Last updated 2026-10-09 · Previous versions
Privacy Policy
What hamzzi.com (including the previous address lodestarastro.com and the magazine blog.lodestarastro.com) and its iOS and Android clients process, who receives it, how long it is kept, and what you can ask for. The clients use the same service account, saved profiles, readings and credits. Additional device, App Store and Google Play flows apply when you use the corresponding feature and are described below.
What we process and why
The address change keeps the same account, saved profiles, readings and Stars. When automatic handoff is available, it carries verified sign-in, limited Hamzzi room settings and measurement refusals. It does not copy birth details, conversations or advertising identifiers. See Address change for the temporary record, expiry and deletion choices.
Submitting our Daangn lead form requests automatic PDF creation and email delivery, independently of payment. Private Google Sheets receive the response; our server uses the birth details for calculation and Google Vertex AI for writing, then Resend emails the completed PDF to the submitted address. Request data expires after 60 days. See the Daangn section for items, recipients and refusal routes.
Whop receives restricted public-page visit events to show visitor counts and traffic sources. It receives no form contents or account identity. Browser privacy signals and any existing measurement-provider refusal stop this connection; native apps, private PDF pages and authentication/gift handoff pages are excluded. Details and refusal routes are below.
If you are signed in, touching Hamzzi requests a short AI line. Google Vertex AI receives only general hamster topics, a Korean-time part of day and an independent random writing variation. Five lines are held in device memory; another AI request happens only on a touch after they run out. Birth details and your private texts are not sent for this feature.
When enabled, Hamzzi raising is offered in Korean. At release, existing active accounts may receive private raising records from verified past attendance, saved eligible paid readings and existing growth records before their first feed. Other accounts start with their first feed; opening a room alone creates no record. The positions and sizes you save for room items are also private raising records. Water and tidying keep their latest Korean dates, and completed-care days count toward fixed outfits. Web reminders have two separate optional choices, and refusing them does not restrict raising or other services.
Account creation and the overseas transfer needed for it are separate required choices at signup. Email updates and creating a shareable friend map from a selected profile are optional. Anyone with its link can preview the chosen alias, Sun sign and lit-planet count before joining; each friend needs separate permission to use your birth details for a paid detailed compatibility reading. We use profile, reading, payment and support information when you ask for those services; statutory transaction records follow the applicable retention duty. GA4, Google Ads, X, Meta and TikTok automatically measure visits and qualifying actions, subject to browser privacy signals and saved provider refusals. Cloudflare separately delivers and protects the site through its CDN and automatically measures page performance with Web Analytics/RUM. The detailed items, periods and refusal routes appear below.
Stardust counts paid readings opened with a bought star and adds a free star for every five. If you join through a friend’s stardust invite link, that friend is credited for your first such reading and sees only counts, never your name or readings. See Stardust and friend invites.
- Whop website traffic
- Permitted public visit → restricted page/campaign data and unrelated browser ID → Whop traffic reporting; no form or account identity capture.
- Standalone PDF: only when you choose to order
- When PDF sales are available and you choose this purchase, we verify the purchased product, any individual Saju section and buyer email, then send a private link for that purchase’s input. The order input, reading text, private PDF and delivery email address are held separately from a member account and expire 90 days after payment confirmation. Resend delivers the intake link and later the completed reading PDF as an attachment with its private link.
For premium Saju, Whop payment opens first. After the receipt is verified, the required birth-information form opens automatically. We validate and normalize the submitted details before calculation and AI generation.
When you buy a PDF from our Shopify store, Shopify checkout is separate from Whop. We verify the order and buyer email, then use the same private Lodestar input and PDF delivery flow. Only fulfillment identifiers and completion state return to Shopify; birth details, questions and private results stay out of that integration.
- Account and profile: required signup choices
- We use the sign-in identifier, supplied name or email, consent record and saved birth profile to open and maintain your account. Service records are held until withdrawal, then privately for 30 days before deletion.
- Ilju character test: share links and optional continuation
- The birth date is calculated in this browser. Choosing to continue to a daily fortune or save a profile temporarily keeps it in this tab for the sign-in return or a save retry, with a 30-minute validity period. It is sent to your account only if you then choose to save it as your profile. A share link carries only character codes (two on a reply link), campaign and creative names that Lodestar has set in advance, a share step number and the link type; it never carries a birth date or account details. The address you return to after sign-in can carry the friend’s character code (and, for a reply link, the recipient’s). When a signed-in member uses a saved profile (the main profile by default), the character is calculated on this device. On a friend’s or reply link, the main profile’s character is also compared with the link on this device to show a hint. Neither is sent.
- Friend compatibility map: optional sharing
- Creating a map stores a reusable invite code. Anyone with the link can preview the selected alias, calculated Sun sign and number of lit planets (up to ten); the friend list and birth details stay private. A connection is stored only after the recipient accepts with their own profile. Paid detailed compatibility requires separate permission for each friend, off by default. You can disable the link or remove a connection; details and refusal routes appear below.
- Work Hamzzi test: optional sign-up to continue
- This test, offered in English, Japanese and Korean with the same handling in each, also calculates the birth date in this browser. Choosing to sign up for the rest of the result, or to save a profile, temporarily keeps it in this tab, apart from the Ilju test, for the sign-in return or a save retry, with a 30-minute validity period. It is sent to your account only if you then choose to save it as your profile. Shared links show a character, without the birth date or account details.
- Requested AI service
- We use birth-profile inputs, calculated astrology details and words you type to generate a reading, daily fortune or chat reply. Finished readings and profile-bound fortunes remain with the account until its deletion; a temporary chat retry record expires after 24 hours.
- Reference city for a missing birth place
- For Saju, Vedic and wealth readings without a birth place, the Korean page uses Seoul and the Japanese page uses Tokyo. The English page reads the device time zone only in this browser and chooses a matching listed city, or London if none matches. The city name, coordinates, time zone and assumed-place flag stay with account-reading requests until account deletion and the following 30-day period; the profile stays unchanged. The same selection can be used for an ordered standalone PDF, whose input-copy deletion and 90-day expiry are explained below.
- Purchase and statutory duty
- We use account, order reference, product, amount and payment status to deliver and refund what you bought. Service orders close with the account; the minimum contract and payment evidence required by Korean law is retained separately for five years.
- Star gifts: optional
- We record the sender and recipient service-account identifiers, source purchase and credit identifiers, count, status, times and a hash of the gift token. These minimum gift records remain for five years from creation, including after account deletion when needed to handle the received balance and a purchaser refund. Names, email and birth profiles are not copied into the gift record.
- Optional email choice
- We keep the optional choice and its change time with your account; the sign-in email, if available, is the potential delivery address. No marketing email delivery is currently connected. You may withdraw the choice on My page.
- Instagram replies: when activated
- For registered posts on @lodestar_astro, a comment starts a DM invitation. A later DM reply of 햄찌 lets us check following and send the site link. We keep only platform IDs, times and response status privately in US Firestore, with expiry 30 days after the last handling; raw comment or DM text and full profiles are not saved.
- Site and advertising measurement
- GA4, Google Ads, X, Meta and TikTok measure visits and selected service events automatically, including before signup. Browser Do Not Track or Global Privacy Control signals and existing provider refusals stop the relevant measurement. Contact privacy@duckgustudio.com to request withdrawal or deletion.
- Cloudflare CDN and performance
- Page requests pass through Cloudflare; its RUM beacon separately sends page and performance information, including before signup. The five-provider refusal and iOS blocking rules do not establish that Cloudflare collection stops. Details and unconfirmed contract conditions appear below.
- iOS account, purchases and device copies
- The same account holds App Store transaction and credit records and a random purchase-account UUID. Offline copies and local reminder settings stay on the device. The iOS daily-fortune feature requires explicit display consent before use; opening today’s saved result then updates the Home Screen widget and automatically starts or updates a supported Live Activity. The iOS integration blocks the five Lodestar measurement providers described below.
- Android account, purchases and optional widget
- A Google Play purchase sends a random purchase-account identifier to Google and a purchase token to our server for verification. We keep its token hash and verified order/credit records, without card details. Device reading copies, optional daily-fortune widget text and local reminders are separate from the server originals. You can use today’s fortune without turning on the Android widget.
- Your browser moves from lodestarastro.com to hamzzi.comWhen automatic handoff is available, a private US Google Cloud record usable once within 60 seconds carries limited room settings, measurement refusals and verified member sign-in to this browser
- When activated, you comment on a registered @lodestar_astro post, then reply 햄찌 to the DM invitationMeta sends a signed event to Lodestar; our server checks following, responds through Instagram and keeps only IDs, times and status privately in US Firestore for 30 days after the last handling
- Verified activity from an existing account is migrated, you first feed a Hamzzi, or you separately choose web remindersRaising records, including saved item positions and sizes, stay in your private account on US Google Cloud; optional encrypted reminders travel through your browser’s push service
- After raising starts, you change water and tidy the roomLodestar saves the latest Korean dates and completed-care day count privately on US Google Cloud to unlock fixed outfits
- Premium Saju: payment first, then required birth details and consentWhop payment → verified receipt → private birth-information form → validation and cleanup → calculation and Vertex AI → private PDF delivery. Checkout references contain no birth details and expire after 24 hours.
- When available, you choose a standalone PDF and pay on Shopify, Gumroad, Whop, Payhip or Ko-fiLodestar verifies the purchased product and any individual Saju section, receives its input through a private link, then creates the result; Resend receives the address, notice, private link and completed reading PDF attachment. Shopify receives only fulfillment identifiers and completion state.
- You create a star gift link; the recipient signs in to acceptLodestar records the reserved credits and the minimum private delivery relationship
- You open a paid reading with a bought star, or a friend who joined through your invite doesLodestar records the grain in the account on US Google Cloud; an inviting member sees only counts
- Choose to continue from the Ilju result, then return after signing inThe birth date waits in this tab; only your separate save action sends it to your account. The return address carries only character codes, and Lodestar’s server-side sign-in state record leaves them out
- You share an Ilju result or send a replyThe link carries only character codes (two on a reply link) and lineage labels: Lodestar’s preset campaign and creative names, a share step number and the link type
- Your saved profile and completed readingsLodestar keeps it in your account on Google Cloud in the US
- Choose to sign up from the Work Hamzzi result, then return after signing inThe birth date waits in this tab, apart from the Ilju test; only your separate save action sends it to your account
- You create a map from your profile and share its linkLink holders preview alias, Sun sign and lit count; after a friend accepts with their profile, Lodestar records the connection
- If you separately allow a friend to use your profile for a paid detailed readingLodestar uses birth details on the server; the purchaser keeps a private result until profile, permission or connection changes
- A Saju, Vedic or wealth request without a birth placeThe browser adds a reference city to the request; Lodestar keeps it for calculation and recovery, without changing the profile
- Calculated astrology details and words you typedGoogle Vertex AI writes a reading, daily fortune or reply
- You touch Hamzzi: general hamster topics, a Korean-time part of day and an independent random variationGoogle Vertex AI writes five short lines; the server keeps a temporary retry record and device memory holds the lines
- Order reference and checkout detailsNICEPAY for Korean checkout; Dodo Payments for English or Japanese. You enter payment details there.
- Visits and selected service eventsLimited events go automatically to GA4, Google Ads, X, Meta and TikTok, unless a privacy signal or saved refusal blocks them
- You request a page and it loadsCloudflare delivers and protects the request; its RUM beacon reports page and performance details separately
- When you leave the serviceService data is deleted after 30 days; required transaction evidence is kept separately
- If you make an iOS in-app purchaseApple processes payment with an account token; Lodestar verifies the transaction and records your credits
- If you choose to save a reading offline or enable a local reminderThe copy and reminder settings stay on this device; deleting a copy leaves the server original
- If you buy through Google Play on AndroidGoogle receives the random account identifier; Lodestar verifies the token and keeps its hash with the order and shared credits
- If you turn on Android’s saved-fortune widgetOpening today’s saved result passes its title and summary to this device for Home Screen display; no new fortune is generated
- After agreeing to the required iOS daily-fortune display notice and opening today’s resultiOS shares a protected local snapshot with the widget
- The same opening of today’s result also updates a supported Live ActivityiOS shows the title in the expanded Dynamic Island; the Lock Screen uses a general prompt without personal fortune text
You can delete your account or ask about a record at the contact below. Statutory transaction records have a separate retention period.
In words: verified activity from existing active accounts is migrated into private raising records at release. For other accounts, the first feed starts the record. Your device works out the Hamzzi’s look from the profile, while the server keeps care, clothing choices and the item positions and sizes you save. Only if you separately agree to both reminder choices does your browser register a reminder address and receive an encrypted notification. You may decline or turn it off.
