1. Introduction
Welcome to HastAI (the "Application" or "Service"), developed by Yash Rayjada, an independent developer operating under the brand name YBR Digital ("Developer," "we," "us," or "our"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy details how we handle the collection, storage, use, and security of information obtained when you utilize our mobile application and backend services.
By using the Application, you explicitly consent to the data collection and processing methods described in this Policy. If you do not agree to these terms, please do not use the Application.
This Privacy Policy applies to all information collected through our mobile application, backend APIs, and any related services, sales, marketing, or events (collectively, the "Service").
2. Information We Collect
We collect information that you explicitly submit, as well as data automatically gathered by the Application during your usage.
A. Personal Information You Provide
- Account Authentication: When signing in, the Application utilizes Google Sign-In. We collect your public Google identifier (Google UID), name, email address, and profile picture URL.
- User Profile: You may provide details such as your gender, mobile number, and country code to customize your user profile.
- Palm Profiles: To generate report interpretations, you create Palm Profiles by providing a first name, last name, gender, and birth details (date of birth, optional time of birth, and place of birth).
- Palm Images: To run palm line readings, you must upload or capture images of your left and right palms. These images are transmitted securely to our backend servers and stored on cloud storage services (see Section 5 for biometric data handling).
- Report Feedback: When you report issues with generated reports, we collect your selected issue category and optional written feedback text.
B. Automatically Collected Information
| Data Category | Specific Data Points | Purpose |
|---|---|---|
| Device Identifiers | Device UUID, Android ID, device brand, model, device name, device type, tablet indicator | Device registration, push notifications, analytics |
| System Information | Operating system name, system version, app version, build number | Compatibility checks, minimum version enforcement, debugging |
| Network Information | Mobile carrier name | Network diagnostics and optimization |
| Push Notification Tokens | Firebase Cloud Messaging (FCM) registration tokens | Delivering push notifications |
| Activity Logs | Page views, transitions, report requests, feature interactions | Analytics, performance monitoring, user behavior insights |
| Error Logs | Error traces, request metadata, device state at time of error | Bug identification, debugging, system stability |
| Notification Interactions | Notification click events (notification ID, user ID, timestamp) | Measuring notification engagement and effectiveness |
| AI Token Usage | Input tokens, output tokens, total tokens consumed per scan/generation | Usage tracking, cost monitoring, quality optimization |
C. Billing & Transaction Data
- Purchase Records: Transaction IDs, product IDs, purchase timestamps, and entitlement status from Google Play Billing via RevenueCat.
- Subscription Records: Subscription product IDs, start/end dates, renewal history, billing status (active, cancelled, billing issue), and trial status.
- Credit Transactions: Credit additions, deductions, refund events, expiration events, with amounts, descriptions, and timestamps.
- Webhook Audit Logs: For billing security, we log webhook event payloads from RevenueCat, including event IDs, event types, IP addresses of webhook origins, and processing status.
3. How We Use Your Information
We process your data strictly to fulfill the Application's core features and improve the Service. Specifically, we use your data to:
- Create and manage your user account and linked palm profiles.
- Perform AI scans of your uploaded palm images to detect palm line structures and features.
- Generate personalized reports across various categories (e.g., Career, Wealth, Love, Health, Personality, Life Timeline, Future Predictions, and more).
- Manage your credit balance, billing transactions, subscription benefits, and purchase history.
- Distribute personalized push notifications and alerts regarding your reports, promotions, and service updates.
- Process referral registrations and track reward eligibility.
- Enforce daily report generation limits and minimum app version requirements.
- Monitor notification engagement through click tracking.
- Identify, debug, and resolve technical system issues using error logs and activity data.
- Improve AI model performance and report quality through aggregated, anonymized usage data.
- Detect and prevent fraud, abuse, and violations of our Terms of Service.
- Communicate important service updates, maintenance schedules, and policy changes.
4. AI Analysis & Processing
Important Note on AI Processing: Your palm images and birth profile details are processed securely using Google Gemini AI models on our backend. We do not use your private images or profile data to train external public AI models.
A. How AI Processing Works
When you request a palm scan report, the following data processing occurs:
- Image Retrieval: Your uploaded palm images are retrieved from our cloud storage (Cloudflare R2) and encoded in base64 format.
- Prompt Construction: Your profile information (name, gender, birth details) and palm analysis data are combined with our proprietary AI prompts to create a structured request.
