Every reading shows its reason.
Privacy Policy
In short
- Taara is offered to adults (18 or over) living in India.
- Taara keeps your account, birth details, readings, chats and matches on its server so the app can work.
- To write readings and replies, Taara sends one AI service (Google Gemini unless the operator has chosen another) your name, your chart, your chat messages and, in Match, the other person's name and chart. The chart is exact enough to work out a birth date and birth time.
- Never sent to the AI service: your email, your password, your birthplace or its coordinates.
- No ads, no analytics, no trackers. Taara does not sell your data.
- You can download your data and delete chats, matches or your whole account yourself, in Settings. You can complain at any time on the Contact page.
0. Short notice: what Taara collects and why
| Data | Why | Shared with |
|---|---|---|
| Email; password and recovery code (stored only as hashes) | Your account | Nobody |
| Your confirmation that you are 18 or over and live in India | Taara is for adults in India | Nobody |
| Your name, birth date, time and place | To compute your chart | Your name and chart go to Google Gemini (AI); your birthplace and coordinates never do |
| Readings | Your daily, weekly and other readings | Written by Google Gemini |
| Chat messages | Taara's replies | Your new message and your last 12 messages go to Google Gemini; messages about self-harm or abuse never do |
| Another person's name and birth details (Match), only with their permission | Compatibility report | Their name and chart go to Google Gemini |
| Place searches | To find a birthplace | Open-Meteo (the text only) |
| Plan and payment status | Pro | Stripe |
| Security records (sign-ins with IP address, kept 1 year) | Protect accounts; Indian law (CERT-In) | Nobody unless the law requires |
| Complaints you send | To answer you | Nobody |
- Withdraw consent or delete your data: Settings > Your data.
- Use your rights: see section 7.
- Complain: on the Contact page, to our Grievance Officer. From 13 May 2027 you can also complain to the Data Protection Board of India.
1. Who we are and how to reach us
Taara is run by [LEGAL NAME] ([BUSINESS FORM (SOLE PROPRIETORSHIP / LLP / PRIVATE LIMITED COMPANY)]), trading as Taara, [PRINCIPAL ADDRESS] ("we", "us"). Website: [DOMAIN]. For anything about your data, write to [PRIVACY EMAIL].
Grievance Officer
[GRIEVANCE OFFICER NAME], [DESIGNATION]
Email: [GRIEVANCE EMAIL] · Phone: [GRIEVANCE PHONE]
Address: [PRINCIPAL ADDRESS]
Taara is offered to adults (18 or over) living in India.
2. What we collect
Your account
- Email address, used to sign in. Taara does not send email and does not verify the address.
- Password: never stored. Taara keeps only a PBKDF2-HMAC-SHA256 hash of it, made with a random salt.
- Recovery code: shown to you once; Taara keeps only a hash of it.
- Which version of the Terms and this policy you agreed to and when, when you saw the notice about the AI service, and when you last changed your password or made a recovery code.
- Your device's time zone, read when you sign up or sign in, so times like "ready tonight at 9:00 pm" are your local time.
Your birth profile
- The name you give, your birth date, your birth time (optional), your birthplace as you typed or picked it, its coordinates, its time zone and UTC offset, and your zodiac system and language choices.
What Taara writes for you
- Your natal reading, daily and weekly readings, the Three Mirrors and Taara's first chat message.
Chat
- Your messages and Taara's replies, with their dates.
- Messages that Taara's safety check recognises as being about self-harm or abuse get a fixed reply with helplines. They are kept, marked, so your conversation reads as it happened; they are not sent to the AI service and are left out of the conversation history sent with later messages.
Match
- What you enter about another person: their name (a nickname or initials is fine), birth date, birth time, birthplace coordinates and UTC offset, plus the score and report Taara writes. See section 8.
Plan and billing
- Your plan, when Pro started and ends, any cancellation date, whether Pro came from a promo code or a card subscription, and short billing notes (for example "Upgraded to Pro").
- Only if card payments are switched on: the customer and subscription ids that Stripe gives us and the subscription's status. Taara never sees or stores card numbers.
Your own AI key
- If you add one in Settings, it is stored encrypted and never shown again.
Complaints and your nominee
- Complaints you send through the form: the ticket number, the category, your description, the contact details you give (email, and a name and phone if you add them), the item you reported (for a reading or reply, its first 1000 characters), the status, our answer and the dates.
- Nominee, if you name one: their name, relationship to you, and the email and phone you give.
