Destini.ai

Privacy Policy

Effective date
30 July 2026
Last updated
30 July 2026
Version
2.0
Document owner
Sri Khushaal. Y
Applies to
The Destini.ai mobile application (Android and iOS), destini.ai and its subdomains, and the Prana Dasha Interpretation Engine API.

1. Who we are

Destini.ai (“Destini”, “we”, “us”, “our”) is operated by Destiinnovation Pvt. Ltd., incorporated in India, CIN U62091TS2023PTC172167, registered office F.no 1001 B3 Sampoornam HIG Flats Venture 2, KPHB Phase 15, Hyderabad 500085, India.

For the purposes of the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”), we are the Data Fiduciary for personal data you provide to us. Where we process data on behalf of an enterprise API customer, that customer is the Data Fiduciary and we act as a Data Processor under contract.

This policy is written to satisfy the DPDP Act and Rules, the Information Technology Act, 2000 and the rules made under it, the CERT-In Directions of 28 April 2022, the Google Play User Data policy and Data safety disclosure requirements, and the Apple App Store Review Guidelines (§5.1 Privacy) and App Privacy disclosure requirements.

2. Summary of the key points

  • We collect only the data needed to run the features you use.
  • We do not sell or rent your personal data, and we do not share it with third parties for their own advertising.
  • Every category of data we hold has a defined retention period. See Section 8.
  • You can delete your account and data from inside the app, or at destini.ai/delete-account. See Section 9.
  • We do not knowingly process the data of children under 18 without verifiable parental consent, and we never run behavioural advertising or tracking against a child’s data.
  • Grievances: techsupport@destini.ai, resolved within 90 days. See Section 15.

3. Personal data we collect

We collect the following. Items marked optional are collected only if you choose to use the associated feature.

3.1 Account and identity data

Name, email address, mobile number, password (stored only as a salted cryptographic hash), profile photo (optional), language and notification preferences, and — if you sign in with Google or Apple — the identifier and email address that provider returns to us.

3.2 Birth and profile inputs (core service data)

Date of birth, time of birth, and place of birth; gender (optional); relationship status (optional). These inputs are required to compute your Prana Dasha timeline and generate predictions. They are the basis of the service and cannot be removed without deleting your account.

3.3 Prediction, chat and interaction data

Questions you ask PREDCTR AI, chat transcripts, prediction requests and the results generated for you, saved or bookmarked insights, and your ratings or feedback on outputs.

3.4 Compatibility and contact data (optional)

If — and only if — you grant the contacts permission, we read the name, phone number and, where present, date of birth of the contacts you explicitly select, in order to compute a compatibility score.

We do not bulk-upload your address book, we do not use contact data for marketing, and we do not share it with anyone. Selected contact identifiers are transmitted over TLS, used to compute the score, and then handled as described in Section 8.

3.5 Wellness inputs (optional)

Self-reported wellbeing preferences and inputs you type into the wellness insights feature. Destini is not a medical or diagnostic service, does not provide medical advice, and does not knowingly collect health records, clinical data or diagnoses. Please do not enter medical information into the app.

3.6 Career and recommendation inputs (optional)

Work history, skills, industry and role preferences you supply to the job-recommendation feature.

3.7 Scrollers, user-generated content and creator data (optional)

Content you create, upload or publish on Scrollers (text, images, video, audio), captions, comments, likes, follows, and — if you monetise — your creator handle, payout preferences and settlement records.

3.8 Payment, wallet and subscription data

Transaction identifiers, purchase and refund history, coin and wallet balances, subscription tier and validity, and GST-relevant billing details.

We never see or store your full card number, CVV, UPI PIN, or net-banking credentials. In-app purchases are processed by Google Play Billing or Apple In-App Purchase; other payments are processed by our PCI-DSS compliant payment gateway, Razorpay. We receive only a masked instrument reference and the transaction outcome.

3.9 Device, technical and diagnostic data

Device model, operating system and version, app version, language and time zone, IP address, a resettable app instance identifier, crash logs, performance traces, and in-app event logs (screens viewed, features used).

