This complete prior version was captured from the published website on 2026-09-30 at 22:53:41 Korean time. Read the current version

EFFECTIVE 2026-09-30

Privacy Policy

What lodestarastro.com and the Lodestar iOS client of this service process, who receives it, how long it is kept, and what you can ask for. The iOS client uses the same service account, saved profiles, readings and credits. Its additional device and App Store flows are described below.

What we process and why

Account creation and the overseas transfer needed for it are separate required choices at signup. Email updates and creating a shareable friend map from a selected profile are optional. Anyone with its link can preview the chosen alias, Sun sign and lit-planet count before joining; each friend needs separate permission to use your birth details for a paid detailed compatibility reading. We use profile, reading, payment and support information when you ask for those services; statutory transaction records follow the applicable retention duty. GA4, Google Ads, X, Meta and TikTok automatically measure visits and qualifying actions, subject to browser privacy signals and saved provider refusals. Cloudflare separately delivers and protects the site through its CDN and automatically measures page performance with Web Analytics/RUM. The detailed items, periods and refusal routes appear below.

Where your information goes
  1. When available, you choose a standalone PDF and pay on Gumroad, Whop, Payhip or Ko-fiLodestar verifies the purchased product and any individual Saju section, receives its input through a private link, then creates the result; Resend receives the address, notice, private link and completed reading PDF attachment
  2. You create a star gift link; the recipient signs in to acceptLodestar records the reserved credits and the minimum private delivery relationship
  3. Choose to continue from the Ilju result, then return after signing inThe birth date waits in this tab; only your separate save action sends it to your account. The return address carries only character codes, and Lodestar’s server-side sign-in state record leaves them out
  4. You share an Ilju result or send a replyThe link carries only character codes (two on a reply link) and lineage labels: Lodestar’s preset campaign and creative names, a share step number and the link type
  5. Your saved profile and completed readingsLodestar keeps it in your account on Google Cloud in the US
  6. Choose to sign up from the Work Hamzzi result, then return after signing inThe birth date waits in this tab, apart from the Ilju test; only your separate save action sends it to your account
  7. You create a map from your profile and share its linkLink holders preview alias, Sun sign and lit count; after a friend accepts with their profile, Lodestar records the connection
  8. If you separately allow a friend to use your profile for a paid detailed readingLodestar uses birth details on the server; the purchaser keeps a private result until profile, permission or connection changes
  9. Calculated astrology details and words you typedGoogle Vertex AI writes a reading, daily fortune or reply
  10. Order reference and checkout detailsNICEPAY for Korean checkout; Dodo Payments for English or Japanese. You enter payment details there.
  11. Visits and selected service eventsLimited events go automatically to GA4, Google Ads, X, Meta and TikTok, unless a privacy signal or saved refusal blocks them
  12. You request a page and it loadsCloudflare delivers and protects the request; its RUM beacon reports page and performance details separately
  13. When you leave the serviceService data is deleted after 30 days; required transaction evidence is kept separately
  14. If you make an iOS in-app purchaseApple processes payment with an account token; Lodestar verifies the transaction and records your credits
  15. If you choose to save a reading offline or enable a local reminderThe copy and reminder settings stay on this device; deleting a copy leaves the server original
  16. After agreeing to the required iOS daily-fortune display notice and opening today’s resultiOS shares a protected local snapshot with the widget
  17. The same opening of today’s result also updates a supported Live ActivityiOS shows the title in the expanded Dynamic Island; the Lock Screen uses a general prompt without personal fortune text

You can delete your account or ask about a record at the contact below. Statutory transaction records have a separate retention period.

Reading this site

Lodestar / Duckgu Studio publishes this website. Notes saved in earlier versions, saved birth profiles and unsent chat drafts may remain in browser storage. None are automatically attached to AI conversations. The site shows no ads. GA4, Google Ads, X, Meta and TikTok measurement runs automatically as described below, subject to browser privacy signals and saved provider refusals.

Browser storage remains until you clear it in Profile or through your browser settings. Clearing browser data, using private browsing, or changing browsers can remove it. It does not sync to the iOS app.

Hosting and technical information

The site is delivered through Cloudflare’s CDN in front of Google Firebase Hosting and Cloud Run. Serving and protecting pages can involve technical request information such as IP address, browser details, requested URLs, and server logs. Google/Firebase processing is described in their notices below; Cloudflare processing is described in the following section.

Google Privacy Policy ↗
Firebase Privacy and Security ↗

Cloudflare delivery and performance measurement

Cloudflare’s CDN receives the network requests used to deliver and protect this site, including the connecting IP address, browser information and requested URL. Separately, an automatically injected Web Analytics/RUM script reports page performance to an address on this same site, including before signup. Observed beacon fields include the page host and path, a random identifier for each page load, page-display and network timing, and memory-performance measurements. A page-load ID is not our service-account identifier. Cloudflare’s published analytics dimensions also include the visitor’s country; this is a country-level location classification, not a claim that GPS is collected. This notice does not establish whether the provider can link these data with other information.

The browser can automatically attach this site’s cookies to that same-origin request. This is distinct from the script reading or using a cookie for tracking: Cloudflare states that its RUM script does not read or store cookies or browser storage. We have not confirmed how the provider handles an automatically attached Cookie header. Cloudflare says RUM receives the IP address during HTTP processing, discards it at the nearest data centre, and does not store it in RUM core databases or logs; that statement does not describe all CDN or security logs.

Cloudflare’s published Web Analytics FAQ describes seven days of unsampled beacon data, followed by aggregation to around 10% of the original volume for longer-term storage, and access to the previous six months. These are supplier descriptions of Web Analytics retention and query access, not a confirmed deletion period for Lodestar’s contract or all Cloudflare CDN logs. The applicable contract entity, processing countries, complete CDN/security-log retention and overseas-transfer basis remain unconfirmed; we will update this notice after verification.

