Skip to content
Ristara
How it works
Star ProfileLove LanguageSoulmate Love Language
Check Compatibility
About usAstrologyMethodologyFAQs
LoginBegin Your Story
Back to Legal

Ristara Privacy Policy

Version 1.0 · Effective: July 25, 2026 · Last updated: July 25, 2026

Table of Contents

  1. 1. Overview and Scope
  2. 2. About Us and How to Contact Us
  3. 3. Plain-Language Commitment
  4. 4. Personal Information We Collect
  5. 5. Sensitive Personal Information
  6. 6. Sources of Personal Information
  7. 7. How We Use Personal Information
  8. 8. Legal Bases for Processing (UK and EEA)
  9. 9. How We Share Personal Information
  10. 10. Our Subprocessors and What We Require of Them
  11. 11. We Do Not Sell or Share Personal Information
  12. 12. Cookies, SDKs, and Similar Technologies
  13. 13. How Long We Keep Personal Information
  14. 14. Security
  15. 15. Caste, Jati, and Community Data (Special Handling)
  16. 16. Your Choices and Privacy Rights (All Users)
  17. 17. California Privacy Rights (CCPA / CPRA), including ADMT, Risk Assessments, and Cybersecurity Audits
  18. 18. Other U.S. State Privacy Rights (including MODPA)
  19. 19. United Kingdom Privacy Rights (UK GDPR)
  20. 20. Canada Privacy Rights (PIPEDA and Quebec Law 25)
  21. 21. Profiling: What We Do and Do Not Do
  22. 22. Automated Decisionmaking Technology (ADMT)
  23. 23. Children
  24. 24. Do Not Track and Global Privacy Control
  25. 25. Third-Party Links and Services
  26. 26. Submitting a Request and Verifying Your Identity
  27. 27. Changes to This Policy
  28. 28. Appendices
  29. Appendix A: CCPA / CPRA Categories Table
  30. Appendix B: Subprocessors and Service Providers
  31. Appendix C: Annual CCPA / CPRA Metrics (Placeholder)
  32. Appendix D: Biometric and Health-Adjacent Information
  33. Appendix E: Quebec Law 25 Notice
  34. Appendix F: United Kingdom GDPR-Specific Notice

Entity: Ristara Inc., a Delaware corporation operating in California Trade Name: Ristara


§0. Plain English Summary

This summary is for your understanding. The full Policy is the binding document.

Who we are. Ristara, operated by Ristara Inc. in California.

What we collect. Your account info, profile (including birth date and optional birth time and place for astrology), photos, communications, location, payment information through Stripe / Apple / Google, and device or usage signals.

What's sensitive. Religion, sexual orientation, caste or jati if you provide it, precise location, account credentials, selfie data, and the contents of your private messages. We treat these as sensitive.

We do not sell your data. We do not sell or share your personal information for cross-context behavioral advertising. We do not run targeted ads.

Selfie verification. If you choose to verify, an automated service checks that the selfie is of a live person and matches your profile photo. We delete the selfie within 30 days. We do not sell biometric data. Annex B of the Terms has the legal-grade details.

Algorithms. Compatibility scoring and the introductions you see are computed by software based on your birth data and preferences. These are tools, not decisions about your rights. You can read more in §22.

Your rights. Depending on where you live, you can see, correct, delete, port, or restrict the personal information we hold about you. See §16 through §19.

Cancel anytime. Account deletion is in Settings. We honor it within the grace period set in §13.

Under 18. The Service is adults-only. We do not knowingly collect personal information from anyone under 18, and we never sell personal information of any user under 18.



1. Overview and Scope

This Privacy Policy explains how Ristara Inc. ("Ristara," "we," "us," "our") collects, uses, shares, and protects personal information when you use the Ristara website at ristara.com, the Ristara mobile applications for iOS and Android, the Ristara public tools and content, the Ristara application programming interfaces, and any related services (collectively, the "Service").

By using the Service, you acknowledge that you have read this Policy. This Policy is incorporated by reference into the Ristara Terms of Service.

Audience. The Service is intended for adults aged 18 or over. We do not knowingly collect personal information from anyone under 18. See §23.


2. About Us and How to Contact Us

The data controller (and, where applicable, business under the CCPA) for personal information processed in connection with the Service is:

Ristara Inc. Attention: Privacy 8409 Florence Ave. Suite 202, Downey, CA 90240 Email: [email protected] (all privacy requests, legal notices, and general support)

Quebec Privacy Officer (Law 25). See Appendix E for the contact details of the person responsible for the protection of personal information under Quebec Law 25.

UK and EU representative. Where required by Article 27 UK GDPR, see Appendix F.


3. Plain-Language Commitment

We commit to writing material consent screens, privacy notices, and disclaimers at an eighth-grade reading level, and to providing a plain-English summary at the top of this Policy and the Terms of Service. Legal-grade language remains in the numbered sections.


