This policy explains what the Kaal Jyoti API does with the data that passes through it, and what we hold about you as a developer. It is separate from the Privacy Policy of the Kaal Jyoti mobile app, which covers the app alone. It forms part of the API Terms of Service.
The short version. Birth details sent to the API are processed and never stored. A request body is used to compute an answer and is then gone: it is not written to any database, it is not written to any log, and answers are cached only in the server’s memory, for at most 24 hours. The two lookups that take their input in the address rather than in a body — GET /v1/timezone and GET /v1/places — are the exception: like every address, theirs is in the access logs for up to 30 days (section 3). What we keep is metadata about the call — which endpoint, when, what status, how long — and the account it belonged to.
1. Who we are
GoAppsters Private Limited (CIN U74999DL2018PTC333768), with its office at A-1601, Tower 2, NX One, Greater Noida West, Uttar Pradesh 201306, India, operates the Kaal Jyoti API at api.kaaljyoti.com and its developer dashboard at kaaljyoti.com/api. We are the data fiduciary (controller) for your account data, and your processor for your users’ data — the distinction is section 3.
2. What we process about you, the developer, and why
- Your e-mail address — to create the account, to sign you in with a one-time code or Google, and to write to you about payments, security and changes to the terms. This is necessary to provide the service you asked for.
- Legal name, country and GST details (GSTIN, billing address and state), if you give them — the country decides your billing currency and tax treatment, and the rest is printed on the tax invoices we issue you.
- Key records — a name you chose, the kind, a 12-character display prefix, the origins you allowed, and the SHA-256 hash of the key. The key itself is shown once, at creation, and never stored: we could not send it back to you if we wanted to.
- Usage counts — per account and per endpoint per day: credits, requests, errors and cache hits, and the monthly total. This is what your dashboard shows and what a plan’s limit is enforced against.
- Billing records — subscription status, period, credit packs bought and what is left in them, and the GST tax invoices and credit notes we issue for your payments. Necessary for the contract, and required by tax law.
- An audit log of account-level events — a key created or revoked, a plan granted, a subscription changed — so that a dispute about what happened can be answered.
- Access logs. Cloudflare and Google Cloud record each request’s IP address, time, full address (the endpoint and its query string), status and user agent — never its body. We use them to keep the service secure, to stop abuse and to investigate faults, and they are deleted within 30 days.
3. What we process on your behalf — your users’ birth details
When your application sends us a date, time and place of birth, that is personal data about your user, and under India’s Digital Personal Data Protection Act, 2023 you are the data fiduciary (controller) for it and we are your data processor. We act on your instruction — the request — and for no other purpose. You are responsible for having a lawful basis to send it, and for telling your users that a third party performs the calculation.
- Computed in memory. The body is validated, the time zone resolved, the calculation run, the answer returned. Nothing from it reaches any persistent store.
- Cached in memory, for at most 24 hours. Deterministic answers are held for up to a day in the memory of the running server, keyed on a SHA-256 of the normalised request rather than the request itself. The cache is never written to disk or to shared storage, and an entry is gone after 24 hours or when the server restarts, whichever comes first.
- Never logged. Our logs record the request id, the endpoint, the status, the duration and the key’s account — never the body, and never a field out of it.
- Except what is in an address. Two lookups take their input in the URL:
GET /v1/timezone(a latitude, a longitude and a date-time, which may be a birth’s) andGET /v1/places(the place name being searched). The access logs of Cloudflare and Google Cloud record every request’s full address, so these values are in them, with the IP address, for up to 30 days. Every other route takes its input in the body. If you would rather they were not logged, derive the zone from the coordinates inside aPOSTrequest instead of calling the lookup, and search places on your side. - Never used for anything else. We do not analyse, profile, enrich, train on, or sell what passes through the API.
4. Error reporting
When a request fails on our side, a report goes to Sentry with the request id, the endpoint and the stack trace. Request bodies are stripped before the report leaves the process, so an error report cannot carry a birth detail.
5. Processors we rely on
- Cloudflare — the edge in front of the service: TLS, rate limiting, and protection from abuse; it also serves this website. Its R2 storage holds the PDF copies of the tax invoices we issue and the database backups, in private buckets.