Security and abuse-prevention records
- Security event log: sign-ups, sign-ins (successful and failed), password and recovery-code events, sign-outs on all devices, account deletions, data downloads, consent changes, nominee changes, admin actions and blocked repeated attempts, each with the India time, the event, its outcome, your user number and the IP address. It never holds passwords, recovery codes, sign-in tokens, birth details, chat, readings or complaint text.
- Sign-in sessions: a hash of the sign-in token, when it was created, when it was last used and when it expires.
- Failed sign-in attempts: the email address typed (in a normalised form), the IP address and the time.
- Sign-up, promo-code, admin-code and complaint-form attempts: the IP address or your user number, and the time.
- Daily counts of your AI requests and of your free chat messages.
After you delete your account
- Deleted-account record: your email address, the date you signed up, the date you deleted the account, and the account number. Nothing else.
Place searches
- The text typed into the birthplace search and the places found. These are kept in a shared cache that is not linked to your account.
3. Why we use it
- To create and run your account and keep you signed in.
- To offer Taara only to adults living in India, as the Terms say.
- To compute your chart (on our server, from your birth details) and to have an AI service write your readings and replies.
- To protect the service and the people who use it from abuse and from runaway costs: limits on sign-in, sign-up, promo-code and complaint attempts, and daily limits on AI requests.
- To handle your plan and, when card payments are on, your payments.
- To answer your complaints and requests, and to let your nominee use your rights when you cannot.
- To meet Indian law: security logging required by CERT-In, and consumer-complaint duties.
- To let the app show your saved readings when you are offline (see section 10).
We do not use your data for advertising, and we do not sell it or share it with anyone not named in section 5.
4. Where it is stored
- In one SQLite database on Taara's server, hosted by [HOSTING PROVIDER] in [HOSTING COUNTRY]. The security event log is kept in the same database on that server.
- Saved AI keys are encrypted with a key held outside the database.
- Sign-in tokens are stored only as SHA-256 hashes; passwords and recovery codes only as PBKDF2 hashes.
- When something is deleted, the database overwrites it in the file (SQLite secure delete).
- Backups are made with Taara's backup tool, which keeps the last 14. The operator is told to keep the server disk and the backups encrypted.
5. Who receives what
Google (Gemini API), the AI service
Taara uses one AI service at a time, chosen by the operator:
- Google Gemini (run by Google) is the default. If a Gemini model is busy or unavailable, the same request goes to the next Google Gemini model in this fixed list: gemini-3.8-flash, gemini-3.6-flash, gemini-3-flash-preview, gemini-3.1-flash-lite-preview.
- Anthropic (Claude), if the operator switches to it.
- OpenRouter, if the operator switches to it. OpenRouter passes each request to the company that runs the chosen model (DeepSeek by default).
To write readings and replies, Taara sends the AI service:
- Your name and your chart: each planet's sign and exact degree (and, for the Vedic chart, its nakshatra), whether you use the Western or Vedic system, and the language to reply in. These degrees are precise enough to work out your birth date and birth time.
- Today's date and today's sky (and, for the weekly reading, the week).
- In chat: your new message and your last 12 messages with Taara (yours and hers).
- In Match: your name and chart, the other person's name and chart, the score and how the two charts relate.
Never sent to the AI service: your email, your password, your birthplace or its coordinates, your IP address, payment details, or messages Taara recognises as being about self-harm or abuse.
Google keeps requests and replies for up to 55 days to detect misuse; authorised Google staff may review flagged content.
Taara is in testing on Google's free Gemini service, under which Google may use requests and replies to improve its products and human reviewers may read them. Taara will move to the paid service before it opens to the public.
If you add your own API key in Settings, your requests go to that provider under your key and your own agreement with them.
Open-Meteo (place search)
When you search for a birthplace (yours, or the other person's in Match), the text you type is sent from our server to Open-Meteo's geocoding service (geocoding-api.open-meteo.com) as you type, after at least 2 characters and a short pause. No account details go with it.
Stripe (card payments, only when switched on)
If the operator switches card payments on, Stripe receives your internal Taara user number and the links to return to the app, and collects your card details on its own payment page. Stripe tells Taara whether your subscription is active, cancelled or unpaid. Taara does not send Stripe your email address.
Our hosting provider
[HOSTING PROVIDER] runs the server that stores everything described in this policy, as our host.
Government agencies and courts
Government agencies or courts, only when Indian law requires it (requests go to [LEGAL EMAIL]).
Nobody else
We never sell your data; no ads, analytics or trackers. Taara's fonts and icons are served by Taara itself.
