Dharmica is a guidance app drawn from the Bhagavad Gita. You can ask in text or voice and read in English or Hindi. The app works without an account, but if you create one we keep your bookmarks, history, and 7-day trial tied to your login so they survive reinstalls and follow you across devices.
Sign-in is handled by Firebase Authentication. We support email + password and Sign in with Google. Firebase stores your email (or your Google account id) and a salted password hash; we never see your password. We do not collect your name, phone number, or profile photo.
The app does ask for some personal details if you use the Janm Kundali (birth chart) feature: your name, date of birth, time of birth, place of birth, and (if you pick a city) the geographic coordinates of that place. These stay on your device and are used locally to compute the chart; they are not sent to our servers.
If you use the cloud guidance path, the question you ask is sent to our guidance server. The server persists a normalised version of the question and its answer to a Firestore semantic cache so that similar future questions can be answered instantly. This cache is keyed by a random UUID, not by your account id, and never contains your name or birth details.
If you bring your own AI key (Settings → Your AI keys), the key is held in your device's preferences and is forwarded only for the request you make. The server does not log it and does not retain it. When you use your own key, your question is not written to the cache.
If you start a paid subscription, payment is handled by Google Play / Apple App Store via RevenueCat. Dharmica never sees your card number. We receive a non-personal subscription identifier and your subscription state (active / trial / expired).
You can delete everything we hold at either time — either from inside the app (Settings → Privacy) or by emailing us.
If you choose to create an account, Firebase Authentication stores:
| Data | What it is | Where it lives |
|---|---|---|
| Email address | The address you provide, or the one Google returns when you use Sign in with Google. Used as your account identifier and to send password-reset emails. | Firebase Authentication (us-central1) |
| Password hash | A salted hash managed entirely by Firebase. We never receive or store your plaintext password. | Firebase Authentication (us-central1) |
| Firebase user id (uid) | An opaque identifier Firebase assigns to your account. We use it as the key for your trial record and to mirror your account state into RevenueCat. | Firebase Authentication + Firestore (trial record) |
| Account creation & last sign-in timestamps | Standard Firebase metadata. | Firebase Authentication |
Sign-in with Google additionally shares the email and basic profile fields Google exposes on its consent screen (typically name, profile photo URL) with Firebase. Dharmica itself uses only the email and uid.
| Data | What it is | Where it lives |
|---|---|---|
| Trial start timestamp | The UTC time your 7-day trial began, recorded against your Firebase uid. Idempotent — reinstalling does not reset it. | SharedPreferences on device, plus Firestore under your uid. |
| RevenueCat app user id | Your Firebase uid, mirrored into RevenueCat so your subscription follows the account. | RevenueCat (managed by RevenueCat; see their privacy policy). |
| Entitlements & product identifiers | Which subscription tier you hold, when it renews, and whether you are in a trial period. No payment instrument is held by us. | RevenueCat. |
All of the following is stored in your device's private app storage (Android: /data/data/com.trivartha.dharmica/; iOS: the app's sandboxed Documents / Library directory).
| Data | What it is | Stored under |
|---|---|---|
| Install identifier | A UUID v4 generated on first launch. Used as the key for the anonymous daily quota on the server. Rotated on account deletion. | dharmica.device_id |
| Personal profile (Janm Kundali) | Name, date of birth, time of birth, place of birth (free text), latitude, longitude, timezone offset. You can leave any of these blank. Used locally to compute the sidereal birth chart. | dharmica.personalProfile |
| Conversation history | The last 200 questions you asked, each with its verse reference and timestamp. The full four-section answer is also written to disk so the Journey tab can re-render offline. | dharmica.history + <docs>/conversations/*.json |
| Personal cache (LRU) | Up to 100 of your most recently answered questions, keyed by SHA-256 hash. Lets the app re-open recent answers without re-running a model. | <docs>/profile/cache.json |
| Retrieval bias profile | Theme weights, verse recency ledger, and a small bag of meaningful words drawn from your past questions. Used to nudge retrieval toward verses that have historically resonated with you. | <docs>/profile/profile.json |
| Bookmarks | Verses you have saved, with the full four-section guidance text and the question that drew them. | dharmica.bookmarks |
| App preferences | Theme (Night / Sandalwood / System), response language, scripture display options, default guidance source, onboarding state. | dharmica.theme_mode, dharmica.response_language, dharmica.show_transliteration, dharmica.guidance_source, dharmica.onboarded |
| BYOK credentials | Your API keys for Google Gemini, OpenAI, Anthropic, or any OpenAI-compatible endpoint (OpenRouter, Groq, Mistral, DeepSeek, Together, or a self-hosted URL), plus the model override and base URL. Persisted in shared preferences. Not hardware-backed keystore storage. | dharmica.byok.configs, dharmica.byok.active |
| On-device AI models | Optional model files you download (Gemma, Qwen, Phi, Llama) for fully offline guidance. Stored as files in your app's private storage. | Files under <docs>/ + index under dharmica.ai_models.installs, dharmica.ai_models.active_spec_id, dharmica.ai_models.dismissed_updates, dharmica.ai_models.partials |
| Knowledge Centre cache | Top-level manifest (JSON) + an ETag for revalidation + downloaded files per Knowledge Centre entry you've opened (HTML, JS, CSS, images, audio, video). | <docs>/kc/ + dharmica.kc |
| Device hardware snapshot (transient) | Total RAM, free storage, CPU cores/clock, ABIs, SoC info, Android SDK version. Read from /proc, /sys, and device_info_plus to decide which AI models your device can run. Not written to disk; not transmitted. |
In memory only |
The cloud guidance endpoint receives:
If you are signed in, the server also receives your Firebase uid so it can mirror your sign-in state into RevenueCat's appUserId for entitlement checks. The uid is not joined with any question or cache record.
