At PlanetsXP, we are committed to protecting the privacy of the developers who use our API services, as well as the privacy of the end-users whose data is processed through our infrastructure. This Privacy Policy outlines how we collect, use, process, and protect data when you use the PlanetsXP website, dashboard, and API endpoints.
1. Information We Collect
We collect information in two distinct categories: Developer Account Data (information about you as our customer) and API Payload Data (information about your end-users that you pass to our servers for calculation).
A. Developer Account Data
When you register for an account, subscribe to a paid plan, or contact support, we collect:
- Identity Data: Full name, email address, and company name.
- Billing Data: Credit card information and billing address. (Note: Payment details are securely processed directly by our payment gateway, e.g., Stripe. We do not store raw credit card numbers on our servers).
- Usage Data: API access logs, IP addresses accessing the developer dashboard, API request volumes, and rate limit telemetry.
B. API Payload Data (End-User Data)
As an API provider, we act as a Data Processor for the end-user data you send to us. To generate astrological calculations, you may pass the following through our endpoints:
- Dates of birth, times of birth, and geographic coordinates (latitude/longitude).
- Names (for numerology and PDF generation).
- Specific questions or prompts (for Astro AI generation).
2. How We Handle End-User API Data
We understand that astrological birth data is highly personal. PlanetsXP does not sell, rent, or independently monetize your end-users' birth data.
- Ephemeral Processing: For standard calculation endpoints (e.g., generating planetary positions or dashas), the data payload is processed in-memory to generate the JSON response and is immediately discarded.
- Short-term Caching: To improve API performance, certain identical requests may be temporarily cached at our edge nodes. This cache is automatically purged on a rolling basis.
- PDF Generation: If you use our PDF API, the generated PDF document is stored securely on a temporary CDN link that automatically expires and is permanently deleted after 24 hours.
- AI Processing: Data sent to our Astro AI endpoints is used strictly for generating the requested text. We do not use your end-users' prompts or birth data to train our foundational language models.
3. How We Use Developer Information
We use your Developer Account Data to:
- Provide, maintain, and secure our API services.
- Process subscription payments and calculate overage billing.
- Send critical service notices, API deprecation warnings, and security alerts.
- Provide technical support and troubleshoot integration issues.
4. Data Sharing and Disclosure
We do not sell your personal information. We may share data with trusted third parties only in the following circumstances:
- Service Providers: We use third-party cloud infrastructure (e.g., AWS, Cloudflare), payment processors, and email delivery services to operate PlanetsXP. These providers are bound by strict data processing agreements.
- Legal Requirements: We may disclose information if required to do so by law, court order, or government request, or to protect the rights, property, or safety of PlanetsXP, our users, or the public.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your developer account data may be transferred as a business asset.
5. Data Security
We implement industry-standard security measures to protect your data:
- All data in transit (between your app and our API, and between our API and our databases) is encrypted using TLS/SSL (HTTPS).
- All sensitive data at rest is encrypted using AES-256 encryption.
- API keys are heavily hashed and obscured in our database. We only display them once upon creation.
6. Cookies and Tracking
We use cookies on our marketing website and developer dashboard to maintain active sessions, remember your theme preferences (Light/Dark mode), and analyze aggregate site traffic. We do not use tracking cookies within the API requests themselves.
7. Your Rights (GDPR & CCPA Compliance)
If you are a resident of the European Economic Area (EEA) or California, you have the right to:
- Access the personal data we hold about your developer account.
- Request correction of inaccurate data.
- Request deletion of your account and associated data ("Right to be Forgotten").
- Export your account data in a portable format.
To exercise any of these rights, please contact our privacy team at privacy@planetsxp.com. Note: If your end-users request data deletion, you must fulfill that request within your own database, as we do not permanently store their birth records.
8. Data Retention
We retain Developer Account Data for as long as your account is active. If you delete your account, we will purge your identity data within 30 days, retaining only necessary billing records as required by tax laws. Aggregated, anonymized API usage logs (which contain no PII) may be kept indefinitely for system analytics.
9. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. We will notify you of any material changes by sending an email to the address associated with your developer account and updating the "Last Updated" date at the top of this page.
10. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Data Protection Officer at:
Email: privacy@planetsxp.com
Address: PlanetsXP Inc., [Address Placeholder], Delhi, India