Privacy Policy
Palja is built on the most personal input there is — the moment you were born. This policy explains what we collect, how we use it, and the one rule everything else follows: your birth details stay private. People see your chart, never your inputs.
Last updated: July 12, 2026
1. Who we are and what this covers
This Privacy Policy is issued by PALJA Inc. ("Palja," "we," "us"), the data controller for the Palja mobile app, the website at palja.com, and related services (together, the "Service"). It is part of our Terms of Service. It does not cover third-party services that have their own policies (for example, the Apple App Store or Google Play).
2. Information we collect
Information you give us
- Account information. Your email address and basic profile details, provided directly or via Google or Apple sign-in (handled by our authentication provider). We never see your passwords for Google or Apple accounts.
- Birth details. Your birth date and, optionally, your birth time and birth place — the inputs your chart is computed from. These are the most sensitive data we hold and are treated as private by default (§6).
- Profile. Your handle, display name, card name, and any other profile details you set.
- Other people's birth details. If you add a friend or partner to see compatibility, we store the birth details you enter for them, linked to your account. You must have their permission (Terms §7); charts for non-users are visible only to you.
- Messages and questions. Questions you ask in readings or consults, and feedback you send us.
- Referral information. The handle of whoever invited you, if you enter one.
Information collected automatically
- Usage and device data. Events like screens viewed, features used, and shares made, with device type, OS version, app version, and coarse technical identifiers — via our analytics provider (PostHog in the app; Google Analytics on the websites).
- Crash and error data. Crash reports and diagnostic traces (Sentry) so we can fix problems.
- Notification data. Your push token and timezone, if you enable notifications, so we can deliver them at a sensible local hour.
- Server logs. Standard request logs (including IP address) for security, rate limiting, and debugging.
Information from your device, only with permission
- Camera — only to scan a friend's QR code. Images are not stored.
- Photo library — only to save share cards you create.
- Contacts — see §3; your address book never leaves your device.
When you type a birth city, the search query is sent to OpenStreetMap's Nominatim geocoding service to look up the place; we store the place you pick as part of your (private) birth details.
3. Contacts matching — hashes only
Finding friends from your contacts is optional and designed so we never receive your address book. If you grant contacts access, the app computes a one-way SHA-256 hash of each contact email on your device and sends only those hashes to our server. We compare them against hashes of our users' emails to find matches, return the matches to you, and do not use the uploaded hashes to build a contact list or profile of non-users. Raw contact names, phone numbers, and emails are never uploaded.
4. How we use information
- To provide the Service: compute your Four Pillars chart, generate readings and daily content, show compatibility with the people you connect with, and run social features like your Circle and profile page.
- To send notifications you've enabled — daily readings, Circle updates, and similar — which you can turn off any time in Settings.
- To process payments for Palja Pro. Purchases are billed by the app store; RevenueCat verifies the store receipt for us and tells our servers whether your subscription is active. We never see or store card details.
- To improve the Service: understand which features are used, fix crashes and errors, and develop new content. Where practical we use aggregated or de-identified data for this.
- To keep the Service safe: enforce rate limits, detect abuse and fake accounts, and enforce our Terms.
- To communicate with you about support requests, and to comply with legal obligations.
Legal bases where GDPR applies: performance of our contract with you (providing the Service you signed up for — including processing the birth details the Service is built on), our legitimate interests (analytics, security, improvement), your consent where we ask for it (device permissions, notifications), and legal compliance. We do not use your information for third-party behavioral advertising, and we do not sell it.
5. Language-model processing
Your chart is computed by our own saju engine, on our servers. To phrase readings and answer the questions you ask, we send chart-derived data (your pillars, elements, and similar computed values), relevant profile context, and your questions to a language-model provider (currently OpenAI) via its API. Under the provider's API terms, this data is not used to train their models. Generated readings are cached so repeat views don't require re-processing. We don't use automated processing to make decisions about you with legal or similarly significant effects.
6. What's visible to others — and what never is
- Never public: your birth date, time, and place. No public page, shared card, or connected friend ever sees your raw inputs — only the chart and persona derived from them.
- Your profile page (palja.com/your-handle) shows your handle, display name, archetype, and elemental chart. You control its visibility — including whether search engines may index it — in Privacy settings; private pages are served with a no-index instruction.
- People you connect with see relational content computed between your charts (synergy, pair readings). Compatibility pages involving you are only indexable if your own settings allow it.