Do Not Track, Global Privacy Control, saved provider refusals and the iOS integration’s blocking rules below cover Lodestar’s five providers: GA4, Google Ads, X, Meta and TikTok. We have not verified that they stop Cloudflare RUM or CDN processing. Some browser content blockers may stop the RUM script; this does not stop requests required to deliver pages through the CDN. Contact privacy@duckgustudio.com about Cloudflare processing, objection or deletion; we will explain the available action and any effect on page access after verifying the request.

Cloudflare Web Analytics FAQ ↗ · Cloudflare RUM ↗ · Cloudflare Web Analytics dimensions ↗ · Cloudflare Privacy Policy ↗

Site measurement and refusal

This site uses Google Analytics 4 and Google Ads tags to automatically measure visits, selected service actions and confirmed conversions, including visits before signup. When you arrive through an X, Meta or TikTok ad, this site stores the relevant ad click ID and can send a qualifying signup or confirmed purchase to that provider from our server. Those three do not load their pixels on this site. Browser privacy signals and saved provider refusals block the relevant measurement. The recipient, country, items, timing, purpose and retention are listed under Overseas transfers below. Refusing measurement does not restrict pages, accounts, payments or readings.

The GA4 property is linked to our Google Ads account, so Analytics data can also be available to that linked Ads account. The Google Ads browser conversion tag is controlled separately. Google consent signals for ad user data and ad personalization remain denied in the tag.

In a browser that supports it, enable Do Not Track or Global Privacy Control to stop new measurement by GA4, Google Ads, X, Meta and TikTok. Existing provider refusals saved in this browser or on your signed-in account remain in effect. You can remove browser identifiers through the browser’s data settings; clearing stored data alone does not stop future measurement and may also remove a refusal saved only in that browser. For provider-specific withdrawal, deletion or questions about records held by us, contact privacy@duckgustudio.com. These steps cannot recall data already received by a provider. Dodo Payments may independently measure activity on its own checkout under its own privacy policy.

Friend compatibility map and invitations

The friend map is optional. A signed-in member chooses one saved birth profile to create a map, then shares its reusable link. Anyone holding a valid link can preview that profile’s alias, calculated Sun sign and lit-planet count, even without signing in or accepting. The preview contains no friend list, account identifier, birth date, time or place, or detailed-reading permission. If the profile describes someone else, create and share the map only with that person’s authority to show those preview fields; detailed-reading use also requires their authority to use the birth details. The server stores the random code with the map owner’s account and sign-in identifiers, the selected profile identifier and referral attribution. A connection record is stored in both accounts only after a friend signs in, chooses their own profile and accepts. Opening the link alone does not connect accounts. Invitations and acceptance provide no stars, money or other reward.

Each accepted friend lights one of ten symbolic planet illustrations on the map. The link preview shows only how many are lit, capped at ten even if more friends connect; it does not identify them. Connected members see each other’s chosen profile alias (which may be blank) and the Sun sign calculated from its birth date for a simple sign-based compatibility view. We do not show birth date, time, place, email, account identifiers or optional identity details. Editing a map profile updates its displayed alias or sign; switching profiles follows the new selection. Editing or switching turns off that member’s detailed-reading permissions and erases earlier linked results and recovery inputs until the member opts in again. Deleting the selected profile stops its display and erases those records.

Detailed compatibility is a separate paid reading. Permission to use your selected profile’s birth details is set for each connected friend and is off for a new connection by default. Accepting a link does not give every friend this permission. At the paying member’s explicit request, our server checks that specific connection and permission, reads the other profile internally and uses both people’s birth details to make the reading. Raw birth date, time and place are not returned to the paying member as profile data. The completed result and the original input kept for recovery may be stored privately under the paying member’s account. Only that member can open the linked result; it cannot be published with the reading share-link feature. One paid reading uses one star under the purchase terms. The simple sign view does not itself send either profile to Vertex AI or spend a star.

You may decline an invitation, turn off your map link while keeping existing connections, edit or switch its profile, withdraw detailed-reading permission for one friend, or remove that connection without losing ordinary account access. A disabled link no longer allows a preview or new join. Editing, switching or deleting either map profile, removing a connection or withdrawing its detailed permission prevents new linked detailed readings using the old profile or permission and deletes the related result and recovery copy held in the other member’s account. An edit or switch also requires renewed permission for each affected friend before that profile can be used again. The purchaser can no longer open a deleted result; a star already spent is not automatically restored, without limiting applicable refund rights. Deleting either account immediately invalidates its map link and removes its connections from other accounts; the closed account’s remaining service records are purged after 30 days. You can also ask privacy@duckgustudio.com to inspect, correct or erase a referral or connection record.

Accounts, profiles and AI

A saved birth profile can include a birth date, optional birth time, selected birth city, that city’s centre coordinates and time zone, and a name or alias. City coordinates are kept with their supplied decimal precision; they are not a reading of your device’s current GPS location. Optional identity choices include gender or your own description, pronouns, and who you are attracted to, including women, men, any gender or the ace/aro spectrum. These choices can reveal sexual orientation. We store supplied choices with the account profile and use the wording to personalise requested readings; we do not infer them from a chart. You can leave them blank, choose not to answer, or edit or delete the saved profile. Please do not include unrelated sensitive information in free text. Profile and recovery records follow the retention rules below.