6. Transfers outside India
Google (the AI service) and Stripe (card payments) may process the data they receive outside India. Google acts under its own terms for the Gemini API; Stripe acts under its own terms. The Government of India has not restricted transfers to any country under the Digital Personal Data Protection Act so far; if it does, we will follow that.
7. Your rights and how to use them
- See and download everything: Settings > Your data > Download my data (a JSON file). It includes your complaints, your nominee, your own security events and the list of who receives your data.
- Correct your birth details: Settings > My chart > Birth details. This recomputes your chart and clears your readings. To change your email address, write to [PRIVACY EMAIL].
- Delete your chat history: Settings > Your data > Delete chat history.
- Delete a match: open it in Match and tap Delete this match.
- Delete your account and everything in it: Settings > Your data > Delete account and data. Your password is needed. If you pay by card, the subscription is cancelled at the end of the paid period first.
- Withdraw your consent: delete your account (this stops all processing for Taara's purposes).
- Name a nominee who can use these rights for you if you die or cannot act yourself: Settings > Your data > Nominee.
- Change your password, or make a new recovery code: Settings > Account.
- Sign out on all devices: Settings > Sign out > Sign out on all devices.
- Complain: the form on the Contact page or in Settings > Help & legal.
How fast we answer: we acknowledge a complaint or request within 24 hours (the form does it on screen at once, with a ticket number); we answer rights requests within 30 days; we aim to resolve complaints within 7 days, and at the latest within 30 days.
If you are not satisfied: from 13 May 2027 you can complain to the Data Protection Board of India after using our grievance process. For consumer complaints you can contact the National Consumer Helpline (consumerhelpline.gov.in).
Requests made by a parent or lawful guardian for someone who cannot act for themselves: write to [PRIVACY EMAIL].
What deletion cannot reach: copies the AI service keeps under its own terms, Stripe's own records, backups until they rotate out (the last 14 are kept), server console output, place-search cache entries (not linked to you; gone after 90 days), and the records we keep after deletion: the deleted-account record (180 days), complaints (3 years after they close) and the security event log (365 days).
8. Other people's data (Match)
Only enter another person's birth details if you have their permission; the app asks you to confirm that each time. A nickname or initials is fine instead of their name. They must be 18 or over: Taara refuses a birth date less than 18 years ago. Taara stores their name, birth date, birth time, birthplace coordinates and UTC offset with the report. It sends the AI service their name and chart, which is exact enough to work out their birth date and birth time. If you search for their birthplace, the text you type goes to Open-Meteo as described above.
You can delete a match at any time (open it in Match, then Delete this match), and deleting your account deletes all your matches. If someone entered your details without your permission and you want them removed, use the complaint form on the Contact page with the category "My details were entered by someone else", or write to [PRIVACY EMAIL].
9. How long we keep it
A clean-up runs when the server starts and every 24 hours.
| What | Kept for |
|---|---|
| Sign-in sessions (stored hashed) | 30 days after last use |
| Failed sign-in records (email typed, IP address, time) | 24 hours |
| Sign-up, promo-code, admin-code and complaint-form attempt records (IP address or user number, time) | 48 hours |
| Daily AI-usage counters | 7 days |
| Daily free-chat counters | 7 days |
| Daily readings | 90 days |
| Weekly readings | 365 days |
| Place-search cache (text typed and places found; not linked to you) | 90 days |
| Stripe event ids (no personal data) | 90 days |
| Account, birth profile, natal reading, Three Mirrors, chat, matches, billing notes, saved AI keys | Until you delete them or your account |
| Security event log | 365 days (1 year) |
| Deleted-account record (email, sign-up and deletion dates, account number) | 180 days after deletion |
| Complaint tickets | 3 years after they are closed |
| Nominee | Until you remove it or delete your account |
| Accounts that declared an age under 18 | Deleted after 7 days |
| Google's abuse-monitoring copies | Up to 55 days (on Google's side) |
| Database backups | The last 14 backups (older ones are deleted as new ones are made) |
| Server console output | Not written to files by Taara; the operator's process manager decides |
Editing your birth details also deletes the readings written from the old details. Open complaints are never deleted before they are closed.