- API Transmission: The encoded images and prompt data are sent to the Google Gemini AI API (generativelanguage.googleapis.com) via encrypted HTTPS connection for analysis.
- Response Processing: The AI-generated response is parsed, validated, and stored as structured report sections in our database.
B. Data Sent to Google Gemini AI
The following data is transmitted to Google's Gemini AI API during processing:
- Base64-encoded left and right palm images.
- Profile metadata: first name, last name, gender, birth date, birth time, and birth place.
- Previously generated palm analysis JSON data (for section-specific report generation).
- Structured prompt instructions (our proprietary templates).
Google Gemini AI processes this data under Google's API terms of service. We use the paid API tier, which means your data is not used by Google to train their public AI models. For more details, refer to Google's Generative AI Terms.
C. Token Usage Tracking
For each AI processing request, we record the number of input tokens (data sent to the AI), output tokens (data received from the AI), and total tokens consumed. This data is used for internal cost monitoring and usage optimization and is not shared with third parties.
5. Palm Image & Biometric Data
Sensitive Data Notice: Palm images may be considered biometric or sensitive personal data under certain jurisdictions (including but not limited to GDPR, CCPA/CPRA, the Illinois Biometric Information Privacy Act, and India's Digital Personal Data Protection Act). Please read this section carefully.
A. What We Collect
We collect photographs of your left and right palms. These images are used exclusively for AI-based palm line analysis. We do not extract or store biometric templates, fingerprints, or palm vein patterns. The images are analyzed by AI to identify visual palm features (lines, mounts, shapes) for the purpose of generating palmistry reports.
B. How Palm Images Are Stored
- Cloud Storage: Palm images are stored on Cloudflare R2 (an S3-compatible cloud object storage service). Images are associated with your unique palm profile UUID and are not publicly accessible.
- Access Control: Palm images are accessible only through authenticated API requests. Only you (the account owner) and authorized backend processes can access your images.
- Deletion: When you delete a palm profile or your account, the associated palm images are permanently removed from cloud storage after the 30-day soft-deletion grace period (see Section 9).
C. Your Consent
By uploading palm images to the Application, you provide explicit, informed consent for us to:
- Store your palm images on our cloud storage infrastructure.
- Transmit your palm images to Google Gemini AI for analysis.
- Display your palm images within the Application for your personal use.
- Delete your palm images upon your request or account deletion.
You may withdraw consent at any time by deleting your palm profiles or requesting account deletion (see Section 9).
6. Third-Party Integrations & SDKs
We work with select third-party service providers to ensure secure hosting, authentication, payment processing, AI analysis, and application metrics. Each provider has their own privacy policy governing their data handling:
| Service Provider | Purpose | Data Shared |
|---|---|---|
| Google Sign-In | User authentication | Google UID, name, email, profile picture |
| Firebase Authentication | Session management, token validation | Auth tokens, user identifiers |
| Firebase Cloud Messaging (FCM) | Push notification delivery | FCM tokens, notification payloads |
| Firebase Analytics | App usage analytics, event tracking | Device info, app events, user interactions |
| Firebase Crashlytics | Crash reporting, stability monitoring | Crash logs, device state, stack traces |
| Google Play Billing | In-app purchases, subscription management | Purchase tokens, product IDs, transaction IDs |
| RevenueCat | Purchase verification, entitlement sync, webhook events | App user IDs, purchase data, subscription status |
| Google Gemini AI API | Palm image analysis, report content generation | Palm images (base64), profile metadata, prompt data |
| Cloudflare R2 | Cloud object storage for palm images | Palm image files |
| Sanctum | API authentication token management | Auth tokens (server-side only) |
We do not sell, rent, or trade your personal data to third parties for marketing purposes. Data is shared with third-party providers only to the extent necessary to provide the Service.
7. Purchases & Credit Systems
All in-app purchases are handled via Google Play Billing and processed through RevenueCat. The Application operates on a credit system:
- Credits Allocation: Credits can be earned via sign-up bonuses, referral incentives, or purchased via Credit Packs and Subscriptions.
- Subscription Credits: Allocated monthly or periodically depending on your subscription plan. Unused subscription credits do not roll over and will expire at the end of each billing cycle.
- Purchased Credits: Credits purchased via consumable Credit Packs remain in your account and expire 1 year (365 days) from the purchase date if they are left unused.
- Transaction History: We maintain a complete record of all credit transactions (additions, deductions, refunds, and expirations) associated with your account. This data is available to you through the Application's wallet history feature.
