Trikona Privacy Policy
1. Who this policy covers
Trikona is a practice tool for astrologers. This policy describes what we collect about you, the practitioner (your account), and how we handle your clients' birth data on your behalf — the two are different relationships, covered separately below.
2. Your account data (we are the data fiduciary)
For your own account we act as the Data Fiduciary under the Digital Personal Data Protection Act, 2023: your email address, a hashed authentication token, subscription tier, and — if you compute your own chart — your own birth details. This data is used to run your account, authenticate you, and operate your subscription.
3. Your clients' data (we are a data processor)
When you add a client — their name, birth date, birth time, birth place, and any consultation notes — you are the data fiduciary for that record; you are responsible for having a lawful basis (typically consent) to hold it and for telling your client what you use Trikona for. We process it only on your instructions: to compute the chart, keep it available in your client list, and act on your export/delete requests. We do not use client records for any purpose beyond running the product for you, and we do not sell any data.
4. Encryption and storage
Personally-identifying fields (names, birth details) are encrypted at rest; the database never stores this data in plaintext. API tokens are stored hashed and shown to you once at issuance. Data resides on infrastructure the operator controls (Railway, with a persistent volume); backups are retained on a rolling window.
5. Export and deletion
You can delete a client record at any time from inside Trikona
(DELETE /v1/clients/{id}), which removes that client's stored data. To export
or delete your entire account — including every client record you hold — email
[email protected]; we acknowledge such requests within 24 hours and complete them within 15 days.
If you delete a client record on a client's instruction to you, that satisfies your obligation
as their data fiduciary; we do not independently retain a copy after deletion, other than
backups that roll off the retention window above.
6. Who else sees this data
Payments are processed by Razorpay; we do not store your full card details. Infrastructure is hosted on Railway. We do not sell data to third parties, run third-party advertising, or use your clients' birth data or notes to train any model beyond what is needed to generate your own session's chart output.
7. Your rights
As a data principal under the DPDP Act, you can access, correct, or erase your own account data, and withdraw consent, by writing to [email protected]. As the data fiduciary for your clients, the same rights belong to your clients through you — Trikona gives you the export/ delete tools to honor those requests; the underlying obligation to your client is yours.
8. Changes to this policy
We may update this policy; the effective date above changes when we do, and we will notify you in-app or by email of material changes before they take effect.
9. Contact
Privacy questions or data-rights requests: [email protected]. General support: [email protected]. See also our Grievance Redressal & Contact page.