Privacy Policy

Last updated: July 2026

This Privacy Policy explains how we collect, use, share, and protect your personal data when you use Solis. It is written to meet our obligations under India's Digital Personal Data Protection Act, 2023 (“DPDP Act”), the EU and UK General Data Protection Regulation (“GDPR”), and the California Consumer Privacy Act as amended (“CCPA/CPRA”). Please read it together with our Terms of Use.

1. Who We Are

Solis is operated by SOLIS Intelligence Private Limited, a company incorporated in India under the Companies Act, 2013, with its registered office at Noida, Uttar Pradesh, India (“Solis”, “we”, “us”). For data-protection purposes we are the Data Fiduciary under the DPDP Act and the Data Controller under the GDPR.

Grievance Officer / Data Protection contact: Poornima Verma, reachable at solis.contactus@gmail.com. We acknowledge grievances within 48 hours and endeavour to resolve them within 30 days. We do not currently operate an establishment in the EU or UK; EU/UK users may still contact us at the address above.

2. The Personal Data We Collect

(a) Data you provide:

  • Account details: phone number or email address.
  • Birth details: full name, date of birth, birth time (optional), and birth place. These are used to compute your astrological profile, and we treat them with care.
  • Additional birth profiles you create for other people.
  • The content of messages you send to our AI guides (Archi, Nova and others), and any voice input you record.
  • Feedback and ratings you submit.

(b) Data we collect automatically:

  • Session and authentication data (see Cookies, Section 9).
  • Device and usage information, and product-analytics events about how you use the app (see Cookies, Section 9).
  • IP address and browser/user-agent, recorded for security and referral integrity.
  • Payment-related information when you purchase credits, processed by our payment provider (we do not store full card details).

(c) Data we derive about you: From your birth details we compute and store your Vedic birth chart, a long-range planetary (dasha) timeline, and inferred profile models describing personality themes and life-area emphasis (for example career, relationships, health and finances). These are software-generated inferences for the purpose of providing readings, not statements of fact about you.

3. Why We Use It, and Our Legal Basis

  • To provide the service (compute your chart, generate readings, maintain conversation continuity, process payments). Legal basis: performance of our contract with you; under the DPDP Act, your consent.
  • To use your birth details to compute your chart and generate astrological, numerological and reflective guidance — the core service you ask us for. Legal basis: performance of our contract with you; under the DPDP Act, your consent.
  • To secure accounts and prevent fraud and abuse (including referral integrity). Legal basis: our legitimate interests; legal obligation where applicable.
  • To understand and improve the product through anonymous, aggregated analytics. We configure our analytics so events are not linked to your identity, so this does not process your personal data and does not rely on your consent.
  • To communicate with you about your account and, where you opt in, via WhatsApp. Legal basis: consent and/or legitimate interests.
  • To measure and improve our advertising, we share a limited set of events — that you opened the app and that you completed sign-up — with Meta (Facebook), so we can understand which campaigns bring new users and reach similar audiences. We do not share your birth details, the content of your readings, or any sensitive data for this purpose. Legal basis: your consent, which we ask for before any advertising cookie or pixel loads. You can withdraw it at any time (see Sections 9 and 11).

4. Handling Your Birth Details

You give us your birth details — name, date of birth, and optionally time and place of birth — so we can compute your chart and generate the readings you ask for. We use them only for that purpose and to run the service, and we do not consider them, in themselves, to be special-category data under the GDPR. Some readings or messages you choose to share may touch on themes such as beliefs, health or relationships; you decide what to share, we use it only to provide the readings you request, and you can delete this data or your account at any time (see Section 11).

5. Automated Processing and Profiling

Solis uses automated software to profile your birth chart and generate personalised guidance. These readings are intended for personal reflection, self-awareness and entertainment, and do not produce legal or similarly significant effects. You may object to this profiling or ask questions about it by contacting us at solis.contactus@gmail.com.

6. Who We Share It With

We share the minimum data necessary with the service providers (sub-processors) below. We do not sell your personal data. We share a limited set of sign-up and page-view events with Meta for advertising measurement, as described below and in Section 9; we never share your birth details, the content of your readings, or any sensitive data with advertisers.

