Privacy Policy
This policy explains how Das Creative LLC handles personal information when you use Zohvia. Birth date, exact birth time, place, and relationship context deserve particular care. This policy describes the current web product; it does not claim certification or compliance with every privacy law.
1. What stays in the browser and what is sent
The optional Search with OpenRouteService button sends the search text you entered to Zohvia's server, which forwards it to OpenRouteService (operated by HeiGIT) to suggest birth-site coordinates. This includes anything you put in that search field; include only the place to look up. The provider request contains that text and a result limit, authenticated with Zohvia's service credential. The provider sees Zohvia's server network address. Zohvia does not forward your browser's IP address, referrer, account/session identifier, or the other birth-profile fields. The hosting service receives your lookup request and operational network data as described below. You can use the bundled city/timezone selector and enter coordinates yourself without external lookup.
Information is sent to our servers when you deliberately use an available server-backed action, including when you:
- request an external birth-site lookup;
- sign in or use account export or deletion;
- start checkout, manage a subscription, or request payment support;
- create, view, download, share, revoke, or correct a paid report;
- contact support or submit a product-research form; or
- allow optional first-party analytics.
Hosted AI is disabled. The current Service does not send names, birth details, report facts, compatibility facts, or questions to an AI provider.
2. Information we handle
Birth and report information
A calculation uses the name you enter, birth date, exact birth time, birth place, timezone, derived coordinates, derived chart facts, selected preferences, and—when matching—the same categories for another adult plus your confirmation of permission. Saved reports and links contain the inputs and calculated report facts needed to render the requested report scope.
Account, purchase, and support information
- Account identifier, email, sign-in-provider data, session data, and account timestamps;
- Stripe customer, checkout, payment, refund, dispute, amount, currency, product, and entitlement references;
- Support messages and practitioner or business research responses you choose to submit; and
- Security and operational data such as request timing, transient network address, rate-limit keys, and sanitized errors.
Zohvia does not receive or store your full payment-card number; Stripe collects payment details in its checkout.
Your browser can store theme and text-size preferences, the accepted Terms and Privacy Policy versions and acceptance time, and your analytics choice. If analytics is allowed, the browser also stores the pseudonymous identifiers described below. Moving a result from an inline calculator into the app uses same-tab navigation state that is scrubbed on arrival. During same-tab sign-in for a pending paid export, Zohvia can keep that pending calculation—including entered birth details—in tab-scoped session storage for at most 15 minutes; it is consumed on return or discarded when invalid or stale. A Stripe checkout-return identifier can also remain in tab-scoped session storage until verification. Free calculation does not otherwise persist birth details, chart facts, or compatibility results in local or session storage.
3. How we use information
- to provide the calculation, report, PDF, share, correction, account, purchase, refund, and deletion actions you request;
- to confirm account and report ownership and prevent unauthorized access;
- to process payment and maintain transaction and entitlement records;
- to enforce consent, rate limits, security controls, and acceptable-use rules;
- to investigate errors and provide support; and
- with separate permission, to understand pseudonymous product usage.
We do not sell birth details or use them for third-party advertising. Zohvia's astrology output does not make legal or similarly significant automated decisions about you.
4. No hosted AI processing
Hosted AI is not included in Zohvia Plus or either one-time report product. The release requires AI feature flags to be off and no AI-provider credential to be configured. Any future AI feature requires a separately reviewed product contract and privacy disclosure before an intentional action can send data to a provider.
5. Optional pseudonymous analytics
Analytics is off until you allow it. If allowed, Zohvia creates random browser and tab-session identifiers and records consent version/time, a non-secret route template, selected supported language, and coarse product-action names. With the September 5 analytics choice, this also includes a 20-by-20 click grid within selected public navigation, hero, pricing, and footer sections, a mobile/tablet/desktop viewport class, and fixed browser error categories. We do not record sessions, DOM text, form contents, error messages, or stack traces. Click maps exclude calculators, reports, account dialogs, and unmarked sections. The analytics allowlist does not accept names, email addresses, birth date/time/place, partner identity, compatibility scores, dosha flags, report-link identifiers, raw URLs or referrers, campaign parameters, Checkout or Stripe identifiers, payment events, or raw chart placements. These events are stored in Zohvia's Supabase database.
