Privacy
Privacy policy
Last updated 20 September 2026.
The short version: your birth date and time are used to calculate your chart in this browser, on your own device, and never leave it. The one thing about a birth that travels anywhere is the place name you type, which your browser sends straight to a mapping provider to turn into coordinates — never through a server of ours. For anonymous visitors — everyone, today — we store nothing at all about you on our servers. The rest of this page is the detail behind those sentences, including the two honest caveats: the mapping provider, and the AI provider we currently use.
The chart is computed on your device
The chart is computed in the browser. The birth moment never enters a network request. The server receives a derived chart — sign and house positions, nakshatra, dasha periods — and nothing else: no name, no account, no email, no birth date field, no coordinates and no UTC offset. The full technical account, including exactly what is and is not sent, is on the method page.
The one exception, which changed on 20 September 2026. To turn the place name you type into the coordinates a chart needs, that name alone is sent from your browser directly to a mapping provider — with no date, no time, no name and nothing that identifies you attached, and never through a server we run. Until that date, place search ran against a dataset downloaded into your browser, and this site described that search as reaching no one at all. That is no longer true, so the claim is retired here rather than quietly softened. What is left, and is the whole of the claim now: your birth date and time never leave this device, and nothing about your birth ever reaches a server of ours.
What a precise chart still reveals
A chart precise enough to produce a specific reading is, in effect, the birth moment expressed in another coordinate system — no amount of field-name hygiene changes that. Positions are rounded to one degree and no true mahadasha start date is ever sent, which brings the birth instant an analyst with an ephemeris could reconstruct from the sent chart down to roughly nine minutes, for someone who already knows the birth city. Birth place is far less exposed: positions are geocentric, so place is constrained only through the lagna, to a longitude band thousands of kilometres wide. Nothing that identifies a person is ever sent — no name, no account, no email, no IP-linked session — and a reading cannot be tied to anyone without data we do not hold and never collect. The birth moment never travels as a field, though a precise chart does narrow it. See the method page for how that number was measured.
The AI provider — the one real caveat
Readings are generated by Google’s Gemini API on the free developer tier, and on the free tier Google may use request data to improve their products. The paid tier is exempt. This touches one of this product’s stated pillars, so it is disclosed here plainly rather than glossed over:
Your birth date and time are used to calculate your chart in this browser and never leave this device. The place name alone is sent from your browser to our mapping provider to turn it into coordinates — never through a server of ours, and never with your date or time attached. The finished chart — planetary positions only, with nothing that identifies you — is sent to Google’s Gemini API to write your reading. We currently use Google’s free developer tier, which means Google may use that chart data to improve their models. Your name, your birth date and your location are never part of it.
When we move to a paid tier, that last sentence goes away — a genuine, non-cost reason to upgrade, and something we will update this page to reflect the day it happens.
What we collect, by category
| Data | Leaves your device? | Retention |
|---|---|---|
| Birth date and time | Never | Kept on your device only, until you clear it |
| The birth place name you type | Yes — from your browser to a mapping provider, to get coordinates. Never to us | We never receive it and never store it; the provider’s own retention applies |
| Coordinates and time zone, once resolved | Never | Kept on your device only, until you clear it |
| Derived chart (signs, houses, nakshatra, dasha) | Yes — to generate a reading | Never written to a database or a log by us |
| Generated readings | Produced by the server, returned to you | Yours on your device; also held in the server’s memory for about a day, to avoid spending the same capacity twice |
| Whether a reading resonated, if you say | Never | Not stored at all today — it lives only on the open page |
| Your IP address, when you ask for a reading | Used to count requests against a daily limit, never as itself | Held in server memory, or as a keyed one-way hash in a counter that expires within a day. Never logged, never attached to a chart or a reading |
| Payment information | Not collected | Jataka is free; there is nothing to collect |
Three rows deserve a sentence more than a table cell gives them. Readings are held in the generating server’s own memory for roughly a day, indexed by a fingerprint of the chart rather than by the chart itself, so that asking for the same reading twice does not spend a second slice of a daily capacity somebody else needs. Nothing there is written to disk, nothing is logged, and a restart loses all of it. Your IP address is used to stop one visitor exhausting that capacity for everyone, and for nothing else: on a single server it sits in memory and dies with the process; where a shared counter is configured, what is written is a keyed one-way hash of the address, not the address, and the counter expires on its own within the day. Ratings — the “did this resonate?” question — are not recorded anywhere at all yet; the answer lives on the open page and is gone when you leave it.
No behavioural analytics, error-monitoring or email vendor is connected to this product today. If that changes, this page will say which vendor, what it receives, and why — before it ships, not after.