- Content you share (cards, pair images, invite links) is visible to whoever you share it with — that's the point — so share intentionally.
7. When we share information
We share personal data only with service providers who process it on our instructions to run the Service, in the situations below. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
| Provider | Purpose |
|---|---|
| Cloudflare | Hosting, database, storage, and content delivery |
| OpenAI | Phrasing readings from chart-derived data (§5) |
| RevenueCat | Verifying app-store subscription receipts for Palja Pro |
| Apple / Google | Sign-in when you choose it, app distribution, and in-app billing |
| PostHog | Product analytics (app) |
| Google Analytics | Website analytics |
| Sentry | Crash and error reporting |
| Expo | Push-notification delivery |
| OpenStreetMap (Nominatim) | Birth-city search when you type a place name |
We may also disclose information if required by law or to protect the rights, safety, or property of Palja, our users, or the public; and if Palja is involved in a merger, acquisition, or sale of assets, personal data may transfer as part of that transaction under this policy's protections. Aggregated or de-identified data that cannot reasonably identify you may be used and shared freely.
8. How long we keep information
We keep your information while your account exists. When you delete your account (Settings → Delete account), we permanently delete your personal data from our production systems — including your birth details, charts, generated readings, connections, and stored images — and delete your record with our authentication provider. Server logs, analytics events, and encrypted backups age out on short, fixed schedules. We may retain limited records where the law requires it (for example, payment records for tax purposes).
9. Your rights and choices
- Delete your account yourself, any time, in Settings → Delete account.
- Access, correct, or export your data: update profile and birth details in the app; for a copy of your data or corrections you can't make in-app, email support@palja.com and we'll respond within 30 days.
- Notifications: turn each type off in Settings, or disable them at the OS level.
- Device permissions (camera, contacts, photos) are optional and revocable in your OS settings; the related features simply stop working.
- Visibility: control your public page and search-engine indexing in Privacy settings.
- Analytics on the web: standard browser controls and opt-out tools apply to Google Analytics.
We do not discriminate against you for exercising any privacy right.
10. Security
We protect your information with encryption in transit, scoped access controls, hashed contact matching (§3), verified-identity API access, and isolation of the most sensitive fields (birth inputs) from all public and shared surfaces. No system is perfectly secure — if we learn of a breach affecting your personal data, we will notify you and the relevant authorities as the law requires.
11. Children
The Service is not directed to children under 13 (or the higher minimum age your local law sets for data processing without parental consent), and we do not knowingly collect personal data from them. If you believe a child has created an account, contact us at support@palja.com and we will delete it.
12. International data transfers
We are a U.S. company and process data in the United States (with global delivery through Cloudflare's network). If you use the Service from outside the U.S., your information is transferred to and processed in the U.S. and other countries where our providers operate, which may have different data-protection laws than yours. Where required — for example, for transfers from the EEA, UK, or Switzerland — we rely on appropriate safeguards such as standard contractual clauses with our providers.
13. Public figures
The Service includes charts of notable public figures, computed from publicly available birth records. These pages are unofficial, are not affiliated with or endorsed by the person, and contain only public-record inputs and our interpretive content. If you are the subject of such a page and want it changed or removed, contact support@palja.com.
14. Additional regional rights
EEA / UK / Switzerland (GDPR): you have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time where processing is based on consent. Exercise them in-app or via support@palja.com. You may also lodge a complaint with your local supervisory authority.
California (CCPA/CPRA): you have the right to know, delete, and correct personal information, and the right to opt out of "sale" or "sharing" — we do not sell or share personal information as those terms are defined in the CCPA, and we have no actual knowledge of selling data of consumers under 16. You may exercise rights through an authorized agent; we will verify requests via your account email.
Other regions: where local law grants similar rights, the same contact route applies.
15. Changes to this policy
We may update this policy as the Service evolves. If a change is material, we will notify you — in the app or by email — before it takes effect. The "Last updated" date above reflects the current version; continued use after the effective date means the updated policy applies.
16. Contact us
PALJA Inc.
Email: support@palja.com
Summary of the important parts (the full text above controls): your birth details are never shown to anyone — only your derived chart is. Contacts matching uploads one-way hashes, never your address book. We don't sell your data or use it for third-party ads. Readings are computed from your chart by our own engine and phrased with language-model help — never used to train models. Delete your account any time in Settings.