Legal
Privacy Policy
Last updated 30 August 2026
Twinbat is built around the moment you were born, which is unusually personal data. So the defaults are restrictive: your birth time, exact birthplace, birth year and location are private unless you change that, we never sell personal information, and the two most sensitive things we can process — face data and journal contents — are opt-in and deletable on demand.
1. Who we are
Twinbat (“we”) operates the Twinbat mobile application and this website. For the purposes of the EU and UK GDPR we are the data controller for the personal data described here. Under India’s Digital Personal Data Protection Act 2023 we act as a Data Fiduciary, and under the UAE Personal Data Protection Law as a Controller.
Contact us at privacy@twinbat.com for anything in this policy, including to exercise the rights in section 9.
2. What we collect
Account
Display name, and an email address or phone number used to sign you in. We do not store passwords — sign-in is by one-time code.
Birth details
Date, time and place of birth, plus how confident you are about the time. The birthplace is converted to coordinates and a timezone so your chart can be calculated correctly.
Derived astrological data
Your computed chart: sun, moon and rising signs, nakshatra, planetary positions and dasha periods. Derived from your birth details, not collected from you.
Profile
Bio, photo, interests, language, growth goal and your privacy settings.
Location
Only if you turn on location discovery. We store an approximate city or area, never a live or precise position.
Content
Posts, comments, messages, journal entries, poll votes and reports you submit.
Face data
Only if you enable face matching. See section 3.
Technical
Device type, app version, IP address, push token and diagnostic logs.
Purchases
Subscription status and transaction references. Card details are handled by the payment provider and never reach our servers.
3. Sensitive data, and why we treat it separately
Two categories get stricter handling because they are special category data under GDPR Article 9 and equivalent provisions elsewhere.
Face data (biometric)
If you enable face matching we derive a numerical embedding from a selfie and use it only to suggest people with a similar appearance, and only where both people opted in. It is never used to verify your identity, gate access to any feature, or rank attractiveness. It is processed on your explicit consent alone, you can withdraw at any time, and withdrawal deletes the embedding immediately rather than at the next cleanup.
Journal entries
Journal content is private to you. It may reveal information about your mental or emotional state, so we treat it as sensitive: it is never used to target advertising, never shown to other users unless you explicitly share it, and never used to train third-party models. AI reflection on journal entries only runs if your plan includes it and you request it.
If an entry suggests you may be at risk, the app shows crisis support resources. That is a display decision made on your device from the model’s output — we do not report it to anyone, and it does not restrict your account.
4. Why we use it, and our lawful basis
To provide the service — contract
Creating your account, calculating your chart, finding matches, running groups and chat, and processing subscriptions.
Safety and moderation — legitimate interests
Detecting abuse, spam and harmful content, handling reports, and keeping the platform usable. We balance this against your rights and keep the checks proportionate.
Location discovery, face matching, marketing — consent
Each is off by default and each can be withdrawn independently without affecting the rest of the service.
Legal obligations
Tax, accounting, and responding to lawful requests.
We do not carry out automated decision-making that produces legal or similarly significant effects on you. Match scores and AI readings are suggestions; they do not restrict your access to anything.
5. AI processing
Readings, comparisons and suggestions are generated by large language models hosted on Microsoft Azure within our own tenancy. Two things follow from how that is built:
The model never calculates your chart. Positions are computed by an ephemeris on our servers and passed to the model as data, so the astrology does not depend on the model being right about astronomy.
Your prompts and the resulting outputs are not used to train the underlying models. We send the minimum needed: a compact chart summary and the specific question or entry. We log the output, the model used and the token cost so we can audit quality and spend.
AI content is for self-reflection and entertainment. It is not medical, legal, financial or emergency advice, and you should not rely on it as such.
7. International transfers
We operate globally, so your data may be processed outside your country. Where we transfer personal data out of the EEA, the UK or Switzerland we rely on the European Commission’s Standard Contractual Clauses together with the UK Addendum, and we assess the destination country’s laws before transferring. For transfers from India and the UAE we rely on the mechanisms permitted under the DPDP Act and the PDPL respectively. You can request a copy of the safeguards we use.
8. How long we keep it
While your account is open
Account, birth, chart, profile and content data.
30 days after deletion
A grace window in which your account can be restored. After it, personal data is erased or irreversibly anonymised.
Immediately on withdrawal
Face embeddings, when you turn face matching off.
Up to 12 months
Security and abuse logs, so repeat offenders can be identified.
As required by law
Transaction records, typically 6–7 years for tax purposes.
9. Your rights
Wherever you live, you can ask us to do the following, and we will respond within 30 days:
Access
Get a copy of the personal data we hold about you.
Correction
Fix anything inaccurate or incomplete.
Deletion
Delete your account and personal data. Available in the app under Profile, and by email.
Portability
Receive your data in a structured, machine-readable format.
Restriction and objection
Ask us to pause processing, or object to processing based on legitimate interests.
Withdraw consent
Turn off location discovery, face matching or marketing at any time. Withdrawal is as easy as giving consent and does not affect processing carried out beforehand.
Complain
Lodge a complaint with your supervisory authority. We would rather you came to us first, but you are not required to.
We will not discriminate against you for exercising any of these rights.
10. Regional rights
EEA and UK (GDPR)
All rights in section 9 apply. Our lawful bases are set out in section 4. You may complain to your national supervisory authority or, in the UK, the Information Commissioner’s Office.
California (CCPA/CPRA)
You have the right to know, delete, correct, and to limit the use of sensitive personal information. We do not sell or share personal information as those terms are defined, so there is no “Do Not Sell or Share” action to take — but you may still submit a request and we will confirm this in writing. You may use an authorised agent.
India (DPDP Act 2023)
You may access, correct and erase your data, nominate another person to exercise your rights if you are incapacitated, and raise a grievance with us before approaching the Data Protection Board. Grievances go to privacy@twinbat.com and are acknowledged within 7 days.
UAE (PDPL)
You may access, correct, erase, restrict and port your data, and object to processing. Cross-border transfers follow the mechanisms permitted by the PDPL.
Brazil (LGPD), Canada (PIPEDA), Australia (Privacy Act), Singapore (PDPA), South Africa (POPIA)
Equivalent rights of access, correction, deletion and complaint apply and are handled through the same contact address.
11. Security
Data is encrypted in transit and at rest. Access is limited to staff who need it and is logged. Sign-in uses one-time codes rather than stored passwords, and session tokens are stored only as hashes so a database leak cannot be replayed as a login.
No system is perfectly secure. If a breach affects your rights we will notify you and the relevant authority within the timeframes the law requires — 72 hours under GDPR.
12. Age
Twinbat is for adults aged 18 and over. We do not knowingly collect data from anyone under 18. If you believe a minor has an account, contact us and we will remove it.
13. Changes
If we make a material change we will tell you in the app or by email before it takes effect, and where the change requires consent we will ask again rather than assume your previous choice still covers it.
Questions about this policy
Write to privacy@twinbat.com. If you are in the EU or UK you may also contact our data protection representative at the same address, and you have the right to lodge a complaint with your local supervisory authority.