Privacy & Security

Multiple layers of security at Shatatara, to protect your data — from login, to transit, to storage

Passwords Never Storedbcrypt Hashing

Passwords are hashed using bcrypt with a salt before storage. We never store your actual password — it cannot be recovered even by our team.

Social LoginOAuth 2.0

Google and Facebook login uses OAuth 2.0. Your password is managed entirely by them — we never receive or store it. We only store what is needed to identify your account.

What Data We Collectwith sensitive data encrypted
  • Account: name, email address
  • Profiles: name, date of birth, birth time, birth place, coordinates

Used solely to generate astrological charts. Not sold or shared with third parties.

Encrypted Data StorageData at Rest
Encrypted Data in TransitApplication-Level Encryption
Secure Session ManagementHTTP-only Cookies
Restricted API AccessCORS Policy
HTTPS / TLSEncrypted Transport
OWASP Best PracticesTop 10 Protections