Privacy Policy
Version 1.0 · Effective 3 September 2026
A kundli is a personal document. This page sets out exactly what GoodLuck collects, why, who else sees it, how long we keep it and how you get it back or get rid of it — in specifics rather than in generalities.
BluKernel Labs is a sole proprietorship, so it has no CIN, and it is not registered for GST at present. The sections about accounts, charts, consultations and payments describe the app, which has not launched; the section about this website describes what is happening as you read it.
Where this stands today
This is the privacy policy for GoodLuck — the Android app, and the website at getgoodluck.in.
GoodLuck has not launched. There is no Google Play listing, there are no user accounts, and nobody's birth details are in our systems. What follows describes what the app will collect and how it will be handled from the day it opens, and what this website does today. We are publishing it before launch rather than after, so that you can read it before you decide to hand us anything.
We will keep it current. If something described here is not yet true of the live app, we will say so on this page rather than leave you to find out. We keep every earlier version, and we will send you any of them if you ask.
Who we are, and who is answerable for your data
GoodLuck is operated by BluKernel Labs, a registered sole proprietorship in India. BluKernel Labs is not a company and not a limited liability partnership, so it has no CIN and we are not going to publish one. BluKernel Labs is also the developer named on the app's Play Store listing; the two names refer to the same operation.
- Service
- GoodLuck — the Android app, and the website at getgoodluck.in
- Operator
- BluKernel Labs, a registered sole proprietorship in India
- Address
- 11th Floor, Innov8 Coworking Space, Prestige Tech Park, Platina 2, Outer Ring Road, Kadubeesanahalli, Bengaluru, Karnataka 560087, India
- hello@getgoodluck.in
- Telephone
- +91 8088955890, Monday to Saturday, 10.00 to 18.00 IST, except public holidays
- Grievance Officer
- Sheuli Mondal — sheuli@blukernel.com
Under the Digital Personal Data Protection Act, 2023, BluKernel Labs is the Data Fiduciary for the personal data described in this notice. That means we decide what is collected and why, and we are answerable for it. We do not pass that responsibility on to anyone we work with, and no contract we sign with a supplier moves it.
If you have a question about how your personal data is handled, write to hello@getgoodluck.in. A person reads it. It is the same address our Grievance Officer uses, and the block further down gives the full details and the times we commit to.
The law this is written under
You do not need to read anything else to understand this page. Where we mention our Terms of Use or our Refunds and Cancellations policy we link to them, but nothing here depends on a definition kept somewhere else, and consenting to this notice is a separate act from accepting those terms.
This notice is published under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025; section 43A of the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011; and Rule 3 of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
One point about timing, because it matters and most policies skip it. The DPDP Act and its Rules were brought into force in stages by notifications dated 13 November 2025. Most of the Act's substantive duties — notice, consent, your rights, security, breach reporting and the penalties — commence on 13 May 2027. Until then, section 43A of the Information Technology Act and the 2011 Rules remain the operative law, and they apply to us now.
We have written this notice to the 2027 standard already, because building it in is easier than retrofitting it onto people who have already signed up. Where we describe something as a right you have, you have it because we are giving it to you, whether or not the section conferring it has commenced. We are not going to cite a statute we have not implemented.
The language this is written in
This notice is written in English.
The Act gives you the right to read this notice, and every request for your consent, in English or in any language in the Eighth Schedule to the Constitution of India. When the app opens we will publish it in the languages the app itself supports, and we will list them here rather than promise a set we have not built yet.
If you want this notice in an Eighth Schedule language we have not yet published, write to hello@getgoodluck.in and we will have a translation made for you. If a translation and the English version ever disagree, tell us — that is a mistake on our side, and we will correct both.
What we collect, and exactly why
Item by item, with the reason next to it. If a use is not named here, we are not making it.
Things you type in
- Your name, or the name you would like to be called by — to address you, and to head your chart.
- Your mobile number, verified by a one-time password — this is how you sign in. There is no password to remember and none for us to lose.
- Your email address, if you give one — to send you a receipt, an invoice and account notices. You can use GoodLuck without giving one.
- Your date, time and place of birth — to compute your janam kundli: lagna, rashi, nakshatra, the twelve bhavas, planetary positions and the dasha sequence. That is the whole purpose. Nothing else.
