Lunar Astro Audit Repository

← Back to Master Index

Module 07: Data Privacy Violations

Subject: Deepanshu Giri / Lunar Astro

Audit Type: Cybersecurity & Data Protection

Focus Area: App Permissions & PII Mishandling

1. Invasive Application Permissions

A technical teardown of the Lunar Astro mobile application reveals highly invasive permission requests that are entirely unnecessary for an astrology or e-learning platform. The app requests access to local storage, contacts, and location data, creating a massive surveillance footprint on the user's device.

Critical Finding: Lunar Astro collects highly sensitive Personally Identifiable Information (PII)—including exact birth times, locations, family details, and financial anxieties—without clear GDPR or DPDP (Digital Personal Data Protection) compliance frameworks in place.

2. Weaponization of Personal Data

The danger of this data collection is amplified by the organization's business model. By storing detailed logs of a user's deepest fears and vulnerabilities, the proxy network (Code 5007) can weaponize this data during future consultations, using the user's own stored history to manufacture "accurate" predictions and extract further payments.