Privacy Policy

Effective date: 21 October 2026 · Last updated: 13 August 2026

Æshar (“Æshar”, “the app”, “we”, “us”) is an astrology and self-reflection app made by Yogesh Gahlot, based in Edmonton, Alberta, Canada. This policy explains what the app does and does not do with your information. If anything here is unclear, email support@aeshar.app.

The short version

Who we are

Æshar is operated by Yogesh Gahlot (“the developer”). For any privacy question, request, or complaint, contact support@aeshar.app.

No account, no identity

Æshar works entirely on your device without an account. We do not collect your name for our records, your email, or any login. The app generates a random, anonymous device identifier (a hashed value) used only to verify your subscription and to route optional push notifications. It is not linked to your identity and we cannot use it to contact you.

Information you provide, and where it lives

When you set up your chart you may enter your name, birth date, birth time, and birth place. If you use the numerology feature, your name is also read as numbers. All of this is stored only on your device (in the app's local storage and, for sensitive recovery data, the device Keychain). We do not have a copy.

Your conversations (The Arc)

Conversations with Æshar are stored on your device, encrypted with a key held in your device's Keychain (AES-256-GCM, this-device-only). They are never uploaded to us or synced to our servers. We cannot read them. Older sessions are pruned automatically, and you can delete them yourself at any time.

What is sent off your device

To generate a reading, the app sends a request to our secure relay server (hosted on Cloudflare) which forwards it to our AI provider, Anthropic (the Claude API). A request contains only:

Your name is not included. Requests are sent over encrypted connections (TLS). We do not store the content of these requests on our servers. Anthropic processes the request to produce a response and, per their terms, does not use API content to train their models. See Anthropic's privacy terms.

Each request also carries a device-integrity token (Apple App Attest) and your subscription receipt, used solely to confirm the request comes from a genuine copy of the app and that your subscription is valid. These do not identify you.

Location

If you grant permission, the app uses your current location while you are using the app (never in the background) to name your current city for context in readings. Your location is used on your device only and is not transmitted to us or to any third party. You can decline or revoke this permission in iOS Settings.

Notifications

Notifications are private by default: they are generated and scheduled entirely on your device, with no server involvement.

You may optionally switch to Connected delivery. In that mode only, we register your device's push token with our server and briefly store the text of your daily reading (for up to about 48 hours) so it can be delivered via Apple's Push Notification service. This text contains no name, birth data, or identifiers. Switching back to Private mode removes your token and stored content from our server.

Subscriptions and purchases

Purchases are handled entirely by Apple through the App Store. We never see your payment details. We receive only Apple's signed receipt confirming which subscription you hold, used to unlock features.

Backup and recovery (optional)

You can export an encrypted archive of your profile, protected by a passphrase only you know. We cannot open it and cannot recover it if you lose the passphrase. If you reset your profile, some non-identifying data (such as your streak and chart signs — never your name) may be kept for a 30-day grace period so you can restore it, then deleted. Any recovery data on your device may be included in your normal iCloud device backup, which is controlled and encrypted by Apple under your iCloud account, not by us. Your birth data always requires re-entry on a new device — it never leaves the device to begin with.

Third parties

We use no analytics, advertising, tracking, or crash-reporting services of any kind. The only external parties that ever receive data are:

Data retention

Your choices and rights

Because your data lives on your device, you are in control of it:

Depending on where you live (including under Canada's PIPEDA, the EU/UK GDPR, and California's CCPA/CPRA), you may have rights to access, correct, or delete personal information, and to lodge a complaint with a regulator. Since we hold essentially no personal data on our servers, most of these rights are exercised directly on your device; for anything else, email support@aeshar.app and we will respond within the time your law requires. We do not sell or share personal information, and we do not use it for advertising.

Children

Æshar is not directed to children. You must be at least 16 years old to use the app. We do not knowingly collect information from children under that age.

International use

The app is operated from Canada and uses service providers (Anthropic, Cloudflare, Apple) that may process data in the United States and other countries. Where required, these transfers rely on appropriate safeguards.

Changes to this policy

If we change this policy we will update the date above and, for significant changes, note it in the app. Continued use after a change means you accept the updated policy.

Contact

Questions or requests: support@aeshar.app
Developer: Yogesh Gahlot, Edmonton, Alberta, Canada.