Privacy
Insculpt AI makes AstroShruti and a small number of invite-only products. We hold your data for one reason: to run the product you are using. We do not sell personal data, we do not run advertising, and we do not build profiles of you for anyone else.
Who we are
“Insculpt AI,” “we” and “us” mean the developer and operator of insculpt.ai and AstroShruti, which is currently operated by its founder. We decide how the data described here is used. Write to support@insculpt.ai about anything in this policy.
The policy has three parts: your insculpt.ai account, the invite-only products you reach through it (such as our tool for drafting and publishing posts to your own social media accounts), and AstroShruti. What applies to all of them follows after.
Your insculpt.ai account
Signing in with Google
You sign in to insculpt.ai with Google. Google tells us your name, email address and profile picture, and nothing else: we ask only for your basic profile, and we never see your Google password or anything else in your Google account.
Access
Access to our products is by invitation. For each account we record whether it is approved, pending or blocked, whether it is an administrator, and which products it may use.
Cookies and browser storage
- A sign-in cookie. Signing in stores your session in a cookie. It is set for insculpt.ai and its subdomains, so one sign-in works across our products, and signing out removes it. It is strictly necessary: without it, you cannot stay signed in.
- Two small browser-storage entries. Your light or dark theme, and, only while you sign in, the page to return you to afterwards.
- Nothing else. No advertising or analytics cookies, and no third-party tracking scripts.
Invite-only products
This part covers our tool for drafting, approving and publishing posts to your own social media accounts, currently X and LinkedIn. It applies only if you have been invited and use it.
What we hold
- Connected accounts. When you connect an X or LinkedIn account, the platform gives us that account's ID, name and handle, the permissions you granted, and the access tokens (and, where the platform issues one, a refresh token) that let us publish for you, with their expiry dates. We store the tokens encrypted.
- Your posts. The drafts, posts and threads you write or generate; any images you attach; when you approved each one and the exact text you approved; when it is scheduled; and what happened when it was published, including the post's ID, its link and any error.
- Your own AI keys, if you add any. Stored encrypted. We only ever show you a label and the last four characters.
- A record of AI use. For each request to an AI model: which provider and model, how many tokens it used, what it cost, and whether it succeeded. Not the text you sent or the text it wrote.
- A record of spending on X. X charges us for each post published through our app, more for a post with a link, so we record each post's price against your monthly allowance.
- An activity log. Every approval, schedule, account connection and key change, with its time. It is the record of what you approved, and it never contains a token or key.
What we do with it
- Draft posts when you ask, check them, and publish the ones you approve, at the time you choose, to the accounts you connected.
- Nothing is published without your approval of its exact text. AI-drafted text is only ever a draft that you can edit, and if you change a post after approving it, it needs approving again.
- Check a post before it can be submitted or approved: for harmful content, for the platform's content rules and length limits, and for the same text going to several of your accounts.
- Keep each month's AI and X use within your allowance, and show it to you.
We do not read your timeline, followers, messages or anyone else's posts. We do not like, follow, reply, repost or send messages for you. We do not use your posts, or anything we receive from X or LinkedIn, for advertising or profiling, or to train AI models, and we never sell or share it for anyone else's purposes.
Connecting an account is your choice
We connect an account only when you click to connect it and approve the permissions on the platform's own consent screen, which lists what you are granting. You can disconnect an account in the product at any time, which deletes its tokens at once, and you can also revoke our access in your X or LinkedIn settings.
Drafting from a web page
If you ask for a draft based on a web page, our server fetches that page, and its text is sent to the AI model together with your request.
AstroShruti
Account details
Your email address, or the basic profile a Google sign-in returns: name, email address and profile picture. Nothing more. Password-based sign-in is handled by our authentication provider; we do not have access to your readable password.
Birth details
Date, time and place of birth for each chart you create, plus any label you give it. These are the inputs a Vedic or KP calculation cannot be performed without; they are stored so your charts persist between sessions.
Your city, when you give it
A location for panchang and muhurat calculations: sunrise, tithi and the rest are local by nature. You may type a city instead of granting device location, and device location is never read without your permission.
Conversations with Agastya
The questions you ask and the replies you receive, plus anything Agastya has explicitly saved as a memory. Memories are listed in Settings, and you can switch memory off or delete every memory at any time.
What we do with it
- Compute charts, dashas, transits, panchang and predictions from the birth details you enter.