- Your own age, asked once when you first open the app — to confirm you are 18 or over, and for nothing else.
- The name and birth details of another person, if you draw their chart or run a kundli milan — to compute that chart or that milan.
- The city you ask about — to compute the panchang, the choghadiya and the muhurat timings for that place.
- Your language and the tradition you prefer — to show you the right chart style and to suggest practitioners who work in it.
- The question you write when you start a consultation — so that the practitioner you chose knows what you want to ask before the meter starts.
Things that come into being when you use the app
- Which free tools you opened, and when — counted so we know what to improve. We do not build a behavioural profile of you from it and we do not sell it.
- Consultation records — which practitioner, the date, the length, the language and the amount charged. This is the transaction record.
- Consultation content — the chat messages, and the recording of the call if the consultation is by call. This is the most sensitive thing you will give us, and the next section but one sets out exactly who can read it and for how long it is kept.
- Payment references — the order reference, the gateway's transaction reference, the amount, the date and whether it succeeded. Not your card.
- Device and diagnostic data — device model, Android version, app version, language and time zone, and an app instance identifier. Used to make the app work on the phone you actually own, and to read a crash report when it stops working.
- Your IP address and ordinary server logs — to run the service, find faults and detect abuse.
- What you write to us, and any complaint you raise — to answer you, and to keep a record that we did.
Things we ask your permission for, and only when you use the feature
- Microphone — only for a call consultation, only while the call is running. Refuse it and chat consultations still work.
- Notifications — only if you switch them on. Turning them off does not affect anything else.
- Approximate location — only if you tap "use my location" on the panchang. Typing a city name does the same job. We do not collect precise location, and we do not collect location in the background.
Your birth details, and what we do with them
A kundli is a personal document. Your date, time and place of birth are, taken together, close to a unique description of one person — more precise than several of the identifiers people guard carefully. We treat them that way, and we would rather say so here than assume you had worked it out.
We use them for one purpose: to compute and display your chart and the readings drawn from it. We do not use them to identify you. We do not use them to profile you. We do not use them to target anything at you or to build an audience for anyone else. We do not sell or rent them. The only person outside GoodLuck who sees them is the practitioner you yourself choose to consult, and then only for that consultation.
Charts are computed on our own servers, from ephemeris data we hold ourselves. Your birth details are not sent to a third-party horoscope service to be calculated. They are stored encrypted, and a member of our team can see them only where there is a logged reason to look — a fault you have reported, or a request you have made.
If you correct your birth time later, and many people do, the chart is recomputed from the corrected time. We will not go on showing you a chart drawn from a time you have told us is wrong.
When the birth details are somebody else's — a partner for a milan, a parent, a child — they belong to that person, not to you. Enter them only if that person knows and agrees, or, in the case of a child, if you are the child's parent or guardian. We do not create an account for that person, we do not build a profile of them, and we do not use their details for anything except the chart you asked for.
What happens in a consultation
A consultation is between you and an independent practitioner. GoodLuck lists them, carries the call or the chat, takes the payment and enforces a standard of conduct. We do not supply the advice ourselves.
What the practitioner sees
- The name you choose to be shown by.
- Your birth date, time and place, and the chart computed from them.
- The second person's birth details, if the consultation is about a milan.
- The question you wrote before starting.
- The chat, or the call, itself.
What the practitioner does not see
- Your mobile number. Calls run through a masking service, so each of you sees a temporary number. Neither of you learns the other's real number from us, and neither of you can ring the other outside the app.
- Your email address, your postal address, or anything about how you paid.
- Any other consultation you have had, with them or with anyone else.
- Any other chart saved in your account.
The record we keep, and who may read it
Chat messages are stored, and calls are recorded. You are told this before the consultation starts, on the screen where you confirm the price, and the recording indicator stays visible for the length of the call. We keep it for two reasons and no others: so that a refund claim can be decided on what actually happened, and so that we can act if a practitioner breaks the standard they agreed to — including the promise never to raise fear of harm or misfortune in order to sell you something. Without a record, that promise would be unenforceable, and we would rather it were enforceable.
Only a small, named group at GoodLuck can open it, and only when one of four things happens: you ask for a refund and the claim turns on what took place; you or the practitioner raise a complaint; a court or a lawfully authorised officer orders it in writing; or somebody reports that a person is in danger. Every access is logged, with the reason and the name of the person who opened it. Nobody at GoodLuck browses consultations.