4. Personal Information We Collect

4.1 Information you provide

  • Account information. Name, email, phone number, password (hashed), OAuth tokens from Google or Apple, and a unique user identifier.
  • Profile information. Display name, gender, photos, height, education, occupation, religion, marital status, languages, lifestyle attributes, bio, prompt answers, marriage timeline, children preferences, ancestral state or region, and community or jati where you choose to provide it. See §15 for the special handling of caste, jati, and community fields.
  • Birth information used for astrology. Birth date, birth time (if you provide it), birth location, and your calculation preferences. We record the precision of birth time you provide.
  • Astrological output stored about you. Derived attributes including Moon nakshatra, rashi, lagna, planetary positions and houses, manglik status and any cancellations, kaal sarp status, dasha periods, and Ashtakoota inputs.
  • Preferences. Match preferences, notification settings, visibility settings, and other in-app preferences.
  • Photos and verification media. Profile photos, photo prompts, and, where you choose to verify, selfie images or selfie video frames used for liveness detection and face comparison. See §4.6 and ToS Annex B.
  • Communications. Messages and voice notes between users, content of support tickets, survey responses, feedback, reports of other users, and reviews.
  • Payment information. Stripe (web) and Apple or Google (in-app) collect payment details. We do not store your full payment-card number. We receive limited information such as the last four digits, card brand, billing zip, and a tokenized reference.
  • Contact details if you import or refer friends. Used only to send the invitation. We do not retain them as marketing leads.

4.2 Information we collect automatically

  • Device and technical information. Model, OS, app and browser version, time zone, IP address, mobile-network info, crash and performance data.
  • Usage information. Pages, screens, features, taps, scroll depth, search queries, time stamps, session duration, and inferred engagement.
  • Approximate location. Derived from IP.
  • Precise location. Only if you grant device-level permission and use a feature that requires it.
  • Cookies and similar technologies. See §12.

4.3 Information from third parties

  • Authentication providers (Google, Apple).
  • Payment processors (Stripe, Apple, Google).
  • Fraud-prevention vendors.
  • Communications carriers and providers (Twilio and similar).
  • Public sources.

4.4 Information we infer

We infer engagement level, churn risk, and astrological alignment between profiles. We do not infer race, color, ancestry, national origin, citizenship, religion or creed (beyond what you state), sex, gender, gender identity, sexual orientation, age, disability, or other protected characteristics for advertising. We do not infer characteristics about you that you have not provided, except as strictly necessary to operate the Service.

4.5 Information you share through chat

Messages and voice notes you exchange with other users are personal information of both you and the recipient. We process this content to deliver, moderate, and secure chat, to prevent abuse, and to comply with legal obligations. We may scan messages with automated tools, retain them as set out in §13, and review them when responding to a report or legal process.

4.6 Selfie verification and biometric-adjacent data

If you choose to verify, we process a selfie video and a reference frame through AWS Rekognition Face Liveness and CompareFaces (or successor services) for liveness detection and face comparison. Detailed BIPA, CUBI, MHMDA, California, Quebec, and UK / EU notices are set out in ToS Annex B (Biometric and Verification Data Notices) and in Appendix D below.

  • We delete selfie video, reference frames, and any biometric identifiers within 30 days of the verification decision.
  • We do not sell biometric data.
  • We do not use biometric data for profiling or advertising.
  • You can decline verification at any time.

5. Sensitive Personal Information

For California, Colorado, Connecticut, Virginia, Utah, Oregon, Texas, Montana, Maryland, New Jersey, and other state privacy laws, sensitive personal information includes:

  • Religious or philosophical beliefs. You may enter religion or spiritual community.
  • Caste, jati, gotra, or ancestral information, where you choose to provide it. We treat this as sensitive personal information by contract whether or not your state law expressly enumerates it. See §15.
  • Sexual orientation, including as indicated by your "looking for" preference.
  • Precise geolocation. Only with your device-level permission.
  • Account credentials.
  • Biometric data, as described in §4.6 and ToS Annex B.
  • Contents of private communications.
  • Information regarding a known child (we do not knowingly collect this).
  • Genetic data (we do not collect this).

We do not use Sensitive Personal Information to infer characteristics about you for advertising or for any purpose other than: (a) providing the Service you requested (including matchmaking based on your stated preferences); (b) detecting security incidents and resisting malicious, deceptive, fraudulent, or illegal actions; (c) ensuring the safety of users and the public; (d) verifying or maintaining the quality or safety of the Service; (e) performing services on our behalf; and (f) complying with law. These uses fall within 11 CCR § 7027 and do not require an opt-out, but you may still request that we limit our use. See §17.

We do not sell or share Sensitive Personal Information.


6. Sources of Personal Information

You; your devices; authentication providers (Google, Apple); payment processors (Stripe, Apple, Google); communications and verification providers (Twilio, AWS); other users; public sources.


