Privacy Policy
This Privacy Policy explains how Unlock Ease collects, uses, stores, and protects information.
Unlock Ease is created, owned, operated, and promoted by Adnan Vahanvaty, unless otherwise stated.
Unlock Ease includes an Astro Sonic Tonic feature that allows practitioners to create reflective sound-listening experiences for clients.
The platform is designed as a business-to-business SaaS tool for practitioners. Practitioners and admins log in. Clients generally do not. Clients usually access experiences through no-login listening links or public/client-facing pages.
1. Information we may collect
Depending on how the platform is used, we may collect the following types of information.
Practitioner and admin information
- name
- email address
- practitioner profile details
- studio name
- bio, specialties, region, directory visibility, and branding preferences
- login and account access information
- plan, subscription, credit, or usage information
Client and consultation information
Practitioners or clients may enter information needed to create Astro Sonic Tonics, such as:
- client name or display name
- birth date
- birth time
- birth city or location
- consultation details
- practitioner observations or notes
- generated tonic summaries, reports, links, and listening-room data
Payment and billing information
Where payment features are enabled, payment processing may be handled by a third-party payment provider.
We may store payment metadata such as:
- plan type
- transaction status
- subscription status
- credit or Tonic allowance activity
- payment reference IDs
We do not intend to store full card details on our own servers.
Technical and usage information
We may collect technical information such as:
- device and browser information
- page visits and access logs
- listening-link access events
- error logs and diagnostic data
- IP address or approximate location data where required for security, compliance, or platform operation
2. How we use information
We may use information to:
- create and manage practitioner accounts
- generate Astro Sonic Tonics
- calculate astrology or frequency-related outputs
- provide listening rooms and stateless links
- manage client vaults and practitioner workflows
- deliver reports, summaries, or notifications
- operate the public practitioner directory
- process payments, credits, and plan access
- improve platform reliability, safety, and user experience
- detect misuse, errors, fraud, or unauthorised access
- respond to support, access, correction, or deletion requests
3. Client no-login access
Clients generally do not create accounts or log in.
Clients may receive listening links or access links from practitioners. These links may be secure, temporary, stateless, or token-based.
Anyone with a valid link may be able to open the related listening experience. Practitioners and clients should keep links private and share them responsibly.
4. Practitioner responsibility for client data
Practitioners are the client-facing service providers and are responsible for the client relationships they manage through Unlock Ease.
Practitioners are responsible for obtaining appropriate consent before entering client information into the platform.
Practitioners should only enter client data that is relevant and necessary for the intended reflective wellness experience.
Practitioners are responsible for their own client communication, consent process, professional boundaries, confidentiality practices, and legal compliance.
Unlock Ease and Adnan Vahanvaty provide the SaaS platform and are not responsible for practitioner misuse, unauthorised entry of client data, failure to obtain consent, or practitioner-client disputes arising from the practitioner’s handling of client information.
Controller and processor roles
For client information that a practitioner enters into Unlock Ease — such as a client's name, birth date, birth time, birth location, consultation details, practitioner notes, and any tonic, summary, or listening record derived from that information — the practitioner acts as the data controller and Unlock Ease acts as the data processor on the practitioner's behalf.
This means the practitioner decides what client data is collected, why it is collected, how long it is kept inside the practitioner's Studio, and how it is shared with the client. Unlock Ease processes that data only to operate the platform, generate the listening experience, and deliver the features the practitioner has enabled.
For practitioner account information, studio identity, plan and billing records, public directory listings, platform logs, and operational telemetry, Unlock Ease is the data controller.
Clients seeking access, correction, or deletion of information that a practitioner has entered should contact that practitioner directly. Unlock Ease will support the practitioner in responding to such requests in line with applicable law.
5. Service providers
We may use trusted service providers to operate the platform, including:
- database, authentication, and storage providers
- email delivery providers
- payment processors
- product analytics, logging, or diagnostic tools
- hosting and infrastructure providers
These providers may process information only as needed to support the platform.
Examples may include Supabase for authentication, database, and storage; an email delivery provider such as ZeptoMail or Resend; a payment provider such as Razorpay; and a product-analytics provider such as PostHog, depending on the active environment and configuration.