10. On your device
Taara uses no cookies. It keeps these items in your browser's local storage for the web address you use:
| Item | What it holds |
|---|---|
taara_token | Your sign-in token. |
taara_snap | An offline copy so the app works without a connection: your email, your birth profile, today's reading, the weekly reading, your charts, natal readings, the Three Mirrors, your last 50 chat messages, your match list and the match reports you opened. It is not encrypted: anyone using this unlocked browser can read it. |
taara_lang | Your language. |
taara_renew_seen_<date> | Remembers that you have seen a renewal reminder. |
taara_logout_pending | Only after you signed out while offline: the old sign-in token, kept until the sign-out reaches the server (at most 30 days). |
Everything except your language and pending sign-outs is removed when you sign out, and whenever the server no longer accepts your sign-in (for example after 30 days unused, or after "Sign out on all devices").
Each web address keeps its own storage. If you used Taara at an address you no longer open, its copy stays in that browser until you open the address again or clear the browser's site data.
The app's offline cache (its service worker) holds only Taara's own files, never your data. Your recovery code is never stored on your device.
11. Security measures
- Passwords: PBKDF2-HMAC-SHA256 with 600,000 rounds and a random salt; very common passwords are refused; older, weaker hashes are upgraded when you next sign in.
- Sign-in tokens: random, stored only as hashes, and they expire after 30 days unused. "Sign out on all devices" ends every session at once, and changing your password ends every other session.
- Recovery codes are stored only as hashes; a reset with one ends every session and gives you a new code.
- Saved AI keys are encrypted.
- Limits on failed sign-ins (by default 5 per account and IP address, 20 per account and 50 per IP address in 15 minutes), on sign-ups per IP address, on promo-code, admin-code and complaint-form attempts, and on AI requests per day.
- A security event log of sign-ins, account changes and admin actions (see section 2), kept for 365 days, with the India time of each event.
- Size limits on every request; a strict content security policy (only Taara's own scripts run, nothing from other sites).
- HTTPS when the operator deploys it, with Strict-Transport-Security (HSTS).
- The server's request log (separate from the security event log) records only the method, the path and the result of each request: no IP address, no search text, no request contents.
We report qualifying cyber incidents to CERT-In within 6 hours. If a breach affects your data we will tell you, and from 13 May 2027 the Data Protection Board, as the law requires.
No system is perfectly secure.
12. Children
Taara is only for people aged 18 or over who live in India. By creating an account you confirm that you are 18 or over. Taara does not check your age at sign-up. If we learn that an account belongs to someone under 18, we close it and delete its data. If you think someone under 18 is using Taara, please contact us (section 1).
13. Changes to this policy
Each version of this policy has a version number; this one is 2026-10-02.2. When it changes, Taara asks you to read and agree to the new version before you continue.
14. Languages and Hindi summary
This policy is written in English. A short summary in Hindi follows. If the summary and the English text differ, the English text prevails.
सारांश (हिन्दी)
Taara एक AI ऐप है जो आपकी जन्म-कुंडली के आधार पर आत्म-चिंतन और मनोरंजन के लिए पाठ लिखता है। यह चिकित्सा, कानूनी, वित्तीय या मनोवैज्ञानिक सलाह नहीं है।
Taara केवल भारत में रहने वाले 18 वर्ष या उससे अधिक आयु के लोगों के लिए है। खाता बनाकर आप पुष्टि करते हैं कि आप 18 वर्ष या उससे अधिक के हैं; साइन-अप पर आयु की जाँच नहीं होती।
हम क्या रखते हैं: ईमेल, पासवर्ड (केवल हैश), आपका नाम, जन्म की तारीख, समय और स्थान, Taara के लिखे पाठ, चैट संदेश, Match में दूसरे व्यक्ति का विवरण (उनकी अनुमति से), शिकायतें, और सुरक्षा रिकॉर्ड (साइन-इन और IP पता, 1 वर्ष)।
किसे भेजा जाता है: आपका नाम और कुंडली (जिससे जन्म-तिथि और समय पता चल सकता है) और चैट संदेश Google Gemini (AI सेवा) को भेजे जाते हैं। जन्म-स्थान की खोज Open-Meteo को जाती है। भुगतान Stripe संभालता है। हम आपका डेटा नहीं बेचते।
आपके अधिकार: Settings में अपना डेटा डाउनलोड करें, सुधारें या खाता हटाएँ; सहमति वापस लेने के लिए खाता हटाएँ। शिकायत /contact पर करें: हम 24 घंटे में पावती देते हैं और एक महीने के भीतर समाधान करते हैं। 13 मई 2027 से आप डेटा संरक्षण बोर्ड से भी शिकायत कर सकते हैं।
पूरी जानकारी अंग्रेज़ी Privacy Policy में है; किसी अंतर की स्थिति में अंग्रेज़ी पाठ मान्य होगा।