7. How We Use Personal Information

7.1 Provide and operate the Service. Create and manage your account; calculate Vedic astrological attributes from the birth data you supply; deliver introductions; compute compatibility; show profiles; enable chat; deliver Muhurta and timing insights; process payments; deliver notifications; provide support.

7.2 Personalization. Tailor the experience to your preferences and inferred engagement.

7.3 Trust and safety. Detect and prevent fraud, spam, harassment, scams, impersonation, romance fraud, and abuse; investigate reports; enforce the Terms; cooperate with law enforcement when required.

7.4 Verification. Confirm that selfies represent a live person reasonably matching the profile photo (§4.6).

7.5 Communications. Send transactional notices, respond to support, and, with consent where required, send marketing.

7.6 Improve the Service. Analyze usage and feedback to fix bugs, develop features, run A/B tests, and tune matching using a self-hosted PostHog instance. We do not use User Content to train or fine-tune AI / ML models without separate consent (ToS §11.5).

7.7 Comply with the law. Meet record-keeping, tax, accounting, audit, age-verification, and other legal obligations; respond to lawful requests; enforce our rights.

7.8 Legitimate interests of Ristara or a third party (UK / EEA), where not overridden by your rights.

7.9 Aggregate or de-identified data. We may create de-identified or aggregated information for analytics, research, marketing, and similar purposes. We commit, by contract and by technical control, not to attempt re-identification.


8. Legal Bases for Processing (UK and EEA)

Where you are in the United Kingdom or the European Economic Area, our legal bases include:

  • Performance of a contract with you.
  • Compliance with a legal obligation.
  • Consent, including explicit consent under Article 9 UK GDPR for special-category data (religion, sexual orientation, biometric data processed to uniquely identify you). You may withdraw consent at any time.
  • Legitimate interests (for example, securing the Service and preventing abuse), where not overridden by your rights.
  • Vital interests in narrow safety cases.

Detailed UK-specific disclosures, including transfer mechanisms and representative information, are in Appendix F.


9. How We Share Personal Information

9.1 With other users. Information on your profile is visible to other users in accordance with your visibility settings. Caste, jati, community, and ancestral information are not shown until a mutual connection is formed (§15). Chat content is shared with the user you communicate with.

9.2 With our service providers (processors). We engage trusted vendors under contract. They may only use your information to provide services to us. We require, by Data Processing Addendum:

  • Purpose limitation and confidentiality
  • Sub-processor approval, sub-processor pass-through obligations, and a current sub-processor list
  • Breach notification within 48 hours of vendor discovery
  • Data return or destruction on termination
  • Cooperation with our CPPA cybersecurity audit obligations under §17
  • Cooperation with our Quebec Law 25 privacy impact assessment obligations
  • Restrictions on use of Sensitive Personal Information
  • Compliance with applicable cross-border transfer mechanisms (SCCs, UK IDTA)
  • Audit rights or equivalent assurance
  • No selling or sharing of personal information

Categories: cloud hosting and storage; payments; authentication; email delivery; SMS delivery; push notifications; identity and content moderation; analytics (self-hosted); monitoring and operations. A current list is in Appendix B.

9.3 In connection with legal matters. We may disclose personal information to comply with law, regulation, lawful process, court order, subpoena, or government request; to enforce our Terms; to respond to claims; to protect the rights, property, or safety of Ristara, our users, or any third party; and to investigate or prevent fraud or abuse. Where lawful, we will challenge requests we believe are overbroad and notify users of legal demands.

9.4 In connection with a business transaction. Merger, acquisition, financing, reorganization, sale of assets, or bankruptcy, subject to confidentiality obligations and restrictions in this Policy and law.

9.5 With your direction or consent. When you share a public match link, generate a shareable compatibility card, or post about Ristara on social media via integrations.

9.6 De-identified or aggregated information. We may share de-identified or aggregated information for research, analytics, marketing, and similar purposes, subject to the contractual non-re-identification commitments in §7.9.


10. Our Subprocessors and What We Require of Them

A current list of principal subprocessors is in Appendix B. An updated list is available at any time on request to [email protected]. We review every new subprocessor for security and privacy practices before onboarding, with heightened review where sensitive personal information is involved.


11. We Do Not Sell or Share Personal Information

We do not "sell" personal information for money or other valuable consideration as defined in the CCPA, and we do not "share" personal information for cross-context behavioral advertising as defined in the CCPA and analogous state laws (Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Maryland, and others).

  • We do not allow third-party advertising networks to set tracking cookies or SDKs on the Service for cross-context behavioral advertising.
  • We do not disclose personal information to data brokers.
  • We do not engage in profiling for advertising decisions producing legal or similarly significant effects (§21).
  • We do not sell sensitive personal information.
  • We do not sell the personal information of any user under 18.

We may engage in contextual advertising or first-party marketing communications (ToS §18). These are not a "sale" or "share."


