Privacy policy
numiVeda · Last updated 5 October 2026
This policy describes what numiVeda collects, why, where it goes, how long it is kept, and how to get rid of it. It describes the app as it is actually built today — not a product we intend to build. If something below stops being true, this page is wrong and it is a defect.
Who we are
numiVeda, operated by WishReiki Services (sole proprietor: Arunav Talukdar). Questions about this policy, or about the data we hold on you, go to support@numiveda.com.
What we collect
Most of it you give us: you type it in, or Google hands it over if you choose to sign in with Google. Some of it the app writes for you — charts, cards and answers. And some it records about how you use the app, such as how many questions you asked today. We do not buy data, we do not go looking for it anywhere else, and we do not track you across apps or websites.
- Your email address. It is how you sign in, and how we send a confirmation link or a password reset. We do not send marketing email.
- Your password, if you create one. It is stored only as a cryptographic hash by our sign-in provider; nobody at numiVeda can read it. If you sign in with Google there is no password at all.
- Account numbers. The app gives your account, and each profile in it, an identifying number. If you sign in with Google, we also receive the identifier Google uses for your account with this app, and the name on that Google account.
- A mobile number, if you check one in myNumbers. It is read as a number for that check, on our server. We keep only its last four digits, with the reading; the full number is never stored, never written to our logs and never sent to Google. A vehicle number checked there is kept the same way: its last four characters.
- A name for each profile you add — a nickname is fine. It tells your profiles apart, and the app uses it to address the person in a card or a reading.
- Birth details for each profile: the date, time and place of birth, how exactly the time is known, who the person is to you, and the language you want readings in. And what the app writes from them: the chart, the day cards, and the answers it gives.
- Where a profile lives now, if you add it: a city you pick from a list. The app uses it to work out the local date and the day's timings where the person actually is. It is not your device's location.
- What you ask in myAstrologer, and the replies. The questions you type are kept, with the replies written to you, as a conversation you can come back to. A conversation's title can be the first words of your question. The same for what you ask about a myApps reading — "Ask about this reading": each follow-up question and its answer are kept under the reading, for as long as the reading is kept, and go when you delete it. As with a reading, a follow-up question is kept only after our safety check has read it; if the check could not run, the answer is kept but the question is not.
- Which scripture door you consulted in myApps, and when. Each time you ask a question at a myApps door — for example the Upanishads or a Buddhist text — the app records which door it was, the day, the answer it wrote and the passages it drew on. Over time that is a record of which scriptures you have consulted, day by day, and it could be read as saying something about your beliefs. We do not ask what you believe, and you may open a door out of simple curiosity, but the record exists, so we tell you. How long it is kept depends on the app you asked in — see "How long we keep it".
- What you ask at a myApps door — on the website, and in an Android app whose ask screen says so. There the question you type is kept with its answer until you delete them, so that you can find a reading again by what you asked. It is kept only once you have an answer, and only after our safety check has read it. That check is Google's Gemini model, so what you type is sent to Google to be read — every question, including one that turns out to be about being in danger (see "Google (Gemini API)" below). If the check could not run, the answer is kept but the question is not. If what you write suggests you are in danger, we show you where to get help and we keep nothing of it — not the question and not an answer, in our database or in our logs. Google keeps what it was sent only for a limited period to detect abuse, under its own terms. In an Android app whose ask screen says "Your question is not kept", the question is not kept.
- How much you use the app: how many questions and cards you asked for each day, and when your conversations and answers happened. This is how the daily limits work. And what you report: if you tap Report on something the app wrote — a myAstrologer reading, a myApps answer or a day card — we keep which one it was, when you reported it, and which of four reasons you picked, so that we can read it.
- A notification token for each device you allow notifications on. If you turn on notifications in the Android app, it gives us the token Google's Firebase Cloud Messaging uses to reach that device, with the app's version, the device type and its time zone. We use them only to send the notification you asked for, at the hour you chose in your own time zone. Signing out removes that device's token; deleting your account removes them all.
- Your credits and what you bought. If you buy credits, we keep a record of each credit pack: which pack, whether it was bought through Google Play or on the website, the order and payment numbers, the price and whether it was paid or refunded. We keep your credit balance and a line for each credit added or used, with the app it was used at. Your card, UPI or bank details go to Google Play or Razorpay when you pay; we never receive them.
- The city name you type to find a place. It is sent to find matching cities and is not kept.
Birth data can be about other people. If you add a profile for your spouse, your child or anyone else, you are giving us their name and their date, time and place of birth. Only add someone else's details if you are entitled to — for a child in your care, or with the person's agreement. Deleting your account deletes their data with it.
Health. The app does not ask about your health. If you describe a symptom in a question that is kept — in myAstrologer, or at a myApps door where the question is kept — it is kept with that question, like any other words you type.