Reading this site
Lodestar / Duckgu Studio publishes this website. Notes saved in earlier versions, saved birth profiles and unsent chat drafts may remain in browser storage. None are automatically attached to AI conversations. The site shows no ads. GA4, Google Ads, X, Meta and TikTok measurement runs automatically as described below, subject to browser privacy signals and saved provider refusals.
Browser storage remains until you clear it in Profile or through your browser settings. Clearing browser data, using private browsing, or changing browsers can remove it. It does not sync to the iOS app.
Hosting and technical information
The site is delivered through Cloudflare’s CDN in front of Google Firebase Hosting and Cloud Run. Serving and protecting pages can involve technical request information such as IP address, browser details, requested URLs, and server logs. Google/Firebase processing is described in their notices below; Cloudflare processing is described in the following section.
Cloudflare delivery and performance measurement
Cloudflare’s CDN receives the network requests used to deliver and protect this site, including the connecting IP address, browser information and requested URL. Separately, an automatically injected Web Analytics/RUM script reports page performance to an address on this same site, including before signup. Observed beacon fields include the page host and path, a random identifier for each page load, page-display and network timing, and memory-performance measurements. A page-load ID is not our service-account identifier. Cloudflare’s published analytics dimensions also include the visitor’s country; this is a country-level location classification, not a claim that GPS is collected. This notice does not establish whether the provider can link these data with other information.
The browser can automatically attach this site’s cookies to that same-origin request. This is distinct from the script reading or using a cookie for tracking: Cloudflare states that its RUM script does not read or store cookies or browser storage. We have not confirmed how the provider handles an automatically attached Cookie header. Cloudflare says RUM receives the IP address during HTTP processing, discards it at the nearest data centre, and does not store it in RUM core databases or logs; that statement does not describe all CDN or security logs.
Cloudflare’s published Web Analytics FAQ describes seven days of unsampled beacon data, followed by aggregation to around 10% of the original volume for longer-term storage, and access to the previous six months. These are supplier descriptions of Web Analytics retention and query access, not a confirmed deletion period for Lodestar’s contract or all Cloudflare CDN logs. The applicable contract entity, processing countries, complete CDN/security-log retention and overseas-transfer basis remain unconfirmed; we will update this notice after verification.
Do Not Track, Global Privacy Control, saved provider refusals and the iOS integration’s blocking rules below cover Lodestar’s five providers: GA4, Google Ads, X, Meta and TikTok. We have not verified that they stop Cloudflare RUM or CDN processing. Some browser content blockers may stop the RUM script; this does not stop requests required to deliver pages through the CDN. Contact privacy@duckgustudio.com about Cloudflare processing, objection or deletion; we will explain the available action and any effect on page access after verifying the request.
Cloudflare Web Analytics FAQ ↗ · Cloudflare RUM ↗ · Cloudflare Web Analytics dimensions ↗ · Cloudflare Privacy Policy ↗
Instagram comment and DM replies
Database expiry-deletion policies for these response and session records are configured. This confirms the deletion setup, not the deletion time of a particular record or live DM delivery.
This applies only when our own API reply feature is activated for registered posts on @lodestar_astro. Activation requires configuration, the applicable Meta access conditions and actual delivery checks. It does not mean the feature is live or every permission is approved. Posts handled through a separately configured external tool retain that separate setup.
Any comment can start one private invitation. The invitation asks you to follow the account and reply 햄찌. We bind the messaging recipient returned by the private-reply API, then check following only after your incoming DM opens the messaging interaction. We do not infer following or DM consent from a comment author ID. After following is confirmed, we send the public site link. A public reply may direct you to the DM or message-request folder. A platform send acknowledgement does not confirm arrival in your inbox.
Meta supplies comment and media IDs, the platform sender or messaging recipient ID, message IDs and event times. We read the event text temporarily to handle the reply and look up only the fields needed to check following. Our response records save those IDs, processing times, send status and expiry, not raw comment or DM text, profile names, photos or full profiles. These records are not linked to a website membership and are not sent to Vertex AI.
To deliver the response through Instagram, we send Meta the comment or messaging recipient identifier and our prepared invitation, public-reply wording or public site link. We do not copy your raw comment/DM text or birth information into that outgoing response. Meta’s own storage and processing follow its policy; the exact processing location for this API exchange has not been confirmed separately.
Our server stores these records privately in Google LLC’s US Firestore database (us-central1) over the network when handling the event. Each record expires 30 days after its last handling. We reject expired sessions and stale reply windows. Physical deletion begins after the database TTL policy is configured and can occur later than expiry. Before activation, the expiry and deletion setup must be checked. Instagram/Meta keeps its own copies under its own policy; deleting our records does not remove a public comment or a DM already held by Meta or the recipient.
To avoid a new response, do not comment on a reply-enabled post, do not reply to its invitation, or block the account’s DMs in Instagram. For access, correction, deletion or a processing-halt request for our records, contact support@duckgustudio.com with your Instagram handle and, where available, the public comment link. Do not send a password or access token. We identify the relevant records before handling the request. This is separate from deleting a website account; clearing browser data or leaving the website does not delete Instagram response records.
Site measurement and refusal
Whop traffic measurement sends only page events with a public path, allowlisted UTM campaign labels, public referrer or external origin, event ID/time, browser User-Agent/language and a random browser visitor ID unrelated to your account. The local ID expires after 30 days; blocked storage results in a new ID per page and less accurate unique-visitor counts. No Whop auto-capture SDK, form scraping, fingerprinting, contact fields, account identity, birth/profile data, private URL tokens, personalized titles or purchase events are used. Private PDF pages, native apps and authentication/gift handoffs are excluded. The browser sends no cookies or Referer header to this endpoint, although Whop receives the network IP address. After existing account choices are checked, DNT/GPC or any stored refusal for GA4, Google Ads, X, Meta or TikTok also stops Whop visits and removes the local Whop ID. Refusing does not limit the service. Contact privacy@duckgustudio.com for Whop-specific withdrawal/deletion requests; previously received data cannot be recalled by clearing browser storage. Whop’s exact traffic retention and overseas-transfer basis remain unconfirmed.
Hamzzi Analytics events have only closed values: hamzzi_room_view state (guest/member/no_profile/not_started) and from (tab/home/push/ilju/work/fortune/reading/other); hamzzi_feed result (fed/already/failed/signed_out); hamzzi_adopted via (room/ilju/work); hamzzi_place slot_kind (wall/floor/rug/beside/outfit) and change (place/remove); hamzzi_push_step step (shown/enabled/declined/os_denied/unsupported/off/failed). Home card positions are the card’s current rendered order (1–40). Names, profile IDs, stages, items, outfit IDs, birth-year animals and Ilju characters are not event fields.
This site uses Google Analytics 4 and Google Ads tags to automatically measure visits, selected service actions and confirmed conversions, including visits before signup. When you arrive through an X, Meta or TikTok ad, this site stores the relevant ad click ID and can send a qualifying signup or confirmed purchase to that provider from our server. Those three do not load their pixels on this site. Browser privacy signals and saved provider refusals block the relevant measurement. The recipient, country, items, timing, purpose and retention are listed under Overseas transfers below. Refusing measurement does not restrict pages, accounts, payments or readings.
The GA4 property is linked to our Google Ads account, so Analytics data can also be available to that linked Ads account. The Google Ads browser conversion tag is controlled separately. Google consent signals for ad user data and ad personalization remain denied in the tag.
In a browser that supports it, enable Do Not Track or Global Privacy Control to stop new measurement by GA4, Google Ads, X, Meta and TikTok. Existing provider refusals saved in this browser or on your signed-in account remain in effect. You can remove browser identifiers through the browser’s data settings; clearing stored data alone does not stop future measurement and may also remove a refusal saved only in that browser. For provider-specific withdrawal, deletion or questions about records held by us, contact privacy@duckgustudio.com. These steps cannot recall data already received by a provider. Dodo Payments may independently measure activity on its own checkout under its own privacy policy.
Friend compatibility map and invitations
The friend map is optional. A signed-in member chooses one saved birth profile to create a map, then shares its reusable link. Anyone holding a valid link can preview that profile’s alias, calculated Sun sign and lit-planet count, even without signing in or accepting. The preview contains no friend list, account identifier, birth date, time or place, or detailed-reading permission. If the profile describes someone else, create and share the map only with that person’s authority to show those preview fields; detailed-reading use also requires their authority to use the birth details. The server stores the random code with the map owner’s account and sign-in identifiers, the selected profile identifier and referral attribution. A connection record is stored in both accounts only after a friend signs in, chooses their own profile and accepts. Opening the link alone does not connect accounts. Friend-map invitations and acceptance provide no stars, money or other reward; stardust invite links are a separate feature described below.
Each accepted friend lights one of ten symbolic planet illustrations on the map. The link preview shows only how many are lit, capped at ten even if more friends connect; it does not identify them. Connected members see each other’s chosen profile alias (which may be blank) and the Sun sign calculated from its birth date for a simple sign-based compatibility view. We do not show birth date, time, place, email, account identifiers or optional identity details. Editing a map profile updates its displayed alias or sign; switching profiles follows the new selection. Editing or switching turns off that member’s detailed-reading permissions and erases earlier linked results and recovery inputs until the member opts in again. Deleting the selected profile stops its display and erases those records.
Detailed compatibility is a separate paid reading. Permission to use your selected profile’s birth details is set for each connected friend and is off for a new connection by default. Accepting a link does not give every friend this permission. At the paying member’s explicit request, our server checks that specific connection and permission, reads the other profile internally and uses both people’s birth details to make the reading. Raw birth date, time and place are not returned to the paying member as profile data. The completed result and the original input kept for recovery may be stored privately under the paying member’s account. Only that member can open the linked result; it cannot be published with the reading share-link feature. One paid reading uses one star under the purchase terms. The simple sign view does not itself send either profile to Vertex AI or spend a star.
You may decline an invitation, turn off your map link while keeping existing connections, edit or switch its profile, withdraw detailed-reading permission for one friend, or remove that connection without losing ordinary account access. A disabled link no longer allows a preview or new join. Editing, switching or deleting either map profile, removing a connection or withdrawing its detailed permission prevents new linked detailed readings using the old profile or permission and deletes the related result and recovery copy held in the other member’s account. An edit or switch also requires renewed permission for each affected friend before that profile can be used again. The purchaser can no longer open a deleted result; a star already spent is not automatically restored, without limiting applicable refund rights. Deleting either account immediately invalidates its map link and removes its connections from other accounts; the closed account’s remaining service records are purged after 30 days. You can also ask privacy@duckgustudio.com to inspect, correct or erase a referral or connection record.
Accounts, profiles and AI
Hamzzi touch lines use the separate, limited inputs and temporary storage described below, not your astrology or conversation context. Hamzzi AI-line details
A saved birth profile can include a birth date, optional birth time, selected birth city, that city’s centre coordinates and time zone, and a name or alias. City coordinates are kept with their supplied decimal precision; they are not a reading of your device’s current GPS location. Optional identity choices include gender or your own description, pronouns, and who you are attracted to, including women, men, any gender or the ace/aro spectrum. These choices can reveal sexual orientation. We store supplied choices with the account profile and use the wording to personalise requested readings; we do not infer them from a chart. You can leave them blank, choose not to answer, or edit or delete the saved profile. Please do not include unrelated sensitive information in free text. Profile and recovery records follow the retention rules below.
The Ilju character test calculates its result in your browser without sending your birth date to our server. When you choose to continue to a daily fortune or save a profile, we temporarily keep the Gregorian birth date, the late-night birth choice, your and the shared character codes (for a reply link, also the recipient’s), the share link’s campaign name, creative name and share step number, a random profile identifier and expiry time in this tab’s session storage. This restores the result after sign-in in the same tab and lets a failed save be retried. This stored information is not transferred to another browser. However, when you continue to sign-up or sign-in, the address you return to carries the friend’s character code (and, for a reply link, the recipient’s character code too), and if you move from an Android in-app browser to your default browser to sign in, that address goes with you. For sign-in methods that pass through Lodestar’s server, such as Kakao, Naver and Instagram, the sign-in state record is stored without the character codes. After signing in and completing any required signup choices, choosing the button that saves this birth date to your profile sends the date to our server to create your birth profile without overwriting an existing profile. We associate the local save record with the signed-in account identifier to keep accounts separate. Signing in alone does not save the birth date to your account. An Ilju share link carries only the sender’s character code (one of 60; a reply link carries two, for the person replying and the person replied to), the campaign and creative names showing which Lodestar ad or post the chain of shares started from, a step number (1–9) showing how many shares deep the link is, and the link type. Only campaign and creative names that Lodestar has set in advance are carried; any other value is replaced with ‘ilju_organic’ and ‘none’. Anyone with the link can see these, and the address may remain in request logs for pages opened from it. It never contains a birth date, name, profile identifier, account information or ad-click identifier. When a signed-in member uses a saved profile (the main profile unless they choose another) to see a character or a match from a friend’s link, the character is calculated on this device from that profile’s birth date, which the account has already loaded; the birth date is not sent to our server again. When a signed-in member opens a friend’s link or a reply link, the page also compares the main profile’s character with the characters in the link on this device, only to show a line saying they are the same; the result of that comparison is not sent to our server or to analytics. Opening a link does not connect accounts or permit use of anyone’s birth details.