12. Cookies, SDKs, and Similar Technologies

We use cookies and similar technologies for:

  • Strictly necessary purposes (authentication, login persistence, request routing).
  • Functional purposes (preferences and recognized device).
  • Analytics for first-party product analytics, hosted by us (self-hosted PostHog).
  • Security for detection of malicious activity.

We do not use advertising cookies that share data with third-party advertisers.

You can manage cookies through your browser. In the UK and EEA, we present a cookie banner that lets you accept, reject, or manage non-essential cookies. We honor the Global Privacy Control signal in jurisdictions that recognize it (§24).


13. How Long We Keep Personal Information

Data categoryRetention
Active account informationLife of account
Account information after deletion requestUp to 30-day grace period during which you may reactivate; then full deletion subject to backup rotation up to 90 days
Birth data and derived astrological dataDeleted with the account, subject to backup rotation
Selfie video and reference framesUp to 30 days from verification decision (typically same day)
Biometric identifiersUp to 30 days from verification decision; no template retained
Selfie confidence scores and outcomesAudit log up to 24 months; outcome record until account deletion
Chat contentLife of conversation; deleted bilaterally on unmatch, report, or account deletion subject to safety, audit, and legal-hold needs
Payment records (tax and audit)Up to 7 years
Marketing-SMS consent records (TCPA)At least 4 years (ToS §18.3)
Auto-renewal consent records (CA AB 2863)3 years from consent, or 1 year post-termination, whichever is longer (ToS §7.8)
Operational logsUp to 12 months
BackupsUntil rotated out per backup schedule (typically up to 90 days)
Safety enforcement records (post-ban)Hashed identifier and ban reason retained to prevent re-registration

Where you have been suspended or terminated for safety reasons, we may retain a limited record (hashed identifier, ban reason, date) to enforce the suspension and prevent re-registration.


14. Security

We use administrative, technical, and physical safeguards designed to protect personal information from unauthorized access, disclosure, alteration, and destruction. Measures include:

  • Encryption in transit and at rest where appropriate
  • Access controls and role-based authorization
  • Password hashing
  • Secure development practices
  • Periodic vulnerability scanning
  • Vendor diligence and DPAs
  • Incident-response procedures
  • Logging and monitoring

However, no security control is perfect. We cannot guarantee absolute security and you use the Service at your own risk. If you believe your account has been compromised, contact [email protected] immediately. We will notify affected users and regulators of a personal-data breach as required by applicable law.

We commit to annual cybersecurity audits per CPPA regulations on the staggered Apr 1, 2028 / 2029 / 2030 certification timeline (see §17).


15. Caste, Jati, and Community Data (Special Handling)

Caste, jati, gotra, ancestral state, and community-preference fields are offered in the Service because they matter to many users who seek partners within a community context.

We handle these fields with the following commitments:

  • Sensitive by contract. We treat caste, jati, gotra, and community-preference fields as sensitive personal information whether or not the applicable state privacy law expressly enumerates them.
  • Off by default. These fields are not pre-filled, not inferred from your other inputs, and not collected unless you affirmatively choose to provide them.
  • Post-match disclosure only. These fields are not displayed to other users until you have formed a mutual connection and the other user has separately viewed them.
  • No discrimination. Use of these fields to harass, exclude, demean, or discriminate against any user is prohibited under ToS §14.13.
  • Civil-rights context. We acknowledge that caste-based discrimination is unlawful in the City of Seattle (Feb. 2023 ordinance), the City of Fresno (2023 ordinance), and is interpreted as protected under the existing FEHA category of "ancestry" by the California Civil Rights Department. Even where the California legislature has not enumerated caste as a separate protected class (as of the effective date, SB 403 was vetoed October 7, 2023), use of these fields to discriminate is impermissible under our Terms.
  • Deletion on request. You may delete these fields at any time without affecting any other aspect of your account.
  • Not sold, not shared, not used for advertising. These fields are not sold, not shared for cross-context behavioral advertising, and not used to train any AI / ML model.

16. Your Choices and Privacy Rights (All Users)

Regardless of where you live, you can:

  • Edit your profile to change or remove information
  • Control visibility in Settings (hide distance, hide active status, pause profile)
  • Manage notifications in Settings
  • Opt out of marketing email and SMS at any time
  • Delete your account in Settings, subject to a grace period and the retention rules above
  • Contact us at [email protected] to request access, deletion, correction, portability, restriction, objection, opt-out, or limit on Sensitive PI

See §26 for how to submit a request.


17. California Privacy Rights (CCPA / CPRA), including ADMT, Risk Assessments, and Cybersecurity Audits

This Section applies to California residents and supplements the rest of this Policy. It is provided in compliance with the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and the California Privacy Protection Agency's implementing regulations, including the package of ADMT, Risk Assessment, and Cybersecurity Audit regulations approved by the Office of Administrative Law on September 23, 2025.

17.1 Notice at collection

Appendix A summarizes the categories of personal information we collect, the purposes for which we collect each category, the categories of third parties to which we disclose each category, and our retention. We collect personal information for the purposes described in §7. Retention is in §13.