What we do not collect
- Your device's location. The app requests no location permission of any kind. Places come from a list you search by typing.
- Your photos. The app requests no access to them.
- Your videos. The app requests no access to them.
- Your microphone or any recording.
- Your files or documents.
- Advertising identifiers. There is no advertising in this app and no advertising SDK in it. A notification token (above) reaches your device; it does not identify you to anyone else.
- Your contacts or calendar, and no analytics or behavioural tracking: no analytics SDK, no session recording, no cross-app tracking.
Notifications
The Android app can send you one notification each morning, at the hour you choose: the date and one line about the day from your day card. It never shows anything more personal than that — nothing about your health, your money or anyone you added. It is off until you allow notifications on your device, and you can turn it off in the app at any time. To send it, the notification's title and that one line go to Firebase Cloud Messaging with your device's token.
Where your data goes
Producing a reading means sending some of what you gave us to services that do the calculating and the writing. Here is every one of them, and what each receives. Every connection between them is encrypted (HTTPS).
1. Our astrology calculation service
Charts, planetary periods and the daily timings are calculated by numiVeda's own astrology engine, which runs on a server operated by the same business that operates numiVeda. It is not another company, but it is a separate machine on the internet, so your data does leave the app's database to reach it. For the profile being read, it receives the date, time, latitude, longitude and time zone of birth; the latitude, longitude and time zone of where the profile lives; and, for one calculation, the name on the profile. It does not receive your email address. We are still checking what that server keeps in its logs, and for how long.
2. Google (Gemini API)
The words the app writes — day cards, myAstrologer readings and myApps answers — are written by Google's Gemini model, which also checks each question before it is answered — including a question that suggests you are in danger. That one is sent to Google to be checked, and then we show you where to get help and keep nothing of it ourselves. For all of this, Google receives:
- the question you typed, and the recent conversation in the same myAstrologer thread
- the name on the profile
- the date, time and place of birth
- where the profile lives
- the chart, planetary period and daily timings calculated from those details
Google does not receive your email address or your password.
Google handles this as a service provider for us. The app uses the paid Gemini API: each of the two keys it uses belongs to a Google Cloud account with active billing of its own. Under Google's terms for paid use, Google does not use what is sent to improve its products, and keeps it only for a limited period to detect abuse. If the first key fails and the second is used, the same terms apply. Google's terms are at ai.google.dev/gemini-api/terms.
3. Google (Sign-In) — only if you choose it
This is a different Google service from the one above. It does not
receive anything from us: if you tap "Continue with Google", Google tells us who you
are — the email address on that Google account, the name on it and a link to your
profile picture if you have one, and an identifier for your account with this app. We
ask for the standard sign-in permissions (email, profile and
openid) and nothing else. None of your birth data goes to Google
Sign-In, and you never have to use it: email and password work exactly as well.
The app asks for no advertising identifier. The library that provides Google sign-in on Android tried to add advertising and attribution permissions to the app; they were removed, and an automated check fails the build if they come back. The installed app holds exactly one permission — internet access.
4. Our infrastructure providers
- Supabase hosts the database and handles sign-in. Everything listed under "What we collect" that is kept is stored there, encrypted at rest. It holds the data only to run the service for us.
- Firebase Cloud Messaging, Google's notification service, receives a device's notification token and the notification itself — the date and one line about the day — only if you turn notifications on. It delivers the notification for us and does nothing else with it.
- Google Play takes the payment when you buy credits in the Android app. We send it the purchase's token to check what was bought and mark it used; we send it nothing about you. Google keeps its own record of the payment, under its own terms.
- Razorpay takes the payment when you buy credits on the website. We send it the pack's price, an order number and your account's number as a note on the order; you give your card, UPI or bank details to Razorpay directly, and they never reach us.
- Vercel hosts the website and the server code that talks to the services above, and keeps logs of requests to it. It handles the data only to run the service for us.
What we never do
- We do not sell your data. Not to anyone, not in any form.
- We do not share it with advertisers or data brokers.
- We do not use it to train any model of our own.
- We do not use it for advertising, profiling for advertising, or scoring.
How long we keep it
Different things are true of different information. For myApps readings it also depends on the app you asked in, because each version of the app told you, on the screen where you typed, what it would do with your reading — and we keep to what it told you, for as long as that version is in use.
- Your profiles, charts, day cards and myAstrologer conversations are kept for as long as the account exists. A chart and a day card are about a birth moment and a particular day, and they do not go stale; a conversation is there for you to come back to. When you delete your account they all go at once.
- myApps readings asked on the website, or in an Android app whose ask screen says they are kept, are kept until you delete them — your question, the answer, the passages it drew on, and which door and which day. Delete one under the reading or in Account → Your readings, or all of them at once there. Deleting your account removes them all. If a myApps door asks about another person and you enter their details for that reading alone — their name and their date, time and place of birth — they are kept with that reading, are not saved as a profile, and are deleted with the reading. The questions you ask about a reading, and their answers, are kept with it and deleted with it.
