Destini.ai
Destini.ai (“Destini”, “we”, “us”, “our”) is operated by Destiinnovation Pvt. Ltd., incorporated in India, CIN U62091TS2023PTC172167, registered office F.no 1001 B3 Sampoornam HIG Flats Venture 2, KPHB Phase 15, Hyderabad 500085, India.
For the purposes of the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”), we are the Data Fiduciary for personal data you provide to us. Where we process data on behalf of an enterprise API customer, that customer is the Data Fiduciary and we act as a Data Processor under contract.
This policy is written to satisfy the DPDP Act and Rules, the Information Technology Act, 2000 and the rules made under it, the CERT-In Directions of 28 April 2022, the Google Play User Data policy and Data safety disclosure requirements, and the Apple App Store Review Guidelines (§5.1 Privacy) and App Privacy disclosure requirements.
We collect the following. Items marked optional are collected only if you choose to use the associated feature.
Name, email address, mobile number, password (stored only as a salted cryptographic hash), profile photo (optional), language and notification preferences, and — if you sign in with Google or Apple — the identifier and email address that provider returns to us.
Date of birth, time of birth, and place of birth; gender (optional); relationship status (optional). These inputs are required to compute your Prana Dasha timeline and generate predictions. They are the basis of the service and cannot be removed without deleting your account.
Questions you ask PREDCTR AI, chat transcripts, prediction requests and the results generated for you, saved or bookmarked insights, and your ratings or feedback on outputs.
If — and only if — you grant the contacts permission, we read the name, phone number and, where present, date of birth of the contacts you explicitly select, in order to compute a compatibility score.
We do not bulk-upload your address book, we do not use contact data for marketing, and we do not share it with anyone. Selected contact identifiers are transmitted over TLS, used to compute the score, and then handled as described in Section 8.
Self-reported wellbeing preferences and inputs you type into the wellness insights feature. Destini is not a medical or diagnostic service, does not provide medical advice, and does not knowingly collect health records, clinical data or diagnoses. Please do not enter medical information into the app.
Work history, skills, industry and role preferences you supply to the job-recommendation feature.
Content you create, upload or publish on Scrollers (text, images, video, audio), captions, comments, likes, follows, and — if you monetise — your creator handle, payout preferences and settlement records.
Transaction identifiers, purchase and refund history, coin and wallet balances, subscription tier and validity, and GST-relevant billing details.
We never see or store your full card number, CVV, UPI PIN, or net-banking credentials. In-app purchases are processed by Google Play Billing or Apple In-App Purchase; other payments are processed by our PCI-DSS compliant payment gateway, Razorpay. We receive only a masked instrument reference and the transaction outcome.
Device model, operating system and version, app version, language and time zone, IP address, a resettable app instance identifier, crash logs, performance traces, and in-app event logs (screens viewed, features used).
Coarse or precise location, only if you grant the permission, and only to auto-fill a place of birth or a location-dependent calculation. You may deny or revoke this at any time and enter locations manually instead.
Support tickets, emails, in-app messages and any attachments you send us.
We do not collect Aadhaar numbers, PAN (except where legally required for creator payouts), biometric data, government identity documents, precise health or clinical records, or data about your caste, religion, political affiliation or sexual life.
| Permission | Why we ask | If you decline |
|---|---|---|
| Notifications | Daily prediction alerts, transit alerts, account and payment notices | No push alerts; app fully usable |
| Contacts (optional) | Compatibility scoring for contacts you select | Compatibility feature unavailable |
| Camera / Photos (optional) | Profile photo, Scrollers uploads | Cannot upload media |
| Location (optional) | Place-of-birth and location-based calculations | Enter locations manually |
| Storage / Media (optional) | Saving and sharing generated content | Cannot save locally |
Permissions are requested in context, only at the point of use, and can be revoked at any time in your device settings. Revoking a permission stops further collection immediately and triggers deletion of the associated data as set out in Section 8.
We process your personal data on the basis of your consent, which you may withdraw at any time, and — where applicable — for the legitimate uses permitted under Section 7 of the DPDP Act (for example, compliance with a legal obligation, or responding to a threat to security).
| Purpose | Data used |
|---|---|
| Create and secure your account | 3.1 |
| Generate predictions, dashboards and Prana Dasha timelines | 3.2, 3.3 |
| Operate optional features you switch on | 3.4, 3.5, 3.6, 3.7, 3.10 |
| Process payments, subscriptions, coins and creator payouts | 3.8 |
| Provide support and respond to grievances | 3.11 |
| Detect fraud, abuse and security incidents | 3.9 |
| Fix crashes, measure performance, improve features | 3.9, aggregated 3.3 |
| Send service and transactional communications | 3.1 |
| Send marketing, only with separate opt-in consent | 3.1 |
| Meet statutory, tax and regulatory obligations | 3.8, 3.9 |
Model training. We do not use your identifiable birth details, chat content or wellness inputs to train third-party foundation models. Where we improve our own interpretation engine, we use aggregated or de-identified data only. If we ever wish to use identifiable content for model improvement, we will ask for separate, specific and revocable consent first.
Our primary data storage is in India. Some processors (for example AI inference or email delivery) may process data outside India. Where that happens we transfer only what is necessary, under contractual safeguards, and only to countries and territories not restricted by the Central Government under Section 16 of the DPDP Act and Rule 15 of the DPDP Rules. Where a legal requirement mandates local storage of a category of data, we store that category in India.
This section states our data retention practices in full, as required by the Google Play User Data policy.