We will not make a refund conditional on your letting us read or listen to your consultation. If you would rather we did not open it, say so, and we will decide the claim on the other evidence — the connection logs, the duration, and what you and the practitioner each tell us. You will not lose your refund by refusing, and where we cannot tell what happened we decide in your favour.
Chat transcripts and call recordings are deleted 90 days after the consultation ends. You can delete a consultation yourself before then, from the app. If you do, we will tell you plainly at the time that we will no longer be able to check a refund claim about that consultation against the record.
We do not publish consultation content anywhere. We do not quote it in marketing. We do not use it, or your chart, to train or fine-tune any artificial intelligence model. If we ever want to, we will come back and ask you separately, and you will be free to say no and carry on using GoodLuck exactly as before.
Practitioners are bound by a written agreement not to keep, copy, reuse or disclose anything you tell them, and not to contact you off the platform. We can enforce that, and we can de-list a practitioner for breaking it. What we cannot do is technically prevent a person from remembering, or writing down, what you chose to tell them. That is true of any consultation with any human being, and we would rather state it than let you assume otherwise.
One more thing, said quietly because it matters. If you tell a practitioner that you may harm yourself or someone else, they are instructed to stop the consultation and give you emergency numbers, and we may pass on what is necessary to emergency services. We will not do this casually. If you are in distress now, Tele-MANAS is 14416, free, in many Indian languages, at any hour.
What we deliberately do not collect
It is easier to trust a list of what a company does not take than a list of what it does, so here is ours.
- Card numbers, CVV, UPI PIN or bank credentials. These are entered on the payment gateway's own screen and never reach our servers. We could not leak them if we tried.
- Your contacts. GoodLuck does not ask for your address book and has no feature that needs it.
- Your photo gallery, your camera roll, your SMS messages or your call logs.
- The list of other apps installed on your phone.
- Precise location, and location in the background.
- Any advertising identifier. We do not run advertising in GoodLuck.
- Caste, religion, sexual orientation or health as fields you are asked to fill in. If you choose to raise any of these in a consultation, it is protected as consultation content under the section above.
- Biometrics of any kind. No face, no palm, no fingerprint.
- A password. We sign you in with a one-time password sent to your mobile number, so there is no password of yours for us to store or lose.
The website you are reading this on
getgoodluck.in is a set of static pages. It is not the app, and it collects very little.
- There are no cookies on this website, no analytics, no tag manager, no advertising pixel and no tracker. Nothing is stored in your browser by us.
- Our web server keeps ordinary access logs — your IP address, the page requested, the time, and your browser's user-agent string. They are used to keep the site up and to spot abuse, and they are deleted after 12 months.
- The site loads its typefaces from Google Fonts, so your browser makes a request to fonts.googleapis.com and fonts.gstatic.com, and Google sees your IP address when it does. We are telling you because it is true, not because it is significant. We intend to self-host the fonts so that it stops being true.
- If you email us to join the waitlist, we receive your email address and whatever you write. Nothing else. That address is used to send you one message when the app is ready, and then it is deleted. Ask us sooner and we will delete it sooner.
When the app launches, the parts of this notice about accounts, charts, consultations and payments will start to apply. Until then this section is the whole of it.
Consent: how we ask, and how you take it back
We ask separately for separate things, and nothing is ticked for you in advance.
When you first sign in you will be asked, as distinct choices:
- To create an account, and to let us compute and store your charts from the birth details you enter. Without this there is no account and no saved chart. You can still use the panchang for a city without an account, because that needs nothing about you.
- To take part in a consultation, and to have the chat or the call recorded and kept for 90 days for the reasons set out above. You choose this at the point of booking, not at sign-up.
- To receive messages about your account, your bookings and your payments. These are necessary to run the service and you cannot turn them off while you have an account, because they are how we tell you a practitioner is ready or a refund has gone through.
- To receive news about GoodLuck. This is off unless you switch it on, it is a separate choice, and refusing it changes nothing else. We will not make a consultation, a refund or a chart conditional on your agreeing to hear from us.
We do not use a single "I agree to the Terms and the Privacy Policy" tick to obtain consent for handling your data. Accepting the Terms of Use and consenting to this notice are two different acts.
