Privacy Policy
Operator or commercial-policy values are not configured. This draft must be completed before commercial launch.
This policy describes actual and planned account, calculation, advertising and payment processing. It is not legal advice. Controller: Korean Astrology; privacy contact: Korean Astrology ([email protected]).
Data we process
- Account: identifier and email or relay address supplied by Google sign-in or by login-ID and password registration; login and security events.
- Member profile: birth date, time, city or place identifier, coordinates/time zone needed for calculation, sex where supplied, saved names or labels, and reading history.
- Service activity: generations, tabs or features used, credit balance, fair-use counters, errors and security logs. Aggregate product demand is counted without an account identifier.
- Purchase: plan, order and transaction identifiers, amount, currency, status and refund record. Full card details are handled by the payment provider, not stored by us.
- Advertising: if display advertising is switched on, the provider may process device/browser and approximate network information together with consent state. It is never tied to unlocking a reading.
Purposes and legal bases
We use data to authenticate accounts, calculate and save requested readings, sync history, administer credits and fair-use access, process payments, secure the service, prevent abuse, answer requests and improve reliability. Depending on jurisdiction, bases may include performance of a contract, consent, compliance with law and legitimate interests balanced against user rights.
Signed-in use and aggregate statistics
Calculating a chart requires being signed in, so birth inputs are always processed under an account. They are written to the member profile database only where you choose to save a chart. Product demand metrics are aggregate counts; we do not intentionally create a persistent visitor profile for product analytics. Ordinary infrastructure may still process IP address and request metadata for delivery and security.
Storage and separation
Account and member data are stored in a dedicated saju database within the existing managed RDS environment, separated logically from other products through database credentials, schema/database boundaries and least-privilege access. This is separation, not a claim that the hardware is physically dedicated.
Member birth retention: [[UNSET:SAJU_MEMBER_BIRTH_RETENTION]]. Member activity retention: [[UNSET:SAJU_MEMBER_ACTIVITY_RETENTION]]. Guest aggregate retention: [[UNSET:SAJU_GUEST_AGGREGATE_RETENTION]]. These unresolved values block commercial launch; no period is invented.
Processors and international transfers
Authentication providers (Google, Apple and email delivery), cloud/RDS hosting, payment providers, advertising partners and the configured language-model provider (currently OpenAI or Google Gemini) may process data for their stated function. The language model receives projected interpretation facts needed to write a reading; direct birth date, time, city and account identifier should be excluded unless a later feature expressly discloses and justifies them. Requests use available provider controls such as no-training/no-storage settings, but provider operational retention may still apply.
Providers may process data outside your country. Applicable transfer mechanisms and regional safeguards must be documented before launch.
Cloudflare, Inc. operates the network in front of this site. Every request reaches us through it, so Cloudflare processes the network address, the requested address and request metadata to deliver pages and protect the service. Cloudflare also adds its own page-performance measurement to HTML pages; that measurement sets no cookie and reads nothing from your device, and it does not receive birth date, birth time, birth place, sex or account identifiers.
Website measurement uses Google Analytics 4, so Google is a recipient where it is active. Google receives the page address, the referring address, device and browser information, and an approximate location derived from the network address. Birth date, birth time, birth place, sex and account identifiers are not sent: those values never appear in a page address, and no measurement event carries them.
Advertising and analytics
Detailed time-based readings are metered in credits, not unlocked by advertising. Signing up grants a fixed number; generating a new reading spends the published amount and a failed generation returns it. Member activity statistics may be account-linked to enforce allowances and understand use. Aggregate product statistics carry no account identifier. Advertising consent and opt-out controls are described in Cookies and Browser Storage.
When measurement is active it records page views and one custom event, sent when a calculation reaches its result screen. That event carries no parameters; it exists to count how many visits finish a calculation and is not used to build a profile of an individual.
Your choices and rights
Subject to local law, you may request access, correction, deletion, restriction, portability or objection, withdraw consent, manage saved profiles, or close the account. Send requests to [email protected]. We may verify identity proportionately. Some transaction or security records may be retained when legally required or necessary to establish claims. Closing the account erases your data, with two exceptions we disclose here: transaction records kept where legally required, and a one-way keyed hash of the sign-up email retained so that the one-time free credits cannot be claimed again by deleting and re-registering. That hash stores no address and identifies no one on its own.
Security and children
We use access controls, encrypted transport, secret management, logging and backups appropriate to the service, but no system is risk-free. The service is not directed to children who cannot consent under applicable law. Account age handling and parental-consent requirements must be configured before marketing to minors.
Changes and contact
Material changes receive a new effective date and version and, where required, account notice or consent. Questions and complaints: [email protected]. You may also complain to the competent data-protection authority. Rights and obligations vary by jurisdiction; this policy does not promise legal conclusions beyond the service facts stated here.