We retain personal data only for as long as the purpose for which it was collected continues to be served, and then erase it. Retention is enforced by scheduled, automated jobs — not left to discretion. Specifically:
| Data category | Retention period | Trigger for erasure |
|---|---|---|
| Account and identity data (3.1) | For the life of your account | Erased within 30 days of account deletion |
| Birth and profile inputs (3.2) | For the life of your account | Erased within 30 days of account deletion |
| Prediction and chat history (3.3) | 24 months rolling from creation, or until you delete it | Auto-purged at 24 months; immediately when you delete an item; within 30 days on account deletion |
| Contact and compatibility data (3.4) | Contact identifiers are held only for the active session needed to compute the score, to a maximum of 7 days in transient cache. Only the derived compatibility score and any label you assign are stored, for the life of your account. | Immediate purge of all contact-derived data when you revoke the contacts permission, remove a contact in-app, or delete your account |
| Wellness inputs (3.5) | 12 months from entry, or until you delete them | Auto-purged at 12 months; within 30 days on account deletion |
| Career inputs (3.6) | For the life of your account | Erased within 30 days of account deletion |
| Scrollers content (3.7) | Until you delete the content or your account | Removed from public view immediately; erased from primary storage within 30 days |
| Creator payout and settlement records (3.7, 3.8) | 8 financial years, as required by the Companies Act, 2013 and applicable tax law | Erased once the statutory period lapses |
| Payment and transaction records (3.8) | 8 financial years (statutory books of account, GST and income-tax records) | Erased once the statutory period lapses |
| Device and diagnostic data, crash logs (3.9) | 90 days | Automatic expiry |
| Traffic data, access logs and processing logs (3.9) | 12 months, the minimum required by Rule 6 of the DPDP Rules. ICT system logs are retained 180 days within India per the CERT-In Directions of 28 April 2022. | Automatic expiry after the longer applicable period |
| Location data (3.10) | Not stored as a location trail. Used at the moment of the request and discarded; only the resolved place name you save is kept, for the life of your account. | Immediate on permission revocation |
| Support communications (3.11) | 24 months from ticket closure | Automatic expiry |
| Consent and consent-withdrawal records | Life of your account plus 3 years, as evidence of lawful processing | Erased after that period |
| Marketing suppression list (hashed email / phone) | Retained in hashed form for as long as needed to honour your opt-out | Retained solely to respect your choice |
| Encrypted backups and disaster-recovery snapshots | Maximum 90 days, then overwritten | Deleted records do not survive beyond 90 days in backups |
| Aggregated and irreversibly anonymised statistics | Indefinitely | Not personal data; cannot be linked back to you |
Inactive accounts. If you do not interact with your account for 3 continuous years, we treat the purpose of processing as no longer served. We will notify you at your registered email address at least 48 hours before erasure, giving you the opportunity to log in and retain your account. If you do not, we erase your personal data other than records we are legally required to keep.
Retention beyond these periods occurs only where a specific law, a court or regulatory order, or the establishment or defence of a legal claim requires it. In that case we retain only the specific records needed, restrict access to them, and erase them once the requirement ends.
Withdrawal of consent. If you withdraw consent for a purpose, we stop that processing without undue delay and erase the data collected for it within 30 days, unless retention is legally required.
You can delete your account and associated personal data at any time:
What happens next:
You can also delete data without deleting your account. Individual chats, predictions, wellness entries, Scrollers posts and saved contacts can each be deleted in-app, and revoking a device permission purges the data that depended on it.
Under the DPDP Act you have the right to:
How to exercise them. Use Settings → Privacy → My Data in the app, or email privacy@destini.ai. We may ask you to verify your identity. We respond within 30 days, and in any event within the 90-day statutory maximum for grievances.
Your duties. The DPDP Act also requires you not to impersonate another person when providing data, not to suppress material information, and not to file false or frivolous grievances or erasure requests.
Destini.ai is intended for users aged 18 and above. We do not knowingly process the personal data of a child (a person under 18) without verifiable parental consent obtained in accordance with Rule 10 of the DPDP Rules. We do not undertake tracking, behavioural monitoring or targeted advertising directed at children, and we do not process children’s data in a way likely to have a detrimental effect on their wellbeing.
For a person with a disability who has a lawful guardian, we process data only with the guardian’s verified consent.
If you believe a child has registered, write to techsupport@destini.ai and we will verify and delete the account and its data promptly.
We apply technical and organisational safeguards proportionate to the sensitivity and volume of the data we process, including:
No system is perfectly secure. Please keep your credentials confidential and notify us immediately of any suspected unauthorised access.
If a personal data breach occurs, we will inform affected users without delay, in clear language, describing the nature and extent of the breach, its likely consequences, the measures we have taken, and the safety measures you can take. We will notify the Data Protection Board of India without delay and file a detailed report within 72 hours, and will report qualifying cyber incidents to CERT-In within 6 hours as required by the 2022 Directions.
| Role | Contact |
|---|---|
| Privacy / Data Protection contact | Sri Khushaal. Y, techsupport@destini.ai |
| Postal address | F.no 1001 B3 Sampoornam HIG Flats Venture 2, KPHB Phase 15, Hyderabad 500085, India |
| General support | techsupport@destini.ai |
We acknowledge grievances within 72 hours and resolve them within 90 days, as required by Rule 14 of the DPDP Rules. If you are not satisfied with our response, you may escalate to the Data Protection Board of India.
We will post any change on this page and update the “Last updated” date. For material changes we will give notice in the app or by email at least 7 days before they take effect, and where the change requires it, we will seek fresh consent.
This policy is governed by the laws of India. Courts at Hyderabad, Telangana, India have exclusive jurisdiction, without prejudice to your right to approach the Data Protection Board of India.