17.2 Categories of personal information and sensitive personal information

See §4, §5, and Appendix A.

17.3 Right to know

You have the right to request that we disclose: (a) categories of personal information collected; (b) categories of sources; (c) business or commercial purpose; (d) categories of third parties to which it is disclosed; and (e) specific pieces of personal information we have about you.

17.4 Right to delete

You have the right to request deletion, subject to CCPA § 1798.105(d) exceptions.

17.5 Right to correct

You have the right to request correction of inaccurate personal information.

17.6 Right to data portability

You have the right to receive a copy of your personal information in a portable, readily usable format.

17.7 Right to opt out of sale and sharing

We do not sell or share personal information as those terms are defined (§11). No action is necessary. If our practices ever change, we will provide an opt-out as required by law.

17.8 Right to limit use of Sensitive Personal Information

We use Sensitive Personal Information only for purposes permitted under 11 CCR § 7027, which do not require an opt-out. You may nonetheless request that we limit our use to those permitted purposes by contacting [email protected].

17.9 Right to non-discrimination

We will not discriminate against you for exercising your privacy rights.

17.10 Automated Decisionmaking Technology (ADMT)

See §22 for our detailed ADMT disclosures, opt-out, and human-review appeal commitments.

17.11 Risk assessments

For processing initiated on or after January 1, 2026, where required by 11 CCR § 7150 et seq., we conduct a risk assessment before initiating such processing and on a periodic basis thereafter. We commit to submitting an attestation to the CPPA covering risk assessments conducted from January 1, 2026 to December 31, 2027 by April 1, 2028, and annually thereafter on the schedule the CPPA prescribes. Internal records of our restrict-or-prohibit decisions on high-risk processing are maintained for at least five years.

17.12 Cybersecurity audits

We commit to obtaining annual independent cybersecurity audits as required by 11 CCR § 7120 et seq., with our first certification of completion submitted to the CPPA on the staggered schedule (Apr 1, 2028, 2029, or 2030 depending on annual gross revenue and processing thresholds the CPPA has set). We require by contract that all subprocessors cooperate with our cybersecurity audit obligations.

17.13 Authorized agent

You may use an authorized agent to submit a request on your behalf. The agent must provide written, signed authorization, and we may require you to verify your identity directly.

17.14 Submitting a request

See §26.

17.15 California "Shine the Light"

Cal. Civ. Code § 1798.83 entitles California residents to request information about our disclosures, if any, of personal information to third parties for those third parties' direct marketing purposes. We do not engage in such disclosure.

17.16 Metrics

Annual metrics on CCPA requests will be reported in Appendix C beginning after the first full reporting period.


18. Other U.S. State Privacy Rights (including MODPA)

If you are a resident of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Indiana, Tennessee, New Hampshire, Maryland, New Jersey, Nebraska, Rhode Island, Kentucky, or Minnesota, you may have, to the extent provided by applicable law:

  • Confirm and access.
  • Correct.
  • Delete.
  • Portability.
  • Opt out of (a) targeted advertising, (b) sale, and (c) profiling in furtherance of decisions that produce legal or similarly significant effects. We do not engage in any of (a), (b), or (c) in the regulated sense. If our practices change, we will provide the required mechanisms.
  • Appeal if a request is denied; we provide the statutorily required response period and, in Colorado and certain other states, information about filing a complaint with the state attorney general.

18.1 Maryland Online Data Privacy Act (MODPA)

For Maryland residents, we additionally commit to:

  • Data minimization. We collect and process only personal data that is reasonably necessary and proportionate to provide or maintain the specific product or service requested by you.
  • No sale of sensitive personal information. Effective.
  • No sale of personal data of consumers under 18. Effective.
  • No targeted advertising for consumers we know to be under 18.
  • Heightened sensitive-data protections consistent with Md. Code Ann., Com. Law § 14-4607.

18.2 Other states

We comply with the comprehensive privacy laws of the states listed above as they apply. Specific rights are exercised through §26.


19. United Kingdom Privacy Rights (UK GDPR)

If you are in the United Kingdom, see Appendix F for the full UK-specific notice including lawful bases, special-category processing, transfer mechanisms (UK IDTA), retention, and your rights.


20. Canada Privacy Rights (PIPEDA and Quebec Law 25)

If you are a resident of Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial laws (Quebec Law 25, BC PIPA, Alberta PIPA) apply. See Appendix E for the Quebec-specific notice.

You may:

  • Access your personal information
  • Request correction of inaccurate information
  • Withdraw consent, subject to legal or contractual restrictions
  • File a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca) or the provincial commissioner (CAI for Quebec)

For CASL, marketing emails contain identification of the sender and an unsubscribe mechanism.


21. Profiling: What We Do and Do Not Do

We compute compatibility scores, curate introductions, and schedule notifications using algorithmic systems based on the birth data, preferences, and engagement signals associated with you and other users.