The Work Hamzzi test, offered in English, Japanese and Korean, handles birth dates the same way as the Ilju test in all three languages and calculates its result in your browser without sending your birth date to our server. When you choose to sign up to see the rest of the result, or to save a profile, we temporarily keep, separately from the Ilju test, the Gregorian birth date (only when it could become your own profile at age 14 or older), the late-night birth choice, your and the shared coworker’s character codes, a random profile identifier and expiry time in this tab’s session storage. This restores the result after sign-in in the same tab and lets a failed save be retried; we do not transfer it to another browser, and the address the test’s sign-up button returns you to after sign-in carries no character code. If you open a coworker’s link and use Log in or Sign up at the top of the page instead, the address you return to can carry the coworker’s character code; sign-ins that pass through Lodestar’s server, such as Kakao, Naver and Instagram, store their sign-in state without it. After signing in and completing any required signup choices, choosing “Save this birthday to my profile” sends the date to our server to create your birth profile without overwriting an existing profile. We associate the local save record with the signed-in account identifier to keep accounts separate. Signing in alone does not save the birth date to your account. A shared link identifies only one of the 60 characters and may be viewed by anyone with the link; it contains no birth date, profile identifier or account information. The two coworker characters shown with a result are chosen from traditional pairings of the characters and say nothing about any real person.
When you sign in, Firebase Authentication and the selected provider process account identifiers and any name or email the provider supplies. A verified email address is recorded on your Firebase account so that it can be told apart from others. It is never used to find or link an account: that is always the account identifier the provider itself supplies. Instagram Login supports professional accounts. Sign-in state is retained in this browser. Birth profiles saved while signed in are kept on your web account, including the name, birth date, time and place you enter and any optional information about yourself. Profiles saved while signed out stay in this browser.
Kakao and Naver sign-in, offered to visitors connecting from Korea, are run by this server rather than by Firebase directly. From Kakao we request the profile nickname and the account email address. From Naver we receive the account identifier, the nickname and the email address, which are the items this application is registered to receive. The permanent identifier each provider gives is what names your account here. The email address a provider supplies is a secondary record, and is never used to identify, match or link an account. To sign in, this server exchanges a one-time code for an access token with Kakao or Naver. That token and the refresh token issued with it are kept on the server so the connection can be revoked, and the address the provider supplied is kept with them; none of them are sent to your browser. Deleting your website membership disconnects the app at the provider, and the stored tokens and address are deleted whether or not the provider confirms. You can also disconnect Lodestar yourself in your Kakao or Naver account settings.
When you request Saju, Vedic or wealth without a birth place, the browser uses Seoul on the Korean page or Tokyo on the Japanese page. On the English page only, it reads the device time-zone setting with the browser’s Intl API and selects the first city in our existing list with that time zone; if it cannot read the setting or finds no matching city, it uses London. This setting is used only inside the browser to select a city and is not separately sent or stored. The chosen city’s name, centre coordinates, time zone and a flag marking the place as assumed are sent to our server; account readings retain them in the original request, generation attempt and recovery records. Standalone PDF orders have the separate input-copy deletion and expiry described below. The device’s current GPS location is not read. We do not write the reference city to your profile or fill a missing birth time in the stored request. If the time is absent, Saju uses three pillars; Vedic and wealth omit the ascendant and houses and use planetary positions calculated at a reference time. Results describe these limits. Changing the profile later does not alter an earlier reading or its recovery request.
A daily fortune is generated only when a signed-in member explicitly requests one for a selected profile and local date. The server uses that profile’s birth date to calculate a Sun sign, birth-year animal and Sun-sign segment. It sends those derived values, the local date, language and a writing variation to Google Vertex AI, without the structured birth date, profile label or account identifier. The generated text is saved under that profile in the member’s account so it can be read again. A journal view, when available, uses the same profile-bound result. On the website home page, for a signed-in member who has completed the required signup choices, the page asks our server, without a tap, whether the main profile (or, if none is set, the first profile in the list) already has today’s fortune in the page’s language. The page sends that profile’s identifier, today’s date on this device and the page’s language. After checking that the profile belongs to the account, the server reads, of the saved fortunes, only that profile’s one record for today’s local date and the page’s language, and returns only whether it exists, never its text; it does not generate a fortune or call Vertex AI. The card shows that profile’s name (unless it has no name of its own) and whether today’s fortune has been opened, not the fortune text. Opening the home page while signed out avoids this lookup.
When you send a message, the server receives that message, up to eight recent messages, the selected birth details or year-ahead reading context, language, and your own birth date for the age check. It recalculates the astrology context before sending the resulting placements and conversation to Google Vertex AI. Structured birth dates, place names, coordinates, profile names and account identifiers are not included in the model prompt. Personal information you type into a message is sent with that message.
The server keeps usage-limit records. To recover interrupted responses without generating twice, it stores the reply and a hashed request fingerprint in a temporary account-bound record that expires after 24 hours and is removed by database cleanup. Raw structured birth inputs and user messages are not saved in that record. Conversation history remains in this browser and is separated by signed-in account; it does not synchronize across devices. Processing may occur outside your country under Google Cloud terms.
We do not use your questions, messages, generated readings or Hamzzi lines to train a model or instruct Google to do so. Google Cloud’s service terms prohibit training on customer data without the customer’s prior permission or instruction. Google may retain limited request information for service safety under its terms; our 24-hour chat retry period is not a promise about Google’s own retention. You can avoid a new AI transfer by not requesting a reading, daily fortune or chat response, and not touching Hamzzi for an AI line. Report an inappropriate result or request review at privacy@duckgustudio.com. Google Cloud data governance ↗
Optional email updates
At signup, you may separately choose email updates about new readings and offers. We keep that choice and the time it was last changed with your account; if an email address was supplied by your sign-in provider, it is the address available for those updates. No marketing-mail delivery is currently connected to this website. You can turn the choice off at any time on My page without losing your account, purchase or readings.
Purchases and payment
Buying opens Dodo Payments’ own checkout, where Dodo Payments, as merchant of record and under its own privacy policy, collects your name, email address, billing address and card details, sends the receipt to the email address you enter there and handles tax. This website does not receive or store card numbers, and Lodestar does not receive your card details from Dodo Payments.
Pressing buy writes an order here before you leave for the checkout: which reading, which account, and a random reference that identifies the order and nothing else. What goes to Dodo Payments is that reference and the package’s product identifier (not your name and not your email address) plus, if you have paid through Dodo Payments before, the customer identifier it issued at that earlier purchase, so that it keeps one customer record for you. Dodo Payments returns the reference when it reports the completed payment, which is how the stars reach the right account even when you pay with a different email address. Lodestar keeps the order: the reading it was opened from, the package, the reference, the email address from your sign-in if there is one, Dodo Payments’ checkout, payment and customer identifiers, the amount and currency, the payment method type, the decline code if a payment is declined, and the account it belongs to. When checkout follows an X, Meta or TikTok ad and measurement is permitted, private short-lived records under the order may also hold the click identifier and receipt time described above; the Meta and TikTok records also hold the checkout User-Agent. These values are not sent to Dodo Payments or returned in the operations console. Nothing you enter on Dodo Payments’ checkout (your name, email address, billing address or card details) is copied into the order. It is what makes a reading open for you, stop opening if the sale is refunded, and be repairable by hand if the report never arrives. An order paid through Whop before the switch to Dodo Payments also holds the transaction reference and the email address recorded with that sale, and a Whop sale that reached us with no order waits under the email address it was paid with until an account with that verified address signs in. What Dodo Payments holds about your order is covered by its own privacy policy, and what Whop holds about an earlier order by Whop’s.
Opening a reading you bought sends the information on screen to this website’s server, which checks your purchase and calculates the chart. To write the AI-generated parts, the server sends Google Vertex AI the resulting placements, current date, calculated age where applicable, chosen language, and any question, relationship or work context, or optional identity wording you supplied. Structured birth dates, user-supplied birth-place names, coordinates, your own profile label and account identifiers are not included in that model prompt. For Saju, Vedic or wealth readings that use a reference city, the prompt includes that city’s name and the fact that its place is assumed, without its coordinates or time-zone identifier. The other person’s name shown for a compatibility reading, including a label from a saved profile, may be included. The finished reading is kept on your account so it opens again at no charge while access remains available; linked friend readings have the deletion conditions below. For recovery, the server also keeps a validated copy of the original inputs: the birth details used, optional identity information, relationship or work status, any question or context you entered, and the chosen language. A fingerprint identifies the request. Pending or failed generation attempts are also recorded with their inputs and status so a support request can be investigated and the original reading can be retried.
If you filled in the optional lines about yourself on a birth profile (your gender in your own words, how you are referred to, who you are drawn to), they travel with that request in the same way, so the reading can address you correctly instead of writing around it. They are never guessed at, never derived from a chart, and never used to decide what a reading says about you; leaving them blank simply leaves them out. They are stored with the profile you put them on: in this browser while you are signed out, and on your account once you sign in. You can change or delete that profile. For ordinary readings, changing or deleting that profile does not change an earlier result or remove its recovery input; you can request deletion through the contact below. For a detailed compatibility reading linked to a friend, editing, switching or deleting either shared profile erases the linked result and recovery input, and editing or switching turns detailed permission off until renewed consent.
When you contact support from a signed-in account, authorised support staff can review the account details, saved birth profiles, purchase and entitlement status, generation attempts and finished readings linked to that inquiry. An administrator can regenerate an eligible reading from its original saved inputs to resolve a delivery or generation problem. Recovery actions record the operator, reason and outcome. Raw prompts and birth details are not written to application logs.
Dodo Payments Privacy Policy ↗
Whop Privacy Policy (purchases before the switch) ↗
Standalone PDF purchases
When our Shopify PDF sales are enabled, you pay through Shopify checkout and its selected payment provider, separately from a Whop purchase. Our server receives authenticated order notifications and queries Shopify for the buyer email, order and item identifiers, SKU, report language, quantity, amounts, currency, payment/refund/cancellation state and processing times. We do not copy checkout names, phone numbers, billing or shipping addresses or card details into the PDF adapter. After payment verification, each purchased PDF has a private Lodestar order and input link. Birth details and questions are entered only on Lodestar; this integration does not send them, the finished text, PDF file or private access link to Shopify. After Resend accepts the completed PDF emails for the order, we return only fulfillment identifiers, quantities and completion state to Shopify. Email acceptance is not confirmation of inbox arrival. Shopify’s own store processing follows its DPA and privacy policy; the PDF input, result and retention rules below remain separate.
After premium Saju payment is verified, a private form opens automatically and requires birth date, birth time, country and processing consent; compatibility requires both people’s details, and Daewoon also requires its calculation basis. City is optional: a chosen city uses catalog coordinates and historical time-zone rules; otherwise the selected country’s named reference city is marked as assumed. We classify birth/calculation data separately from optional questions and names, validate required fields and types, normalize text and remove non-printing controls before calculation. Whop receives a random purchase reference and return URL with a checkout-verification key, never birth details or questions. The embedded Whop payment surface receives your payment information directly. The checkout reference on our existing US Google Cloud service contains no birth input, expires after 24 hours and is deleted by the cleanup worker. Submitted birth details are stored only in the verified private paid order; generation starts after all required details and consent are supplied. You can decline by leaving before saving. No member account or signup consent changes are required.
This processing applies only when standalone PDF sales are available and you choose to order one. It does not require a Lodestar account or add or spend account credits. To prepare the selected reading, we receive its type, any purchased individual Saju section and language, your date of birth and any time, place, coordinates or time-zone details needed for that reading, a question where requested, relationship or work context, the other person’s details and name for compatibility, and the consent record. Provide another person’s details only with their permission. Birth details and questions are entered through the private form after payment confirmation; its link is also sent by email. We receive the delivery email address from the verified marketplace purchase, not from a pre-payment form.
A non-premium Saju, Vedic or wealth PDF uses the same reference-city rules when its birth place is absent: Seoul for Korean, Tokyo for Japanese, and, for English only, the first listed city matching the device time zone read in this browser, or London. The device setting is not separately sent or stored. The chosen city’s name, coordinates, time zone and assumed-place flag are included in the private order’s input snapshot; no member profile is changed and a missing birth time stays missing. The snapshot is deleted after the finished text is saved, or by the order’s 90-day expiry cleanup if generation does not finish. The result and PDF retain the reference-city name and calculation limits. Only the reference-city name and assumption are included in the Vertex AI prompt, without coordinates or a time-zone identifier. The no-birth-time calculation limits described above also apply.