We keep a record of which version of this notice you were shown, in which language, on what date, and what you agreed to. The law puts the burden on us to prove we asked properly, and we would rather hold the evidence than argue about it later.
Withdrawing consent
In the app: Settings, then Privacy, then Manage consent. It is one tap, the same as giving it. Or write to hello@getgoodluck.in. We will not put a retention offer, a survey or a phone call in your way.
- Withdraw consent for charts and we stop computing them, delete the saved charts and your birth details, and close the account. You lose your saved kundlis, and we cannot get them back.
- Withdraw consent for the consultation record and we cannot connect you to a further consultation, because we are not prepared to run one with no record at all — that would leave both you and the practitioner with no way to prove what happened. Consultations already completed are unaffected.
- Withdraw consent for news about GoodLuck and the messages stop. Nothing else changes.
When you withdraw, we stop, and we tell the suppliers who process data for us to stop, within seven days. Anything we did before you withdrew stays lawful — withdrawal works forwards, not backwards — and a consultation you have already had and paid for is still a consultation you had. A short list of records survives withdrawal because the law requires it, and that list is set out in full below.
If a Consent Manager registered with the Data Protection Board of India becomes available and you would rather give, review or withdraw your consent through it, we will accept that. You do not have to use one.
Children, and the eighteen-year line
GoodLuck is for adults. You must be 18 or over to create an account, to save a chart, or to book a consultation.
When you first open the app we ask for your own date of birth. Not "are you 18?", which invites the obvious answer, but the actual date, checked on our servers. If it shows you are under 18, we do not create an account, we do not save what you entered, and we delete the entry. We use that date for the age check and for nothing else.
There is one part of GoodLuck that does not need an age check, because it does not collect anything about you: the panchang and choghadiya for a city on a date. Ask it for Bengaluru tomorrow and nothing about you is stored, so there is nothing to protect. Everything that involves your own details, or a practitioner, is behind the eighteen-year line.
Under the DPDP Act a child is anyone under 18, and processing a child's personal data requires verifiable consent from a parent or guardian. We have chosen not to build that. It is the honest choice for a product whose paid half is a conversation with an adult stranger about marriage, money and health.
We do not track children, we do not monitor their behaviour, and we do not direct advertising at them. Section 9(3) of the Act prohibits all three outright, and it is easy for us to comply with, because we do not do behavioural tracking or advertising to anyone of any age. There is no advertising SDK in GoodLuck at all.
If the chart you are drawing is a child's — a newborn's kundli, most commonly — enter those details only if you are the child's parent or guardian. We do not create an account for the child, we do not build a profile of them, we do not show them anything, and we will never use their birth details for any purpose beyond drawing the chart you asked for.
If you believe a person under 18 has an account with us, write to hello@getgoodluck.in. We will check, and if it is so we will close the account and delete the data, and we will tell you when it is done.
Who we share your data with, and what each one sees
We share as little as the job needs, and we will tell you what each recipient actually receives rather than listing them as "third parties".
- The practitioner you chooseSees your display name, your birth date, time and place, the chart drawn from them, the second person's birth details if it is a milan, the question you wrote, and the consultation itself. Does not see your mobile number, your email address, your payment details, your other charts or your other consultations. Calls are masked in both directions.
- The payment gatewayPayments are taken through an Indian payment aggregator authorised by the Reserve Bank of India. It receives your name, the amount, the order reference, the contact detail needed to send you a receipt, and the card or UPI details you enter on its own screen. We never see or store your card number, CVV or UPI PIN. We receive the payment and issue any refund to the same method you paid from — refunds do not go to a wallet, because GoodLuck has no wallet, no stored card and no recharge balance. The aggregator is named on the payment screen before you pay, and in the supplier list below.
- Hosting and storageGoogle Cloud Platform, in Google's Indian regions. Holds everything the app stores, encrypted. Google does not use it for its own purposes; it is a supplier processing on our instructions under a written contract.
- Crash and performance reportingSees your device model, Android version, app version, an app instance identifier, and the technical state of the app at the moment it stopped working. Does not see your birth details, your chart or your consultation content.
- Usage countingCounts which screens and features are opened, so we know what to improve. Sharing with Google for advertising is turned off, and Google Signals is turned off. It is not used to build an advertising profile of you, by us or by anyone else.