3.10 Location data (optional)

Coarse or precise location, only if you grant the permission, and only to auto-fill a place of birth or a location-dependent calculation. You may deny or revoke this at any time and enter locations manually instead.

3.11 Communications

Support tickets, emails, in-app messages and any attachments you send us.

3.12 Data we do not collect

We do not collect Aadhaar numbers, PAN (except where legally required for creator payouts), biometric data, government identity documents, precise health or clinical records, or data about your caste, religion, political affiliation or sexual life.

4. Device permissions

PermissionWhy we askIf you decline
NotificationsDaily prediction alerts, transit alerts, account and payment noticesNo push alerts; app fully usable
Contacts (optional)Compatibility scoring for contacts you selectCompatibility feature unavailable
Camera / Photos (optional)Profile photo, Scrollers uploadsCannot upload media
Location (optional)Place-of-birth and location-based calculationsEnter locations manually
Storage / Media (optional)Saving and sharing generated contentCannot save locally

Permissions are requested in context, only at the point of use, and can be revoked at any time in your device settings. Revoking a permission stops further collection immediately and triggers deletion of the associated data as set out in Section 8.

5. Purposes and lawful basis

We process your personal data on the basis of your consent, which you may withdraw at any time, and — where applicable — for the legitimate uses permitted under Section 7 of the DPDP Act (for example, compliance with a legal obligation, or responding to a threat to security).

PurposeData used
Create and secure your account3.1
Generate predictions, dashboards and Prana Dasha timelines3.2, 3.3
Operate optional features you switch on3.4, 3.5, 3.6, 3.7, 3.10
Process payments, subscriptions, coins and creator payouts3.8
Provide support and respond to grievances3.11
Detect fraud, abuse and security incidents3.9
Fix crashes, measure performance, improve features3.9, aggregated 3.3
Send service and transactional communications3.1
Send marketing, only with separate opt-in consent3.1
Meet statutory, tax and regulatory obligations3.8, 3.9

Model training. We do not use your identifiable birth details, chat content or wellness inputs to train third-party foundation models. Where we improve our own interpretation engine, we use aggregated or de-identified data only. If we ever wish to use identifiable content for model improvement, we will ask for separate, specific and revocable consent first.

6. Who we share data with

We share personal data only with the following, and only to the extent needed:

Recipient categoryPurposeExamples
Cloud hosting and databaseRunning the serviceMicrosoft Azure
AI / LLM inference providersGenerating prediction and chat textGoogle, Meta (Llama)
Payment processorsPayments, refunds, payoutsRazorpay
Analytics and crash reportingStability and product analyticsFirebase, MongoDB
CommunicationsEmail, SMS and push deliveryOneSignal, Spring Edge
Professional advisers, auditorsLegal, tax and audit obligationsCA Revenue Prasad, CS Sailaja B
AuthoritiesWhere compelled by valid legal processCourts, law enforcement, regulators

Every processor is engaged under a written contract that limits them to our instructions, imposes confidentiality and security obligations, restricts onward transfer, and requires deletion or return of data on termination. We do not sell, rent or trade personal data, and we do not disclose it to data brokers or advertising networks.

In a merger, acquisition or restructuring, data may transfer to the successor entity, which will remain bound by this policy or a policy no less protective. We will notify you in advance where feasible.

7. Cross-border transfers

Our primary data storage is in India. Some processors (for example AI inference or email delivery) may process data outside India. Where that happens we transfer only what is necessary, under contractual safeguards, and only to countries and territories not restricted by the Central Government under Section 16 of the DPDP Act and Rule 15 of the DPDP Rules. Where a legal requirement mandates local storage of a category of data, we store that category in India.

8. Data retention

This section states our data retention practices in full, as required by the Google Play User Data policy.

