Privacy Policy
Last updated: 4 September 2026 Effective date: 31 March 2026
1. Introduction
Skybond ("we", "us", "our", "the Service") is a personal guidance application for iOS and the web, operated by Akshay Dhiman, an individual operating under the laws of India.
This Privacy Policy explains what personal data we collect, why we collect it, how it is used and stored, the safeguards we apply, and the rights you have over your data.
We process personal data as a Data Fiduciary under India's Digital Personal Data Protection Act, 2023 (DPDP Act) and, where applicable, in a manner consistent with the General Data Protection Regulation (GDPR) for users in the European Economic Area.
The sign-in screen links to this policy and to our Terms of Service. By creating an account you acknowledge this policy.
2. Data Fiduciary / Controller
| Name | Akshay Dhiman |
| Role | Data Fiduciary (DPDP Act) / Data Controller (GDPR) |
| [email protected] | |
| Address | 288, Bank Enclave, Laxmi Nagar, Delhi, India 110031 |
For privacy questions or data-rights requests, contact [email protected]. For product support, contact [email protected].
3. Data We Collect
3.1 Account Data (Apple, Google, or email OTP)
You create an account with Sign in with Apple, Google, or an email one-time passcode. We do not ask you for a password, and we do not receive your Apple ID or Google account password.
Sign in with Apple
| Data | Purpose |
|---|---|
| Apple user identifier | Account identification |
| Email address, or an Apple Hide My Email relay address if you choose that option | Account identification and communication |
| Name, if Apple provides it (typically only the first time you authorise Skybond) | Personalisation |
| Data | Purpose |
|---|---|
| Email address | Account identification and communication |
| Display name | Personalisation |
| Profile picture URL | Personalisation |
| Email verification status | Account security |
Email one-time passcode (web)
| Data | Purpose |
|---|---|
| Email address | Account identification, sending the sign-in code, and communication |
| Six-digit sign-in code | Verifying that you control the inbox. Codes expire after 10 minutes |
We store the authentication records needed to keep you signed in (including provider account identifiers and session tokens). Those records are encrypted at rest by our infrastructure.
3.2 Birth and Place Data (onboarding)
This is sensitive personal data. We use it only to compute your birth chart and personalised guidance.
| Data | Purpose |
|---|---|
| Date of birth | Birth-chart calculation |
| Time of birth | Birth-chart calculation |
| Birth-place name | Display and chart context |
| Geographic coordinates of the place you select | Precise chart computation |
| Timezone offset | Chart accuracy |
| Birth-time accuracy indicator (exact or approximate) | Qualifying interpretation fidelity |
We do not collect your device's live or current location. You search for a birth place (via Apple Maps / MapKit) and select it. Only the place you choose is stored.
Birth details are collected during onboarding and shown in Profile. The app does not currently let you edit them after onboarding. To correct them, contact [email protected] or delete your account and create a new one.
3.3 Derived Chart Data
Computed from your birth data and stored with your profile:
- Full natal chart (planetary positions, houses, aspects)
- Life-period timeline (major and minor chapters)
- Calendar metadata for your birth place
- Chart strength scores
- Supplemental divisional charts used for deeper readings
- Profile summary (Moon sign, Ascendant, birth star, current life chapter)
Some chart rendering also happens on your device. Natal calculation for stored profiles is performed by our chart-computation service (see Section 7).
3.4 AI Interaction Data
| Data | Purpose |
|---|---|
| Questions you submit in Ask, including questions asked in a Bond | Generating AI-powered personalised answers |
| AI-generated answers and articles | History, caching, and display in the app |
| Feedback (helpful / not helpful) | Improving answer quality |
3.5 Relationship Data (Bonds)
| Data | Purpose |
|---|---|
| Another person's birth details, if you add a custom profile | Compatibility analysis |
| Email address of someone you invite | Managing bond invitations and sending the invite email |
| Invitation status | Showing whether an invite is pending, accepted, or declined |
| Relationship type(s) you select | Tailoring compatibility content |
If you connect with another Skybond user through an invitation, their chart comes from their own profile. You are solely responsible for obtaining consent when you enter someone else's details or invite them. See Section 11.
