Effective 19 August 2026
Privacy Policy
BirthIQ AI asks for genuinely personal things: when you were born, where, and some of what has happened to you since. This page explains exactly what we do with that, in plain language rather than legal boilerplate.
Who runs this site
BirthIQ AI is an independent project operated by an individual based in India. It is not an incorporated company. For anything on this page, including data deletion, write to [email protected].
What we collect
Only what the calculation needs. You do not need an account to use the rectification or the kundli, and without one we never ask for your name, email address or phone number. If you choose to create an account, there is a separate short list under Accounts below.
- Birth details. Your birth date, the birth time or time window you believe is right, and your birthplace, which we convert to coordinates and a timezone.
- Life events. For each event you add: a category (such as marriage or a job change), the date, how precisely you know that date, and an optional short label you write yourself.
- Nothing else, unless you sign in. No payment details and no identity documents, ever. Without an account there is no name, email or phone number either.
Anything you type into the optional label is stored as you wrote it, so please leave out details you would not want stored.
What we do with it
We use it to compute your charts and to run the rectification: building a chart for each candidate birth time and scoring it against the events you gave us. That is the whole purpose. We do not sell it, rent it, or share it for advertising, and we never use it to train a machine learning model ourselves.
There is one exception you choose, and it is set out in full under AI assisted intake below: if you switch that on, the text you write in that box is sent to an outside AI provider so it can be read into the form.
Accounts (optional)
You can create an account so your rectifications are saved and reachable from any device, and so you can keep several people (yourself, a spouse, a child) without retyping their details. Everything on this site works without one. There is no password anywhere in this: you prove an address or a number, and that signs you in.
- How you sign in. One of three, and you choose: an email address, a mobile number, or a Google account. We store the address or number you signed in with, so we recognise you next time. From a Google sign-in we store Google’s own account identifier and, when Google says it is verified, the email address on it. We never receive your Google password.
- One-time codes. When you sign in by email or phone we store the destination and a one-way hash of the six digit code, so the code itself is not in our database. These rows are how the five-per-hour limit is enforced, and they are deleted a couple of hours after the code stops working, whether or not you finished signing in.
- People you save. For each saved person: the name and relationship you typed, and their birth date, birth time, birthplace, coordinates and timezone. This is birth data about someone who may not be you, so please only save details you are entitled to hold. It is encrypted at rest exactly like everything else here.
- Your rectification history. Runs you made while signed in, plus any you made beforehand in the same browser and the same sitting, are attached to your account so they appear in your history. You can file each one under a saved person.
- A sign-in cookie. Named
bq_session, set when you sign in and sent back to us on every request while you stay signed in. It holds a random value and nothing else: no name, no email, no birth details. It is HttpOnly, so no script on the page can read it. Signing out ends it on our side as well as removing it from your browser. It lasts 30 days by default if you do not sign out. - Sign-in times and your browser’s user agent are recorded against a session, so an unexpected sign-in is something we could investigate.
Deleting. You do this yourself, from the account page, and it happens at once. Removing a saved person takes that person. Deleting the account takes all of it: the account, its sign-in methods, its saved people, and every rectification with the birth details behind it. Nothing is kept for a waiting period, and any result link you shared stops working immediately. See Your rights.
Backups are the one exception, and we would rather say so than imply otherwise. The database is backed up so that a failed server does not lose everyone’s work. Those backups are encrypted, and they are overwritten on a rolling 14 day cycle, so an account deleted today is gone from the live service at once and out of the last backup within 14 days. We do not restore a backup to bring back an account somebody asked us to delete.
AI assisted intake (optional, off by default)
On the rectification page you can switch on AI assisted and describe your birth and your life events in your own words instead of filling the form field by field. It exists to save typing. The ordinary form does exactly the same job, so you never have to use this, and nothing is sent anywhere unless you switch it on and press the button.
What is sent: the text you type into that box, and nothing else. Not your account, not your email address, not any chart or result you have saved here, and not anything from a previous visit.
Who it goes to: one of the two providers below, depending on how the service is configured at the time. We do not show you which one answered, so please assume either is possible and read both before you use it.
- Google (Gemini). Depending on how the service is configured, Google may use what you send to improve its own models. That is the case on Google's free tier and not on the paid one, and we will not tell you on the page which is running, so assume it may happen. If you would rather it did not, leave the toggle off and use the form, which reaches the same result with no outside provider involved.
- DeepSeek. Used as a fallback when Google is unavailable or over quota. DeepSeek is based in China.
Both providers process your text outside the UK and the EEA.
Please keep this in mind when deciding what to write. Life events can be sensitive: a bereavement, an illness, a hospital stay, a divorce. If you would rather none of that left this site, leave the toggle off and use the form, which reaches the same result with no outside provider involved.
What it does not touch. The rectification itself never uses AI. Your birth time is worked out by the same deterministic engine as always, from planetary positions and fixed astrological rules, and it would produce an identical answer whether you typed the events by hand or had them read in for you. The AI only fills in a form, and you confirm what it filled before anything runs.
How it is stored
- Encrypted at rest. Your birth details, your life events and your rectification result are all encrypted in our database. Someone with raw access to the database file cannot read them.
- That includes the label you write yourself. The category, the date, how precisely you know it and your own wording are encrypted with everything else.
- Stored under an opaque identifier, a random ID with nothing personal in it. Without an account that ID is the only thing the record is filed under. With one it is also linked to your account, so it appears in your history.
- In transit, everything travels over HTTPS.