For ordinary marketplace checkout, you purchase the product directly on Gumroad, Whop, Payhip or Ko-fi. The verified product fixes the reading type and language for the private order. We do not send birth information, the question, finished text or private PDF access key to the store. You enter payment information directly on the store or its payment provider. We obtain the payment identifier, product, amount, currency, payment or refund status and buyer email through provider-server verification or an authenticated transaction report. After purchase confirmation, the buyer supplies the required details through the private link before the reading starts. The calculation and Google Vertex AI processing follow the existing United States flow described above; the result belongs to this private order, not a member profile.
The entered details are used for the requested purchase, calculation and delivery. The server discards the separate input snapshot after saving the finished text. The order input, paid reading text, PDF and delivery address expire 90 days after payment confirmation. Access stops at expiry, and the scheduled cleanup removes these private copies. Confirmed refunds revoke access and queue deletion. Minimum payment identifiers, product, amount, currency and processing times remain separate from birth details and text for payment reconciliation. These financial records are retained for five years from the initial payment or confirmed refund, then deleted through Firestore’s automatic expiry. Repeated callbacks do not restart that period. Processing events become eligible for automatic deletion after seven days. The private access key can stay in this browser tab’s session storage, and a PDF you download remains on your device until you delete it.
For intake and completion notices, Resend receives the marketplace-confirmed email address, a short notice and the private order link. Completion email also includes the purchased reading and calculated chart references in a PDF attachment. Raw birth input and questions are not sent as separate email fields, but the attachment contains the personal reading requested. The purchased product and any individual Saju section are fixed by the verified purchase; an individual section purchase receives that section’s text. Only staff with commerce access can see the order list: buyer email, product, payment and delivery status, amount, currency and processing times. The list does not show birth details or reading text. Lodestar blocks its GA4, Google Ads, X, Meta and TikTok measurement on PDF pages. Cloudflare delivery and independently operated marketplace pages remain subject to their own processing described in this policy or their notices.
You may decline this purchase and its necessary processing; ordinary public pages remain available. Without the required input and delivery processing, we cannot create and deliver this PDF. To request access, correction, deletion or withdrawal for a private order, email privacy@duckgustudio.com from the purchase address with the order or payment identifier. Do not send the private access key. We verify the purchase before acting and explain any retention required by law. Already delivered email and your downloaded copies cannot be recalled.
Shopify Privacy Policy ↗ · Shopify DPA ↗ · Gumroad Privacy Policy ↗ · Whop Privacy Policy ↗ · Payhip Privacy Policy ↗ · Ko-fi Privacy Policy ↗ · Resend DPA ↗ · Resend Privacy Policy ↗
Daangn PDF requests and automatic delivery
- You submit a Daangn form → the response is added to the business’s private Google Sheet
- The server validates birth details → chart calculation → Vertex AI writes the report
- Private PDF storage → Resend delivers the PDF to your submitted email
We receive the response time, campaign/ad identifiers, name, phone number, solar-calendar birth date, birth time, optional birth city and delivery email from Daangn. Daewoon also asks for its traditional male/female calculation basis. Compatibility also asks for the other adult’s birth date/time, optional city, relationship and confirmation of their permission. Name and phone remain in the response sheet; the PDF worker retains only the delivery email, necessary birth/relationship details and private processing state. An omitted city uses Seoul with an assumption notice. Invalid or unknown birth times are not guessed; a valid email receives a private correction link.
Daangn collects and transfers the form under its own notices. Google Sheets stores the response when it is submitted; Google’s processing locations follow the business account’s service terms and settings and are not verified as Korea-only. The existing US Google Cloud storage and Vertex AI processing, and US Resend email delivery, also apply here. Vertex receives calculated chart information, relationship context and the assumed-city notice, not the response-sheet name, phone or email. Resend receives the delivery email, private link and completed personal report attachment. Provider backups and logs follow provider terms; deleting our live records does not guarantee immediate deletion of every provider copy.
Form submission is the delivery request; it does not prove or require Daangn payment. Our response-sheet cells, email, input, reading and PDF expire 60 days after submission and are removed by the automated worker. This request creates no five-year payment record. Daangn’s original records, provider recovery copies and emails or PDFs you already downloaded follow their separate rules. Refuse this processing by not submitting the form. Contact privacy@duckgustudio.com with your request time and email for access, correction, deletion or a processing halt; already-delivered copies cannot be recalled.
Star gifts and private delivery records
The optional gift-link feature reserves eligible credits bought by the sender and records delivery to the signed-in recipient. The private record contains only service-account identifiers for sender and recipient, source sale and credit-lot identifiers, count, status, timestamps and a hash of the random gift token. It does not copy names, email addresses, birth information or reading content. The preview does not reveal the sender or recipient identity. Anyone with the link may be able to accept it, so send it only to the intended recipient. The random token is in the link fragment, rather than the page path or query, and is submitted to our server for preview or acceptance. Gift pages are configured to block Lodestar measurement and search indexing; this does not prevent a person from forwarding a link.
An unaccepted link lasts at most seven days and ends sooner at the earliest original expiry of the reserved credits. The sender can cancel it before acceptance; cancellation or expiry returns the reserved credits with their original validity; credits whose original expiry has passed remain expired. Received gifts cannot be sent again. Minimum gift transaction and delivery-relationship records are retained for five years from gift creation for delivery, purchaser refunds and dispute handling, including after account deletion where a received balance remains. At the end of that period the relationship information is removed; any received balance still follows its original credit-lot validity, including no expiry for App Store credits. This retention does not restore a deleted account or its profiles. Choosing not to create or accept a gift avoids this gift record. Contact privacy@duckgustudio.com for access, correction or deletion requests; retention required for these transaction records may limit immediate deletion.
Stardust and friend invites
Stardust counts paid readings opened with a star that was bought, including a bought star received as a gift, and adds one free star for every five, as set out in the Terms. To provide it we keep, in your account on US Google Cloud: for each counted reading, the reading and star-credit identifiers, when it was counted and whether a refund cancelled it; and a card with the counts, how many stars were made and when the last was made, and when the card was last checked. To tell bought stars from free ones, our server compares the purchase records we already hold (the sale claim and order status); no new payment information is collected. A star made from stardust is kept in your credit records like any other star, with a grant record numbered with your account identifier; after the account is purged only a marker that the grant was closed remains, as for other grants.
Friend invites are optional. When you create an invite link we store a random code with your account and sign-in identifiers. The code is in the link fragment; if the person opening it signs up from that page, it is also carried in the return address and, for Kakao, Naver or Instagram sign-in, in our sign-in state record that expires after 10 minutes. Opening the invite link while signed in, or signing in or up on its page, accepts the invite automatically. When an account created within the previous 24 hours accepts, we store the inviting member’s account identifier and the time in that account and add one to the inviting member’s count of people joined. When that member first opens a paid reading with a bought star, including a gifted one, after accepting, we mark that grain as the invite’s, add a grain record to the inviting member’s account, named by a hash of the invited member’s sign-in identifier, and add one to the inviting member’s count of grains from friends. The inviting member sees only these two numbers, never the invited member’s name, birth details or readings. With few invited friends, the numbers may still suggest that a friend opened a paid reading or had it refunded. To avoid this, sign up without an invite link.
These records are kept while the account exists. Deleting an account closes its invite link at once, and its remaining stardust records, including the inviter’s identifier it kept, are purged with the account 30 days later. A friend grain already recorded in an inviting member’s account stays there, with its hash name, after the invited member leaves; it holds no name or contact details. If the inviting member leaves, their account identifier stays in the invited account until that account is purged. Refunds cancel the related grains as described in the Terms. You can ask privacy@duckgustudio.com to inspect, correct or erase these records, or to stop this processing; erasing an invite connection may stop later grains for that invite.
Hamzzi raising
This section applies from 2026-09-30.
Except for the existing-account migration below, the first feed starts an account’s raising record, and opening a room before it creates none. We use these records to show growth, feeding, decorating and outfits, prevent duplicate actions and reverse experience from a refunded reading. They are stored privately in Google Cloud Firestore in the United States (Google LLC).
After raising starts, explicit water-change and room-tidy actions save only the latest Korean calendar date for each action in that profile’s Hamzzi record. The account keeps a cumulative count of days when feeding, water and tidying were all completed, plus the latest counted day, to unlock fixed outfits without duplicate awards. Only server-confirmed actions count; missed days do not erase progress. No extra experience, new currency, random reward or automatic AI generation is added. These care fields follow the same raising-processing halt and account-purge deletion rules.
At release, existing active accounts are migrated using verified past attendance, retained eligible paid readings and existing growth records. Their current saved profiles may have Hamzzi records before a first feed. We preserve existing experience, care, decor, outfits and shared items, and use the migration cutoff as the start time where no raising start was recorded; it is not a historical adoption time. Missing history is not estimated. Purchases alone, weekly records and past daily fortunes do not receive new rewards. Closed, deleted or purged accounts and raising records whose processing was stopped are excluded; deleted profiles are not recreated.
For each profile we store experience, the most recent fed date and fed-day count, up to three recent daily-fortune reward dates and up to two award times, placed item IDs and optional per-slot relative x/y positions and scale, one chosen outfit ID (or empty for the profile’s birth-year costume), and creation and update times. The stage is calculated from experience, rather than stored separately. No name, birth date, birth-year animal, Ilju character or element is copied into the Hamzzi record.
For the account we store the start time; items and outfits received, receiving profile, time and seen status; attendance and fortune day counts, last dates, current and best streaks; up to three recent fortune dates and up to two award times; fed-day count and last date; highest stage reached; reading count and product kinds; reconciliation times; and the last action time, request ID, request-content hash and hourly action count. A rewarded reading has a separate record with its reading ID, product, experience, credit source, receiving profile, time and any reversal time. Raising creates no new per-day attendance or fortune documents; migration adds the receiving profile, migration version and cutoff to retained historical growth events. The independently saved fortune texts are described under AI.
Saved decoration values are relative positions and sizes inside the room, not your physical location. The room holds up to six placed items. To compare repeated actions, the account summary also keeps up to 120 recent request IDs with a content hash and time. Those entries are used for a 24-hour retry comparison and expired entries are removed on the next raising-record write; an inactive account is not physically cleared after 24 hours. The last-request fields remain separately. Request bodies, names and birth details are not copied into this receipt list. These records follow the raising-processing halt and account-purge rules below.
To resume migration and prevent duplicate awards, each migrated account also keeps the migration version and cutoff, processing phase and last source-record ID, prior raising start and attendance/reading counts, processed counts and product kinds, last attendance date and streak, result and missing/excluded-record totals, and inventory-check, start, update and completion times. These records are deleted on a raising-processing halt or account purge. A separate private operational record temporarily keeps up to five account identifiers and a processing lease, with version, cutoff, mode, status, counts and update time. When the run completes, account references and the lease are cleared; version, cutoff, mode, status, counts and update time remain. It contains no names, birth details or reading text, and account identifiers are not written to migration logs.
When signed in, the room and other-Hamzzi list calculate characters on this device from profiles already loaded, without an extra tap. Character values are not sent as API or Analytics fields and are not stored on the server. Costume and portrait files are loaded from this site: their file addresses can identify a character and remain in Cloudflare CDN or hosting request logs and browser cache. While signed out the room shows a fixed sample. The room requests its state with account authentication, including the primary Hamzzi’s experience, decor positions and outfit, other-Hamzzi summaries, the account drawer, fed-day count and reminder state. The home page does not automatically request this room state. While signed out, no member room state is requested.
Deleting a profile deletes its Hamzzi and removes that profile’s attribution from the shared drawer and reward records. Other raising records remain until service-account purge 30 days after account closure. Ask privacy@duckgustudio.com to stop raising processing: staff delete the raising documents, reminder record and subscriptions, keeping only the halt flag and first request time until account purge so activity cannot recreate the records. Signing out avoids on-device member-character calculation and member room-state requests, but does not delete existing records.
Short AI lines when you touch Hamzzi
From 2026-10-01, a signed-in member’s first touch, or a touch after the five saved lines run out, asks Google Vertex AI in the United States multi-region to write five Korean lines of at most 40 characters each. Only general hamster topics, a Korean-time part of day and an independent random variation are sent to the model. Account/profile identifiers, names, birth information, diaries, reading text and birth-derived animal or element are excluded. Other touches use the device-memory pool. Opening the room does not generate lines; there is no free text, conversation history, fortune generation or experience reward. Existing AI limits are shared and prepared lines are used if generation is unavailable. From 2026-10-07, this uses gemini-3.8-flash, with gemini-3.7-flash as a fallback.