3.6 Reading Progress
| Data | Purpose |
|---|---|
| Articles you have opened | Picking up where you left off |
| How far you have read in an article | Showing your reading progress in the app |
3.7 In-App, Push, and Email Notifications
| Data | Purpose |
|---|---|
| Notification records (type, title, body, deep link, read, push, and email timestamps) | Showing your in-app inbox and sending related alerts |
| APNs device token, platform, app version, and device timezone | Sending push notifications to your devices at an appropriate local hour |
| Email article preference | Whether we send Today, timing, and transit emails. On until you turn it off |
Push notifications require your permission in iOS. You can disable them in iOS Settings. That does not delete in-app notification history.
We email Today, timing, and transit articles, and bond invites, using Cloudflare Email Sending. Article emails are on by default. You can turn them off in Profile or by opening the unsubscribe link in an email — that link unsubscribes you immediately. Sign-in codes and bond invites still send.
3.8 Subscriptions (Skybond+)
If you subscribe to Skybond+ on iPhone through the Apple App Store, or on the web through Razorpay or PayPal:
| Data | Purpose |
|---|---|
| Apple original and latest transaction identifiers | Matching an App Store purchase to your Skybond account |
| Razorpay subscription and payment identifiers | Matching a web purchase to your Skybond account |
| PayPal subscription identifiers | Matching a PayPal purchase to your Skybond account |
| Product identifier, status, and environment (sandbox or production / test or live) | Providing and restoring Skybond+ access |
| Purchase, expiry, and trial dates; auto-renew status | Showing subscription state in the app |
We do not collect payment card numbers, Apple ID passwords, UPI PINs, or full billing addresses. Apple, Razorpay, or PayPal processes payment. See Apple's Privacy Policy, Razorpay's Privacy Policy, and PayPal's Privacy Statement.
Deleting your Skybond account removes our record of the subscription. It does not cancel auto-renewal. Cancel an App Store plan in Settings → Apple ID → Subscriptions, or from Profile on iPhone. Cancel a web plan from Billing on getskybond.com.
3.9 Usage Analytics
| Data | Purpose |
|---|---|
| Screen and tab names | Understanding which parts of the app are used |
| Interaction types (views, clicks, reads) | Improving product quality and reliability |
| Session identifier generated on your device | Grouping activity within one app visit |
| App version and platform | Diagnosing version-specific issues |
| Your Skybond account identifier (added on our server when you are signed in) | Connecting usage to an account without putting birth data or questions in analytics |
Analytics are first-party (Cloudflare Analytics Engine). We do not use analytics for advertising, do not use the advertising identifier (IDFA), and do not track you across other companies' apps or websites. Client analytics payloads are not allowed to include question text, birth data, email addresses, or other sensitive personal content.
3.10 Session and Technical Data
| Data | Purpose |
|---|---|
| IP address | Security and session validity |
| User agent (device / browser string) | Security and session validity |
| Session token | Authentication |
3.11 Data Stored on Your Device
The iOS app stores some data locally, including:
- Session token in the iOS Keychain
- Cached articles and chart data, so screens load when you are offline
- Appearance (theme) preference
- Optional speech / listen settings (voice and speed)
- Generated speech audio for articles you choose to hear, produced on-device
On-device text-to-speech is not uploaded to us. Clearing the app or signing out removes the local session.
4. How We Use Your Data
We use your data to:
- Provide, operate, and maintain the Skybond service
- Create and authenticate your account via Sign in with Apple, Google, or an email one-time passcode
- Generate personalised life-guidance content via AI
- Submit your birth data to our chart-computation service to generate and store your natal chart
- Answer your questions by passing your chart summary and current timing context to an AI model
- Maintain your account and enforce session security
- Apply rate limits and prevent abuse
- Measure product usage through privacy-conscious analytics
- Deliver in-app, push, and email notifications
- Provide, restore, and manage Skybond+ subscriptions
- Comply with legal obligations
We do not sell your personal data. We do not share it for cross-app or cross-website advertising. We do not use your data for advertising.