Your result link is a secret
When a rectification is saved you get a link containing that random ID. Anyone who has that link can open the result, so treat it like a password. We keep those pages out of search engines, but a link you post publicly is public.
Who else touches your data
We keep this list short on purpose.
- GeoNames receives the city name you type into the birthplace search, so it can return coordinates and a timezone. It does not receive your birth date, your birth time or your events.
- Our hosting and database providers store the encrypted data on our behalf and cannot read your birth details.
- Brevo sends the sign-in code when you sign in by email, and therefore receives your email address. It receives nothing else: no birth details, no events, no result link.
- Google receives your Google sign-in if you use that button, and verifies the number if you sign in by phone. Neither receives your birth details.
- Google Analytics receives the pages you visit on this site, plus the broad location and device information described below. It never receives your birth details, and it never receives the link to a saved result.
Cookies, analytics and advertising
We use Google Analytics (GA4) to see how visitors use this site: which pages get read, and broad location and device information (country or city level, derived from IP address, not stored as a full IP). We use this only to improve the site. We do not sell it, use it for advertising, and we run no ad network or retargeting pixel of our own.
We deliberately strip the web address before it reaches Google. The link to a saved result is the one thing on this site that works like a password, so what we send for those pages is a placeholder rather than the link itself, and we never send anything after the question mark in an address.
In the UK and the EU we ask before any of this happens. Until you answer, no Google script is loaded and no analytics cookie is set, and if you say no, nothing is loaded at all. Elsewhere analytics is on by default. Either way the button below is the switch and it works in both directions. Turning analytics off stops the tracking immediately and removes the cookies it had set, though a cookie written for a different path or domain cannot always be removed from a page; if one is left behind the control below says so, and your browser settings will clear it.
Google Analytics sets two cookies, _ga and one beginning _ga_, which assign your browser a random ID so repeat visits can be grouped together. That ID does not include your name, email or birth details. Google processes this data under Google’s own privacy policy, not ours.
The bq_session sign-in cookie described under Accounts is the only thing your browser stores that is sent back to us. Everything below stays on your device and is never transmitted anywhere:
- Your theme choice (light or dark), kept in local storage so the page does not flash the wrong colours when it loads.
- Your progress through the rectification form, kept in session storage so a refresh does not lose your typing. Your browser discards it when you close the tab, and we clear it when you finish or when you sign out.
- A short list of your recent charts. By default this is kept in session storage and your browser discards it when you close it, which is the safe answer on a shared or public computer. When the first result is ready we ask once whether to keep it on that device instead; only if you say yes does it move to local storage and survive between visits. Either way it holds only the chart reference and the optional name you typed, never your birth date, time or place. Clear it any time with the Clear button on that list.
- A few small housekeeping values that go with that list: your answer to the question above, which chart references this browsing session produced, and any that were still waiting to be saved to your account when you signed out. They are references only, they carry no names, and the session-scoped ones are gone when you close the browser.
- Your answer to the cookie question, kept in local storage so we do not ask again on every page. It records only yes or no.
We run no advertising network today. If that changes, this page will say so before it goes live.
How long we keep it
A saved rectification is kept so the result link keeps working, until it is deleted: by you from the account page if it is on your account, or by us on request if it was made without one. If you use the site without saving a run, nothing is stored at all.
With an account: your sign-in methods, saved people and history are kept for as long as the account exists, and go the moment you delete it. A sign-in code expires after ten minutes, and its row is deleted a couple of hours later, so a code you asked for and never used does not leave your address with us either. The codes still linked to your account go with the account. A sign-in session expires 30 days after you last signed in, or the moment you sign out.
Your rights
You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it.
Most of this you do yourself. If you are signed in, the account page lets you edit or remove a saved person, remove a sign-in method (as long as one remains, otherwise you would be locked out), see every run on your account, and delete the whole account. That last one is immediate and permanent: it takes your saved people, your sign-in methods, and every rectification with the birth details behind it. You do not have to ask us and there is nothing to wait for, apart from the encrypted backups described above, which are overwritten within 14 days.
Email [email protected] for a run made without an account, which is the one case the account page cannot reach: there is no account it belongs to. Send the result link, since that link is what identifies the record and nothing else is attached to it. We will action those requests within 30 days, and deletion is permanent: the birth profile, its events and the run all go together.
If you are in India, these rights sit under the Digital Personal Data Protection Act, 2023. If you are in the UK, EU or another region with its own data protection law, we will honour equivalent requests regardless of where you are.
Children
This site is not intended for anyone under 18. Please do not submit a child's birth details without holding parental responsibility for them.
Security, honestly stated
We encrypt birth details at rest, serve everything over HTTPS, and keep third parties to a minimum. No system is perfectly secure, and we will not pretend otherwise. If you find a security problem, please report it to [email protected] before disclosing it publicly. If a breach happens that is likely to affect you, we will notify you and the relevant authority as the law requires, and do what we reasonably can to limit the damage. Nothing on this page reduces any right you have under the Digital Personal Data Protection Act, 2023, or an equivalent law where you live, and nothing here disclaims the responsibility we hold as a data fiduciary under that law.
Beyond that statutory responsibility, our liability for how we handle your data is governed by the Terms of Service, including its Limitation of Liability section.
Changes to this policy
If this policy changes in a way that affects how your data is handled, we will update the effective date at the top and describe what changed.
Contact
Questions, requests or complaints: [email protected]. See also our Terms of Service and how the rectification works.