Privacy & Security
Multiple layers of security at Shatatara, to protect your data — from login, to transit, to storage
Passwords Never Stored— bcrypt Hashing
Passwords are hashed using bcrypt with a salt before storage. We never store your actual password — it cannot be recovered even by our team.
Social Login— OAuth 2.0
Google and Facebook login uses OAuth 2.0. Your password is managed entirely by them — we never receive or store it. We only store what is needed to identify your account.
What Data We Collect— with sensitive data encrypted
- ›Account: name, email address
- ›Profiles: name, date of birth, birth time, birth place, coordinates
Used solely to generate astrological charts. Not sold or shared with third parties.
Encrypted Data Storage— Data at Rest
Encrypted Data in Transit— Application-Level Encryption
Secure Session Management— HTTP-only Cookies
Restricted API Access— CORS Policy
HTTPS / TLS— Encrypted Transport
OWASP Best Practices— Top 10 Protections