Analytics, cookies, and similar technologies
Unlock Ease may use a product-analytics service (PostHog) to understand how the platform is used and to improve reliability, performance, and user experience.
When analytics is enabled, the following privacy defaults are applied:
- session recording is disabled by default
- all text and element attributes are masked, so visible content is not captured even if recording were enabled
- automatic page-view collection is disabled; only specific, scoped product events are sent
- anonymous distinct identifiers are used; we do not attach PII (such as email, name, phone, or client data) to analytics events
- event properties are filtered through a deny-list to prevent accidental capture of sensitive fields
Analytics is a feature-flagged capability and can be disabled at the platform level. Where required by applicable law, analytics will be subject to consent.
Unlock Ease uses cookies, local storage, and similar browser-storage technologies to:
- keep practitioners signed in to their Studio session
- remember user-interface preferences (such as tab, theme, or language)
- carry session and access tokens needed to operate the platform
- support security, fraud prevention, and abuse detection
These are operational technologies needed for the platform to function. Where strictly-necessary categories do not apply under local law, you may control cookies through your browser settings; doing so may affect the operation of certain features.
6. Payment processing
Payments may be processed by a third-party payment provider.
When you make a payment, the payment provider may collect and process payment information according to its own terms and privacy policy.
Unlock Ease may receive payment metadata needed to confirm access, update subscription status, issue credits, or maintain billing records.
7. Public directory information
Practitioners may choose, or be approved, to appear in the public practitioner directory.
Directory information may include:
- practitioner name or studio name
- public bio
- specialties
- region
- public profile details
- contact or connect-request options
Practitioners should not include sensitive personal information in public directory fields unless they intentionally want it displayed.
Practitioners are responsible for ensuring that their public directory information is accurate, lawful, and appropriate to display.
8. Data sharing
We do not sell personal data.
We may share limited data:
- with service providers needed to operate the platform
- with payment providers for billing and subscription handling
- with email providers for login, notification, or delivery messages
- with practitioners when a client submits a connect request
- when required by law, safety, fraud prevention, or platform protection
- with consent or at the direction of the user
If a client communicates with a practitioner or submits a request through the platform, relevant information may be shared with the practitioner for the purpose of responding to that request.
9. Data security
We use reasonable technical and organisational safeguards to protect data.
However, no digital system can be guaranteed to be completely secure. Users and practitioners should use the platform responsibly and avoid sharing sensitive links or access credentials unnecessarily.
Practitioners are responsible for how they store, download, copy, export, discuss, or otherwise handle client information outside the platform.
10. Data retention
We may retain information for as long as needed to:
- provide the platform
- maintain practitioner accounts
- preserve client vault and tonic history
- comply with legal, tax, billing, or operational requirements
- resolve disputes or support requests
- protect against misuse or fraud
Retention periods may vary depending on the type of data and the stage of the product.
11. Access, correction, and deletion requests
Users may contact us to request access, correction, or deletion of personal information where applicable.
Some data may need to be retained for legal, billing, security, audit, or legitimate operational reasons.
Clients may also need to contact the practitioner they worked with if the practitioner entered or manages their information.
To make a request, contact:
12. Children, minors, and minimum age (18+)
Unlock Ease is intended for use by adults who are at least 18 years old, or the age of majority in their jurisdiction, whichever is higher.
Practitioner accounts and direct platform access are not offered to children.
Where a practitioner enters information related to a client who is a minor, the practitioner is responsible for ensuring that they have appropriate parental or guardian consent on file before doing so, and for handling that information in line with applicable child-protection and privacy law.
If we learn that personal information of a person under the applicable age threshold has been collected through the platform without appropriate consent, we will take reasonable steps to remove it.
13. International use
The platform may be accessed from different countries.
Data may be processed or stored using service providers located in different jurisdictions, depending on infrastructure and service-provider configuration.
14. Changes to this Privacy Policy
This Privacy Policy is the current deployment copy and may be updated as the platform, service providers, legal requirements, or product features evolve.
15. Contact
For privacy questions or data requests, contact: