Legal
Privacy policy
Last updated 4 September 2026
This policy describes what sidereal.chat stores, why, who else sees it, and how to have it deleted. It covers the service at sidereal.chat and nothing else.
Who is responsible
Wishcoin Media operates sidereal.chat and is the data controller for the information described here. Contact details are on the contact page.
What we store
We hold five kinds of data, and nothing beyond them:
- Google account identity. When you sign in with Google we receive and store your Google account identifier, your email address and your display name. We never receive your Google password, and we ask Google for no permission beyond your basic profile and email.
- Birth details. The name you enter, your date of birth, your time of birth where you give one, and the birth place you confirm — its label and its latitude and longitude. We also store whether the time is exact, approximate or unknown.
- The computed chart. Planetary positions, houses, divisional charts, daśā periods and yogas, calculated once from your birth details and stored so they are never recomputed.
- Readings. The text of each reading generated for you, with the model used and the token counts it cost.
- Conversations. The questions you ask and the answers you receive.
If you subscribe, we also store the Razorpay subscription identifier, its status and its renewal date. We never see or store your card number, UPI identifier or bank details; those are handled entirely by Razorpay.
Birth details and chart data are sent to Google's Gemini API
Readings and answers are generated by Google's Gemini API. To produce them we send your computed chart — planetary positions, houses, daśā periods, yogas and the birth date, time and place they derive from — together with the question you asked and the earlier turns of that conversation, to Google.
This is a transfer of your personal data to Google, and it happens every time a reading is generated or a question is answered. If you are not willing for your birth details to be processed by Google, do not use this service. Google's handling of that data is governed by its own API terms, which we do not control.
We do not send your email address, your name as it appears on your Google account, or your payment details to Gemini.
What we do not do
- We do not sell your data, and we do not share or rent it for advertising.
- We do not contact you for sales, and we send no marketing email.
- We run no analytics, no tracking pixels and no advertising scripts.
- We load only two third-party resources: Google Fonts for typefaces, and Razorpay Checkout on the payment screen. Neither is used to profile you.
- We do not build behavioural profiles, and there are no streaks, badges or notifications designed to bring you back.
Cookies
One cookie, sidereal_session, keeps you signed in. It is signed, HttpOnly, restricted to same-site requests, sent only over HTTPS in production, and expires after thirty days. There are no advertising or analytics cookies.
Deleting your data
Deleting a conversation. Every chart page carries a “Delete this conversation” control. It permanently removes every question and answer in that conversation. Your chart and your reading are kept.
Deleting your account. Visit your account page and confirm. This permanently removes your charts, readings, conversations, messages, subscription records and your sign-in identity. If you have an active subscription it is cancelled at Razorpay first; if that cancellation fails, nothing is deleted and we tell you, rather than leaving billing running against a deleted account.
Deletion is immediate and irreversible. There is no recovery window and no archived copy kept for you.
By email. You can also write to madhurishkatta97@gmail.com and ask us to delete your account or send you a copy of your data. We will action it within thirty days and confirm when it is done.
Retention
We keep your data until you delete it. We do not expire accounts or purge inactive ones on our own initiative.
Two things survive an account deletion, and neither identifies you. Records of payment events that Razorpay sends us are retained where accounting law requires them. Operational logs — errors and timing, used to keep the service working — are kept briefly and hold no birth details, reading text or conversation content.
Encrypted database backups are retained for fourteen days. A deletion is therefore removed from live data immediately, and disappears from backups within fourteen days.
Security
Traffic is served over HTTPS. Secrets are held in environment variables and never in the codebase. Payment card data never reaches our servers. We are a small operation and make no claim to formal certification.
Your rights
You can ask us for a copy of your data, ask us to correct it, or ask us to delete it. Account deletion is available to you directly, without asking. For anything else, write to madhurishkatta97@gmail.com.
Children
This service is not intended for anyone under 18, and we do not knowingly hold data about children. If you believe a child has created an account, write to us and we will remove it.
Changes
If we change this policy we will update the date at the top of this page. If a change materially affects what we do with your data, we will say so on the site before it takes effect.