- The SMS providerSees your mobile number and the text of the one-time password or account message we are sending. Registered on the TRAI DLT platform, as Indian law requires.
- The call and chat providerCarries the consultation and performs the number masking. Sees the connection metadata and, for the length of the call, the audio.
- Government agenciesWe disclose personal data to a lawfully authorised government agency where we receive a written order stating the purpose, and we do so within 72 hours as Rule 3(1)(j) of the IT Rules, 2021 requires. We insist on the written order first. We keep a record of every such request and response, and where we are permitted to tell you, we will.
If the business is ever sold or transferred, your data moves with it. We will tell you at least 30 days before that happens, and you will be able to delete your account first.
Every supplier that handles your data
Every Android app is built partly out of other people's code. Ours is too, and pretending otherwise would be silly. A handful of software kits inside GoodLuck are written and maintained by other companies, and some of them send data back to those companies — the crash reporter sends crash reports, the calling library carries the call, the payment library talks to the gateway. When they do, it is still our responsibility. Google Play's rules say so, the DPDP Act says so, and we agree with both.
So, four commitments.
- We will keep the list on this page — every supplier that handles personal data for us, what it does, what it receives and where it processes — rather than on a page you have to go looking for. The section above is that list, and the named suppliers will be filled in as each is contracted, before launch.
- There is no advertising kit in GoodLuck, and no attribution or install-tracking kit either. Not switched off — not present. That is the commonest way an app quietly leaks a user's behaviour to companies the user has never heard of, and the simplest fix is not to include one.
- If we add a supplier or a kit that handles personal data, we will say so here 30 days before it ships.
- We will update the Google Play Data safety declaration in the same release that changes what we collect, not afterwards.
We would rather tell you which strangers are in the building than say we "work with trusted partners".
What we will never do with your data
Short section, and every line of it is meant literally.
- We do not sell your personal data. Not to advertisers, not to data brokers, not to anyone, for money or for anything else of value.
- We do not rent, licence or trade it.
- We do not run advertising in GoodLuck, and we do not use your birth details, your chart, your questions or your consultations to target advertising at you or at anybody else.
- We do not use your consultation content or your chart to train or fine-tune artificial intelligence models. If that ever changes we will ask you separately, and you will be free to refuse and carry on using GoodLuck unchanged.
- We do not publish your birth details, your chart or anything you say in a consultation. Nothing you tell a practitioner will appear in a review, a testimonial, a case study or a marketing page.
- We do not use a review, a rating or a testimonial from you without asking you first, in that specific instance.
- We will not make a refund, a consultation or access to your own chart conditional on your agreeing to marketing, to profiling, or to our reading your consultation.
- We will not treat you worse for exercising any right on this page. No slower service, no higher price, no feature withdrawn.
If any of this ever ceases to be true, it will be changed here first, with 30 days' notice, and not quietly.
Where your data is kept, and whether it leaves India
Your personal data is stored in India, on Google Cloud Platform's Indian regions.
A small amount of technical data may be processed outside India by our suppliers — a crash report handled by an engineering team abroad, for example. Where that is so we will say which supplier and which data, above. Your birth details, your charts and your consultation content are not among it. They stay in India.
Under section 16 of the DPDP Act, transfers out of India are permitted unless the Central Government restricts a particular country by notification. No country has been restricted as at the date of this notice. If one is, we will comply, and we will say so here. We are not going to claim standard contractual clauses or an adequacy decision, because Indian law does not work that way and claiming otherwise would be theatre.
Payment data is subject to the Reserve Bank of India's directive of 6 April 2018, which requires the entire payment transaction data to be stored only in India. Our payment aggregator is authorised by the Reserve Bank and stores that data in India accordingly.
How long we keep things
The trigger for deletion is whichever comes first: you ask us to delete it, or the purpose it was collected for has ended. We do not keep anything "for as long as reasonable".
- Your account, profile and saved charts, including your birth detailsWhile your account is open. Deleted within 30 days of your asking us to close it.
- Birth details of another person you enteredDeleted when you delete that chart, and in any case with your account.
- Consultation content — chat transcripts and call recordings90 days from the end of the consultation, then deleted. Sooner if you delete the consultation yourself. If a refund claim, a complaint or a lawful order is open, that one record is held until the matter closes and is then deleted.