For safe retries without generating twice, a separate private US Firestore record stores the account and profile identifiers, hashed request fingerprint, processing status, processing lease, timestamps and five generated lines. It expires after 24 hours and is removed by existing expired-record database cleanup, or during service-account purge. Raw birth inputs, diaries and reading text are not copied into it. Deleting the profile, stopping raising processing or closing the account blocks use of cached and in-progress results, but the operational retry record may remain until its expiry and cleanup; this is not immediate erasure. The device pool is temporary memory, not a synchronized saved conversation. To avoid a new AI transfer, do not touch Hamzzi; other raising actions remain available. The model-training and report/review guidance in the AI section also applies to these lines; our retry period does not describe Google’s retention.
Optional Hamzzi web reminders
This section applies from 2026-09-30.
Web reminders are separate from the iOS app’s local daily reminder below. They are offered only in a supported browser when enabled, after raising starts. Collection/use and overseas transfer have two separate unchecked optional choices. A permission prompt appears only when you choose to receive reminders. Refusal leaves raising and all other services available.
We store the account identifier, push endpoint and host, encryption keys, selected send hour, collection/use and transfer consent times, notice version, mode, two-year expiry and withdrawal time; last sent day, unanswered count and cadence; device creation, last seen, check and send times and failure count. Designated test accounts also have their test-send day, last time and daily count stored. These records deliver reminders, apply your choices, avoid duplicates and remove stale or unusable subscriptions.
The server sends end-to-end encrypted notification content to the push service chosen by your browser. Allowed endpoint hosts are fcm.googleapis.com, web.push.apple.com, updates.push.services.mozilla.com and subdomains of notify.windows.com. The endpoint reveals which service is used. The service receives its endpoint and encrypted message and the network request’s technical information. Provider legal names, processing countries and contact routes require verification before public sending; this draft does not infer them from the hostname. Turning off reminders does not erase information the provider already received.
A reminder is sent only when the primary Hamzzi has not been fed that day, at the selected Korean time from 08:00 to 20:00 (default 19:00), at most once per day. Message expiry is limited to end delivery before 21:00; no sending occurs from 21:00 to 08:00. Repeated non-response changes frequency and can pause reminders. The notice and consent name say whether advertising mode is used; advertising mode labels messages accordingly. This page does not decide the legal classification. A mode or notice-version change requires fresh consent, and no reminder is sent during reconfirmation.
Consent lasts two years; we ask again during the final 30 days and stop sending until renewed. Turn off on the reminder screen, through My page’s reminder link, or through the notification’s off action where the browser supports it. Turning off or closing the account immediately deletes server subscriptions. The account-purge cleanup also removes subscriptions unused for 90 days or whose consent has expired, independently of sending switches. It is designed for the hourly account-purge job; processing proceeds in bounded batches. Consent and withdrawal evidence remains until account purge 30 days after closure; a raising-processing halt also deletes that reminder record.
iOS device and App Store flows
When you use an iOS version with in-app purchases, Apple handles the App Store payment. To assign credits to the correct service account and prevent duplicate or mismatched grants, our server creates a random account UUID and the app sends it to Apple as an appAccountToken. It is an account identifier, not an advertising or hardware identifier. Our server verifies the signed transaction and keeps its transaction and product identifiers, environment, amount, currency, purchase/refund times and credit grant/use/reversal records with the service account. We do not receive your App Store payment-card or bank details or add web advertising-click records to Apple orders. The account UUID is removed with the service account after the 30-day withdrawal period. Minimum transaction evidence follows the separate five-year retention below; transaction/order tombstones used to prevent a deleted purchase from being granted again are distinct from a usable account.
Apple processes its own store account and payment information under its App Store privacy notice. Our service-account deletion and retention periods do not delete or set the retention of Apple’s separate records. You can decline a new App Store transfer by not making an in-app purchase; purchasing requires the account token and transaction verification. App Store & Privacy ↗
If you choose Save offline on an opened reading, the iOS app keeps its identifier, title, text, service URL and save time in an account-separated device library. Files use iOS file protection and are excluded from backup. This feature does not upload a new device copy; the original account reading remains on our server. Device copies remain until you remove them individually or together, change accounts, sign out or delete your service account. Removing a local copy does not remove the server original. Sharing opens the iOS share sheet only at your request; the recipient or app you select receives the content or link you share.
Before using the iOS daily-fortune feature, you must explicitly agree to its device-display notice. Agreement enables the Home Screen preview. When you open a daily fortune already saved for the selected profile and today’s local date, the app stores a separate snapshot in its protected App Group container shared with its widget extension. The snapshot contains an opaque profile identifier, local date, language, a headline of up to 120 characters and the first 160 characters of the summary. It has complete iOS file protection and is excluded from backup; this does not upload another copy to our server. Small and medium Home Screen widgets may show those personal words to anyone who can see your screen. There is no Lock Screen widget. The widget stops showing the saved text after the local date changes, but the file is not erased at midnight; a later snapshot replaces it. Turning the preview off, signing out, changing accounts, or deleting all device copies removes it. When you edit, delete or switch profiles in the iOS app, it requests removal of the device snapshot. If that cleanup fails, an earlier copy may remain; turn the preview off or delete all device copies to remove it. Removing the device snapshot does not erase the original fortune saved to your service account.
After that agreement, opening today’s saved result automatically starts or updates a Live Activity when the device supports it and iOS permits it. There is no separate start button below the result. The app does not override iOS permission or support limits. Its on-device attributes include a SHA-256 hash of the service member identifier, selected profile identifier, local date and language so the app can check the account and date before opening the result; the raw member identifier is not copied to the activity or App Group snapshot. The expanded Dynamic Island can show its headline; compact Island and Lock Screen views show a general prompt without the personal words. The personal headline stops being shown by the earlier of local midnight or eight hours after the activity starts; iOS controls when the stale activity is removed. Turning the preview off, signing out, changing accounts, or deleting all device copies ends the activity. The app also requests its end when you edit, delete or switch profiles; if that fails, use the device-copy controls to end it. The widget and Live Activity do not create a new AI fortune or buy credits in the background; ordinary readings and the web service remain available without agreeing to the iOS daily-fortune display feature.
This required agreement is limited to the iOS daily-fortune display feature. Nothing is checked or accepted for you. The app keeps the accepted notice version on this device for the current account. Turning off the preview in App settings withdraws the agreement, removes the widget copy and ends its Live Activity; signing out, changing accounts or deleting all device copies also clears the agreement. You must agree again before using today’s fortune in the app. This does not grant advertising, location, notification or other permissions. Adding a Home Screen widget and allowing Live Activities are separately controlled by you and iOS.
Daily reminders are optional local notifications. The enabled choice, hour, minute and app language stay on the device; this feature does not register an APNs push token with our server. Enabling a reminder asks for notification permission. You can turn it off in App settings or iOS notification settings. Signing out or deleting the service account disables the app reminder. A reminder does not generate a reading or purchase credits automatically.
The iOS integration blocks Lodestar’s GA4, Google Ads, X, Meta and TikTok measurement in its embedded service and native sign-in handoff/return pages. This does not verify that Cloudflare CDN or automatically injected RUM processing stops; see the Cloudflare section. It does not change your ordinary web-account measurement preferences. Apple’s store services and the sign-in provider you choose have their own processing notices; the app’s local controls do not erase data already received by those providers. The ordinary website measurement and withdrawal choices above continue to apply when you use the website separately.
Android device and Google Play flows
When you buy through an Android version with Google Play Billing, Google handles its store account and payment. Our server creates a random 64-character purchase-account identifier, which the app sends to Google as obfuscatedAccountId to link the purchase to the correct service account. It is not an advertising or hardware identifier. The app sends the purchase token and product identifier to our server; the server queries Google’s purchase and order APIs, checks the account and payment state, then records the token’s SHA-256 hash as the transaction identifier, Google order and product identifiers, environment, amount, currency, purchase/refund times and credit grant/use/reversal records. The raw token and full Google payload are not stored in our order or notification ledger. We do not receive your card or bank details, copy a new buyer email into the Play order, or attach web advertising-click information to it.
The random purchase-account identifier stays with your service account and is removed when it is purged 30 days after withdrawal. Minimum transaction evidence follows the separate five-year period below; duplicate-grant prevention tombstones are separate from an active account. Choosing not to make an in-app purchase avoids the new purchase transfer. Google’s independent store-account and payment records follow its own terms and privacy policy; deleting your Lodestar account does not delete Google’s records. The applicable Google contracting entity, processing countries and independent retention depend on the store service and are not fixed by our US Cloud Run/Firestore location. Google Privacy Policy ↗
Android device copies and reminders are optional. Saving an opened reading offline keeps its identifier, title, text, service URL and save time in the device library for that signed-in account; this does not upload a new copy. Use App settings and device library from My page to manage copies, widget display and reminder settings. Removing a device copy leaves the server original. Signing out, changing accounts or deleting your service account requests device cleanup; if a bridge or device cleanup fails, use the device library controls or Android’s app-data deletion. Sharing sends the content or link to the recipient or app you choose.
The Android daily-fortune widget is off by default and does not require consent to use today’s fortune. If you choose to show saved fortune text, opening a saved result for the selected profile and local today passes the account/profile identifiers, local date, language, headline and summary to the device widget. The Home Screen can then show personal fortune text to anyone looking at it. It stops showing that text after the local date changes; hiding the text or deleting device copies is separate from deleting the server fortune. This feature does not generate a fortune or start an iOS Live Activity. A daily reminder is an optional local notification with device-stored enabled/time/language settings; it does not register a server push token or generate a reading. Stop it in app settings or Android notification settings.
The Android integration blocks Lodestar’s GA4, Google Ads, X, Meta and TikTok in its embedded service and native sign-in handoff/return pages. This does not confirm that Cloudflare CDN or injected RUM collection stops; those processing and refusal details remain in the Cloudflare section. Separate browser visits and external sign-in/store services follow their corresponding notices. For account access, correction, deletion or processing-halt requests, use My page or privacy@duckgustudio.com. Account deletion is also available on the website after signing in, so it does not require reinstalling the Android app.
Address change and browser data
The service uses hamzzi.com while lodestarastro.com and blog.lodestarastro.com remain within this policy. Your account, saved profiles, readings and Stars stay in the same service account. If automatic sign-in handoff fails, sign in with the same method you used before. Browser storage at the two addresses is separate.
When automatic handoff is available, our server verifies any existing sign-in before carrying the same account. Private US Google Cloud stores limited pixel-room progress and decoration, names of refused measurement providers, and one-time proof, state and expiry values. For verified members only, the record also includes the account identifier and permitted profile selectors; guest records have no account identifier. The random code is stored only as a hash. It can be used once within 60 seconds; successful exchange deletes the temporary record. An unused record becomes unusable after expiry, while physical database TTL deletion, once configured, can occur later.
This handoff excludes names, email addresses, birth details, profiles themselves, questions, conversations, reading text and advertising click IDs. Measurement refusals only add to refusals already saved at the new address; the handoff never turns measurement on. If the previous browser settings cannot be read safely, measurement stays off. Existing account data continues under the retention and rights rules in this policy.
Moving the address does not erase the old browser copy. In your browser settings, open site data or cookies and stored data, select lodestarastro.com and delete its data. This removes that browser’s old sign-in and local progress, notes, guest profiles and settings; it does not delete the account or server records. Clear hamzzi.com separately to remove the new local copy. Close old tabs to end their temporary tab storage. Use My page or privacy@duckgustudio.com for account-record deletion. You can stop automatic handoff or continue with measurement off; account sign-in may need to be repeated.
How long information is kept
Instagram comment and DM response records are separate from membership data. When activated, they expire 30 days after their last handling; an expired session cannot send another response. Actual database TTL deletion follows expiry and may be delayed. The activation process must first verify the deletion setting. See Instagram replies for the separate deletion-request route and Meta’s own copies.
The browser uses sessionStorage keys beginning lodestar.growth-notice. for account, date and experience/item notices in the same tab, and localStorage lodestar:reading-growth-announced for at most 20 reading request IDs so a notice is not repeated. These are kept until a notice is cleared, the tab session ends (sessionStorage), or you sign out or clear site data (localStorage). They do not contain birth-derived character values. Optional web reminders register /hamzzi-sw.js with scope /ko/hamzzi/ and a browser push subscription; this worker does not cache pages or intercept their requests. Turning off removes the device subscription where possible; a worker registration may remain until browser site data is cleared.
Raising retention and processing halt · Reminder deletion and consent evidence
Premium checkout references contain no birth input, expire after 24 hours and are deleted by the cleanup worker. A standalone PDF order is separate from membership deletion: when this purchase is available and chosen, its input, private paid result and delivery address expire 90 days after payment confirmation. Refunds and privacy requests have the separate handling described in the PDF section. PDF details
The Ilju continuation data is valid for 30 minutes and is removed the next time the test reads it after expiry. Closing the tab ends its storage session. Once you save the birth date to your profile, the temporary birth date is removed. The tab retains the character codes, the share link’s campaign name, creative name and share step number, and the profile, account and validity information needed to reopen the correct result. The saved profile follows the account retention and deletion rules below.