These outputs do not produce legal or similarly significant effects. They are informational tools. They do not determine your access to financial services, employment, housing, healthcare, insurance, education, or essential goods or services. They do not determine eligibility for the Service. They do not determine pricing in a way that produces legal or similarly significant effects.

We do not engage in profiling for ad-targeting purposes. We do not use Sensitive Personal Information to infer protected characteristics for advertising or for any purpose other than those listed in §5.

If automated decisions used in the Service ever begin to produce legal or similarly significant effects, we will update §22, provide notice, offer an opportunity to obtain human review, and offer the rights required under applicable law.


22. Automated Decisionmaking Technology (ADMT)

This Section is provided pursuant to the CPPA's Automated Decisionmaking Technology regulations approved September 23, 2025 and effective for covered uses on January 1, 2027, and pursuant to analogous laws in other jurisdictions.

22.1 What we use and why

  • Compatibility scoring. Algorithmic computation of Ashtakoota and related scores from your birth data and the other user's birth data.
  • Introduction curation. Algorithmic selection and ordering of the introductions you see, based on your preferences, engagement signals, and compatibility outputs.
  • Notification scheduling. Algorithmic selection of when to deliver transactional notifications.
  • Photo and content moderation. Automated detection of policy-violating content (nudity, weapons, hate symbols, and similar). False-positive appeals are reviewed by humans.
  • Selfie verification. Automated liveness and face-comparison checks (see §4.6 and ToS Annex B). False-rejection appeals are reviewed by humans within 24 hours of request.

22.2 What we do not use ADMT for

We do not use ADMT to make decisions about you that produce legal or similarly significant effects, including decisions about employment, housing, healthcare, financial services, education, insurance, government services, criminal justice, or essential goods and services. We do not use ADMT to make decisions about your eligibility for the Service.

22.3 Pre-use notice

This Section serves as our pre-use notice. We will update it before introducing any new ADMT use that falls within CPPA scope.

22.4 Right to opt out

Where the CPPA regulations require an opt-out for a particular ADMT use, we will provide it. as of the effective date, no use of ADMT in the Service has been classified as requiring an opt-out under 11 CCR §§ 7200 et seq.; nevertheless, you may request an opt-out from any specific ADMT use by emailing [email protected], and we will respond with whether the use is opt-outable and how.

22.5 Right to access information about ADMT

You may request information about the logic and parameters of any ADMT we use that affects you, the categories of inputs, and the rough nature of the output, subject to trade-secret protection and to the limits of CPPA regulations.

22.6 Human review

For any ADMT outcome you wish to contest (false-positive moderation, false-rejection selfie verification, suppression of an introduction you believe should have appeared), you may request human review by emailing [email protected]. Routine reviews are completed within five business days; safety-critical reviews (selfie verification, content moderation) within 24 hours.

22.7 Vendor ADMT

Our subprocessors (AWS Rekognition, Firebase, and others) may operate ADMT on our behalf. The contractual restrictions in §9.2 and §10 apply.


23. Children

The Service is intended exclusively for adults aged 18 or over. We do not knowingly collect personal information from anyone under 18.

  • If we learn that we have collected personal information from a person under 18, we will delete that information and terminate the account.
  • We never sell or share the personal information of any user under 18.
  • We do not knowingly collect any personal information from children under 13 (COPPA, 15 U.S.C. § 6501 et seq.).
  • For California minors under 18 who created an account in violation of the Terms, California Business and Professions Code § 22581 also gives them a right to request removal of content they posted, which is built into the deletion flow.
  • For UK users we identify or reasonably suspect as being under 18, the ICO Age Appropriate Design Code applies.

If you are a parent or guardian and believe a minor has provided us with personal information, contact [email protected].


24. Do Not Track and Global Privacy Control

Our Service does not respond to "Do Not Track" browser signals because there is no consensus standard. We do recognize and honor the Global Privacy Control (GPC) browser signal as an opt-out preference signal from California and other states that recognize it.

How we honor GPC.

  • Our web servers detect the Sec-GPC: 1 header on each request.
  • When detected, we (a) confirm in our records that the user from that browser session is opted out of any sale or sharing for cross-context behavioral advertising, and (b) treat the signal as a valid request to confirm and maintain that status under §11.
  • Because we do not sell or share personal information for cross-context behavioral advertising, the GPC signal does not change our processing.
  • A user-visible confirmation is provided on the privacy settings page.

25. Third-Party Links and Services

The Service may contain links to third-party sites or integrate with third-party services. Each is governed by its own privacy policy. We are not responsible for the privacy practices of third parties.


26. Submitting a Request and Verifying Your Identity

To submit a request:

  • Email [email protected]
  • In-product form in Settings → Privacy (where available)

To protect your account, we will verify your identity before fulfilling a request, typically by confirming control of your registered email and matching information on file. For sensitive requests, additional verification may be required.

