show what you agreed to and when. If we change either document in a way that matters, we publish a new version and ask you to accept it again before it applies to you.

How to Exercise Your Rights

Submit requests through:

  • Settings → Privacy in your account (consent switches, data and deletion requests)
  • Email: privacy@astraflow.app

Response time: 30 days (15 days for India DPDP requests)

9. Data Security Measures

Technical Safeguards

  • Encryption: AES-256 at rest, TLS 1.3 in transit
  • Password Security: Bcrypt with adaptive salt rounds
  • Infrastructure: AWS with VPC isolation
  • Access Control: Role-based with MFA
  • Monitoring: 24/7 intrusion detection
  • Backups: Daily encrypted backups, geo-redundant

Organizational Measures

  • Employee background checks and NDAs
  • Regular security training
  • Principle of least privilege
  • Annual security audits
  • Incident response plan
  • Vendor security assessments

Data Breach Protocol

In case of a breach affecting your data:

  • Notification within 72 hours (GDPR requirement)
  • Direct email to affected users
  • Public disclosure if required
  • Assistance with protective measures
  • Regulatory authority notification

10. International Data Transfers

Primary Data Location

Primary servers: AWS US East (Ohio), USA

Backup servers: AWS US-West-2 (Oregon, USA)

AI model providers: United States

Transfer Safeguards

For EU/UK Users:

  • Standard Contractual Clauses (SCCs) implemented
  • Supplementary measures per Schrems II
  • Transfer impact assessments conducted

For Indian Users:

  • Explicit consent for cross-border transfer
  • Data localization roadmap in progress
  • Indian server deployment planned Q2 2025

For Chinese Users:

  • PIPL compliance measures
  • Security assessment completed
  • Separate consent mechanism

© 2024 AstraFlow. All rights reserved.

This privacy policy was last updated on 2026-09-08 and is effective as of 2026-09-08.

For questions about this policy, contact privacy@astraflow.app