The Work Hamzzi test’s continuation data follows the same rules and is kept separately from the Ilju test’s: it is valid for 30 minutes, is removed the next time the test reads it after expiry, ends when the tab closes, and loses the temporary birth date once you save it to your profile.
Kakao and Naver connection tokens are replaced at each sign-in and deleted when the app is disconnected or the membership is purged. Temporary AI chat and Hamzzi-line retry records expire after 24 hours; expired Hamzzi-line records are removed by existing expired-record database cleanup. Saved web profiles, profile-bound daily fortunes, finished readings, their original inputs, generation attempts, support recovery records and entitlements are separate server records; the chat retry period does not apply to them. Clearing browser data or deleting a sign-in identity does not itself erase these records. Delete your website membership from My page → Delete account. Access and shared links end immediately, and the saved website information cannot be restored. Service information is held privately for 30 days, then automatically purged, except for the separate statutory records described below. Signing in again creates a new website membership without the deleted information or purchases. This same service-account deletion also applies when that account is used through the Lodestar iOS client; local device copies have the separate cleanup described above. Operational and security logs with no account link are normally kept for 90 days. Google Analytics event data is kept for no longer than 14 months. X, Meta and TikTok ad click identifiers are usable for no more than 30 days in the browser and in their private order records; the Meta and TikTok order records’ checkout User-Agent follows the same period. Each order copy is then automatically eligible for database deletion and is deleted earlier after successful reporting. Notes saved in earlier versions, unsent chat drafts and conversation history stay in your browser until you clear them.
Map invitation codes, selected-profile and friend-specific permission settings, referral attribution and connection records are service information. A member can edit or switch the map profile, remove one connection or withdraw detailed-reading permission for that friend; deleting the selected profile also stops its link preview. These actions erase the affected linked detailed results and recovery inputs from the other account. Editing or switching the map profile turns off detailed permission across that member’s connections until separately renewed. Linked detailed results cannot be published with the reading share-link feature. Account deletion immediately disables its map link and removes its connections from other accounts. Remaining account-bound settings and records are privately held for 30 days and then purged with that account. The friend map creates no referral reward or payment ledger; stardust records are described separately.
Stardust grain and card records and an accepted invite connection are kept with the account and purged 30 days after deletion. A friend grain in an inviting member’s account is kept with that member’s account. No stardust grain or card record is kept after an account is purged; a closed-grant marker remains for stars made from stardust, as for other grants.
General support tickets, including those from visitors without accounts, are deleted no later than three years after their last activity. Account-linked tickets are deleted with service data after withdrawal unless statutory retention applies. For completed sales, we separate the minimum contract, withdrawal, payment and supply evidence from service data for five years. If an account has a completed or refunded purchase, its inquiries are also separately retained for up to three years from the last handling, regardless of the inquiry category, so a payment complaint is not lost under another category. Other account inquiries are not included in that archive. These copies hold order, payment or inquiry evidence rather than separate profile or reading records; an inquiry may contain information you chose to write in it. They are deleted when the periods end.
For an App Store or Google Play order, the minimum transaction copy is kept separately for five years from the latest recorded order creation, payment or refund time. It excludes the service account UID, random purchase-account identifier, reading inputs and advertising context. Where a paid customer’s support record is retained as complaint/dispute evidence, its separate period is three years from closure, or the latest update/creation if no closure is recorded. These statutory copies are subject to expiry deletion; they do not restore a deleted service account or its readings.
Transfers of personal data abroad
When address handoff is available, the temporary proof and limited settings described under Address change travel over the network to the same Google LLC sign-in and private US Firestore services at the handoff request. They are used only to carry sign-in, room settings and measurement refusals, with one use within 60 seconds and possible delayed TTL deletion as explained there. Google’s contact and existing service-processing terms are below; stopping handoff avoids that new temporary record.
Optional browser push uses the endpoint-specific services and separate transfer choice described under web reminders. Provider legal names, countries and contacts remain a required verification before public sending.
These transfers occur over the network when the relevant feature is used; page delivery can occur before signup. There is no separate bulk or physical transfer. We request separate agreement at signup for the Google Cloud transfer needed to create an account. The five measurement services (GA4, Google Ads, X, Meta and TikTok) below automatically receive the described events during visits and qualifying actions, unless browser privacy signals or a saved provider refusal block them. Measurement can begin before signup.
Cloudflare: CDN delivery, protection and Web Analytics/RUM
Technical request and page-performance information is processed automatically during page use. The applicable contract entity, processing countries, overseas-transfer basis and complete CDN-log retention are not yet confirmed. The RUM data, supplier retention explanation and refusal limitations are disclosed separately above. Cloudflare details
Google Play purchases have a separate store flow, available in any page language when that Android feature is enabled. At purchase, the app sends the random purchase-account identifier to Google; the server sends the purchase token to Google’s authenticated APIs for verification. Store-account and payment details are handled by Google under its own notice. This store flow’s applicable contract entity, processing countries, independent retention and overseas-transfer basis require separate store/contract confirmation; they must not be inferred from the Google Cloud hosting row. Items, purpose, our retention and how to avoid a new transfer are in the Android section. Android and Google Play details
When standalone PDF sales are available and chosen, order input, the buyer email, the finished text and private file are also processed on the existing Google Cloud service. Premium checkout references contain no birth input and expire after 24 hours; paid order input and private results expire 90 days after payment confirmation. Cleanup and rights are described in the separate PDF section. The Resend and PDF-marketplace rows apply only to that purchase, including for Korean readers.
Google LLC: Hosting, sign-in and database
- What is transferred
- Account identifier; sign-in provider and its identifier for you; the name and email address the provider supplies, where there is one; signup and optional email choices with their timestamps; saved birth profiles (label, date, time, place, optional details); friend invitation code, selected profile and detailed-reading permission, referral and connection records; stardust grain and card records, stardust invite code and invite connection; finished readings, their original inputs and profile-bound daily fortunes; order and entitlement records; minimum private gift-delivery records; support messages; and technical request information such as IP address and browser details.
- Country
- United States (Cloud Run and Firestore, us-central1)
- Purpose
- Serving the site, sign-in, storage of accounts and friend connections, readings and security.
- Held for
- Service information: until membership deletion, then 30 days privately. General support tickets: no more than three years after their last activity, or deleted with an account unless statutory retention applies. Separate statutory order evidence: five years; inquiries from accounts with a completed or refunded purchase: up to three years from their last handling. Minimum gift transaction and delivery-relationship records: five years from gift creation, with the account-deletion exceptions explained above. Operational and security logs without an account link: normally 90 days.
- Contact
- googlekrsupport@google.com
Google LLC (Vertex AI): AI readings, daily fortunes, chat and Hamzzi lines
- What is transferred
- For readings and chat: calculated placements, the current date, a calculated age where it applies, the chosen language, and what you typed: your question, relationship or work context, optional identity wording, and up to the last eight chat messages. A compatibility reading may include the other person’s name. For daily fortunes requested by a signed-in member: their local date, language, Sun sign, birth-year animal, Sun-sign segment and a writing variation calculated from the account, profile and date. Structured birth dates, user-supplied birth-place names, coordinates, profile labels and account identifiers are not sent. When a Saju, Vedic or wealth reading uses a reference city, its name and the fact that the place is assumed are sent; the reference coordinates and time-zone identifier are not. For Hamzzi touch lines, only general hamster topics, a Korean-time part of day and an independent random writing variation are sent. No account or profile identifier, name, birth information, diary, reading text or birth-derived animal or element is sent for those lines.
- Country
- United States (Vertex AI US multi-region)
- Purpose
- Generating AI reading text, daily fortunes, chat replies and short Hamzzi lines.
- Held for
- Sent at the moment the request is handled, under Google Cloud terms. Our own 24-hour retry record is described under retention above.
- Contact
- googlekrsupport@google.com
Google LLC (Firestore: Hamzzi): Private raising and reminder records
- What is transferred
- The raising, saved decor positions and sizes, outfit choice, duplicate-action, reward, optional reminder and temporary AI-line retry records listed in the Hamzzi sections.
- Country
- United States (Firestore, us-central1)
- When and how
- During the release migration of existing active accounts, or after first feeding through actions and account bootstrap; reminders only after their separate choices, and AI-line retry records only on a generation-requesting touch. Sent by this site’s server over the network.
- Purpose
- Showing care and outfits, preventing duplicate rewards, delivering chosen reminders and recovering AI-line requests without generating twice.
- Held for
- Per-profile Hamzzi until profile deletion; other records until account purge after 30 days; subscriptions and processing halts have the earlier deletion rules below. AI-line retry records expire after 24 hours and are removed by existing expired-record database cleanup.
- Contact
- googlekrsupport@google.com
Google LLC (Firestore: Instagram replies): Private comment and DM response records, when activated
- What is transferred
- Comment, media and message IDs; the platform sender or messaging recipient ID; processing times, response status and expiry. Raw comment or DM text and full profiles are not saved in these records.
- Country
- United States (private Firestore database, us-central1)
- When and how
- When a signed Instagram event is handled for a post registered to our own @lodestar_astro reply feature; transmitted by our server over the network.
- Purpose
- Responding to comments, linking a requested DM reply to its response and preventing duplicate sends. Website accounts and AI generation are not used for this response.
- Held for
- Expires 30 days after the last handling. Expired sessions cannot send another response. Physical deletion uses the database TTL policy after it is configured and can be delayed after expiry.
- Contact
- googlekrsupport@google.com
Whop Inc.: website traffic: Public page visits and traffic sources
- What is transferred
- Public page path, allowlisted campaign labels, a referring public page or external origin, event ID and time, an unrelated random browser visitor ID, browser User-Agent and language. Whop receives the connecting IP address through the network. No service account ID, name, email, phone, birth information, private text, private URL token or personalized page title is sent.
- Country
- United States; Whop also describes worldwide service-provider processing. Exact storage regions are unconfirmed.
- When and how
- On a permitted page visit, the browser sends a page event to Whop over HTTPS. Measurement starts only after existing account choices have been checked.
- Purpose
- Counting page visits and browser visitors and identifying traffic sources in the Whop dashboard. This integration sends no purchase or identity events.
- Held for
- The local visitor ID expires after 30 days and is removed when measurement is refused. Whop describes purpose-based retention without a fixed traffic-event deletion period; its specific retention and overseas-transfer basis remain unconfirmed.
- Contact
- support@whop.com · 300 Kent Ave #401, Brooklyn, New York 11249
Dodo Payments Inc.: Checkout and payment
- What is transferred
- The random order reference and the package’s product identifier. If you have paid through Dodo Payments before, also the customer identifier Dodo Payments issued at that earlier purchase, so that it keeps one customer record for you. Not your name and not your email address. Your name, email address, billing address and card details are entered by you on Dodo Payments’ own checkout and never pass through this site.
- Country
- United States
- When and how
- When you press buy, this site’s server sends these items to Dodo Payments over the network to open your checkout.
- Purpose
- Providing the checkout, taking payment and issuing refunds, sending the receipt, and handling tax as merchant of record.
- Held for
- Under Dodo Payments’ own privacy policy.
- Contact
- support@dodopayments.com
Whop Inc.: Purchases made before the switch to Dodo Payments
- What is transferred
- For a purchase made before English and Japanese checkout moved to Dodo Payments: the random order reference and the package identifier, sent when you pressed buy, not your name and not your email address. Your payment and billing details were entered by you in Whop’s own checkout and never passed through this site. New purchases are charged by Dodo Payments.
- Country
- United States (New York)
- Purpose
- Refunds and records of the payments Whop took before the switch, including their receipts and tax as merchant of record.
- Held for
- Under Whop’s own privacy policy.
- Contact
- support@whop.com
Plus Five Five, Inc. (Resend): PDF delivery, only when ordered
- What is transferred
- Buyer email, delivery notice and private order link; completion email also includes the purchased reading and calculated chart references as a PDF attachment. Raw birth inputs and questions are not sent as separate email fields.
- Country
- United States
- When and how
- When the requested PDF needs intake or completion delivery, our server sends it to Resend over HTTPS.
- Purpose
- Delivery of the requested PDF intake email and completed PDF attachment.
- Held for
- On our current Free plan, Resend retains email and log data for 30 days. Remaining customer data is deleted within 90 days after our Resend account terminates. These periods are separate from the order’s 90-day private-result expiry.
- Contact
- privacy@resend.com
Shopify (PDF): PDF storefront and order processing
- What is transferred
- You enter checkout information directly on Shopify or the selected payment provider. Our adapter reads buyer email, order and purchased-item identifiers, SKU, language, quantity, amounts, currency, payment/refund/cancellation state and processing times. We return fulfillment identifiers and delivery-completion state, without birth input, questions, reading text, PDF files or private access links.