Who else is involved
Four companies touch this product. None of them is sent anything that names you.
- Vercel hosts the site and runs the one server-side endpoint, so it sees the ordinary connection facts any web host sees — an IP address, a URL, a user agent.
- Geoapify, with map data from OpenStreetMap, answers the birth-place search. It receives the place name your browser sends it, and nothing else about you from us.
- Google receives the derived chart, and only when you ask for a reading. See the caveat above about the free developer tier.
- Upstash, when it is configured, holds the request counters that keep the daily limit honest across servers — as expiring numbers under a keyed hash, never an IP address and never a chart.
Anonymous by default
No account is required for a full reading. There is no account system in this product today: nothing you do here is tied to an email address, a login or a persistent identifier. Your chart and any readings live in your own browser’s storage. Clearing your browser data clears them; there is nothing on our side left to delete, because nothing was stored there in the first place.
Shared reading links
If you choose to share a reading, the link that is generated encodes a small, reduced summary — a few lines you can pick, plus a coarse view of your current planetary period — directly inside the link itself. It is not stored in a database on our side; there isn’t one yet. That means a shared link works without our involvement at all, but it also means it cannot currently be revoked once shared — treat sharing a link the way you would treat sharing a screenshot. A shared link never contains your name, birth date, birth place or full chart. What it does leave open, measured rather than waved away: because the planetary-period wheel is drawn starting from your birth nakshatra’s ruling planet, someone determined could narrow your birth year to a window between six and twenty years wide. No month, no day, no place, no coordinate. Details on exactly what it encodes are on the method page.
When an account appears
An account is planned as an optional way to sync a chart across devices — never required, and never a condition of getting a reading. It does not exist in the product yet. When it does, it will follow the same rule as everything else here: an account will store your derived chart and generated readings, never your birth date, time or place, and self-service deletion will be available from day one. This page will be updated, with a new date at the top, before that feature ships.
Legal basics
- No special-category data. We do not ask for or process health, biometric or belief data. Readings are framed as reflection, not as information about your health.
- No consent banner. We set no advertising or analytics cookies, so there is nothing to ask your consent for.
- No sale or sharing of personal information. There is essentially none to sell — see the table above.
- Age. Jataka is intended for people aged 16 and over (13 and over where locally permitted). We do not knowingly collect data from younger children, and we run no behavioural profiling of any user.
- AI-generated content. Readings are written by an AI model from your chart and are labelled as such wherever they appear.
- Entertainment, not advice. Nothing on this site is medical, financial or legal advice, and no reading predicts, diagnoses or guarantees an outcome. See the terms of service.
- No payments. Jataka is currently free and non-commercial: no paywall, no ads, no affiliate links, and therefore no payment or billing data of any kind.
- Licensing. Birth-place search is answered by Geoapify over map data from OpenStreetMap contributors, licensed ODbL, attributed in full on the method page. The chart engine itself is permissively licensed (MIT); no AGPL or GPL code runs on our server or ships in what your browser downloads.
Who runs this, and which law applies
Jataka is run by one person, Jayathri Ranasinghe, based in Sri Lanka. It is not a company: there is no registered entity, no company number and no registered office. The data-protection law that applies to us is Sri Lanka’s Personal Data Protection Act No. 9 of 2022.
Most of the people this is built for do not live in Sri Lanka, and this site is reachable from the EU and the UK. So the rights below are offered to everyone who asks, wherever you are, rather than only to the people a particular law happens to cover.
Your rights, and the honest limit on them
You can ask us what personal data we hold about you, ask us to correct it, and ask us to delete it. Email privacy@jataka.app. You can also complain to a data-protection authority — in Sri Lanka that is the Data Protection Authority established under Sri Lanka’s Personal Data Protection Act No. 9 of 2022; elsewhere it is your own country’s regulator.
The honest limit is worth stating up front, because it cuts both ways. We have almost certainly nothing to give you and nothing to delete. We hold no account, no email address, no identifier and no cookie that could connect a request to you, so there is no record to look up, and asking us for a copy of your data will usually be answered with an accurate “we hold none.” That is the point of the design, and it is also the reason we cannot verify that a request is yours in the first place. Your chart, your readings and anything you typed live in this browser: clearing this site’s data deletes all of it, immediately, without asking us and without waiting for us.
Questions
Privacy questions, and requests to see, correct or delete data, go to privacy@jataka.app. Anything else — including questions about the terms of service — goes to hello@jataka.app. Both reach the same one person, so a reply takes days rather than minutes.