trialStartedAt (UTC).quotas/{install-id} with fields day (UTC day boundary) and used (number of fresh generations today).cache. Each entry holds the normalised question text, the embedding, the four-section answer, the cited verse reference, the offered verse refs, creation time, hit count, and a seeded flag. Entries are keyed by a random UUID, not by your install id or uid, so the cache cannot be reverse-traced to you. Only the answer and question survive — your name, birth details, BYOK key, and email never enter the cache. Requests that use your own key are not written to the cache and not served from it.us-central1) for sign-in accounts (uid, email, password hash).us-central1) for the guidance pipeline.huggingface.co) when you download an on-device AI model. The request resolves a model repo id to a signed download URL and streams the file. No account is required.Dharmica does not embed analytics, advertising, or crash-reporting SDKs. The endpoints we contact are:
| Endpoint | When | What leaves the device |
|---|---|---|
dharmica.trivartha.com/ai/manifest.json | App startup, when the model catalog is refreshed. | A standard HTTPS GET. No identifiers. |
dharmica.trivartha.com/knowledge-centre/ | When you open Knowledge Centre entries. | Manifest + asset GETs with ETag revalidation. No identifiers. |
HuggingFace Hub (huggingface.co/api, huggingface.co) | When you download an on-device model. | GETs to resolve the repo and stream the model file. No identifiers. |
| Dharmica guidance Cloud Function | When you ask on the cloud path. | Question text, install id, optional uid, optional BYOK key. See §2.4. |
| Firebase Authentication endpoints | When you sign up, sign in, sign out, reset your password, or delete your account. | Email + password hash (managed by Firebase); OAuth tokens when you use Sign in with Google. |
| RevenueCat SDK & API | When you view the paywall, start a purchase, or restore purchases. | A non-personal subscription identifier and your uid. No payment instruments. |
| Google Play Billing / StoreKit | When you complete or restore a subscription. | Handled entirely by the platform. Dharmica receives only the receipt / entitlement. |
| BYOK provider (Google, OpenAI, Anthropic, or your OpenAI-compatible endpoint) | When you have set a key and chosen "Your key" or "Auto". | Question text, conversation history. Their terms apply. |
| System speech recognizer (Android: typically Google) | Only while you are holding the mic button. | Spoken audio. The recognised text is what reaches our guidance server. |
| System TTS engine (Android: Google TTS · iOS: AVSpeechSynthesizer) | When you tap "Listen" on the answer screen. | Text to be spoken aloud. Audio is generated and played on-device. |
External providers' privacy policies govern anything they receive:
Accounts are optional. Dharmica works without sign-in. You only need an account if you want your trial, history, and bookmarks to follow you across reinstalls and devices, or to start a paid subscription.
Sign-in is handled by Firebase Authentication using:
Trial. The first time you sign in on a fresh install, Dharmica starts a 7-day free trial of the premium tier. The trial is tied to your Firebase uid, so signing in on another device carries the trial with you. Deleting your account ends the trial immediately. Uninstalling without deleting your account preserves the trial.
Subscriptions are sold through Google Play (Android) and Apple App Store (iOS) and processed by RevenueCat. Dharmica never holds a payment instrument. Your subscription state (active / trial / expired / billing issue) is mirrored from RevenueCat using your Firebase uid as the appUserId. We do not share questions, history, or birth details with RevenueCat.
Cancelling a subscription. You cancel from your store's subscription settings (Google Play Subscriptions / Apple Subscriptions). Cancelling stops the next renewal but keeps access until the end of the paid period. Deleting your Dharmica account does not automatically cancel a paid subscription — see Account Deletion.
Hold-to-speak input. When you press the mic orb, the app starts a system speech recognition session. On Android this is typically the on-device Google speech recognizer; on iOS, Apple's Speech framework. The recognizer transcribes your speech to text on the device; only the resulting text is sent to the guidance server. Audio is not stored by Dharmica.
"Listen" on the answer screen. Text-to-speech is rendered by the system TTS engine (Google TTS on Android, AVSpeechSynthesizer on iOS) using on-device or system voices. No audio leaves your phone.
The Knowledge Centre fetches entries from dharmica.trivartha.com/knowledge-centre/. There are four entry types:
entryHtml page plus its companion files, loaded into an in-app WebView via a per-entry loopback HTTP server. JavaScript runs unrestricted inside that webview; the page can call back into Flutter over a bridge. The HTML and JS come from our origin, but the webview is the same engine a browser uses — please don't enter sensitive information into an interactive entry unless you've read its source.Manifests and assets are revalidated with If-None-Match ETags. Cached files live under your device's private storage and are wiped when you uninstall or clear the cache.
Dharmica is not directed to children under 13. We do not knowingly collect personal information from children. If you believe your child has created an account or entered birth details, write to us and we will explain what is on the device and how to clear it.
All network traffic is HTTPS. The guidance server processes questions in memory and discards them on response completion, except for the cache write described in §2.5. No question text is written to Cloud Logging or BigQuery. Passwords are handled entirely by Firebase Authentication and never reach our application server in plaintext. The BYOK credentials live in shared preferences on the device; they are not stored in hardware-backed secure storage — moving them there is on the roadmap.
If we change what we collect or how we use it, we will update this page and bump the version number at the top. Material changes will be announced in-app before they take effect.
Trivartha · Dharmica
support@trivartha.com