- Country
- The store’s Shopify customer-data hosting location is the United States. Shopify’s DPA also describes processing in Singapore, Canada and other countries where its affiliates or subprocessors operate. This applies to Shopify checkout data; birth input stays in Lodestar’s private intake.
- When and how
- During Shopify checkout and order processing; authenticated HTTPS notifications and API queries verify purchases and update fulfillment after PDF email acceptance.
- Purpose
- Operating the store, verifying purchases, handling refunds and recording fulfillment.
- Held for
- Shopify processes store data for the service relationship and the applicable legal, dispute, security and backup retention periods under its DPA and privacy policy. Lodestar’s 90-day private-result expiry does not automatically delete Shopify’s order record.
- Contact
- https://privacy.shopify.com/
Gumroad, Inc. / Whop, Inc. (PDF): The PDF marketplace you choose
- What is transferred
- Payment and product identifiers used for server verification; premium Whop checkout also receives a random purchase reference and return URL with a payment-verification key. Birth details and questions are excluded. You supply payment information directly to the selected marketplace.
- Country
- United States; the marketplace’s own notice also describes its other processing locations.
- When and how
- For premium Whop checkout, our server creates the payment configuration before purchase. After the purchase, our server receives a transaction report and verifies the payment and product through the marketplace API over HTTPS.
- Purpose
- Payment verification, refunds and order matching.
- Held for
- Under the selected marketplace’s own privacy policy; no fixed supplier period has been verified for this integration.
- Contact
- Gumroad: support@gumroad.com / Whop: support@whop.com
Payhip Limited (PDF): PDF store, only when chosen
- What is transferred
- Selected store product; you supply the checkout details directly to Payhip or its payment provider.
- Country
- United Kingdom company. Its policy says EU servers and possible transfers outside the EEA; the exact countries for this integration are not confirmed.
- When and how
- When you choose the Payhip checkout and its authenticated transaction report is received.
- Purpose
- Checkout and purchase verification for the selected PDF.
- Held for
- Payhip’s policy lists ten years for digital-product transaction details for EU VAT. The scope applicable to this integration must be confirmed.
- Contact
- privacy@payhip.com
Ko-fi Labs Limited (PDF): PDF shop, only when chosen
- What is transferred
- Selected shop product; you supply the checkout details directly to Ko-fi or its payment provider.
- Country
- United Kingdom company. Its policy describes transfers outside the UK and EEA but does not list the exact processing countries for this integration.
- When and how
- When you choose the Ko-fi shop checkout and its authenticated transaction report is received.
- Purpose
- Checkout and purchase verification for the selected PDF.
- Held for
- Its policy bases retention on service and legal needs; the period applicable to this creator purchase has not been confirmed.
- Contact
- https://help.ko-fi.com/hc/en-us/requests/new
Google LLC (Google Analytics 4): Site analytics
- What is transferred
- Page URL and referrer, IP address and browser information sent with the request, Google Analytics cookie and client/session identifiers, visit and selected service-event names and parameters (language, product, sign-in method or a fixed error code). In the Ilju and Work Hamzzi tests, events also carry how the page was reached (directly or through a shared link), how a result was shared or saved, whether a result came back after sign-in, and which reading was chosen next. An IljuTI result sends only which reading was chosen next, not the day pillar or MBTI. The Ilju test also sends one of the five elements calculated from the birth date (not when calculated from a saved profile), result-picture type and format, share step number, Lodestar campaign and creative names, how the result was obtained (a typed birth date, a saved profile, or a reply confirmed as one’s own), in-app browser type, profile save type and whether a sign-up continued from the test; the Work Hamzzi test does not send an element. On the website home page, a card tap also sends which card it was, the section it sat in and its position, and whether the today’s fortune card was showing the member’s own content. A tap on the start link in the English and Japanese home page introduction is sent as the Ilju test card in the introduction section, without a position. Birth dates, birth times and places, the 60 test characters, questions and reading text are not sent as event parameters, and the character codes in Ilju and Work Hamzzi links are removed from the page address sent to Analytics. If signed in, a separate pseudonymous analytics user ID may be set. Confirmed purchase, refund and first-reading events can include an opaque transaction ID, product, amount and currency.
- Country
- United States
- When and how
- During visits and actions, the Google tag automatically sends browser events over the network; our server sends a confirmed conversion through the Measurement Protocol after the event is settled. Browser privacy signals and saved Google Analytics refusals stop this measurement.
- Purpose
- Understanding site use and measuring completed purchases and readings.
- Held for
- Our Google Analytics event-data setting is no longer than 14 months. Google’s handling of its copy follows its privacy information.
- Contact
- googlekrsupport@google.com
Google LLC (Google Ads): Ad-conversion measurement
- What is transferred
- Page URL and referrer, IP address and browser information sent with the Google tag request, Google Ads click and cookie identifiers where present; for a confirmed purchase, an opaque hashed transaction ID, amount and currency. We do not send birth details, questions or reading text.
- Country
- United States
- When and how
- The Google tag automatically sends data from the browser over the network; an authenticated purchase receipt can trigger a conversion event after payment is confirmed. Browser privacy signals and saved Google Ads refusals stop this measurement.
- Purpose
- Measuring whether an ad led to a completed purchase.
- Held for
- Google’s retention follows its advertising privacy information. Browser identifiers can be removed by clearing browser data; use Do Not Track or Global Privacy Control to stop new measurement.
- Contact
- googlekrsupport@google.com
X Asia Pacific Internet Pte. Ltd. (for X Internet Unlimited Company): X purchase attribution
- What is transferred
- X ad click ID (twclid), purchase time, opaque order reference, product and quantity, payment amount and currency, and the product page URL. We do not send your name, email, birth details, questions or reading text.
- Country
- Singapore (processor); Ireland (X Internet Unlimited Company)
- When and how
- When you arrive with an X ad click ID, we automatically store that ID in this browser. Once a matching purchase is paid and confirmed, our server sends the event through the X Conversions API over the network. Browser privacy signals and saved X refusals stop this measurement.
- Purpose
- Attributing a confirmed purchase to an X advertisement.
- Held for
- Our browser and private order copies of the click ID are used for no more than 30 days and deleted earlier after successful reporting. X handles the event under its privacy terms.
- Contact
- X Asia Pacific Internet Pte. Ltd., Legal Department, 138 Market Street, CapitaGreen #21-04, Singapore 048946
Meta Platforms Inc.: Meta purchase attribution
- What is transferred
- Meta ad click ID (fbclid), checkout browser User-Agent, purchase time, opaque order reference, product and quantity, amount and currency, and product page URL. We do not send your name, email, birth details, questions or reading text.
- Country
- United States
- When and how
- When you arrive with a Meta ad click ID, we automatically store it in this browser. Once a matching purchase is paid and confirmed, our server sends the event through Meta Conversions API over the network. Browser privacy signals and saved Meta refusals stop this measurement. No Meta Pixel is loaded.
- Purpose
- Attributing a confirmed purchase to a Meta advertisement.
- Held for
- Our browser and private order copies of the click ID and order User-Agent are used for no more than 30 days and deleted earlier after successful reporting. Meta handles the event under its privacy terms.
- Contact
- Meta Platforms Inc., 1 Meta Way, Menlo Park, CA 94025, United States
TikTok Pte. Ltd.: TikTok signup and purchase attribution
- What is transferred
- TikTok ad click ID (ttclid), browser User-Agent, event time, event ID, page URL; for a confirmed purchase, opaque order reference, product and quantity, amount and currency. We do not send your name, email, birth details, questions or reading text.
- Country
- Singapore
- When and how
- When you arrive with a TikTok ad click ID, we automatically store it in this browser. On qualifying signup or after a matching purchase is paid and confirmed, our server sends the event through TikTok Events API over the network. Browser privacy signals and saved TikTok refusals stop this measurement. No TikTok Pixel is loaded.
- Purpose
- Attributing a qualifying signup or confirmed purchase to a TikTok advertisement.
- Held for
- Our browser and private order copies of the click ID and order User-Agent are used for no more than 30 days and deleted earlier after successful reporting. TikTok handles the event under its privacy terms.
- Contact
- TikTok Pte. Ltd., 1 Raffles Quay #26-10, Singapore 048583
The Google Ads billing agreement for our South Korean account names Google Korea LLC; the Google Ads row above identifies the overseas Google measurement service reached by the tag, not our billing counterparty. Recipient information: Google Analytics · Google Ads · X · Meta · TikTok
What Dodo Payments collects on its own checkout (your name, email address, billing address and card details) it collects from you directly rather than receiving it from this site, and its own privacy policy governs what it does with it. The same was true of Whop for purchases made before the switch.
Refusing, and what it costs
You may refuse. Refusing the hosting transfer means an account cannot be opened, because the service itself runs on Google Cloud in the United States; declining at signup removes the account that signing in created, and an existing member stops account transfers by deleting their membership. Vertex AI receives no new request unless you ask for an AI-written reading, daily fortune or chat reply, so ordinary public pages remain available. Refusing measurement does not restrict pages, accounts, purchases or readings. Enable Do Not Track or Global Privacy Control in a supported browser to stop new measurement by GA4, Google Ads, X, Meta and TikTok; saved provider refusals remain in effect. To request withdrawal for a provider or ask for deletion of records we hold, contact privacy@duckgustudio.com. This cannot recall data already sent.
Your choices and rights
Instagram response records are separate from your website account. Contact support@duckgustudio.com with your Instagram handle and an available public comment link to request access, correction, deletion or a processing halt. Deleting a website account does not identify or automatically remove those platform records. Blocking DMs or avoiding a new comment/reply stops that new interaction; Meta’s own copies follow its policy.
For Hamzzi raising, you can delete a profile on My page, close your account, or request raising-record deletion and a processing halt at privacy@duckgustudio.com. You can view reminder consent and withdrawal receipts on the reminder screen and turn off without closing the account. Opening the room while signed out avoids member-profile character calculation and member room-state requests.
You can view and share an Ilju result without choosing to continue or save a profile. Use “Clear my result and start again” to clear the test’s temporary data, or close the tab to end its storage session. To keep a birth date out of your account, do not choose the profile save action after sign-in; the result remains available. Once saved, you can edit or delete that profile on My page. Clearing the test result or closing its tab does not delete a profile already saved to your account. No link or picture leaves this device unless you choose to share, reply or save a picture; the page may prepare them on this device in advance. To use another birth date instead of a saved profile, choose “Use a different birthday”. While you are signed in, a friend’s or reply link compares your main profile’s character with the link on this device to show a hint; nothing about it is sent, and opening the link while signed out avoids it.
The same choices apply to the Work Hamzzi test in every language: you can view and share its free result without signing up, clear its temporary data with “Clear my result and start again”, or close the tab. Signing up only to see the rest of the result does not save the birth date to your account.
Profile lets you clear what this browser has stored. To avoid future Vertex AI processing, do not request a new AI-written reading, daily fortune or chat reply, or touch Hamzzi for an AI line; this does not recall information already sent. Where applicable law gives you them, you may request access, correction, deletion, restriction, portability, or withdrawal of consent by writing to privacy@duckgustudio.com. We may need to verify your identity before acting, and we will explain any refusal and the route to appeal it.
To avoid using a reference city or reading the device time zone for a new Saju, Vedic or wealth request, add your birth place before requesting it: in the profile for an account reading, or in the private input form for an ordered PDF. To avoid sending any new reference-city data, do not request that reading; other account features remain available. Editing or deleting a profile does not remove an earlier ordinary reading or its recovery inputs. For access, correction or deletion of those records, contact privacy@duckgustudio.com, or delete the account under the retention rules above.
The friend map has separate controls: decline an invitation, disable the link and its preview without removing existing connections, remove one connection, edit or switch the map profile, and withdraw detailed-reading permission for a specific friend while keeping the sign-level connection. Editing or switching that profile clears permission across its connections until separately renewed. These choices do not affect ordinary account use. To request a copy, correction or deletion of a referral or connection record, use those controls where available or email privacy@duckgustudio.com. Neither a link holder nor a connected friend can obtain your raw birth date, time, place or account identifiers through the map.
You can edit or delete a saved profile, withdraw the optional email choice, and request website account deletion from My page. For access, correction, deletion or restriction of another record, email privacy@duckgustudio.com with the right you want to exercise and the account or record concerned. We will verify the requester or their representative before disclosing or changing private information, then reply through the contact channel you provide. If we cannot comply, we will explain the reason and how to challenge the decision. You can use the same address to ask about legally retained transaction records after account deletion.
United States state privacy notice
For United States residents, the categories processed by this website are identifiers, account information, purchase records, Internet or device activity, content you write, and the inferences described above. Sources are you, your device, the sign-in provider you choose, and the providers listed in this policy. This website has not sold personal information during the preceding 12 months and does not show ads. Limited visit and conversion data is shared automatically with GA4, Google Ads, X, Meta and TikTok described above, subject to browser privacy signals and saved provider refusals. Submit a withdrawal request or an appeal to privacy@duckgustudio.com.