5. Legal Basis for Processing
Under India's DPDP Act, 2023:
- Processing is based on your free, informed, specific, and unambiguous consent given when you create an account and complete onboarding.
- You may withdraw consent at any time by deleting your account (see Section 10).
Under GDPR (for EEA users):
| Processing | Legal basis |
|---|---|
| Providing the service, including your account and Skybond+ | Contract performance (Art. 6(1)(b)) |
| AI personalisation using birth/chart data | Consent (Art. 6(1)(a)) |
| Security, fraud prevention, and first-party analytics | Legitimate interests (Art. 6(1)(f)) |
| Push notifications | Consent (Art. 6(1)(a)), via iOS permission |
| Email article notices | Legitimate interests (Art. 6(1)(f)), with an unsubscribe link and a Profile control |
6. AI Processing Disclosure
Skybond uses AI language models to generate personalised guidance — including Today, Self, Bonds, transits, and Ask answers.
- Your birth-chart summary (not raw birth coordinates) and question text are sent to an AI model to generate personalised responses.
- We use Cloudflare AI Gateway to route requests to AI models. Your summary data may be processed by the underlying AI model provider selected by Cloudflare AI Gateway.
- We do not use your data to train AI models.
- AI-generated content is not a substitute for professional advice — whether medical, psychological, financial, legal, or otherwise. See the AI Disclaimer in the app and at getskybond.com/legal/ai-disclaimer.
7. Third-Party Data Processors
| Service | Purpose | Data shared |
|---|---|---|
| Apple (Sign in with Apple) | Authentication | Apple user identifier, email or Hide My Email relay, name if provided |
| Google (OAuth 2.0) | Authentication | Name, email, profile picture |
| Cloudflare Email Sending | Sign-in codes, bond invites, and article emails | Recipient email address, message content, and delivery metadata |
| Apple Maps / MapKit | Birth-place search | The search query and the place you select; not your live device location |
| Cloudflare D1 (SQLite) | Relational database | All stored account and application data |
| Cloudflare KV | Content caching | AI-generated content fragments |
| Cloudflare Workers | Application hosting | All API request data |
| Cloudflare Analytics Engine | First-party product analytics | Event metadata described in Section 3.9 |
| Cloudflare AI Gateway | AI model routing | Birth-chart summaries, question text |
| Jyotish Ganit API | Birth-chart calculation | Birth date, time, and geographic coordinates of the selected place |
| Apple Push Notification service | Delivering push notifications | Device token and notification payload |
| Apple App Store (In-App Purchase) | Subscription billing on iPhone | Transaction identifiers and subscription status. Payment details stay with Apple. |
| Razorpay | Subscription billing on the web (India) | Name, email, subscription and payment identifiers, and payment status. Card, UPI, and net-banking details stay with Razorpay. |
| PayPal | Subscription billing on the web (international) | Name, email, subscription identifiers, and payment status. Payment details stay with PayPal. |
All data stored in Cloudflare infrastructure is encrypted at rest by Cloudflare. Cloudflare's privacy practices are governed by the Cloudflare Privacy Policy.
8. Data Retention
| Data category | Retention period |
|---|---|
| Account and authentication data | Retained while the account is active |
| Birth profile and chart data | Retained while the account is active |
| AI-generated articles and content | Retained while the account is active; cached fragments expire per their TTL |
| Questions and AI answers | Retained while the account is active |
| Bond relationship and counterpart birth data | Retained while the account is active; deleted when the account is deleted |
| Bond invitation data (invitee email, status) | Retained while the account is active or until the invite is resolved |
| Reading progress | Retained while the account is active |
| In-app notifications | Retained while the account is active |
| Email article preference | Retained while the account is active, or until you unsubscribe |
| Device tokens | Retained while the device is registered; removed when the token is invalidated or the account is deleted |
| Skybond+ subscription records | Retained while the account is active |
| Session data (IP, user agent, token) | 30 days from session creation |
| Data following account deletion | All personal data we hold is purged within 30 days |
We retain data only as long as necessary to provide the Service or as required by law. Apple may retain App Store purchase records under Apple's policies. Razorpay and PayPal may retain payment records under their policies. We do not control those.