Webhook & Billing Audit Trail
For billing security and fraud prevention, we maintain an audit log of all incoming webhook events from RevenueCat. Each webhook log entry records the event ID, event type, raw payload, originating IP address, signature validation status, and processing outcome. This data is retained for billing dispute resolution and is not shared with third parties.
8. Referral Data Sharing
When you participate in our Referral Program, limited data is shared between the referrer and the referred user:
- What the Referrer Sees: The referrer can view the first name of users they have referred, along with the referral status (pending or completed) and the date of referral registration.
- What the Referred User Sees: The referred user can see the referral code they claimed. No additional information about the referrer is disclosed.
- Data Collected: We store referral records linking the referrer and referred user IDs, referral status, reward credit amounts, and timestamps.
- No Public Exposure: Referral data is not publicly visible. Only the direct participants in a referral relationship can see limited referral-related information as described above.
9. Data Retention & Soft Delete
We retain your profile data and generated reports for as long as your account remains active. The Application supports a structured data deletion mechanism:
A. Soft Deletion (Grace Period)
- If you request profile, report, or account deletion, the record is marked as deleted (soft-deleted) and hidden from all active views.
- During the soft-deletion period, the data remains in our system but is inaccessible through the Application. This allows for potential recovery if the deletion was accidental.
B. Permanent Purging
- After a period of 30 days from the soft-deletion date, or upon an explicit administrator command, the record is permanently and irreversibly removed.
- Permanent deletion includes removal of all associated data: palm profiles, uploaded palm images from cloud storage (Cloudflare R2 and local storage), generated reports and report sections, wallet records, credit transactions, subscription records, purchase history, and referral records.
C. Suspended Accounts
If your account is suspended, your data is preserved but inaccessible through the Application. Suspended account data is not subject to automatic deletion and will be retained until the suspension is lifted or you request account deletion.
D. Billing & Audit Data
Billing transaction records, webhook audit logs, and purchase histories may be retained for longer periods as required by applicable tax, accounting, and financial regulations, even after account deletion.
10. Local Device Storage
The Application stores certain data locally on your device to provide a seamless user experience:
- Authentication Tokens: API authentication tokens are stored in SharedPreferences on your device. These tokens are used to authenticate your API requests without requiring you to sign in repeatedly.
- FCM Token: Your Firebase Cloud Messaging push notification token is stored locally and sent to our backend to enable notification delivery.
- User Preferences: App settings, language preferences, and UI state may be stored locally using SharedPreferences or equivalent local storage.
- Cached Data: Report data, profile information, and images may be cached locally to improve load times and enable offline viewing of previously generated reports.
- Exported PDFs: When you export reports as PDFs, the generated files are saved to your device's local storage. These files are under your control and are not managed by the Application after export.
You can clear locally stored data at any time by clearing the Application's data through your device's settings, or by uninstalling the Application.
11. International Data Transfers
Your data may be transferred to and processed in countries outside your country of residence. Our Service utilizes infrastructure and service providers that operate globally:
- Google Cloud Platform / Firebase: Authentication, analytics, crash reporting, and push notifications are processed on Google's global infrastructure.
- Google Gemini AI: Palm images and profile data are transmitted to Google's Generative AI API servers for analysis.
- Cloudflare R2: Palm images are stored on Cloudflare's globally distributed object storage network.
- RevenueCat: Purchase and subscription data is processed on RevenueCat's servers.
- Backend Servers: Our backend may be hosted in specific geographic regions.
When your data is transferred internationally, we ensure that appropriate safeguards are in place, including reliance on the data transfer mechanisms approved by applicable data protection authorities (such as Standard Contractual Clauses for EU data transfers or equivalent mechanisms).
12. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), the United Kingdom, or other jurisdictions that require a legal basis for processing personal data, we process your data under the following legal bases:
| Legal Basis | Applies To |
|---|---|
| Consent | Uploading palm images, providing birth details, receiving push notifications, optional profile details (mobile number, gender) |
| Contract Performance | Account creation, report generation, credit management, subscription processing, referral program participation |
| Legitimate Interest | Analytics, error logging, fraud prevention, service improvement, security monitoring, notification engagement tracking |
| Legal Obligation | Billing record retention, tax compliance, responding to lawful data requests |
You may withdraw your consent at any time (see Section 14 for your rights). Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
13. Security Measures
We implement appropriate technical and organizational security measures to protect your personal data:
- Encryption in Transit: All transmissions between the mobile client and backend services are secured using HTTPS/TLS encryption.