- Google Cloud (Mumbai, India) — runs the gateway that computes your answers. Its request logs are kept in Google Cloud Logging’s global storage.
- Supabase (Mumbai, India) — accounts, keys, usage counts, subscriptions and tax invoices.
- Razorpay — takes the payment and keeps its own record of it. We never see or store your card details.
- Resend — sends account e-mail, such as one-time sign-in codes, billing notices and tax invoices, from its Tokyo (Japan) region.
- Sentry — error reports, with bodies stripped (section 4), stored in its EU region.
- Google sign-in — only if you choose to sign in with it, under Google’s own privacy policy.
6. Cookies
The developer dashboard sets session cookies only — the ones that keep you signed in, plus a bot-check cookie from Cloudflare Turnstile on the sign-in page. There is no analytics and no advertising on any page under /api, including this one, the pricing page and the documentation. The app’s marketing pages elsewhere on this website use Google Analytics, as the app’s privacy policy describes.
7. How long we keep it
- Request bodies — never kept. Cached answers expire within 24 hours.
- Account, key and usage records — while the account exists. Deleting the account deletes them at once: the account, its keys, its usage counts, its subscription and credit-pack records and its branding.
- The audit log — its entries are kept after the account is deleted, and the entry that records the deletion keeps the account’s e-mail address, so that the deletion itself can be shown later. They are not yet deleted on a schedule; when we set a period, it will be stated here.
- Tax invoices — issued and kept by us for eight years, because Indian company and tax law require it. They survive the deletion of your account, with the buyer details — name, e-mail, address, GSTIN and state — as they were issued. Razorpay keeps its own records of the payments, under its own terms and the law.
- Access logs, operational logs and error reports — up to 30 days, then deleted automatically.
- Backups — the database is backed up daily to a private Cloudflare R2 bucket and each backup is deleted after 30 days, so a deleted account can remain in a backup for up to 30 days.
8. Security
Everything travels over TLS. API keys are stored only as SHA-256 hashes, so a database dump cannot be used to call the API. The database enforces row-level security, so an account can read its own rows and no others, and the gateway reaches the database through a secret only the edge holds. Access to production is limited to the people who operate it. No system is perfectly secure, so we cannot promise absolute security — but a birth detail cannot leak from a store that never held one.
9. Your rights
You can see and export your usage, revoke any key, and delete your account and everything tied to it from the dashboard at any time. We also honour the rights India’s Digital Personal Data Protection Act, 2023 gives you — to access and correct your data, to have it erased, to nominate someone to exercise your rights, and to withdraw consent — today, ahead of the provisions that make them statutory rights coming into force; from then you may also complain to the Data Protection Board of India. If you are outside India we will handle an equivalent request — access, correction, erasure, portability, objection — on the same terms. Write to support@goappsters.in; our Grievance Officer is Amit Verma, a@goappsters.in.
For your users’ data we are the processor, so a request from one of them should go to you; we will help you answer it. A data-processing agreement is available for Enterprise accounts on request.
10. Children
The API and its dashboard are for developers and are not intended for anyone under 18. We do not knowingly create an account for a child. Whether your application may be used by children, and what consent that needs, is yours to decide and to comply with.
11. Where data is processed
The gateway and the database are hosted in India (Mumbai). Cloudflare’s edge is worldwide, so a request is terminated at the network edge nearest your caller before it reaches the gateway. Some processing is outside India: Google Cloud keeps request logs in its global log storage, Sentry stores error reports in the European Union, Resend sends e-mail from Japan, and Razorpay processes on its own infrastructure under its terms. Where data crosses a border it stays protected by this policy, by our agreements with those providers, and by applicable law.
12. Changes
We may update this policy. A material change is e-mailed to the address on your account at least 14 days before it takes effect, and the “Last updated” date above is revised.
13. Contact
GoAppsters Private Limited
Email: support@goappsters.in
CIN: U74999DL2018PTC333768
Office: A-1601, Tower 2, NX One, Greater Noida West, Uttar Pradesh 201306, India
Grievance Officer: Amit Verma, a@goappsters.in