The Ilju character test calculates its result in your browser without sending your birth date to our server. When you choose to continue to a daily fortune or save a profile, we temporarily keep the Gregorian birth date, the late-night birth choice, your and the shared character codes (for a reply link, also the recipient’s), the share link’s campaign name, creative name and share step number, a random profile identifier and expiry time in this tab’s session storage. This restores the result after sign-in in the same tab and lets a failed save be retried. This stored information is not transferred to another browser. However, when you continue to sign-up or sign-in, the address you return to carries the friend’s character code (and, for a reply link, the recipient’s character code too), and if you move from an Android in-app browser to your default browser to sign in, that address goes with you. For sign-in methods that pass through Lodestar’s server, such as Kakao, Naver and Instagram, the sign-in state record is stored without the character codes. After signing in and completing any required signup choices, choosing the button that saves this birth date to your profile sends the date to our server to create your birth profile without overwriting an existing profile. We associate the local save record with the signed-in account identifier to keep accounts separate. Signing in alone does not save the birth date to your account. An Ilju share link carries only the sender’s character code (one of 60; a reply link carries two, for the person replying and the person replied to), the campaign and creative names showing which Lodestar ad or post the chain of shares started from, a step number (1–9) showing how many shares deep the link is, and the link type. Only campaign and creative names that Lodestar has set in advance are carried; any other value is replaced with ‘ilju_organic’ and ‘none’. Anyone with the link can see these, and the address may remain in request logs for pages opened from it. It never contains a birth date, name, profile identifier, account information or ad-click identifier. When a signed-in member uses a saved profile (the main profile unless they choose another) to see a character or a match from a friend’s link, the character is calculated on this device from that profile’s birth date, which the account has already loaded; the birth date is not sent to our server again. When a signed-in member opens a friend’s link or a reply link, the page also compares the main profile’s character with the characters in the link on this device, only to show a line saying they are the same; the result of that comparison is not sent to our server or to analytics. Opening a link does not connect accounts or permit use of anyone’s birth details. On the website home page in every language, for a signed-in member who has completed the required signup choices, the character of the main profile (or, if none is set, the first profile in the list) is calculated on this device without any tap, from that profile’s birth date already loaded by the account (its birth time is used only to tell whether the birth fell after 11 p.m.), and the page’s Ilju test card shows that profile’s name (unless it has no name of its own), the day pillar’s name (in Chinese characters on the English and Japanese pages, in Korean script on the Korean page), the character’s name in the page’s language and its picture. The birth date is not sent again and the character is not sent to analytics; tapping the card sends which card it was, its section and position, and whether it was showing the member’s own card, as listed in the Google Analytics row. To show the picture, the browser loads that character’s picture file from this site, so the file address, which identifies the character, goes through Cloudflare’s CDN and our hosting like any other request to this site and can remain in request logs. Nothing is calculated while signed out.

The Work Hamzzi test, offered in English, Japanese and Korean, handles birth dates the same way as the Ilju test in all three languages and calculates its result in your browser without sending your birth date to our server. When you choose to sign up to see the rest of the result, or to save a profile, we temporarily keep, separately from the Ilju test, the Gregorian birth date (only when it could become your own profile at age 14 or older), the late-night birth choice, your and the shared coworker’s character codes, a random profile identifier and expiry time in this tab’s session storage. This restores the result after sign-in in the same tab and lets a failed save be retried; we do not transfer it to another browser, and the address the test’s sign-up button returns you to after sign-in carries no character code. If you open a coworker’s link and use Log in or Sign up at the top of the page instead, the address you return to can carry the coworker’s character code; sign-ins that pass through Lodestar’s server, such as Kakao, Naver and Instagram, store their sign-in state without it. After signing in and completing any required signup choices, choosing “Save this birthday to my profile” sends the date to our server to create your birth profile without overwriting an existing profile. We associate the local save record with the signed-in account identifier to keep accounts separate. Signing in alone does not save the birth date to your account. A shared link identifies only one of the 60 characters and may be viewed by anyone with the link; it contains no birth date, profile identifier or account information. The two coworker characters shown with a result are chosen from traditional pairings of the characters and say nothing about any real person. On the website home page in every language, the same on-device calculation from the main profile (or, if none is set, the first profile in the list) of a signed-in member who has completed the required signup choices also shows, without any tap, that profile’s name (unless it has no name of its own) and that character’s Work Hamzzi picture on the page’s Work Hamzzi test card. The birth date is not sent again and the character is not sent to analytics; tapping the card sends which card it was, its section and position, and whether it was showing the member’s own card, as listed in the Google Analytics row. To show the picture, the browser loads that character’s picture file from this site, so the file address, which identifies the character, goes through Cloudflare’s CDN and our hosting like any other request to this site and can remain in request logs. Nothing is calculated while signed out.

When you sign in, Firebase Authentication and the selected provider process account identifiers and any name or email the provider supplies. A verified email address is recorded on your Firebase account so that it can be told apart from others. It is never used to find or link an account: that is always the account identifier the provider itself supplies. Instagram Login supports professional accounts. Sign-in state is retained in this browser. Birth profiles saved while signed in are kept on your web account, including the name, birth date, time and place you enter and any optional information about yourself. Profiles saved while signed out stay in this browser.

Kakao and Naver sign-in, offered to visitors connecting from Korea, are run by this server rather than by Firebase directly. From Kakao we request the profile nickname and the account email address. From Naver we receive the account identifier, the nickname and the email address, which are the items this application is registered to receive. The permanent identifier each provider gives is what names your account here — the email address a provider supplies is a secondary record, and is never used to identify, match or link an account. To sign in, this server exchanges a one-time code for an access token with Kakao or Naver. That token and the refresh token issued with it are kept on the server so the connection can be revoked, and the address the provider supplied is kept with them; none of them are sent to your browser. Deleting your website membership disconnects the app at the provider, and the stored tokens and address are deleted whether or not the provider confirms. You can also disconnect Lodestar yourself in your Kakao or Naver account settings.

A daily fortune is generated only when a signed-in member explicitly requests one for a selected profile and local date. The server uses that profile’s birth date to calculate a Sun sign, birth-year animal and Sun-sign segment. It sends those derived values, the local date, language and a writing variation to Google Vertex AI, without the structured birth date, profile label or account identifier. The generated text is saved under that profile in the member’s account so it can be read again. A journal view, when available, uses the same profile-bound result. On the website home page, for a signed-in member who has completed the required signup choices, the page asks our server, without a tap, whether the main profile (or, if none is set, the first profile in the list) already has today’s fortune in the page’s language. The page sends that profile’s identifier, today’s date on this device and the page’s language. After checking that the profile belongs to the account, the server reads, of the saved fortunes, only that profile’s one record for today’s local date and the page’s language, and returns only whether it exists, never its text; it does not generate a fortune or call Vertex AI. The card shows that profile’s name (unless it has no name of its own) and whether today’s fortune has been opened, not the fortune text. Paid readings the account already has are marked “Saved” using the account’s reading list that the app already loads. Opening the home page while signed out avoids this lookup.