  • Anthropic (Claude AI) — United States: your messages, conversation history and the birth-chart context needed to answer you are sent to Anthropic to generate responses. Anthropic does not use data submitted through its API to train its models.
  • Google Firebase Authentication — United States: verifies your phone number or email when you sign in.
  • PostHog — United States: product-analytics provider that receives anonymous product-usage events — with no account identifier — so we can understand and improve the app.
  • Meta Platforms (Facebook) — United States: when you open the app and when you complete sign-up, we send Meta a page-view event and a registration event, together with online identifiers such as a cookie ID, your IP address and your browser/user-agent, so we can measure and optimise our sign-up advertising. We have switched off Meta’s automatic data-collection features, and we do not send Meta your name, birth details, readings, or any sensitive data.
  • Razorpay — India: processes payments when you buy credits.
  • Groq — United States: transcribes voice input you choose to record.
  • ElevenLabs — United States: converts the text of voice readings into spoken audio when you use a voice guide.
  • OpenStreetMap (Nominatim): receives the name of your birth place to look up its geographic coordinates for chart calculation.
  • Our birth-chart computation service and database hosting provider (Turso, hosted on AWS in Mumbai, India): store and process your data to operate Solis.

We may also disclose data where required by law or to protect our rights, users or the public.

7. International Transfers

Some of the providers above process data outside your country, including in the United States. Where we transfer personal data internationally we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses and equivalent contractual commitments from our providers. Under the DPDP Act, transfers are made only to countries that are not restricted by the Government of India.

8. How Long We Keep It

  • Account and birth-profile data: kept while your account is active.
  • Chat messages: kept for conversation continuity until you delete them or close your account.
  • Birth charts and timelines: cached for performance and deleted when you delete the related profile.
  • Tarot sessions: ephemeral and not stored.
  • Payment and transaction records: retained as long as required by tax and accounting law.

When you withdraw consent or close your account, we delete or anonymise your personal data unless we are legally required to retain it.

9. Cookies and Analytics

Essential cookies: solis-session (HttpOnly, 90-day expiry) keeps you signed in, and solis-ref (up to 60 days) supports referral and gift links. These are necessary for the service and are always active.

Analytics: we use PostHog to understand how the app is used so we can improve it. We configure it to be anonymous — we do not create user profiles or link analytics events to your account. Because this data does not identify you, it does not rely on your consent; you can still block analytics storage through your browser settings.

Advertising and measurement: we use the Meta (Facebook) Pixel to measure how effective our sign-up advertising is. The pixel loads only after you accept it on the consent prompt shown on your first visit — if you decline, it never loads and no data is sent to Meta. Once accepted, the pixel sets a first-party cookie (_fbp) and reports a page-view event and a sign-up event to Meta, along with online identifiers, which Meta may use for cross-site advertising measurement. We have switched off Meta’s automatic advanced matching, so the pixel does not read or transmit anything you type into forms, including your birth details. You can withdraw consent at any time by clearing this site’s data in your browser, and you can also opt out through your Meta ad settings or industry tools such as the Digital Advertising Alliance opt-out.

10. Security

We protect your data with reasonable technical and organisational safeguards, including HTTPS/TLS encryption for all data in transit, access controls, authentication through Firebase, and secrets held in protected configuration. We do not store passwords. No system is perfectly secure, and we continue to strengthen our safeguards. If a personal-data breach occurs, we will notify the Data Protection Board of India, affected users, and any other supervisory authority as and when required by law.

11. Your Rights

Subject to applicable law, you have the right to:

  • Access the personal data we hold about you and information about its processing.
  • Correct inaccurate or incomplete data, and erase your data.
  • Withdraw consent at any time — this is as easy as giving it — and to restrict or object to certain processing.
  • Data portability: receive your data in a portable format (GDPR).
  • Nominate another person to exercise your rights in the event of death or incapacity (DPDP Act).
  • Opt out of any “sale” or “sharing” of personal data and limit the use of sensitive personal information, and not be discriminated against for exercising your rights (CCPA/CPRA). We do not sell your data; we do share limited advertising-measurement events with Meta, as described in Sections 6 and 9, and you can opt out of this sharing by emailing us or using your browser’s cookie controls.

To exercise any of these rights, email solis.contactus@gmail.com. We will verify your identity and respond within the timelines required by law. You can also withdraw consent or request deletion from within the app where those controls are available.

12. Children

Solis is intended for users aged 18 and above, and by using Solis you confirm you are at least 18. We do not knowingly collect personal data from anyone under 18, and we do not direct profiling or behavioural tracking at children. If you believe a minor has provided us data, contact solis.contactus@gmail.com and we will delete it.

13. Grievances and Complaints

If you have a concern about how we handle your data, contact our Grievance Officer at solis.contactus@gmail.com and we will respond within the period required by law. You also have the right to complain to the Data Protection Board of India, and (for EU/UK users) to your local data-protection supervisory authority, and (for California users) to the California Privacy Protection Agency or Attorney General.

14. Changes to This Policy

We may update this policy from time to time. If we make material changes, we will notify you and, where the law requires, ask for your fresh consent before the change affects you. The “Last updated” date above shows when this policy last changed.