Age, security, and changes
The minimum age is 14. If you have not reached the age of majority where you live, you may use Lodestar only with permission from a parent or legal guardian. Users under 14 may not create an account, because no child-account or verified parental-consent programme is offered. Sign-in and account checks restrict access to saved records; support recovery is limited to authorised staff and records the action taken. Material changes are announced on this website before they take effect.
Links, support, and the app
External source and provider-policy links take you to other websites. If you contact support by email, your email address and message are sent to the support service. Avoid sending sensitive personal information. The iOS client’s additional App Store and device flows are described in this policy; Apple and external sign-in providers also apply their own notices.
Contact and remedies
Personal information protection officer: Lee JungAe, representative of Duckgu Studio. For privacy requests and complaints, email privacy@duckgustudio.com. We handle requests in the language of this policy where possible.
For independent advice or remedies in Korea, contact the Personal Information Infringement Report Center (118) or the Personal Information Dispute Mediation Committee (1833-6972). Report Center ↗ · Dispute Mediation Committee ↗
- Operator
- Lee JungAe, sole proprietor trading as 덕구스튜디오 (Duckgu Studio), Republic of Korea
- Representative
- Lee JungAe
- Business registration
- 756-51-01119
- Mail-order sales registration
- 2026-부산남구-0569
- Business address
- Apt. 1502, Building 104, Gyeongdong Apartments, 202 Dongmyeong-ro, Nam-gu, Busan, Republic of Korea
- Telephone
- 010-3875-7339
- Support
- support@duckgustudio.com
- Privacy
- privacy@duckgustudio.com
Previous policy and changes
2026-10-09: the primary address changed to hamzzi.com. This policy continues to include lodestarastro.com and blog.lodestarastro.com, and explains the conditional 60-second sign-in handoff, limited room settings, measurement-refusal continuity and separate browser-data deletion. The privacy effective date remains 2026-10-07, and required signup choices and existing consent records are unchanged.
Complete published policy before the address change (effective 2026-10-07)
On 2026-10-08, the business telephone number was updated to 010-3875-7339.
The 2026-10-07 Instagram reply update adds a conditional explanation for our own comment and DM responses: platform identifiers, signed-event handling, a follow-and-reply invitation, follower checking after an incoming DM, private US Firestore storage, expiry 30 days after last handling, delayed TTL deletion and separate deletion requests. Raw comment/DM text and full profiles are not saved in these records. This update does not activate replies, confirm Meta permissions or change required signup choices.
Read the published policy before the Instagram response update
The 2026-10-07 Shopify PDF update adds the optional Shopify storefront purchase flow: verified order and buyer-email data, private Lodestar input and PDF delivery, and the limited fulfillment update returned to Shopify. Birth details, questions, private links and results are excluded from that integration. Shopify’s processing and retention are described separately from Lodestar’s 90-day private-order expiry. Required signup choices and earlier consent records remain unchanged.
Complete published policy before the Shopify PDF update (effective 2026-10-07)
The 2026-10-07 update removes descriptions of processing the website home page no longer performs and adds two measurements. The home page’s Ilju and Work Hamzzi cards show the same default pictures to every visitor; they do not calculate a character from a signed-in member’s profile or show a profile name. Paid readings are no longer marked “Saved”. The today’s-fortune card check stays as described in the daily-fortune details, and the today’s-fortune card is now the only home page card whose tap can be reported as showing the member’s own content. Tapping a next-reading card on an IljuTI result sends Google Analytics only which reading was chosen, and a tap on the start link in the English and Japanese home page introduction is sent as the Ilju test card in the introduction section, without a position. Recipients, signup choices and earlier consent records remain unchanged.
The 2026-10-06 update adds stardust and its friend invites: grain and card records in the account, the invite code and the inviting member’s identifier kept in an invited account, the counts an inviting member sees, and their retention and request routes. The friend-map invitation itself still provides no reward. Signup choices and earlier consent records remain unchanged.
Complete published policy before stardust
The 2026-10-02 premium purchase correction opens Whop payment first and the required private birth-information form only after receipt verification. Calculation and AI generation start after submitted details are validated and normalized. New unpaid checkout records contain no birth details.
Complete policy before the premium purchase-order correction
The 2026-10-02 Daangn update adds form-triggered PDF delivery, the private Sheets-to-server-to-email flow, the 60-day request period, city assumptions and correction/refusal routes. It does not turn form responses into payment receipts.
Complete policy before Daangn automatic delivery
The 2026-10-02 premium Saju update adds required birth details and consent before embedded Whop payment, country reference cities, server input validation and text cleanup, private unpaid drafts expiring after 24 hours, and transfer to a paid order only after receipt verification. Birth details are not sent to Whop. Existing signup choices and earlier consent records remain unchanged.
Complete policy before premium checkout input (effective 2026-10-02)
From 2026-10-02, restricted public-page visit reporting to Whop is added. This revision explains the fields, 30-day device visitor ID, browser privacy signals, existing refusal choices, excluded private pages and provider retention limits. Account, birth and reading information is not added to this flow. Other policy dates and previous consent records remain unchanged.
Read the complete policy before the 2026-10-02 update
The 2026-10-01 Hamzzi-line addition describes AI requests on a signed-in member’s touch, the restricted non-birth inputs, five-line memory pool, shared limits, 24-hour retry expiry and existing expired-record database cleanup, and use-blocking after profile deletion or processing halt. The existing Android notice, signup choices, optional reminders and initial Hamzzi release date remain unchanged.
Complete published policy before Hamzzi AI lines (with Android)
The 2026-10-01 Android revision extends the shared-account notice to Android and describes Google Play account identifiers, purchase verification and token hashes, optional device copies, widget text, local reminders, measurement limits and deletion/refusal routes. It does not change existing consent records or the separate PDF, Hamzzi raising and iOS rules. The privacy effective date is 2026-10-01.
Complete policy before Android integration (effective 2026-09-30, with the 2026-10-01 update)
The 2026-10-01 update explains saved room-item positions and sizes, recent duplicate-action receipts and their write-time cleanup, and removal of the home page’s automatic room-state request. These support the same raising and duplicate-prevention purposes. The privacy and initial Hamzzi effective date stays 2026-09-30, and signup and optional-reminder choices are unchanged.
The 2026-09-30 publication and effective date adds Korean Hamzzi raising, migration of verified historical activity for existing active accounts, chosen outfit IDs, device character-file requests and separately optional web push. Raising clauses apply from the same date. Web push sending and daily-fortune rewards remain disabled at release. The shared terms, refund and licence effective date remains 2026-09-14; the terms revision date changes to 2026-09-30, while refund and licence revision dates remain unchanged.
What changed on 2026-09-30
- Raising records and purpose
- Before: this policy did not describe separate Hamzzi raising records. From this revision: private experience, care, item and outfit records support raising; verified historical activity is migrated for existing active accounts. Missing history is not estimated.
- Storage and deletion
- Before: account and profile storage on Google Cloud was already described. From this revision: raising and migration records use the same US Firestore storage. Profile deletion removes its Hamzzi; a processing halt removes raising records and prevents recreation; account purge follows closure after 30 days.
- Optional web reminders
- Before: the iOS app’s local reminder was described. From this revision: separate browser web reminders and their two optional consent choices, endpoint data, browser push route and deletion rules are added. Web sending remains disabled at release; migration does not give reminder consent.
Read the earlier PDF policy version captured before the reference-city update (effective 2026-09-30)
Read the complete previous policy (2026-09-29 until the 2026-09-30 revision)
The 2026-09-30 reference-city and unknown-time update adds reference cities for Saju, Vedic and wealth readings without a birth place. It explains English-only browser time-zone selection, the city fields and assumed-place flag kept in request and recovery records, the reference-city name sent to AI, unchanged profiles, readings without a birth time, and refusal, correction and deletion routes.
Read the policy before the reference-city and unknown-time update (effective 2026-09-30)
The 2026-09-30 revision explains the separate PDF purchase flow that applies only when it becomes available and you choose it: marketplace verification, input fixed to the purchased product, private results and their 90-day period after payment confirmation, Resend delivery with the purchased PDF attachment, staff access and refusal. Required signup choices and existing website checkout do not change.
Read the complete previous policy (effective 2026-09-29)
The 2026-09-29 website home page today’s-fortune check update narrows what the today’s-fortune card on the website home page asks our server. The server no longer returns the fortunes saved for that profile to the browser. After checking that the profile belongs to the account, the server now reads, of the saved fortunes, only that profile’s one record for today’s local date and the page’s language, and returns only whether it exists, never its text. The page sends that profile’s identifier, today’s date on this device and the page’s language for this check. The daily-fortune details describe the same fact. Nothing is generated, and the daily-fortune screen and saved readings do not change.
The 2026-09-29 website home page personalisation update explains that, on the website home page in every language, the main profile (or, if none is set, the first profile in the list) of a signed-in member is used on this device, without a tap, to calculate that profile’s Ilju and Work Hamzzi characters and show them on the test cards; the characters are not sent to analytics, and only their picture files are loaded from this site. The website home page’s today’s-fortune, Ilju and Work Hamzzi cards show that profile’s name (unless it has no name of its own); the today’s-fortune card also shows whether today’s fortune has already been opened, checked against the fortunes already saved for that profile without generating one, and paid readings the account already has are marked “Saved”. The Google Analytics row also lists what a home page card tap sends. With the same update, the Work Hamzzi test, previously offered only in Korean, is also offered in English and Japanese; its handling of birth dates, temporary tab storage, the sign-in return, share links and analytics events is the same in all three languages. It now also says that signing in from the top of the page with a coworker’s link open can put the coworker’s character code in the return address, and sign-ins through Lodestar’s server now leave that code out of their sign-in state record. The Ilju and Work Hamzzi summaries, details and refusal routes, the Work Hamzzi information-flow step, and the daily-fortune details describe the same facts.
Read the complete policy before the website home page personalisation update (effective 2026-09-29)
The 2026-09-29 iOS daily-fortune update replaces the optional preview and separate activity start with explicit required display consent for that feature. After consent, opening today’s saved result updates the widget and supported Live Activity automatically. This revision explains the notice version stored on the device, visible text, withdrawal and re-consent. General signup choices, AI generation and advertising permissions do not change.
Complete policy before required daily-fortune display consent
The 2026-09-29 Ilju reply-link update corrects its description of the analytics items the Ilju test already sent and of how character codes are handled in the sign-in return address. It also explains reply links (two character codes); the Lodestar campaign name, creative name, share step number and link type carried by share links; the on-device calculation from a signed-in member’s saved profile and the main-profile comparison behind hints; and the Ilju analytics event items. The summary, information flow, details and refusal routes describe the same facts.
Read the complete policy before the Ilju reply-link update (effective 2026-09-29)
From 2026-09-29, this policy adds the Korean-only Work Hamzzi test. Like the Ilju test, it calculates the result in your browser. Choosing to sign up for the rest of the result, or to save a profile, keeps the result and, at age 14 or older, the birth date in the same tab for up to 30 minutes, apart from the Ilju test; the birth date reaches your account only when you choose to save it. The Google Analytics row now also lists the event details both tests send. Required signup choices do not change.
Read the complete previous policy (effective 2026-09-28)
The 2026-09-28 iOS widget update adds the optional Home Screen daily-fortune preview and separately requested Live Activity. It explains the protected device snapshot, where personal text can appear, when display expires and when the local file is removed. The account and AI generation rules do not change.
Read the complete policy before the iOS widget update (effective 2026-09-28)
From 2026-09-28, this policy adds the existing Cloudflare CDN and Web Analytics/RUM processing, observed page/performance fields, supplier retention explanations and unconfirmed contract conditions. It clarifies that the existing refusal and iOS blocking rules apply to the five Lodestar measurement providers. This notice does not expand required signup choices.
Read the complete previous policy (effective 2026-09-27)
From 2026-09-27, this policy explains the Ilju character test’s optional continuation: temporary storage in the same browser tab for up to 30 minutes of validity, the separate choice to save a birth date to your account after sign-in, and how to clear the temporary data. It also explains that shared links show a character without the birth date or account details. The summary, information flow and detailed sections describe the same choices.
The 2026-09-27 revision also describes the same-account iOS client, App Store account tokens and transaction records, optional on-device copies and reminders, selected sexual-orientation information and birth-city coordinates, the iOS integration’s measurement limits, and optional gift links with their minimum delivery records and retention.
Read the complete previous policy (effective 2026-09-26)
From 2026-09-26, English and Japanese purchases are charged by Dodo Payments Inc. (United States) as merchant of record instead of Whop. This policy lists what this site sends Dodo Payments, what it keeps from the payment, and Dodo Payments’ privacy contact. Whop remains listed for the refunds and records of purchases made before the switch. Korean checkout is unchanged.
Read the older policy (effective 2026-09-25)