When you send a message, the server receives that message, up to eight recent messages, the selected birth details or year-ahead reading context, language, and your own birth date for the age check. It recalculates the astrology context before sending the resulting placements and conversation to Google Vertex AI. Structured birth dates, place names, coordinates, profile names and account identifiers are not included in the model prompt. Personal information you type into a message is sent with that message.

The server keeps usage-limit records. To recover interrupted responses without generating twice, it stores the reply and a hashed request fingerprint in a temporary account-bound record that expires after 24 hours and is removed by database cleanup. Raw structured birth inputs and user messages are not saved in that record. Conversation history remains in this browser and is separated by signed-in account; it does not synchronize across devices. Processing may occur outside your country under Google Cloud terms.

We do not use your questions, messages or generated readings to train a model or instruct Google to do so. Google Cloud’s service terms prohibit training on customer data without the customer’s prior permission or instruction. Google may retain limited request information for service safety under its terms; our 24-hour chat retry period is not a promise about Google’s own retention. You can avoid a new AI transfer by not requesting a reading, daily fortune or chat response. Report an inappropriate result or request review at privacy@duckgustudio.com. Google Cloud data governance ↗

Optional email updates

At signup, you may separately choose email updates about new readings and offers. We keep that choice and the time it was last changed with your account; if an email address was supplied by your sign-in provider, it is the address available for those updates. No marketing-mail delivery is currently connected to this website. You can turn the choice off at any time on My page without losing your account, purchase or readings.

Purchases and payment

Buying opens Dodo Payments’ own checkout, where Dodo Payments, as merchant of record and under its own privacy policy, collects your name, email address, billing address and card details, sends the receipt to the email address you enter there and handles tax. This website does not receive or store card numbers, and Lodestar does not receive your card details from Dodo Payments.

Pressing buy writes an order here before you leave for the checkout: which reading, which account, and a random reference that identifies the order and nothing else. What goes to Dodo Payments is that reference and the package’s product identifier — not your name and not your email address — plus, if you have paid through Dodo Payments before, the customer identifier it issued at that earlier purchase, so that it keeps one customer record for you. Dodo Payments returns the reference when it reports the completed payment, which is how the stars reach the right account even when you pay with a different email address. Lodestar keeps the order: the reading it was opened from, the package, the reference, the email address from your sign-in if there is one, Dodo Payments’ checkout, payment and customer identifiers, the amount and currency, the payment method type, the decline code if a payment is declined, and the account it belongs to. When checkout follows an X, Meta or TikTok ad and measurement is permitted, private short-lived records under the order may also hold the click identifier and receipt time described above; the Meta and TikTok records also hold the checkout User-Agent. These values are not sent to Dodo Payments or returned in the operations console. Nothing you enter on Dodo Payments’ checkout — your name, email address, billing address or card details — is copied into the order. It is what makes a reading open for you, stop opening if the sale is refunded, and be repairable by hand if the report never arrives. An order paid through Whop before the switch to Dodo Payments also holds the transaction reference and the email address recorded with that sale, and a Whop sale that reached us with no order waits under the email address it was paid with until an account with that verified address signs in. What Dodo Payments holds about your order is covered by its own privacy policy, and what Whop holds about an earlier order by Whop’s.

Opening a reading you bought sends the information on screen to this website’s server, which checks your purchase and calculates the chart. To write the AI-generated parts, the server sends Google Vertex AI the resulting placements, current date, calculated age where applicable, chosen language, and any question, relationship or work context, or optional identity wording you supplied. Structured birth dates, place names, coordinates, your own profile label and account identifiers are not included in that model prompt. The other person’s name shown for a compatibility reading, including a label from a saved profile, may be included. The finished reading is kept on your account so it opens again at no charge while access remains available; linked friend readings have the deletion conditions below. For recovery, the server also keeps a validated copy of the original inputs: the birth details used, optional identity information, relationship or work status, any question or context you entered, and the chosen language. A fingerprint identifies the request. Pending or failed generation attempts are also recorded with their inputs and status so a support request can be investigated and the original reading can be retried.

If you filled in the optional lines about yourself on a birth profile — your gender in your own words, how you are referred to, who you are drawn to — they travel with that request in the same way, so the reading can address you correctly instead of writing around it. They are never guessed at, never derived from a chart, and never used to decide what a reading says about you; leaving them blank simply leaves them out. They are stored with the profile you put them on: in this browser while you are signed out, and on your account once you sign in. You can change or delete that profile. For ordinary readings, changing or deleting that profile does not change an earlier result or remove its recovery input; you can request deletion through the contact below. For a detailed compatibility reading linked to a friend, editing, switching or deleting either shared profile erases the linked result and recovery input, and editing or switching turns detailed permission off until renewed consent.

When you contact support from a signed-in account, authorised support staff can review the account details, saved birth profiles, purchase and entitlement status, generation attempts and finished readings linked to that inquiry. An administrator can regenerate an eligible reading from its original saved inputs to resolve a delivery or generation problem. Recovery actions record the operator, reason and outcome. Raw prompts and birth details are not written to application logs.

Dodo Payments Privacy Policy ↗
Whop Privacy Policy (purchases before the switch) ↗

Standalone PDF purchases

This processing applies only when standalone PDF sales are available and you choose to order one. It does not require a Lodestar account or add or spend account credits. To prepare the selected reading, we receive its type, any purchased individual Saju section and language, your date of birth and any time, place, coordinates or time-zone details needed for that reading, a question where requested, relationship or work context, the other person’s details and name for compatibility, and the consent record. Provide another person’s details only with their permission. Birth details and questions are entered only through the private link sent after payment confirmation. We receive the delivery email address from the verified marketplace purchase, not from a pre-payment form.

You purchase the product directly on Gumroad, Whop, Payhip or Ko-fi. The verified product fixes the reading type and language for the private order. We do not send birth information, the question, finished text or private access key to the store. You enter payment information directly on the store or its payment provider. We obtain the payment identifier, product, amount, currency, payment or refund status and buyer email through provider-server verification or an authenticated transaction report. After purchase confirmation, the buyer supplies the required details through the private link before the reading starts. The calculation and Google Vertex AI processing follow the existing United States flow described above; the result belongs to this private order, not a member profile.