- myApps answers asked in an Android app whose ask screen says "Your question is not kept" are deleted automatically within about two days — between 27 and 52 hours after they are given, together with the record of which door you used and when. The question is not kept. That is what that app told you, and it stays true for every answer asked in it, even after a newer version exists. You can also delete one sooner yourself.
- A myApps answer you report is kept until somebody has reviewed the report, instead of going within two days — it is kept because you asked us to look at it. Once the report has been read, the answer is deleted in the ordinary way the next day. A report on a myAstrologer reading or a day card stays with that reading or card, for as long as the account exists — except that if you change where a profile lives, today's day card is written again and a report on the old one goes with it.
- The myApps daily limit keeps a short record of each reading you are given — which door and which day, never the answer or your question — and deletes it automatically between 27 and 52 hours after that day. It is what the daily limit counts, so it stays even if you delete the reading itself (deleting a reading does not give you the reading back to use again), which means it can outlive a deleted reading by up to two days. A reading that failed before you got an answer is not counted as a reading. Your account keeps a count of that day's failures instead, because after several in one day no new reading starts until midnight, India time.
- Your tarot card of the day is kept for between 30 and 31 days after you pick it — which card you turned over, and when — and then deleted automatically. Only today's is ever shown.
- Backups. The whole database is backed up every day. Those backups are encrypted and kept on a rolling cycle of seven days, then overwritten automatically.
- Logs. Vercel's logs of requests to our servers, which include your account number and can include error details, and Google's logs of requests to the Gemini service, are kept on those providers' own schedules.
Transaction records. When you buy credits, we retain transaction records as required by law. Google Play and Razorpay also keep their own records of each payment.
Deleting your readings, without deleting your account
You can delete any myApps reading or myAstrologer conversation yourself, or all of them at once, without deleting your account: under the reading, or in Account → Your readings. Deleted means removed from our database, not hidden. The short record the myApps daily limit counts stays until it is deleted automatically, as described above, so deleting a reading does not give the day's reading back.
Deleting your account and everything in it
You can delete your account from inside the app, at any time, without asking us: Account → Delete my account. You will be asked to type the word DELETE, and then it happens immediately. There is no grace period.
It removes from our live systems, straight away:
- your account, and its daily usage counts
- every profile you created, with its name, birth details and where it lives
- every chart calculated from those profiles
- every day card ever written for them
- every tarot card of the day picked for them
- the notification token of every device you allowed notifications on
- the record of each morning notification sent to you
- your credit balance — unused credits are lost, and deleting your account is not a refund
- the record of every credit added to and used from your balance
- the record of each credit pack you bought (Google Play and Razorpay keep their own records of the payment)
- every myAstrologer conversation, including its title
- every question you typed in myAstrologer, and every reply written to you
- every myApps reading still kept — the answer, your question where it was kept, and the record of which door you used
- the short-lived record the myApps daily limit counts
- every question you asked about a myApps reading, and every answer
It also removes your sign-in — your email address, your password hash if you have one, and the link to your Google account if you used one.
What deletion does not reach straight away. A copy of your data can remain in our encrypted backups until their rolling cycle of seven days completes and they are overwritten. Operational logs at Vercel and Google are not deleted by this: they expire on those providers' own schedules. The deletion itself is checked: every time someone deletes an account, the app counts what was removed and reports an error if anything in the database survived.
Full instructions, including how to do it without installing the app.
Two things deletion does not do, said plainly: it does not refund anything you have paid for, and it does not cancel a subscription bought through Google Play or the App Store — those are cancelled in that store.
Your rights
Depending on where you live, you may have the right to access the data we hold on you, to correct it, to have it erased, and to receive a copy of it. In practice:
- Access and correction — every profile is visible and editable in the app, and your myAstrologer conversations can be read there. Your usage counts and any myApps answers still kept are not shown in the app; ask us for them.
- Erasure — the delete flow above, which you can run yourself and which we cannot slow down.
- A copy — email support@numiveda.com and we will send you what we hold.
Children
numiVeda is not intended for children under 13, and we do not knowingly create accounts for them. An adult may add a profile for a child in their care; that profile is the adult's data to manage and to delete.
Security
Everything travels encrypted between your device, our servers and the services above. Data is held in a database with row-level security enabled on every table, so one account's queries cannot reach another account's rows. The keys that could bypass that live only on the server and are never shipped in the app.
Changes to this policy
If what we collect or where it goes changes, this page changes before that release does, and the date at the top moves. We will not quietly widen it, and that rests on a check, not only an intention: every proposed change to the app is checked automatically. Each kind of information the app stores is compared against our internal record of what we collect, and this page is compared against that record. A change that leaves either one missing something fails that check, and is flagged before it is merged.