This is a personal site. We keep data collection to what's needed to run it.
What we collect — sign-in details needed for your account (account id, email, display name), language preference, and order records (SKU, amount, currency, status). Your question, cast result, and interpretation are processed to provide the reading and are not retained in the site's first-party statistics table. Card payments are handled by Stripe. We never receive or store full card numbers.
First-party statistics — the site records only the event name, page path, referring domain, three UTM fields, a random 16-character session id, server time, and—only where applicable—the source page or purchase amount. The session id and attribution remain in `sessionStorage`; we do not use analytics cookies, persistent local storage, fingerprinting, or third-party analytics scripts. The statistics table does not store IP addresses, user-agent strings, account ids, emails, questions, hexagrams, interpretations, or other free-form input. A user-agent string may be checked in memory once to reject common bots and is then discarded.
How we use it — to sign you in, generate and show your readings, deliver purchased credits, process payments, prevent abuse, and understand aggregate page and conversion performance without profiling sensitive inputs.
Who we share with — service providers that make the site work: Stripe (payments) and the AI model provider that generates interpretations. First-party statistics are not sent to an analytics provider. We do not sell your data.
Retention — order records are kept as needed for accounting. First-party event records contain only the limited fields listed above and are kept for aggregate reporting. You can ask us to delete account data anytime.
Your choices — closing the tab ends the statistics session, so there is no cross-session attribution. To access or delete account data, email us. Sign-in is via Google; you can disconnect access from your Google account settings.