The entered details are used for the requested purchase, calculation and delivery. The server discards the separate input snapshot after saving the finished text. The order input, paid reading text, PDF and delivery address expire 90 days after payment confirmation. Access stops at expiry, and the scheduled cleanup removes these private copies. Confirmed refunds revoke access and queue deletion. Minimum payment identifiers, product, amount, currency and processing times remain separate from birth details and text for payment reconciliation. These financial records are retained for five years from the initial payment or confirmed refund, then deleted through Firestore’s automatic expiry. Repeated callbacks do not restart that period. Processing events become eligible for automatic deletion after seven days. The private access key can stay in this browser tab’s session storage, and a PDF you download remains on your device until you delete it.

For intake and completion notices, Resend receives the marketplace-confirmed email address, a short notice and the private order link. Completion email also includes the purchased reading and calculated chart references in a PDF attachment. Raw birth input and questions are not sent as separate email fields, but the attachment contains the personal reading requested. The purchased product and any individual Saju section are fixed by the verified purchase; an individual section purchase receives that section’s text. Only staff with commerce access can see the order list: buyer email, product, payment and delivery status, amount, currency and processing times. The list does not show birth details or reading text. Lodestar blocks its GA4, Google Ads, X, Meta and TikTok measurement on PDF pages. Cloudflare delivery and independently operated marketplace pages remain subject to their own processing described in this policy or their notices.

You may decline this purchase and its necessary processing; ordinary public pages remain available. Without the required input and delivery processing, we cannot create and deliver this PDF. To request access, correction, deletion or withdrawal for a private order, email privacy@duckgustudio.com from the purchase address with the order or payment identifier. Do not send the private access key. We verify the purchase before acting and explain any retention required by law. Already delivered email and your downloaded copies cannot be recalled.

Gumroad Privacy Policy ↗ · Whop Privacy Policy ↗ · Payhip Privacy Policy ↗ · Ko-fi Privacy Policy ↗ · Resend DPA ↗ · Resend Privacy Policy ↗

Star gifts and private delivery records

The optional gift-link feature reserves eligible credits bought by the sender and records delivery to the signed-in recipient. The private record contains only service-account identifiers for sender and recipient, source sale and credit-lot identifiers, count, status, timestamps and a hash of the random gift token. It does not copy names, email addresses, birth information or reading content. The preview does not reveal the sender or recipient identity. Anyone with the link may be able to accept it, so send it only to the intended recipient. The random token is in the link fragment, rather than the page path or query, and is submitted to our server for preview or acceptance. Gift pages are configured to block Lodestar measurement and search indexing; this does not prevent a person from forwarding a link.

An unaccepted link lasts at most seven days and ends sooner at the earliest original expiry of the reserved credits. The sender can cancel it before acceptance; cancellation or expiry returns the reserved credits with their original validity; credits whose original expiry has passed remain expired. Received gifts cannot be sent again. Minimum gift transaction and delivery-relationship records are retained for five years from gift creation for delivery, purchaser refunds and dispute handling, including after account deletion where a received balance remains. At the end of that period the relationship information is removed; any received balance still follows its original credit-lot validity, including no expiry for App Store credits. This retention does not restore a deleted account or its profiles. Choosing not to create or accept a gift avoids this gift record. Contact privacy@duckgustudio.com for access, correction or deletion requests; retention required for these transaction records may limit immediate deletion.

iOS device and App Store flows

When you use an iOS version with in-app purchases, Apple handles the App Store payment. To assign credits to the correct service account and prevent duplicate or mismatched grants, our server creates a random account UUID and the app sends it to Apple as an appAccountToken. It is an account identifier, not an advertising or hardware identifier. Our server verifies the signed transaction and keeps its transaction and product identifiers, environment, amount, currency, purchase/refund times and credit grant/use/reversal records with the service account. We do not receive your App Store payment-card or bank details or add web advertising-click records to Apple orders. The account UUID is removed with the service account after the 30-day withdrawal period. Minimum transaction evidence follows the separate five-year retention below; transaction/order tombstones used to prevent a deleted purchase from being granted again are distinct from a usable account.

Apple processes its own store account and payment information under its App Store privacy notice. Our service-account deletion and retention periods do not delete or set the retention of Apple’s separate records. You can decline a new App Store transfer by not making an in-app purchase; purchasing requires the account token and transaction verification. App Store & Privacy ↗

If you choose Save offline on an opened reading, the iOS app keeps its identifier, title, text, service URL and save time in an account-separated device library. Files use iOS file protection and are excluded from backup. This feature does not upload a new device copy; the original account reading remains on our server. Device copies remain until you remove them individually or together, change accounts, sign out or delete your service account. Removing a local copy does not remove the server original. Sharing opens the iOS share sheet only at your request; the recipient or app you select receives the content or link you share.

Before using the iOS daily-fortune feature, you must explicitly agree to its device-display notice. Agreement enables the Home Screen preview. When you open a daily fortune already saved for the selected profile and today’s local date, the app stores a separate snapshot in its protected App Group container shared with its widget extension. The snapshot contains an opaque profile identifier, local date, language, a headline of up to 120 characters and the first 160 characters of the summary. It has complete iOS file protection and is excluded from backup; this does not upload another copy to our server. Small and medium Home Screen widgets may show those personal words to anyone who can see your screen. There is no Lock Screen widget. The widget stops showing the saved text after the local date changes, but the file is not erased at midnight; a later snapshot replaces it. Turning the preview off, signing out, changing accounts, or deleting all device copies removes it. When you edit, delete or switch profiles in the iOS app, it requests removal of the device snapshot. If that cleanup fails, an earlier copy may remain; turn the preview off or delete all device copies to remove it. Removing the device snapshot does not erase the original fortune saved to your service account.