- The consultation record without its contentPractitioner, date, duration, language and amount: eight years, because it is part of the transaction record.
- Payment records and invoicesEight years from the end of the financial year they relate to. Tax law requires at least six; we keep them a little longer because a reassessment can reach back further.
- Your registration information after you close your account180 days. Rule 3(1)(h) of the IT Rules, 2021 requires this, so we cannot promise you that nothing survives. It is then deleted.
- Anything we removed after a complaint180 days, held sealed, because Rule 3(1)(g) of the same Rules requires it for investigation.
- Server, access and processing logs12 months. Rule 8(3) of the DPDP Rules, 2025 sets a floor of one year, and the CERT-In directions of 28 April 2022 require 180 days of system logs to be kept within India.
- Crash reports and diagnostics90 days.
- Emails to and from hello@getgoodluck.in24 months from the last message in the thread.
- Grievance and complaint filesThree years from closure.
- Consent recordsWhich version of this notice you saw, in which language, and what you agreed to: while your account is open, and for three years after it closes, because the law puts the burden on us to prove we asked properly.
- Waitlist email addresses collected before launchUntil we send you the one message saying the app is ready, then deleted within 30 days. Sooner if you ask.
If you do not open GoodLuck for three years, we will delete your account and your data. No law obliges us to do that at our size; we are choosing to. We will write to you 30 days before, by email and by SMS, so that you can keep it by simply opening the app.
One honest note. When we delete something it goes from our live systems immediately, and from our encrypted backups as those backups age out, which takes up to 60 days. It is not restored to a live system in the meantime.
Deleting your account, and what survives it
You can delete your account yourself, from inside the app: Settings, then Privacy, then Delete account. Or write to hello@getgoodluck.in from the email address or mobile number on the account. When the app launches we will also publish a web form so that you can do it without opening the app, which is what Google Play requires of any app with accounts.
Deleting is not the same as deactivating, and we do not offer a freeze. When you delete, the account and the data go.
We give you seven days to change your mind. For seven days after you ask, signing in cancels the deletion and everything is as it was. After the seventh day it proceeds and cannot be reversed. We will tell you this at the moment you ask, and we will email you on the day it becomes final. Deletion is completed within 30 days of the seven-day period ending.
What is deleted: your profile, your name, your email address, your saved charts and the birth details behind them, the birth details of anyone else you entered, your consultation content, your preferences and your device identifiers.
What survives, and why:
- Your registration information, for 180 days, because Rule 3(1)(h) of the IT Rules, 2021 requires it. Then it goes.
- The transaction record and the invoice for anything you paid for, for eight years, because tax law requires it. This is the date, the amount and the reference — not your chart and not your consultation.
- Processing logs, for 12 months, because Rule 8(3) of the DPDP Rules, 2025 sets that floor and it applies even when an account is deleted.
- Anything held under an open complaint, refund claim or lawful order, until that matter closes.
That list is exhaustive. Nothing else is kept, and none of it is used to market to you or to rebuild your profile if you come back.
Your rights, and how to use them
These are yours under the Digital Personal Data Protection Act, 2023. Each one has a route and a time we commit to. Where we say "working days" we mean Monday to Friday, excluding public holidays in Karnataka.
- The right to know what we holdAsk us for a summary of the personal data we hold about you, what we do with it, and the identity of everyone we have shared it with together with a description of what was shared. In the app: Settings, Privacy, My data. Or email us. Within seven working days.
- The right to a copyWe will send you your data as a machine-readable file. The DPDP Act does not give you a portability right. We are giving you one anyway, because it is your chart. Within seven working days.
- The right to correct, complete and updateChange your name, contact details and birth details yourself in the app at any time; charts are recomputed from the corrected details. If you would rather write to us, within seven working days.
- The right to erasureDelete your account in the app, or write to us. Seven days to change your mind, then completed within 30 days. The short list of records that survive by law is set out above.
- The right to withdraw consentSettings, Privacy, Manage consent — one tap, as easy as giving it. Takes effect immediately, and we instruct our suppliers to stop within seven days.