We retain personal data only for as long as the purpose for which it was collected continues to be served, and then erase it. Retention is enforced by scheduled, automated jobs — not left to discretion. Specifically:

Data categoryRetention periodTrigger for erasure
Account and identity data (3.1)For the life of your accountErased within 30 days of account deletion
Birth and profile inputs (3.2)For the life of your accountErased within 30 days of account deletion
Prediction and chat history (3.3)24 months rolling from creation, or until you delete itAuto-purged at 24 months; immediately when you delete an item; within 30 days on account deletion
Contact and compatibility data (3.4)Contact identifiers are held only for the active session needed to compute the score, to a maximum of 7 days in transient cache. Only the derived compatibility score and any label you assign are stored, for the life of your account.Immediate purge of all contact-derived data when you revoke the contacts permission, remove a contact in-app, or delete your account
Wellness inputs (3.5)12 months from entry, or until you delete themAuto-purged at 12 months; within 30 days on account deletion
Career inputs (3.6)For the life of your accountErased within 30 days of account deletion
Scrollers content (3.7)Until you delete the content or your accountRemoved from public view immediately; erased from primary storage within 30 days
Creator payout and settlement records (3.7, 3.8)8 financial years, as required by the Companies Act, 2013 and applicable tax lawErased once the statutory period lapses
Payment and transaction records (3.8)8 financial years (statutory books of account, GST and income-tax records)Erased once the statutory period lapses
Device and diagnostic data, crash logs (3.9)90 daysAutomatic expiry
Traffic data, access logs and processing logs (3.9)12 months, the minimum required by Rule 6 of the DPDP Rules. ICT system logs are retained 180 days within India per the CERT-In Directions of 28 April 2022.Automatic expiry after the longer applicable period
Location data (3.10)Not stored as a location trail. Used at the moment of the request and discarded; only the resolved place name you save is kept, for the life of your account.Immediate on permission revocation
Support communications (3.11)24 months from ticket closureAutomatic expiry
Consent and consent-withdrawal recordsLife of your account plus 3 years, as evidence of lawful processingErased after that period
Marketing suppression list (hashed email / phone)Retained in hashed form for as long as needed to honour your opt-outRetained solely to respect your choice
Encrypted backups and disaster-recovery snapshotsMaximum 90 days, then overwrittenDeleted records do not survive beyond 90 days in backups
Aggregated and irreversibly anonymised statisticsIndefinitelyNot personal data; cannot be linked back to you

Inactive accounts. If you do not interact with your account for 3 continuous years, we treat the purpose of processing as no longer served. We will notify you at your registered email address at least 48 hours before erasure, giving you the opportunity to log in and retain your account. If you do not, we erase your personal data other than records we are legally required to keep.

Retention beyond these periods occurs only where a specific law, a court or regulatory order, or the establishment or defence of a legal claim requires it. In that case we retain only the specific records needed, restrict access to them, and erase them once the requirement ends.

Withdrawal of consent. If you withdraw consent for a purpose, we stop that processing without undue delay and erase the data collected for it within 30 days, unless retention is legally required.

9. Deleting your account and data

You can delete your account and associated personal data at any time:

What happens next:

  1. We verify that the request is genuinely yours.
  2. Your account is deactivated and your content removed from public view immediately.
  3. A 7-day grace window follows, during which you can cancel the deletion by logging in.
  4. Your personal data is erased from primary systems within 30 days of the request, and from encrypted backups within 90 days.
  5. We instruct our processors to erase the data they hold on our behalf.
  6. We retain only: statutory financial and tax records (8 financial years), logs required by Rule 6 and the CERT-In Directions, hashed suppression-list entries, and anything required for an active legal claim or investigation.
  7. We confirm completion to you by email.

You can also delete data without deleting your account. Individual chats, predictions, wellness entries, Scrollers posts and saved contacts can each be deleted in-app, and revoking a device permission purges the data that depended on it.

