Privacy Policy
Last updated: August 2026
MKundali is a Vedic astrology web application operated by Mamgain.app. This Privacy Policy explains how we collect, use, store, and protect information when you use MKundali.
1. Information We Collect
Depending on how you use MKundali, we may process:
- Account information — email address, username, display name, password hash, OAuth identifier (if you use Google Sign-In), subscription tier, trial status, and account status fields.
- Birth and chart data — birth date, birth time, birthplace or city, geographic coordinates, timezone or GMT offset, and other inputs needed to calculate charts.
- Saved content — charts you save, calculation preferences, life-event notes, and related metadata for signed-in users.
- Payment-related information — subscription plan, billing cycle, subscription status, order and subscription identifiers, and payment confirmation references from Razorpay. We do not intentionally collect or store full payment credentials on our servers.
- Technical and operational data — IP address, request timestamps, error details, and security or rate-limiting logs generated when you use the service.
- Device/browser data stored locally — session token, theme, and interface preferences stored in cookies or localStorage on your device.
MKundali does not display advertising and does not use third-party advertising trackers.
2. How We Use Your Information
We use the information above to:
- create and manage your account and authenticate sessions;
- calculate, display, save, and retrieve charts;
- apply your preferences and personalize the interface;
- process subscription purchases and maintain paid access periods;
- send account-related email such as verification and password reset;
- operate, secure, troubleshoot, and improve the service;
- detect abuse, enforce limits, and prevent fraud or unauthorized access.
We do not sell your personal data.
3. Account Information
When you register or sign in, we store the information needed to operate your account. Local email/password accounts require email verification before full access. Google Sign-In is optional and links your Google account identifier to your MKundali profile.
You are responsible for keeping your sign-in credentials secure. We may suspend accounts that violate our Terms of Service or pose a security risk.
4. Birth Charts, Birth Data & Notes
Chart generation requires birth details and location/timezone information. These inputs are processed on our servers to produce astrological calculations and related outputs.
Signed-in users on eligible plans may save charts to their account library, store preferences, and attach life-event notes. Guest users can calculate charts without an account, but guest sessions are not maintained as a personal saved-chart library.
We use saved chart and note data only to provide the features you request. We do not use birth data for advertising.
5. Cookies, Local Storage & Technical Logs
On your device, we use cookies or localStorage to keep you signed in, remember theme and UI preferences, and support basic app functionality.
On our servers, we maintain operational and security logs (for example error records and rate-limit events). These logs help us keep the service reliable and secure. They are not used as product analytics or advertising profiles.
Registration, password reset, and resend-verification flows may use Cloudflare Turnstile for bot protection. Turnstile may process technical signals according to Cloudflare’s policies.
We do not place third-party advertising cookies.
6. Payments and Third-Party Services
MKundali relies on the following third-party services. Each provider processes information under its own privacy policy:
- Razorpay — processes recurring subscription payments on our behalf. Razorpay processes recurring payments according to your subscription schedule. Unless you cancel your subscription before the applicable renewal, recurring payments may continue until the subscription is cancelled or otherwise ends. We receive the information necessary to manage subscription status and paid access (such as plan, billing period dates, and payment confirmation references). We do not intentionally collect or store full payment credentials on our servers.
- Resend — delivers verification and password-reset email.
- Google OAuth — optional Google Sign-In.
- OpenStreetMap Nominatim (via our geocoding integration) — city and location lookup used to obtain geographic coordinates. Timezone information may be obtained through the application’s location and timezone data sources.
- Supabase-hosted PostgreSQL — production database hosting for accounts, subscriptions, saved charts, and related application data.
- Cloudflare Turnstile — bot protection on selected authentication forms.
When you use these services, some information is shared with the provider as needed for that function. We choose providers that help us deliver the service; their handling of data is governed by their own terms and privacy policies.
7. Data Retention and Deletion
We retain account, subscription, saved-chart, and preference data while your account remains active and as needed to provide the service.
If you request account deletion, or if an administrator deletes your account, associated application data such as saved charts and preferences is removed from our active systems when the deletion is processed, except where retention is required or permitted by applicable law — including for legal, accounting, security, fraud-prevention, or dispute-resolution purposes.
Guest calculations are processed to deliver results for that session and are not stored as part of a personal chart library.
Operational logs are retained for a limited period needed for security and troubleshooting, then rotated or removed according to our logging practices.
8. Your Privacy Rights
Depending on applicable law, you may have rights to:
- request information about the personal data we hold about you;
- request correction of inaccurate account information;
- request deletion or erasure of your personal data, subject to legal exceptions;
- withdraw consent where processing is based on consent and withdrawal is permitted by law;
- raise a privacy grievance with us.
To exercise these rights, email [email protected] from your registered email address. We may need to verify your identity before fulfilling a request.
9. Data Security
We use reasonable technical and organizational safeguards designed to protect personal data — including access controls, encrypted transport (HTTPS), and hashed password storage for local accounts. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Children’s Privacy
MKundali is a general-purpose service and is not directed at children under 18. We do not knowingly seek to collect personal data from children. If you believe that a child has provided personal data to us, please contact [email protected].
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top will indicate when the policy was most recently revised. Where appropriate, we may also provide notice of material changes through the service or by email.
12. Contact and Grievance Redressal
Privacy questions and grievance requests: [email protected].
Please include enough detail for us to identify your account and understand your request. We will review and respond to privacy and grievance requests within the timeframe required by applicable law.