After that agreement, opening today’s saved result automatically starts or updates a Live Activity when the device supports it and iOS permits it. There is no separate start button below the result. The app does not override iOS permission or support limits. Its on-device attributes include a SHA-256 hash of the service member identifier, selected profile identifier, local date and language so the app can check the account and date before opening the result; the raw member identifier is not copied to the activity or App Group snapshot. The expanded Dynamic Island can show its headline; compact Island and Lock Screen views show a general prompt without the personal words. The personal headline stops being shown by the earlier of local midnight or eight hours after the activity starts; iOS controls when the stale activity is removed. Turning the preview off, signing out, changing accounts, or deleting all device copies ends the activity. The app also requests its end when you edit, delete or switch profiles; if that fails, use the device-copy controls to end it. The widget and Live Activity do not create a new AI fortune or buy credits in the background; ordinary readings and the web service remain available without agreeing to the iOS daily-fortune display feature.

This required agreement is limited to the iOS daily-fortune display feature. Nothing is checked or accepted for you. The app keeps the accepted notice version on this device for the current account. Turning off the preview in App settings withdraws the agreement, removes the widget copy and ends its Live Activity; signing out, changing accounts or deleting all device copies also clears the agreement. You must agree again before using today’s fortune in the app. This does not grant advertising, location, notification or other permissions. Adding a Home Screen widget and allowing Live Activities are separately controlled by you and iOS.

Daily reminders are optional local notifications. The enabled choice, hour, minute and app language stay on the device; this feature does not register an APNs push token with our server. Enabling a reminder asks for notification permission. You can turn it off in App settings or iOS notification settings. Signing out or deleting the service account disables the app reminder. A reminder does not generate a reading or purchase credits automatically.

The iOS integration blocks Lodestar’s GA4, Google Ads, X, Meta and TikTok measurement in its embedded service and native sign-in handoff/return pages. This does not verify that Cloudflare CDN or automatically injected RUM processing stops; see the Cloudflare section. It does not change your ordinary web-account measurement preferences. Apple’s store services and the sign-in provider you choose have their own processing notices; the app’s local controls do not erase data already received by those providers. The ordinary website measurement and withdrawal choices above continue to apply when you use the website separately.

How long information is kept

A standalone PDF order is separate from membership deletion: when this purchase is available and chosen, its input, private paid result and delivery address expire 90 days after payment confirmation. Refunds and privacy requests have the separate handling described in the PDF section. PDF details

The Ilju continuation data is valid for 30 minutes and is removed the next time the test reads it after expiry. Closing the tab ends its storage session. Once you save the birth date to your profile, the temporary birth date is removed. The tab retains the character codes, the share link’s campaign name, creative name and share step number, and the profile, account and validity information needed to reopen the correct result. The saved profile follows the account retention and deletion rules below.

The Work Hamzzi test’s continuation data follows the same rules and is kept separately from the Ilju test’s: it is valid for 30 minutes, is removed the next time the test reads it after expiry, ends when the tab closes, and loses the temporary birth date once you save it to your profile.

Kakao and Naver connection tokens are replaced at each sign-in and deleted when the app is disconnected or the membership is purged. The temporary AI chat retry record expires after 24 hours. Saved web profiles, profile-bound daily fortunes, finished readings, their original inputs, generation attempts, support recovery records and entitlements are separate server records; the chat retry period does not apply to them. Clearing browser data or deleting a sign-in identity does not itself erase these records. Delete your website membership from My page → Delete account. Access and shared links end immediately, and the saved website information cannot be restored. Service information is held privately for 30 days, then automatically purged, except for the separate statutory records described below. Signing in again creates a new website membership without the deleted information or purchases. This same service-account deletion also applies when that account is used through the Lodestar iOS client; local device copies have the separate cleanup described above. Operational and security logs with no account link are normally kept for 90 days. Google Analytics event data is kept for no longer than 14 months. X, Meta and TikTok ad click identifiers are usable for no more than 30 days in the browser and in their private order records; the Meta and TikTok order records’ checkout User-Agent follows the same period. Each order copy is then automatically eligible for database deletion and is deleted earlier after successful reporting. Notes saved in earlier versions, unsent chat drafts and conversation history stay in your browser until you clear them.

Map invitation codes, selected-profile and friend-specific permission settings, referral attribution and connection records are service information. A member can edit or switch the map profile, remove one connection or withdraw detailed-reading permission for that friend; deleting the selected profile also stops its link preview. These actions erase the affected linked detailed results and recovery inputs from the other account. Editing or switching the map profile turns off detailed permission across that member’s connections until separately renewed. Linked detailed results cannot be published with the reading share-link feature. Account deletion immediately disables its map link and removes its connections from other accounts. Remaining account-bound settings and records are privately held for 30 days and then purged with that account. No referral reward or payment ledger is created.

General support tickets, including those from visitors without accounts, are deleted no later than three years after their last activity. Account-linked tickets are deleted with service data after withdrawal unless statutory retention applies. For completed sales, we separate the minimum contract, withdrawal, payment and supply evidence from service data for five years. If an account has a completed or refunded purchase, its inquiries are also separately retained for up to three years from the last handling, regardless of the inquiry category, so a payment complaint is not lost under another category. Other account inquiries are not included in that archive. These copies hold order, payment or inquiry evidence rather than separate profile or reading records; an inquiry may contain information you chose to write in it. They are deleted when the periods end.

For an App Store order, the minimum transaction copy is kept separately for five years from the latest recorded order creation, payment or refund time. It excludes the service account UID, account UUID, reading inputs and advertising context. Where a paid customer’s support record is retained as complaint/dispute evidence, its separate period is three years from closure, or the latest update/creation if no closure is recorded. These statutory copies are subject to expiry deletion; they do not restore a deleted service account or its readings.

Transfers of personal data abroad

These transfers occur over the network when the relevant feature is used; page delivery can occur before signup. There is no separate bulk or physical transfer. We request separate agreement at signup for the Google Cloud transfer needed to create an account. The five measurement services (GA4, Google Ads, X, Meta and TikTok) below automatically receive the described events during visits and qualifying actions, unless browser privacy signals or a saved provider refusal block them. Measurement can begin before signup.

