Back
DharmaChart

Privacy Policy

Version 1.4 Last updated: June 29, 2026

DharmaChart LLC (“DharmaChart,” “we,” “us,” or “our”) is an Oregon single-member limited liability company. This Privacy Policy describes how we collect, use, store, and protect your personal information when you use the DharmaChart mobile application and related services (collectively, the “Service”).

We take your privacy seriously. This is not a formality. Your spiritual practice data is among the most personal information you possess, and we treat it accordingly.


1. Scope and Applicability

This Privacy Policy applies to all users of the DharmaChart mobile application (iOS and Android), the DharmaChart website, and any associated services.

By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, do not use the Service.

This Policy is designed to comply with the Oregon Consumer Privacy Act (OCPA), effective July 1, 2024, and incorporates protections consistent with the California Consumer Privacy Act (CCPA), the General Data Protection Regulation (GDPR), and other applicable privacy laws.

The Service is intended for users aged 18 and older. See Section 11 for details.


2. Information We Collect

2.1 Information You Provide Directly

Data TypeDescriptionEncryption
Email addressAccount creation and magic link authenticationStored in plaintext for authentication
Birth dataDate, time, and place of birth for natal chart calculationFernet field-level encryption at rest
Journal entriesPersonal reflections, mood tags, dream journals, and metadataFernet field-level encryption at rest
Card reading dataTarot/oracle card selections, spreads, questions, and AI interpretationsFernet field-level encryption at rest
Card reading photosPhotos of physical tarot/oracle cards uploaded for recognitionEncrypted object storage
Companion chat historyConversations with the AI companionFernet field-level encryption at rest
Transit intentionsPersonal goals and reflections tied to transitsFernet field-level encryption at rest
Community postsContent voluntarily shared to the community feed (opt-in)Visible to other users per your settings
Voice recordingsAudio input for the voice companion (streamed to Cartesia for real-time speech-to-text) and journal voice notes (sent to OpenAI Whisper)Not stored by us — transcribed in real time and discarded
Synastry profilesBirth data for relationship chart comparisonsFernet field-level encryption at rest
Feedback and reportsBug reports, feature requests, shake-to-report submissionsStored in issue tracking system

2.2 Information Collected Automatically

Data TypeDescriptionPurpose
GeolocationGeographic coordinates when using astrocartographyAstrocartography calculations; collected only with your permission
Device informationDevice type, OS version, app versionDebugging and service improvement
Usage analyticsFeature usage patterns, session duration, error logsService reliability and improvement
Authentication tokensJWTs stored locally on your deviceSession management

2.3 Information Derived from Your Data

We generate derived data from the information you provide, including:

2.4 Voice Recording Processing

DharmaChart has two distinct voice features, handled differently:

Only the resulting text transcription is retained, subject to the same encryption protections as other user-generated content.


3. How We Use Your Information

We use your information exclusively to provide, maintain, and improve the Service. Specific uses include:

We do NOT use your information for:


4. Data Storage and Security

4.1 Encryption

We employ Fernet symmetric encryption (AES-128-CBC with HMAC-SHA256) at the field level for sensitive data. The following categories are encrypted at rest:

Fernet encryption means that even in the event of unauthorized database access, encrypted fields are unreadable without the encryption key, which is stored separately from the database.

4.2 Infrastructure

ComponentProviderLocation
Application backendRenderUnited States
DatabasePostgreSQL (Render)United States
Object storageCloudflare R2Globally distributed
Email deliveryResendUnited States

4.3 Access Controls


5. We Do Not Sell Your Data

DharmaChart does not sell, rent, lease, trade, or otherwise transfer your personal information to any third party for monetary or other valuable consideration.

We have never sold personal data. We will never sell personal data.

Under the Oregon Consumer Privacy Act and the California Consumer Privacy Act, you have the right to opt out of the sale of personal information. Because we do not sell personal information, there is no sale to opt out of.


6. Third-Party Service Providers

We share limited data with the following third-party service providers, solely to operate the Service. Each provider receives only the minimum data necessary.

6.1 Anthropic (Claude AI)

Data shared: Assembled context: natal chart data, transits, journal excerpts, card reading history, companion conversation history

Purpose: AI companion, transit interpretations, card reading analysis, journal metadata extraction

Privacy policy

6.2 OpenAI

Data shared: Journal voice-note audio (Whisper transcription), some text content (text-to-speech), and text embeddings for semantic search

Purpose: Transcribing journal voice notes, some spoken-audio synthesis, and semantic search

Privacy policy

6.3 Mapbox

Data shared: Geographic coordinates (latitude/longitude)

Purpose: Astrocartography map rendering and reverse geocoding

Privacy policy

6.4 Resend

Data shared: Email address

Purpose: Transactional emails (magic link authentication, password resets)

Privacy policy

6.5 Sentry

Data shared: Error logs, stack traces, device metadata (no personal content)

Purpose: Error monitoring and application stability

Privacy policy

6.6 Cloudflare

Data shared: Uploaded files (card reading photos)

Purpose: Object storage (R2) for user-uploaded content

Privacy policy

6.7 Apple App Store / Google Play Store

Data shared: Subscription status, purchase receipts

Purpose: In-app purchases and subscription management

6.8 PostHog (EU)

Data shared: Pseudonymous product-usage events (feature interactions, screen views) and a SHA-256-hashed user identifier. No email, name, birth data, or user-generated content.

Purpose: Product analytics to understand feature usage and improve the Service. Collected only with your consent.