9. Data Security
We implement the following technical and organisational safeguards:
- Encryption at rest — data in Cloudflare D1 and KV is encrypted at rest by Cloudflare's infrastructure.
- Encryption in transit — communication with our API uses HTTPS/TLS.
- Authentication — sign-in is via Sign in with Apple, Google, or an email one-time passcode; session tokens are signed with a server-side secret; the iOS app stores the session token in the Keychain and the web app stores it in the browser.
- Origin restriction (CORS) — API access is restricted to authorised origins.
- Rate limiting — Ask requests are rate-limited per user per day.
- Access control — API endpoints (except public health and legal endpoints) require a valid authenticated session.
- Analytics hygiene — client analytics properties that look like personal content are rejected.
No system is entirely secure. If you discover a security vulnerability, please report it to [email protected].
10. Your Rights
Under the DPDP Act, 2023 (and where applicable, the GDPR):
| Right | How to exercise |
|---|---|
| Access — obtain a copy of your personal data | Export My Data in Profile shares a PDF of the records listed below |
| Correction — correct inaccurate data | Contact [email protected]. Birth details are not currently editable in the app after onboarding |
| Erasure — delete your account and all associated data | Delete Account in Profile |
| Data portability — receive your data in a structured, machine-readable form | The same export is available as JSON. Contact [email protected] and we will provide it |
| Withdraw consent | Delete your account |
| Grievance redressal (DPDP Act) | Contact the Grievance Officer (Section 15) |
Export My Data includes your account profile, birth and custom profiles (including stored charts), bonds and invitations, questions and answers, personalised articles, reading progress, in-app notifications, and email notification settings.
It does not include device tokens, Apple, Razorpay, or PayPal subscription transaction records, session logs, or analytics events. Subscription status is visible in Billing, in your Apple ID for App Store plans, and in Razorpay or PayPal receipts for web plans. You may request the omitted records from [email protected].
We will action your request within 72 hours of receipt.
Deleting your Skybond account permanently erases the personal data we hold. It does not cancel Skybond+. Cancel an App Store plan in your Apple ID settings. Cancel a web plan from Billing.
11. Bonds Feature — Third-Party Personal Data
Bonds let you explore compatibility with another person. You may invite someone who uses Skybond, or enter their birth details yourself. In either case, you represent and warrant that:
- You have obtained the explicit, informed consent of that person to process their personal data on Skybond — including when you invite them by email or enter their birth details on their behalf.
- That person is 13 years of age or older.
- You will delete the Bond or cancel the invitation — thereby removing their data from our system — if they withdraw consent.
We cannot independently verify this consent. If you receive a complaint from someone whose data you have entered or whose email you have used without consent, you are solely responsible. You may contact [email protected] and we will remove the data upon verification.
12. Children's Privacy
Skybond is not directed at children under 13 years of age. You must be at least 13 to create an account. We do not knowingly collect personal data from children under 13. If you believe we hold data from a child under 13, contact [email protected] and we will delete it promptly.
13. Cross-Border Data Transfers
Your data is stored and processed on Cloudflare's global infrastructure, which may involve transfer to servers outside India. Sign in with Apple, Google sign-in, Apple Maps, Apple Push Notification service, App Store billing, Razorpay billing, and PayPal billing may also process data on Apple's, Google's, Razorpay's, or PayPal's infrastructure in other countries. Such transfers are subject to the safeguards those providers apply, including standard contractual measures where used.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via the app or by email to your registered address. Continued use after the updated effective date constitutes acceptance.
15. Grievance Officer
As required by the DPDP Act, 2023, our designated Grievance Officer is:
| Name | Akshay Dhiman |
| [email protected] | |
| Address | 288, Bank Enclave, Laxmi Nagar, Delhi, India 110031 |
| Response time | Within 72 hours of receipt of complaint |
If your grievance is not resolved satisfactorily, you may lodge a complaint with the Data Protection Board of India under the DPDP Act.
16. Contact
Privacy: [email protected] Support: [email protected] Address: 288, Bank Enclave, Laxmi Nagar, Delhi, India 110031 Website: https://getskybond.com