Response timelines (subject to extensions allowed by law):

LawInitial responseExtension
CCPA / CPRA45 daysOne additional 45-day period
UK GDPR1 monthTwo further months for complex requests
PIPEDA30 daysOne additional 30-day period
Quebec Law 2530 days(No extension by default)
Other US state laws45 days typicalPer applicable statute

If we deny a request, we explain why and, in jurisdictions providing an appeal right, inform you how to appeal. You may also lodge a complaint with your supervisory authority or attorney general.

There is no fee for a privacy request unless it is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse, as permitted by law.


27. Changes to This Policy

We may update this Policy from time to time. The "Last Updated" date reflects the most recent revision. Material changes will be communicated through the Service or by email at least 30 days in advance where they adversely affect you. Continued use after the effective date is your acknowledgment. Where required by law, we will obtain your consent.


28. Appendices


Appendix A: CCPA / CPRA Categories Table

CCPA CategoryExamples we collectPurposesDisclosed for a business purpose toSold?Shared for CCBA?
IdentifiersName, email, phone, user ID, IP, device ID, OAuth IDsAccount, security, communication, fraud preventionHosting, email, SMS, push, authentication, fraud-prevention, moderation providers; legal recipientsNoNo
Customer recordsProfile fields, payment-related info (partial card data, tokens)Provide and bill for the ServicePayment processors; accounting, tax, audit providersNoNo
Characteristics under California or federal lawAge, marital status, religion, sexual orientationProvide matchmakingLimited to providers strictly necessary; other users per visibilityNoNo
Commercial informationSubscription history, transactions, products purchasedProvide the Service, billing, supportPayment processors, accountingNoNo
Internet or network activityPages and screens viewed, taps and clicks, search history, interactions with our notificationsOperate, secure, analyze, improve the ServiceHosting, self-hosted analytics, monitoringNoNo
GeolocationApproximate from IP; precise only with permissionDistance-based discovery, fraud preventionHosting, fraud-preventionNoNo
SensoryPhotos, selfies and selfie video frames (verification), voice notes if usedProfile display, identity verification, communicationModeration, verification, hosting providersNoNo
Professional or employmentOccupation, educationProfile display, matchmakingVisibility per your settings; not disclosed for marketingNoNo
Education informationSchool, degreeSameSameNoNo
InferencesEngagement scores, compatibility outputs, churn riskPersonalization, recommendations, retentionSelf-hosted analytics; no third-party advertisersNoNo
Sensitive personal information (§5)Religion, caste / jati / community (§15), sexual orientation, precise geolocation, account credentials, selfie data, contents of private communicationsAs listed in §5 onlyLimited to providers strictly necessaryNoNo

Appendix B: Subprocessors and Service Providers

Principal subprocessors as of the effective date. An updated list is available on request to [email protected].

ProviderFunctionDataLocationDPA
Amazon Web ServicesCloud hosting; identity verification (Rekognition Face Liveness, CompareFaces); content moderation (Rekognition DetectModerationLabels); email (SES)Account, profile, photos, selfie media, derived signalsUnited StatesExecuted
Stripe, Inc.Web paymentsPayment metadata, contact detailsUnited StatesExecuted
Apple Inc.iOS in-app purchasesPayment metadata, device identifiersUnited States and EUPer Apple terms
Google LLCAuthentication; Android in-app purchases; Firebase Cloud MessagingIdentifiers, device tokensUnited States and EUExecuted
FirebaseAuthenticationIdentifiers, device tokensUnited StatesExecuted
Twilio, Inc.SMS delivery and verificationPhone numbers, message metadataUnited StatesExecuted
PostHog (self-hosted)First-party product analyticsUsage events, identifiersUnited States (our infrastructure)N/A (self-hosted)
Cloudflare, Inc.Edge proxy, DDoS protectionIP addresses, request metadataGlobal edgeExecuted
Better StackUptime, log monitoringOperational logsEU / United StatesExecuted
Coolify (self-hosted on AlmaLinux)Container orchestrationOperational; we control underlying serversOur infrastructureN/A

We review every new subprocessor for security and privacy practices before onboarding.


Appendix C: Annual CCPA / CPRA Metrics (Placeholder)

Metrics to be reported on or before July 1 of each year, where required:

  • Right-to-know requests received, complied with in whole or part, and denied
  • Right-to-delete requests received, complied with in whole or part, and denied
  • Right-to-correct requests received, complied with in whole or part, and denied
  • Median or mean number of days within which we substantively responded

First-year metrics will be published here after our first full reporting period.


Appendix D: Biometric and Health-Adjacent Information

Detailed BIPA, CUBI, MHMDA, and other biometric-specific disclosures are set out in ToS Annex B (Biometric and Verification Data Notices) and are incorporated into this Privacy Policy by reference. Highlights:

  • Selfie video, reference frame, and biometric identifiers deleted within 30 days of verification decision
  • Consent captured via electronic-signature consent screen meeting BIPA written-release standard
  • Texas CUBI separate notice and destruction within one year of purpose expiry
  • Washington: we do not collect "consumer health data" as defined by the My Health My Data Act (RCW 19.373) in the ordinary operation of the Service; if any future feature collects it, we will publish the separate consumer-health-data privacy notice RCW 19.373.020 requires before that feature launches
  • No sale of biometric data; no use for advertising

For the full text, see ToS Annex B.