10. Your rights as a Data Principal

Under the DPDP Act you have the right to:

  • Access — a summary of the personal data we process about you and our processing activities, and the identities of processors with whom we have shared it.
  • Correction, completion and updating — of inaccurate or incomplete data.
  • Erasure — of your personal data, subject to legal retention requirements.
  • Withdraw consent — at any time, as easily as you gave it, in Settings or by writing to us. Withdrawal does not affect processing already lawfully carried out.
  • Grievance redressal — see Section 15.
  • Nominate — another individual to exercise your rights in the event of your death or incapacity. Write to privacy@destini.ai to record a nomination.
  • Data portability — request a machine-readable export of your data.

How to exercise them. Use Settings → Privacy → My Data in the app, or email privacy@destini.ai. We may ask you to verify your identity. We respond within 30 days, and in any event within the 90-day statutory maximum for grievances.

Your duties. The DPDP Act also requires you not to impersonate another person when providing data, not to suppress material information, and not to file false or frivolous grievances or erasure requests.

11. Children and persons with disabilities

Destini.ai is intended for users aged 18 and above. We do not knowingly process the personal data of a child (a person under 18) without verifiable parental consent obtained in accordance with Rule 10 of the DPDP Rules. We do not undertake tracking, behavioural monitoring or targeted advertising directed at children, and we do not process children’s data in a way likely to have a detrimental effect on their wellbeing.

For a person with a disability who has a lawful guardian, we process data only with the guardian’s verified consent.

If you believe a child has registered, write to techsupport@destini.ai and we will verify and delete the account and its data promptly.

12. Security

We apply technical and organisational safeguards proportionate to the sensitivity and volume of the data we process, including:

  • TLS 1.2 or above in transit, and AES-256 encryption at rest.
  • Password hashing with a modern key-derivation function.
  • Role-based access control on a least-privilege basis, with multi-factor authentication for administrative access.
  • Secrets held in a managed key vault; network isolation and private endpoints.
  • Obfuscation, masking and tokenisation where appropriate.
  • Continuous monitoring, logging and periodic review.
  • Vulnerability scanning, patching and periodic penetration testing.
  • Vetted, contractually bound processors.

No system is perfectly secure. Please keep your credentials confidential and notify us immediately of any suspected unauthorised access.

13. Personal data breaches

If a personal data breach occurs, we will inform affected users without delay, in clear language, describing the nature and extent of the breach, its likely consequences, the measures we have taken, and the safety measures you can take. We will notify the Data Protection Board of India without delay and file a detailed report within 72 hours, and will report qualifying cyber incidents to CERT-In within 6 hours as required by the 2022 Directions.

14. Cookies and similar technologies (website)

destini.ai uses strictly necessary cookies for session management and security, and — only with your consent via our cookie banner — analytics cookies to understand site usage. You can withdraw cookie consent at any time from the banner or your browser settings. The mobile app does not use third-party advertising identifiers for cross-app tracking, and does not request App Tracking Transparency permission, because we do not track you across other companies’ apps or websites.

15. Grievance redressal and contact

RoleContact
Privacy / Data Protection contactSri Khushaal. Y, techsupport@destini.ai
Postal addressF.no 1001 B3 Sampoornam HIG Flats Venture 2, KPHB Phase 15, Hyderabad 500085, India
General supporttechsupport@destini.ai

We acknowledge grievances within 72 hours and resolve them within 90 days, as required by Rule 14 of the DPDP Rules. If you are not satisfied with our response, you may escalate to the Data Protection Board of India.

16. Changes to this policy

We will post any change on this page and update the “Last updated” date. For material changes we will give notice in the app or by email at least 7 days before they take effect, and where the change requires it, we will seek fresh consent.

17. Governing law

This policy is governed by the laws of India. Courts at Hyderabad, Telangana, India have exclusive jurisdiction, without prejudice to your right to approach the Data Protection Board of India.

Destini.ai — an AI-powered predictive intelligence platform. Predictions and insights are provided for informational and reflective purposes only and do not constitute medical, legal, financial or professional advice.

Destini.ai Privacy Policy · Version 2.0 · Last updated 30 July 2026