Use the persistent Privacy choices control to withdraw. Withdrawal stops optional capture across open tabs, clears queued events and local identifiers, and requests erasure of events associated with the current browser identifier, including when signed out. Failed erasure requests are retried when connectivity returns. Events become eligible for the daily deletion job after 400 days; a SHA-256 withdrawal marker prevents delayed batches from recreating erased records. Other browsers cannot be linked without their identifier. Private operator reports contain only aggregate counts and click grids.
6. Service providers
| Provider | Current role | Information involved |
|---|---|---|
| Supabase | Authentication, database, and report storage | Account, saved report, entitlement, transaction, historical research, and consented analytics records |
| Vercel | Web hosting and server functions | Requests, responses, and operational network data needed to serve an action |
| OpenRouteService / HeiGIT | Optional birth-site geocoding after the search button is chosen | Entered search text, result limit, Zohvia's service authentication, and Zohvia's server network data; other birth-profile fields and browser identifiers are not forwarded |
| Stripe | Checkout, subscription management, payment, refund, dispute, and transaction support | Account and transaction references plus contact and payment details supplied directly to Stripe |
| Upstash or Supabase | Durable abuse and rate limiting, depending on configuration | Pseudonymous security keys and request counters |
| Sentry (when configured) | Sanitized server error reporting | Error type, scrubbed message, and allowlisted shallow context; no request body by application design |
Providers process information under their own terms and locations. Information may therefore be processed in the United States or other countries. We do not claim a transfer mechanism or contractual protection that has not been separately verified for the production account.
7. Retention and deletion
The geocoding handler does not save query text or lookup results to Zohvia's database, application logs, or analytics. Queries and results remain in page memory while needed for the lookup; edits clear earlier results. Hosting and geocoding providers may handle request logs under their own settings and policies. Cancelling a pending lookup prevents its results from being used; it cannot recall a request already sent.
- Browser-only calculation inputs remain in the page state unless you invoke a server-backed action.
- Account records remain while needed to provide the account or until you delete the account, subject to the limited financial/legal exceptions below.
- Each share link has a finite expiry. Owner revocation hard-deletes that stored report and its corrections immediately; expired or legacy-revoked reports are hard-deleted by a daily bounded retention job.
- Research submissions and support correspondence remain while needed to evaluate or answer them, subject to deletion requests and legal obligations.
- Transaction records may be de-identified rather than deleted where needed for payment, fraud, tax, accounting, or dispute records.
- Provider logs, fraud records, and backups follow provider settings and legal requirements and may persist for a limited period after active deletion.
We do not promise an unverified backup-purge interval or fixed response time. See Data & Account Deletion for the implemented account controls.
8. Security
Zohvia uses HTTPS in transit, server-side session verification for protected actions, owner-scoped data access, payment webhook signatures, rate limiting, and sanitized error reporting. Full card details go directly to Stripe. Application-level field encryption for birth data is not currently claimed. No service is perfectly secure; protect your sign-in method and avoid sharing a report link more widely than intended.
9. Your choices and requests
Depending on where you live, applicable law may provide rights to access, correct, export, delete, object to, restrict, or withdraw consent for certain processing. Signed-in users can request a JSON export or account deletion from the account menu. You may also email us. We verify identity and another person's authority before disclosing or deleting account data. Legal exceptions may apply.
10. Adults only
Zohvia is intended only for people aged 18 or older. Do not submit a child's birth details. If you believe a child provided information, email us so we can investigate and remove it where appropriate.
11. Changes and versioned consent
We may update this policy. The date above identifies the version presented in the product. When the version changes, Zohvia requires acceptance of the current Terms and Privacy Policy before continued product use.
12. Contact
Das Creative LLC — operator of Zohvia
Privacy, export, deletion, and support: support@das.media
See also: Terms of Service · Refund Policy · Data & Account Deletion · Disclaimer