Privacy Policy
The short version. Ojastha stores what you give it — your account, your assessment answers, and anything you type into the chat or the lab reader. It does not sell that to anyone, does not advertise, and runs no third-party tracking. Some of what you write is sent to an AI provider to produce an answer. You can delete your account and everything attached to it at any time.
Who we are
Ojastha is a wellness education platform covering Ayurveda, Siddha, Kalari Marma and Yoga. In this policy “we” means the operator of ojastha.com and the Ojastha mobile applications. For anything in this document, write to privacy@ojastha.com.
What we collect
If you never create an account
You can read the encyclopedia, the recipes, the seasonal notes and the constitution cards, take the dosha assessment and run a guided breathing session without an account. None of that is stored against you. The assessment is scored and returned without being written down, and a breathing session is not recorded at all. Your answers are held in your own browser or phone so you can leave and come back, and you can clear them by clearing site data.
Our servers keep ordinary web request logs, which include IP addresses, for security and troubleshooting.
If you create an account
- Account details. Your email address, and a password stored only as a one-way hash — we cannot read it. If you sign in with Google or Apple instead, we receive your email address and a provider identifier, and never see your password for that service. A display name if you give one.
- Assessment answers and results. Your dosha questionnaire answers, the constitution reading computed from them, and any symptom assessments you complete.
- Health details you choose to enter. Your profile can hold year of birth, sex, height, weight, and self-declared conditions, medications and allergies. These are optional, they exist to make guidance safer, and they are used for nothing else. Some parts of the platform also record safety answers — for example, whether a fasting plan should be withheld.
- What you write. Conversations with Ask Ojastha, and the text or files you submit to the lab reader. Please do not upload a lab report belonging to somebody else.
- Breathing sessions. If you use a breath belt, the measurements it records and the analysis computed from them.
- An audit trail. Administrative and safety-relevant actions are recorded with the acting account, the time and the originating IP address. This is how account changes and content approvals stay accountable, and it is append-only.
- The newsletter, if you subscribe: your email address and your confirmation, which is double opt-in.
What we do not do
- We do not sell or rent personal information to anyone, for any price.
- We run no advertising and no advertising identifiers.
- We use no third-party analytics or tracking cookies. The only storage the site sets is what keeps you signed in and remembers that choice.
- We do not use your conversations, assessments or lab reports to train AI models, and our AI provider is contractually bound not to train on data submitted through their API.
Who your information is shared with
Only the service providers needed to run the platform, and only the minimum each needs:
- An AI provider (currently Anthropic). When you use Ask Ojastha, the symptom assessment or the lab reader, the text you submitted and the relevant reference material are sent to produce a reply. Your name and email are not sent.
- Google Cloud — hosting, the database, file storage, and text-to-speech for the guided breathing voice. The text sent for synthesis is the practitioner-written script, not anything of yours.
- An email provider (such as Resend, SendGrid or Amazon SES) to deliver confirmations, password resets and the newsletter.
- Google or Apple, if you choose to sign in with them.
We may also disclose information where the law requires it, or where it is necessary to protect someone’s safety.
Where it is stored, and for how long
Data is held on Google Cloud infrastructure in the United States. We keep your account and its contents until you delete them. Delete your account and your profile, assessments, results, conversations and sessions go with it. Two things survive, deliberately: entries in the append-only audit trail, which is what makes it an audit trail, and the record of an unsubscribe, so that we do not email you again by accident.
Your choices
- See it. Everything about you is visible in the app — your profile, your results, your conversations and your sessions. Ask us for a copy in a portable format and we will send one.
- Correct it. Profile details are editable at any time.
- Delete it. Write to privacy@ojastha.com and we will delete your account and its contents.
- Stop the emails. Every newsletter carries an unsubscribe link, and it works immediately.
Depending on where you live you may have further rights — to know, to delete, to correct, to portability, and not to be discriminated against for exercising them. Residents of California, Colorado, Connecticut, Virginia and other states with comprehensive privacy laws have these under state law; residents of the EEA and UK have them under the GDPR. We apply them to everybody rather than checking where you are. We do not sell or share personal information as those terms are defined in state privacy law, so there is nothing to opt out of.
Health information
Some of what you may enter — conditions, medications, a lab report — is sensitive. We treat it as such: it is used to make the guidance you see safer and more relevant, and for nothing else.
Ojastha is not a healthcare provider and is not covered by HIPAA. That is worth saying plainly, because people reasonably assume otherwise when an app asks about medications. HIPAA governs healthcare providers, health plans and their business associates. We are none of those, so the protections described here are the ones we commit to in this policy, not ones HIPAA imposes on us. If that matters to you, the practical implication is that you should share only what you are comfortable sharing with a wellness education service.
Security
Traffic is encrypted in transit. Passwords are stored as one-way hashes and are unrecoverable, which is why a forgotten one has to be reset rather than looked up. Password reset links are stored only as hashes, work once, and expire within an hour. Third-party credentials are stored encrypted. Access to production is limited and audited. No system is perfectly secure, and we will not pretend otherwise.
Children
Ojastha is not intended for anyone under 13, and we do not knowingly collect information from children. If you believe a child has created an account, write to us and we will remove it.
The mobile applications
The Ojastha apps for Android and iOS collect the same things as the website and nothing more. They contain no advertising SDK and no analytics SDK. The assessment and the breathing practices work without an account; if you create one, it is the same account as on the website. Your quiz answers are stored on your own device until you complete the assessment.
Changes
If this policy changes materially we will say so on this page and, where the change affects data already collected, by email. The date at the top is the date of the most recent change.