Privacy policy

6.9 PostHog (EU) — Website Analytics

Data shared: With your consent: page views and interactions on the DharmaChart marketing website (dharmachart.com), a persistent identifier (stored in a cookie and in local storage so we can recognise returning visitors), your IP address and the approximate location derived from it, device and browser details, the site that referred you, and session recordings (with any text you type into a field masked out).

Purpose: Understanding how the website is used — where visitors come from, what they view, and how they navigate — so we can improve it. Capture begins only after you accept the cookie-consent banner, and you can withdraw consent at any time.

Privacy policy

6.10 Cartesia

Data shared: Live voice-companion audio — your spoken input (for real-time speech-to-text) and the companion’s spoken replies (text-to-speech) — plus the text of your generated daily reading.

Purpose: Powering the real-time voice companion (speech recognition and spoken replies) and text-to-speech synthesis of your daily reading.

Privacy policy

In-app analytics (6.8) are collected only with your explicit, opt-in consent, which you can grant or withdraw at any time in Settings → Privacy. PostHog data is processed on EU-based infrastructure (Frankfurt, Germany). Session recording is disabled.

Website analytics (6.9) are distinct from in-app analytics. On the marketing website, PostHog is consent-gated: when you first visit, a banner asks for your consent, and nothing is captured until you accept. If you accept, the site sets a cookie and a persistent identifier, captures your IP address and device, and records your session (with any typed input masked). If you decline, no capture occurs. You can change your choice at any time by clearing the site’s stored data. In-app analytics remain strictly opt-in.


7. Data Retention and Deletion

7.1 Retention

We retain your personal data only for as long as your account is active and as necessary to provide the Service.

7.2 Deletion — “Delete Means Delete”

When you delete data or your account, we perform permanent, irreversible deletion — not soft deletion, not archival, not anonymization.

We do not maintain backups of deleted data. Once you request deletion, the data is gone.

Data shared with third-party providers prior to deletion is subject to those providers’ respective data retention policies. We select providers that do not retain API inputs for training purposes.


8. Your Rights Under the Oregon Consumer Privacy Act (OCPA)

If you are an Oregon resident, you have the following rights under the OCPA, effective July 1, 2024:

How to Exercise Your Rights

You may exercise your rights by:

We will respond to verified requests within 45 days, as required by the OCPA. If we need additional time, we will notify you within the initial 45-day period.


9. Rights for Users in Other Jurisdictions

9.1 California Residents (CCPA/CPRA)

California residents have rights similar to those in Section 8, including the right to know, delete, correct, and opt out of sale. We do not sell personal information.

9.2 EEA, UK, and Switzerland (GDPR/UK GDPR)

9.3 All Users

Regardless of your jurisdiction, we extend the core rights — access, deletion, portability, and correction — to all users of the Service.


10. Cookies, Tokens, and Local Storage

DharmaChart does not use advertising cookies. In-app product analytics (PostHog — Section 6.8) is consent-gated: it stores a pseudonymous identifier in your browser’s local storage and only after you opt in; you can withdraw consent at any time in Settings → Privacy. On the DharmaChart marketing website, analytics are also consent-gated (Section 6.9): if you accept the cookie banner, an analytics cookie and identifier are set so we can recognise returning visitors; if you decline, nothing is stored.

MechanismPurposeDuration
JWT access tokenAuthenticationShort-lived (expires automatically)
JWT refresh tokenSession continuityLonger-lived; rotates on use
Capacitor PreferencesAuth state, user settings on mobileUntil user clears app data or deletes account
Service Worker cacheOffline functionality for app shell, fonts, map tilesUntil invalidated by app update
PostHog analytics identifierIn-app product analytics, only if you have opted inUntil you withdraw consent, clear app data, or delete your account
Website analytics cookie & identifierRecognising returning visitors on the marketing website, only if you accept the cookie bannerUntil you decline or clear the site’s stored data

No data stored locally is transmitted to third parties. Local tokens are used exclusively for authenticating with DharmaChart’s own backend.


11. Children’s Privacy

The Service is intended for users aged 18 and older. We do not knowingly collect personal information from anyone under 18.

If we learn that we have collected personal information from a user under 18, we will promptly delete that information and terminate the account.

If you believe a person under 18 has provided us with personal information, please contact us at privacy@dharmachart.com.


12. AI Disclaimer

The Service uses artificial intelligence (Anthropic’s Claude and OpenAI’s models) to generate astrological interpretations, card reading analyses, companion responses, and other content.

All AI-generated content is for entertainment and self-reflection only. It does not constitute:

If you are experiencing a mental health crisis, please contact the 988 Suicide & Crisis Lifeline (call or text 988) or the Crisis Text Line (text HOME to 741741).


13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

Your continued use of the Service after the effective date of a revised Privacy Policy constitutes your acceptance of the updated terms. If you do not agree, you should discontinue use and delete your account.


14. Contact Us

DharmaChart LLC
Portland, Oregon

Email: privacy@dharmachart.com

For privacy rights requests, please include sufficient information for us to verify your identity (the email address associated with your account is typically sufficient).


15. Oregon Consumer Privacy Act — Additional Disclosures

15.1 Categories of Personal Data Processed

15.2 Purposes for Processing

As described in Section 3.

15.3 Categories of Third Parties

As described in Section 6.

15.4 Categories of Data Shared

15.5 No Profiling with Sensitive Data

We do not process sensitive data (as defined by the OCPA) for purposes of profiling in furtherance of decisions that produce legal or similarly significant effects.


Back to DharmaChart