Cloudflare — CDN delivery, protection and Web Analytics/RUM

Technical request and page-performance information is processed automatically during page use. The applicable contract entity, processing countries, overseas-transfer basis and complete CDN-log retention are not yet confirmed. The RUM data, supplier retention explanation and refusal limitations are disclosed separately above. Cloudflare details

When standalone PDF sales are available and chosen, order input, the buyer email, the finished text and private file are also processed on the existing Google Cloud service. Order input and private paid results expire 90 days after payment confirmation; see the separate PDF section. The Resend and PDF-marketplace rows apply only to that purchase, including for Korean readers.

Google LLC — Hosting, sign-in and database

Google LLC (Vertex AI) — AI readings, daily fortunes and chat

Dodo Payments Inc. — Checkout and payment

Whop Inc. — Purchases made before the switch to Dodo Payments

Plus Five Five, Inc. (Resend) — PDF delivery, only when ordered

Gumroad, Inc. / Whop, Inc. (PDF) — The PDF marketplace you choose

Payhip Limited (PDF) — PDF store, only when chosen

Ko-fi Labs Limited (PDF) — PDF shop, only when chosen

Google LLC (Google Analytics 4) — Site analytics

Google LLC (Google Ads) — Ad-conversion measurement

X Asia Pacific Internet Pte. Ltd. (for X Internet Unlimited Company) — X purchase attribution

Meta Platforms Inc. — Meta purchase attribution

TikTok Pte. Ltd. — TikTok signup and purchase attribution

The Google Ads billing agreement for our South Korean account names Google Korea LLC; the Google Ads row above identifies the overseas Google measurement service reached by the tag, not our billing counterparty. Recipient information: Google Analytics · Google Ads · X · Meta · TikTok

What Dodo Payments collects on its own checkout — your name, email address, billing address and card details — it collects from you directly rather than receiving it from this site, and its own privacy policy governs what it does with it. The same was true of Whop for purchases made before the switch.

Refusing, and what it costs

You may refuse. Refusing the hosting transfer means an account cannot be opened, because the service itself runs on Google Cloud in the United States; declining at signup removes the account that signing in created, and an existing member stops account transfers by deleting their membership. Vertex AI receives no new request unless you ask for an AI-written reading, daily fortune or chat reply, so ordinary public pages remain available. Refusing measurement does not restrict pages, accounts, purchases or readings. Enable Do Not Track or Global Privacy Control in a supported browser to stop new measurement by GA4, Google Ads, X, Meta and TikTok; saved provider refusals remain in effect. To request withdrawal for a provider or ask for deletion of records we hold, contact privacy@duckgustudio.com. This cannot recall data already sent.

Your choices and rights

You can view and share an Ilju result without choosing to continue or save a profile. Use “Clear my result and start again” to clear the test’s temporary data, or close the tab to end its storage session. To keep a birth date out of your account, do not choose the profile save action after sign-in; the result remains available. Once saved, you can edit or delete that profile on My page. Clearing the test result or closing its tab does not delete a profile already saved to your account. No link or picture leaves this device unless you choose to share, reply or save a picture; the page may prepare them on this device in advance. To use another birth date instead of a saved profile, choose “Use a different birthday”. While you are signed in, a friend’s or reply link compares your main profile’s character with the link on this device to show a hint; nothing about it is sent, and opening the link while signed out avoids it. While you are signed in, the website home page, in every language, also calculates, on this device, the character of your main profile (or, if none is set, the first profile in the list). The character is not sent to analytics, and only that character’s picture file is loaded from this site; tapping that card sends which card it was, its section and position, and whether it was showing your own card, as listed under Google Analytics. Opening the home page while signed out avoids this; changing the main profile or deleting that profile changes which profile is used, and with no saved profile nothing is calculated.

The same choices apply to the Work Hamzzi test in every language: you can view and share its free result without signing up, clear its temporary data with “Clear my result and start again”, or close the tab. Signing up only to see the rest of the result does not save the birth date to your account. The Work Hamzzi picture on the website home page comes from the same on-device calculation as the Ilju card and is loaded and measured the same way: opening the home page while signed out avoids it, changing the main profile or deleting that profile changes which profile is used, and with no saved profile nothing is calculated.

Profile lets you clear what this browser has stored. To avoid future Vertex AI processing, do not request a new AI-written reading, daily fortune or chat reply; this does not recall information already sent. Where applicable law gives you them, you may request access, correction, deletion, restriction, portability, or withdrawal of consent by writing to privacy@duckgustudio.com. We may need to verify your identity before acting, and we will explain any refusal and the route to appeal it.

The friend map has separate controls: decline an invitation, disable the link and its preview without removing existing connections, remove one connection, edit or switch the map profile, and withdraw detailed-reading permission for a specific friend while keeping the sign-level connection. Editing or switching that profile clears permission across its connections until separately renewed. These choices do not affect ordinary account use. To request a copy, correction or deletion of a referral or connection record, use those controls where available or email privacy@duckgustudio.com. Neither a link holder nor a connected friend can obtain your raw birth date, time, place or account identifiers through the map.

You can edit or delete a saved profile, withdraw the optional email choice, and request website account deletion from My page. For access, correction, deletion or restriction of another record, email privacy@duckgustudio.com with the right you want to exercise and the account or record concerned. We will verify the requester or their representative before disclosing or changing private information, then reply through the contact channel you provide. If we cannot comply, we will explain the reason and how to challenge the decision. You can use the same address to ask about legally retained transaction records after account deletion.

United States state privacy notice

For United States residents, the categories processed by this website are identifiers, account information, purchase records, Internet or device activity, content you write, and the inferences described above. Sources are you, your device, the sign-in provider you choose, and the providers listed in this policy. This website has not sold personal information during the preceding 12 months and does not show ads. Limited visit and conversion data is shared automatically with GA4, Google Ads, X, Meta and TikTok described above, subject to browser privacy signals and saved provider refusals. Submit a withdrawal request or an appeal to privacy@duckgustudio.com.

Age, security, and changes

The minimum age is 14. If you have not reached the age of majority where you live, you may use Lodestar only with permission from a parent or legal guardian. Users under 14 may not create an account, because no child-account or verified parental-consent programme is offered. Sign-in and account checks restrict access to saved records; support recovery is limited to authorised staff and records the action taken. Material changes are announced on this website before they take effect.