- API Authentication: Access to all API endpoints requires valid authentication tokens. Unauthenticated requests are rejected.
- Account Suspension Middleware: Suspended accounts are automatically blocked from accessing API endpoints through server-side middleware.
- Webhook Signature Validation: Incoming billing webhooks from RevenueCat are validated using shared secret tokens before processing.
- Database Transaction Locking: Critical financial operations (credit transactions, purchase processing) use database-level locks to prevent race conditions and double-processing.
- Soft Delete Architecture: Data deletion follows a two-stage process (soft delete → permanent purge) to prevent accidental data loss while ensuring eventual complete removal.
- Cloud Storage Security: Palm images on Cloudflare R2 are stored in private buckets and are accessible only through authenticated server-side requests.
Note: While we strive to protect your data using industry-standard security practices, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your data.
14. Your Rights & Options
Depending on your jurisdiction, you may have the following rights regarding your personal data:
A. Universal Rights
- Access: You can view your profiles, reports, wallet history, and referral records directly within the Application.
- Correction: You can edit your user profile and palm profile details through the Application.
- Deletion: You can delete individual palm profiles and reports within the Application. For complete account deletion, contact our support team (see Section 18).
- Opt-Out of Notifications: You can disable push notifications through your device's notification settings.
B. GDPR Rights (EEA & UK Residents)
If you are a resident of the European Economic Area or the United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR):
- Right to Erasure: Request complete deletion of your personal data.
- Right to Restriction: Request that we limit the processing of your data.
- Right to Data Portability: Request a copy of your personal data in a structured, machine-readable format.
- Right to Object: Object to processing based on legitimate interest.
- Right to Withdraw Consent: Withdraw consent at any time for consent-based processing.
- Right to Lodge a Complaint: File a complaint with your local Data Protection Authority.
C. CCPA/CPRA Rights (California Residents)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to Know: Request disclosure of the categories and specific pieces of personal information we collect.
- Right to Delete: Request deletion of your personal information.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
- No Sale of Data: We do not sell your personal information to third parties.
D. Indian DPDP Act Rights (Indian Residents)
If you are a resident of India, you have rights under the Digital Personal Data Protection Act, 2023 (DPDP Act), including:
- Right to Access: Obtain a summary of your personal data and processing activities.
- Right to Correction & Erasure: Request correction of inaccurate data or erasure of data no longer necessary for processing.
- Right to Grievance Redressal: Submit grievances to our designated grievance officer (contact details in Section 18).
- Right to Nominate: Nominate another individual to exercise your rights in the event of your death or incapacity.
To exercise any of the above rights, please contact us at the address listed in Section 18. We will respond to your request within the timeframe required by applicable law (typically 30 days).
15. PDF Export & Data Portability
The Application provides features that allow you to export and access your personal data:
- PDF Export: You can export your generated reports as PDF documents. PDF generation occurs entirely on your device (client-side). The PDF files contain report content, profile details, and section analyses. Once exported, these files are stored on your device and are not transmitted to our servers.
- In-App Data Access: You can access your complete wallet history, credit transaction records, report history, and palm profiles directly through the Application.
- Data Export Requests: For a comprehensive export of all personal data we hold about you (in a structured, machine-readable format), please contact our support team. We will provide the export within the timeframe required by applicable law.
16. Children's Privacy
Our Service is not directed to individuals under the age of 13 (or the minimum age of digital consent in your jurisdiction). We do not knowingly collect personal data from children under 13.
If we discover that a child under 13 has provided us with personal information without verifiable parental consent, we will take steps to delete that information from our servers as quickly as possible.
If you are a parent or guardian and you believe that your child has provided us with personal information, please contact us at the address listed in Section 18 so that we can take appropriate action.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make changes:
- We will post the updated Privacy Policy on this page and update the "Last Updated" date.
- For material changes that significantly affect how we handle your personal data, we will provide additional notice through in-app notifications, push notifications, or other appropriate communication channels.
- Your continued use of the Service after the updated Privacy Policy takes effect constitutes your acceptance of the changes.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data.
18. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact our support team:
- Developer: Yash Rayjada (operating as YBR Digital)
- Email: info@ybrdigital.in
- Website: https://ybrdigital.in
For data protection inquiries, privacy rights requests, or grievance redressal (under the Indian DPDP Act), please include "Privacy Request" or "Data Protection" in your email subject line for expedited handling.
We will endeavor to respond to all privacy-related inquiries within 30 days of receipt.