- The right to nominateYou may nominate one or more people to exercise these rights on your behalf if you die or become unable to exercise them yourself. Settings, Privacy, Nominee, or by email. Added within seven working days, and you can change or remove a nominee whenever you like. Almost no Indian app offers this. It is in the Act, so it is here.
- The right to stop hearing from usEvery marketing message carries an unsubscribe link, and there is a switch in Settings. Acted on within three working days.
- The right to complain to us, and to be answeredSee the Grievance Officer below. Acknowledged within 24 hours, resolved within seven days.
- The right to complain to the Data Protection Board of IndiaIf we have not put it right. Please use our grievance process first — the Act asks you to — and then the Board is open to you.
- The right to be treated the same either wayUsing any of these rights will not slow your service, raise your price or remove a feature.
You also have a duty under section 15 of the Act not to make a false or frivolous complaint, and not to impersonate someone else when exercising a right. We mention it because the Act says so, not because we expect it to arise.
How we check it is really you
Before we hand over a copy of your data, change it or delete it, we need to be reasonably sure the request comes from you.
The simple route: make the request from inside the app, signed in. That is proof enough and we will not ask for anything more.
If you write to us instead, write from the email address or the mobile number on the account, and tell us your registered mobile number and, if the request is about a consultation, its booking reference. If we cannot match the request to an account we may send a one-time password to the registered number.
We will not ask you to upload a government identity document to answer a question about data you gave us yourself. Demanding more identity data in order to service a privacy request is itself over-collection, and we are not going to do it.
If a nominee is acting for you, we will ask for the nomination on file to match, and for reasonable proof of the death or incapacity. We will handle that conversation with care.
How we keep it safe
What we actually do
- Everything travels over TLS 1.2 or better. Nothing about you moves in the clear.
- Your birth details, your consultation content and your contact details are encrypted where they are stored.
- Access is role-based and least-privilege. A practitioner's account can reach only their own consultations. A support person cannot open a consultation record without recording a reason, and that reason is logged with their name.
- Access to production systems requires multi-factor authentication and is reviewed periodically.
- We keep access and processing logs, and we look at them.
- We take encrypted backups and we test restoring from them.
- No card number, CVV, UPI PIN or bank credential is on our systems at any point, so a breach of GoodLuck cannot expose them.
- We maintain a written information security policy, as Rule 8 of the SPDI Rules requires, and our suppliers are contractually held to the same standard.
What we are not going to claim
- We do not offer end-to-end encryption, and we will not say we do. On the four triggers described earlier, a named person at GoodLuck can read a consultation. A platform cannot both review consultations for refunds and offer end-to-end encryption, and several apps in this category advertise both.
- We are not going to tell you our security is the best, the strongest or unbreakable. No system is completely secure, we are a small operation, and the honest position is that we have taken the measures above and we keep taking more.
If you find a security problem in GoodLuck, write to hello@getgoodluck.in with the subject line "Security". We will reply within 24 hours, we will not threaten you, and we will credit you if you want the credit.
If something goes wrong
If your personal data is exposed in a breach, we will tell you. Not if it is serious enough, not if we think you would want to know — every breach, without delay.
We will tell you through your account in the app and by your registered email and mobile number, in plain language, and the message will contain five things:
- What happened, how much data was involved, and when.
- What it means for you specifically.
- What we have already done about it, and what we are still doing.
- What you can do to protect yourself.
- The name and contact details of a person at GoodLuck who will answer your questions about it.
We will also report it to the Data Protection Board of India without delay, with a full account within 72 hours of becoming aware, and to CERT-In within six hours, as their directions of 28 April 2022 require. The six-hour clock binds us today; the DPDP breach duties commence on 13 May 2027. We are not waiting for 2027.
We will not use the notification to sell you anything, and we will not bury it in a marketing email.
Grievance Officer
If we have got something wrong, this is the person to write to. Not a queue, not a form that vanishes — a named person with a title, an address and a telephone number.
- Name
- Sheuli Mondal
- Designation
- Grievance Officer, GoodLuck (BluKernel Labs)
- sheuli@blukernel.com
- Telephone
- +91 8088955890
- Address
- 11th Floor, Innov8 Coworking Space, Prestige Tech Park, Platina 2, Outer Ring Road, Kadubeesanahalli, Bengaluru, Karnataka 560087, India
- Hours
- Monday to Saturday, 10.00 to 18.00 IST, except public holidays
This officer is appointed under Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and Rule 5(9) of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and handles grievances about your personal data under the Digital Personal Data Protection Act, 2023 as well. One person, one address, for all of it.