Links, support, and the app

External source and provider-policy links take you to other websites. If you contact support by email, your email address and message are sent to the support service. Avoid sending sensitive personal information. The iOS client’s additional App Store and device flows are described in this policy; Apple and external sign-in providers also apply their own notices.

Read the iOS information above

Contact and remedies

Personal information protection officer: Lee JungAe, representative of Duckgu Studio. For privacy requests and complaints, email privacy@duckgustudio.com. We handle requests in the language of this policy where possible.

For independent advice or remedies in Korea, contact the Personal Information Infringement Report Center (118) or the Personal Information Dispute Mediation Committee (1833-6972). Report Center ↗ · Dispute Mediation Committee ↗

Previous policy and changes

The 2026-09-30 revision explains the separate PDF purchase flow that applies only when it becomes available and you choose it: marketplace verification, input fixed to the purchased product, private results and their 90-day period after payment confirmation, Resend delivery with the purchased PDF attachment, staff access and refusal. Required signup choices and existing website checkout do not change.

Read the complete previous policy (effective 2026-09-29)

The 2026-09-29 website home page today’s-fortune check update narrows what the today’s-fortune card on the website home page asks our server. The server no longer returns the fortunes saved for that profile to the browser. After checking that the profile belongs to the account, the server now reads, of the saved fortunes, only that profile’s one record for today’s local date and the page’s language, and returns only whether it exists, never its text. The page sends that profile’s identifier, today’s date on this device and the page’s language for this check. The daily-fortune details describe the same fact. Nothing is generated, and the daily-fortune screen and saved readings do not change.

Read the complete policy before the website home page today’s-fortune check update (effective 2026-09-29)

The 2026-09-29 website home page personalisation update explains that, on the website home page in every language, the main profile (or, if none is set, the first profile in the list) of a signed-in member is used on this device, without a tap, to calculate that profile’s Ilju and Work Hamzzi characters and show them on the test cards; the characters are not sent to analytics, and only their picture files are loaded from this site. The website home page’s today’s-fortune, Ilju and Work Hamzzi cards show that profile’s name (unless it has no name of its own); the today’s-fortune card also shows whether today’s fortune has already been opened, checked against the fortunes already saved for that profile without generating one, and paid readings the account already has are marked “Saved”. The Google Analytics row also lists what a home page card tap sends. With the same update, the Work Hamzzi test, previously offered only in Korean, is also offered in English and Japanese; its handling of birth dates, temporary tab storage, the sign-in return, share links and analytics events is the same in all three languages. It now also says that signing in from the top of the page with a coworker’s link open can put the coworker’s character code in the return address, and sign-ins through Lodestar’s server now leave that code out of their sign-in state record. The Ilju and Work Hamzzi summaries, details and refusal routes, the Work Hamzzi information-flow step, and the daily-fortune details describe the same facts.

Read the complete policy before the website home page personalisation update (effective 2026-09-29)

The 2026-09-29 iOS daily-fortune update replaces the optional preview and separate activity start with explicit required display consent for that feature. After consent, opening today’s saved result updates the widget and supported Live Activity automatically. This revision explains the notice version stored on the device, visible text, withdrawal and re-consent. General signup choices, AI generation and advertising permissions do not change.

Complete policy before required daily-fortune display consent

The 2026-09-29 Ilju reply-link update corrects its description of the analytics items the Ilju test already sent and of how character codes are handled in the sign-in return address. It also explains reply links (two character codes); the Lodestar campaign name, creative name, share step number and link type carried by share links; the on-device calculation from a signed-in member’s saved profile and the main-profile comparison behind hints; and the Ilju analytics event items. The summary, information flow, details and refusal routes describe the same facts.

Read the complete policy before the Ilju reply-link update (effective 2026-09-29)

From 2026-09-29, this policy adds the Korean-only Work Hamzzi test. Like the Ilju test, it calculates the result in your browser. Choosing to sign up for the rest of the result, or to save a profile, keeps the result and, at age 14 or older, the birth date in the same tab for up to 30 minutes, apart from the Ilju test; the birth date reaches your account only when you choose to save it. The Google Analytics row now also lists the event details both tests send. Required signup choices do not change.

Read the complete previous policy (effective 2026-09-28)

The 2026-09-28 iOS widget update adds the optional Home Screen daily-fortune preview and separately requested Live Activity. It explains the protected device snapshot, where personal text can appear, when display expires and when the local file is removed. The account and AI generation rules do not change.

Read the complete policy before the iOS widget update (effective 2026-09-28)

From 2026-09-28, this policy adds the existing Cloudflare CDN and Web Analytics/RUM processing, observed page/performance fields, supplier retention explanations and unconfirmed contract conditions. It clarifies that the existing refusal and iOS blocking rules apply to the five Lodestar measurement providers. This notice does not expand required signup choices.

Read the complete previous policy (effective 2026-09-27)

From 2026-09-27, this policy explains the Ilju character test’s optional continuation: temporary storage in the same browser tab for up to 30 minutes of validity, the separate choice to save a birth date to your account after sign-in, and how to clear the temporary data. It also explains that shared links show a character without the birth date or account details. The summary, information flow and detailed sections describe the same choices.

The 2026-09-27 revision also describes the same-account iOS client, App Store account tokens and transaction records, optional on-device copies and reminders, selected sexual-orientation information and birth-city coordinates, the iOS integration’s measurement limits, and optional gift links with their minimum delivery records and retention.

Read the complete previous policy (effective 2026-09-26)

From 2026-09-26, English and Japanese purchases are charged by Dodo Payments Inc. (United States) as merchant of record instead of Whop. This policy lists what this site sends Dodo Payments, what it keeps from the payment, and Dodo Payments’ privacy contact. Whop remains listed for the refunds and records of purchases made before the switch. Korean checkout is unchanged.

Read the older policy (effective 2026-09-25)

Read the older policy (effective 2026-09-24)

Read the older policy (effective 2026-09-23)