- Answer your questions through Agastya, with your chart as context.
- Keep you signed in, and keep your saved charts and settings where you left them.
- Send service email you would expect (verification, password resets, account notices) and, only if you asked for it, occasional product news.
We do not share your birth details or conversations with data brokers, insurers, employers or any other third party for their own purposes.
Technical records
Standard server and application logs (request time, IP address, device and browser type, error traces), kept to keep the services running and secure and to prevent abuse. The server behind our invite-only products logs only the kind of request, its path and its outcome: never its contents, tokens or keys.
Who else processes it
A small number of service providers act on our instructions, under contract, and only for the purposes above. Each receives only what it needs:
- Cloudflare serves insculpt.ai, our products and the AstroShruti web application, and runs our domains. It handles each request, including your IP address.
- Supabase handles sign-in and is our database. It stores your account and the product data described above; the insculpt.ai database is in the United States. Tokens and AI keys reach it only in encrypted form.
- Render runs the server behind our invite-only products, in the United States. Your requests pass through it, and it holds the key that decrypts tokens and AI keys; that key is never stored in the database.
- Google signs you in, if you choose Google sign-in.
- X and LinkedIn receive your approval when you connect an account and, when a post is published, its approved text and images with the instruction to publish them to your account. What they do with your account is governed by their own privacy policies.
- Anthropic writes drafts when you use the AI included with our products. It receives what you give for the draft (your topic, notes, the text of a web page, the tone and your instructions) and a pseudonymous identifier (a one-way code derived from your account ID) that helps it prevent abuse. It does not receive your name or email address.
- OpenAI checks the text of each post for harmful content when you submit or approve it.
- The provider of your own AI key, if you add one, receives the same material as Anthropic above when you draft with that key, under your own account and that provider's terms.
- Language models for AstroShruti. The model provider that generates Agastya's replies receives the text of your question and the computed chart context needed to answer it. It does not receive your name, email address or account identifiers.
- Maps and places: a geocoding service, to turn a place name into the coordinates a chart calculation needs.
Our AI providers are engaged on terms that do not allow them to train their models on what we send them. We may also disclose data where the law genuinely requires it, or to protect the safety of a person or the integrity of the service.
Where it is processed
Our providers store and process data in the United States and in the other countries where they operate, so your data may be handled outside your own country. We rely on each provider's contractual commitments to protect it wherever it is processed.
How long we keep it
- Accounts and products. What you create (charts, memories, drafts, posts) is kept until you delete it or your account. The records of AI use, X spending and activity are kept while your account exists, because they are the record of what you approved and used.
- Connected accounts. Disconnecting an account deletes its tokens at once.
- Deletion on request. Ask us to delete your data, or delete your account, and we delete the content that came from X, such as your X profile details and the IDs of your X posts, within 24 hours, and all other personal data within 30 days, except where a record must be kept by law.
- Technical logs are kept for a short retention window, measured in days, and then discarded.
Your rights and choices
Wherever you live, you can:
- see the data we hold about you, and get a copy of it;
- correct it, or delete it;
- disconnect any social account, or remove any AI key you added, at any time;
- object to or ask us to limit a particular use of your data, and withdraw any consent you gave;
- in AstroShruti, see, correct or delete any chart, memory or account detail, turn Agastya's memory off, and unsubscribe from product email from any such email without affecting your account.
For anything you cannot do in the product yourself, write to support@insculpt.ai. We answer within 30 days, or within 24 hours for a request to delete content that came from X. You may also complain to the data-protection authority where you live.
Security
Traffic is encrypted in transit. Account tokens and AI keys are encrypted with AES-256-GCM before they are stored, using a key kept outside the database, and they are never shown back to you or to anyone else. Password-based sign-in is handled by our authentication provider, so we never hold your readable password. Access to production data is limited to the people who need it to run the service. No system is perfect; if a breach affects you, we will tell you.
Children
AstroShruti is not intended for children under 13, and we do not knowingly collect their data. If a child's details have been entered as a chart subject by a parent, they are treated exactly like any other chart input, and can be deleted at any time. Our invite-only products are for adults: you must be 18 or older to use them.
Changes
If this policy changes materially, we will update the date at the top and, for anything that affects how your data is used, tell you in the product before the change takes effect.
Contact
Write to support@insculpt.ai with any question about this policy or about the data we hold for you. See also the terms of use.