When you write, please give us your registered mobile number, what happened, and the date. If it concerns a consultation, the booking reference helps.
The times we commit to
- Acknowledged within 24 hours.
- Resolved within seven days. If a matter genuinely needs longer, we will tell you why before the seventh day and finish within 15 days.
- A request to take down content under Rule 3(1)(b), other than sub-clauses (i), (iv) and (xi): within 36 hours.
- A complaint about content that exposes a private area of a person, shows them nude or in a sexual act, or impersonates them — including morphed or synthetically generated images: within two hours, at any hour of any day, including weekends and holidays.
- An order from a court or from a lawfully authorised officer: acted on within three hours.
The legal outer limits are one month under the 2011 Rules and 90 days under Rule 14(3) of the DPDP Rules, 2025. We are not treating either as a target, and we are not going to quote you 90 days.
If we do not put it right
We would rather fix it ourselves, and the times above are what we hold ourselves to. If we miss them, or if you are not satisfied with the answer, you have somewhere to go.
- For anything about your personal data: the Data Protection Board of India. The Act asks you to use our grievance process first, so please do that, and then the Board is open to you.
- For a complaint about content on the platform that our Grievance Officer has decided against, or has not resolved in time: a Grievance Appellate Committee constituted by the Central Government, at gac.gov.in, within 30 days of hearing from us. No rule requires us to tell you this. We are telling you anyway.
- For a consumer complaint about money, service or a refund: the National Consumer Helpline on 1915 or at consumerhelpline.gov.in, and the consumer commissions under the Consumer Protection Act, 2019.
Nothing in this notice, in our Terms of Use or in our Refunds and Cancellations policy takes away a right you have under Indian consumer law. We do not require you to go to arbitration, and we do not ask you to give up the consumer forum where you live.
When you escalate, quote the reference number from our acknowledgement. It makes the file easier to follow, wherever it ends up.
Changes to this notice
This notice will change as the app grows. When it does:
- The version number and the effective date at the top will change, so you can tell at a glance.
- For any material change — a new purpose, a new recipient, a longer retention period, a new kind of data — we will give you 30 days' notice before it takes effect, in the app and by email to the address on your account. It will not take effect the day we post it.
- We keep every previous version with the dates it was in force, and we will send you any of them on request, so you can always see what you agreed to.
- If a change means we need your consent for something new, we will ask you for it separately. We will not treat your continued use of the app as agreement to a new purpose. That is not what informed consent means, and it is not what we intend to rely on.
We will not remove this page or move it to a different address. If the structure of the site changes, the old address will redirect here.
The Google Play Data safety declaration
Google Play asks every developer to fill in a Data safety form describing what the app collects and shares. Users see it on the store listing, next to the reviews.
Ours will match this notice. Every data type declared on the form is described on this page, and this page is the broader of the two documents — where they could differ, this one governs. We check them against each other before every release, and we will not ship a release where they disagree.
We will never declare that GoodLuck collects no data. It collects your birth details and it carries your consultations, and a declaration saying otherwise would be false.
If you ever find something on our Play listing that contradicts this page, write to hello@getgoodluck.in and we will correct whichever one is wrong, and tell you which it was.
How to reach us
One address for everything, read by a person.
- Service
- GoodLuck — the Android app, and the website at getgoodluck.in
- Operator
- BluKernel Labs, a registered sole proprietorship in India
- Address
- 11th Floor, Innov8 Coworking Space, Prestige Tech Park, Platina 2, Outer Ring Road, Kadubeesanahalli, Bengaluru, Karnataka 560087, India
- hello@getgoodluck.in
- Telephone
- +91 8088955890, Monday to Saturday, 10.00 to 18.00 IST, except public holidays
- Grievance Officer
- Sheuli Mondal — sheuli@blukernel.com
Write to us about your data, about a consultation, about a refund, about a practitioner who made you uncomfortable, or about something on this page that is unclear or that you think is wrong. We would rather hear it than not.
We acknowledge within 24 hours and answer within seven days. If we cannot, we will tell you why before the seventh day.
← Back to GoodLuck