Privacy Policy
Last updated
This policy explains what we collect when you use the Occult API, why we collect it, and what we do with it. It covers this website and the API.
1. Who is responsible
Yoga Panchang operates the Occult API and is responsible for the data described here. Contact us at admin@yogatara.app.
2. What we collect
Account details. Your name and email address. If you sign in with Google or GitHub we receive your name, email address and profile picture URL from them — nothing else, and we never receive your password. We only accept an email address that the provider reports as verified.
Usage records. For every API call: which endpoint was called, when, the HTTP status, and the credits it consumed. This is what your usage page and your ledger are built from, and it is how a billing question can be answered.
Payment records. Which pack you bought, when, the amount, and the payment reference. Card details are handled entirely by Razorpay and never reach our servers.
Optional onboarding answers. Your role and what you are building, if you choose to tell us. Skipping is fine and changes nothing about the service.
3. What we do NOT collect
We do not store the contents of your API requests. The dates, times and coordinates you send are used to compute a response and are not retained afterwards — so the birth details of your own users never sit in our database. Only the metadata in section 2 is kept.
We do not store your API keys. They are hashed with SHA-256, which is why a key cannot be shown to you again after it is created.
4. Why we use it
- To give you access to the API and run your account.
- To meter credits, so you are charged correctly and can audit it.
- To process payments and issue receipts.
- To contact you about service matters — a failed payment, a low balance, a change to these terms.
- To keep the service secure and investigate abuse or a leaked key.
5. Who we share it with
Razorpay, to take payments. Google Analytics, for aggregate traffic statistics about this website. Our hosting and email providers, to the extent needed to run the service.
We do not sell personal data, and we do not share it for advertising.
6. Cookies and analytics
We set a session cookie when you sign in. It is httpOnly, so it cannot be read by scripts, and it exists solely to keep you signed in.
Google Analytics sets its own cookies to measure visits. If you would rather not be measured, a browser-level analytics blocker prevents it and nothing on the site stops working.
The API playground stores the API key you type in your browser’s sessionStorage so you are not retyping it as you move between endpoints. It is per-tab, cleared when the tab closes, and never sent to us except as the header of the request you asked us to make.
7. How long we keep it
Account details for as long as the account exists. Usage and payment records are kept while the account exists and afterwards for as long as tax and accounting rules require, because they are the record of a transaction.
8. Your rights
You can ask for a copy of the data we hold about you, ask us to correct it, or ask us to delete your account. Write to admin@yogatara.app. Deleting an account removes your profile; transaction records are retained where we are legally required to keep them.
9. Security
Traffic is served over HTTPS. Keys are stored only as hashes, sessions use httpOnly cookies, and payment card data never touches our systems. No system is perfectly secure, so please report anything that looks wrong to the address above.
10. Changes
If this policy changes materially we will update the date at the top and email account holders. See also our Terms of Service.