Appendix E: Quebec Law 25 Notice

This Appendix supplements the rest of this Policy for users in Quebec, pursuant to the Act respecting the protection of personal information in the private sector (Law 25).

E.1 Person responsible for the protection of personal information

Under article 3.1 of Law 25, the person responsible for the protection of personal information at Ristara is:

Privacy Officer Ristara Inc. 8409 Florence Ave. Suite 202, Downey, CA 90240 Email: [email protected] Subject: Quebec Privacy Officer Inquiry

E.2 Purposes and means of collection

We collect personal information for the purposes described in §7, by the means described in §4.

E.3 Categories of third parties

See §9 and Appendix B.

E.4 Transfer outside Quebec

Personal information about Quebec users is transferred to and processed in the United States and elsewhere where our service providers operate. Before such transfer, we conduct a privacy impact assessment to confirm that the personal information receives adequate protection, considering the sensitivity of the information, the purpose, the protections including contractual measures, and the legal regime in the destination jurisdiction. The contractual safeguards in our DPAs (§9.2) are designed to provide such adequate protection.

E.5 Automated decisionmaking

See §21 and §22 for our disclosure of algorithmic processing. To the extent any decision affecting you in Quebec is based exclusively on automated processing, you have the right to be informed and to request human review. as of the effective date, no use in the Service is exclusively automated within the meaning of Law 25 article 12.1.

E.6 Confidentiality by default

By default, your profile visibility is set so that personal information is not made accessible to persons who do not need it. You may adjust visibility in Settings.

E.7 Biometric data

If you choose selfie verification, biometric data is processed under express consent. We comply with article 44 of Law 25 and, where required, file notification with the Commission d'accès à l'information regarding the creation or use of a biometric database.

E.8 Rights of Quebec users

You may, in addition to the rights in §16, request:

  • Access to your personal information in a structured, commonly used technological format (Law 25 article 27)
  • Correction or rectification
  • Cessation of the dissemination of your personal information and the de-indexing of search results where the criteria in Law 25 article 28.1 are met
  • Withdrawal of consent

To exercise these rights, contact the Privacy Officer above.

E.9 Complaints

If you are not satisfied with our response, you may file a complaint with the Commission d'accès à l'information du Québec (cai.gouv.qc.ca).


Appendix F: United Kingdom GDPR-Specific Notice

This Appendix supplements the rest of this Policy for users in the United Kingdom.

F.1 Controller

Ristara Inc. See Section 2 for contact details.

F.2 UK contact

UK users may direct any inquiry, request, or complaint to [email protected] with the subject line "UK Privacy." We monitor and respond to UK inquiries directly from the United States. As our UK user base grows, we will appoint a formal representative in the United Kingdom under Article 27 UK GDPR and will update this Policy with their contact details when we do.

F.3 Lawful bases (Article 6 UK GDPR)

  • Performance of a contract (§8)
  • Legal obligation
  • Consent
  • Legitimate interests, where applicable

F.4 Special-category data (Article 9 UK GDPR)

Religion, sexual orientation, and biometric data processed for unique identification are processed only with your explicit consent, captured at the relevant signup, profile, or verification screen. You may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.

F.5 International transfers

Transfers to the United States and other jurisdictions are protected by the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with supplementary measures. A copy is available on request.

F.6 Your rights

Access; rectification; erasure; restriction; objection; data portability; withdrawal of consent; lodging a complaint with the Information Commissioner's Office (ico.org.uk).

F.7 Retention

See §13.

F.8 Age Appropriate Design Code

For UK users we identify or reasonably suspect as being under 18, the protections set out in the ICO's Age Appropriate Design Code apply. We do not knowingly maintain accounts for users under 18 (§23).

F.9 Marketing

Marketing communications comply with the Privacy and Electronic Communications Regulations (PECR) and the UK GDPR.


Ristara Privacy Policy v5.0

Questions or notices: [email protected]

Ristara Inc., 8409 Florence Ave. Suite 202, Downey, CA 90240

Ristara

Astrology matchmaking for people ready for depth.

Explore

  • Star Profile
  • Love Language
  • Compatibility
  • Nakshatra Guide
  • Your Birth Chart
  • Ex Compatibility
  • Red Flag Check
  • Capture a Moment

Learn

  • How It Works
  • The Science
  • Vedic Astrology
  • Methodology

Trust & Safety

  • Safety Center
  • Community Guidelines
  • Accessibility Commitment

Company

  • About
  • Pricing
  • Careers
  • Press

Support

  • Help Center
Terms·Privacy·Accessibility·[email protected]

© 2026 Ristara Inc.