Privacy Policy
Last Updated: 2026-09-19
1. Overview
Starry Research Labs Limited (the "Company", "we", "us") operates kaucim.ai (the "Website"). This Privacy Policy explains how we collect, use, store, and protect your personal data.
This policy is drafted in compliance with the Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap. 486).
2. Data We Collect
We may collect the following categories of data:
| Category | Details |
|---|---|
| Usage Data | IP address, browser type, pages visited, sign-number selections, Moon Blocks questions and outcomes, Qi Men questions and board identifiers, Mei Hua casting numbers and question type, almanac or folk-tool inputs, Palmary scenario selections, result identifiers, and basic device or request diagnostics |
| Anonymous iOS App Usage Data | The app shares by default a random persistent installation identifier, a 30-minute session identifier, event identifier, product, action, entry surface, timestamp, app version, build, language, distribution channel, and whether the iPhone has an Apple Watch paired (a yes/no only; nothing is read from the watch). We use these fields to count anonymous active installations, product use, and Apple Watch coverage. They do not use IDFA and never include or join to an email address, name, birth details, question, journal text, payment identity, GA Client ID, or sign-in account. The server stores only HMAC versions of the installation and session identifiers. Events are kept for up to 24 months. |
| Birth Details | The birth date, time, sex, birth-time accuracy note, and relationship-chart inputs you provide when using Zi Wei / BaZi, career and wealth, monthly-flow, compatibility, annual-book, or Five Elements crystal reports (the crystal report needs only a birth date; the hour is optional). Used to generate the relevant personalised analysis report; not used to identify you or for unrelated purposes. Birth details are also covered by the birth details research record described below. |
| iOS Birth Chart and Compatibility Records | The birth date, hour, traditional chart gender, optional name or label, Zi Wei palaces, BaZi pillars, compatibility summary, full report sections, record identifier, language, sync state, and payment state created through the iOS app. Free previews are not added to a paid account record. Paid charts linked to an email address remain in the sync account until you delete the account. A full report opened in the app remains on that device until you delete it. The other person's optional name is used only as your own label for the comparison. |
| Email Address and Report Access | The email address you enter at checkout for current English-language reports and for the 2027 annual reading book, together with the delivery state, single-use sign-in link, pickup identifier, and payment state. Used to confirm the purchase, deliver the report or pickup link, and restore your access on request; not used for marketing. Sign-in links are single-use and expire in 15 minutes. Annual-book job records are kept for about 120 days and delivery markers for up to 90 days. |
| Qi Men Casting and Reading Data | The single question you enter, question type, casting hour, board snapshot and identifier, free preview, full reading, sealed-board state, optional email address, and related payment state. Free castings are kept for about 2 hours. For paid readings, the full question, board snapshot, report, and account link are kept for up to 365 days so the reading can be generated, unlocked, restored, and synced across devices. A report opened in the iOS app remains on that device until you delete it. The question text is also covered by the demand research record described below. |
| Mei Hua Casting and Deep-Read Data | The two numbers you enter, the optional question text and question type, the casting hour, the primary, nuclear, and changed hexagrams, the free verdict, the paid deep read, an optional email address, and related payment state. Free castings are kept for about 2 hours and paid records for about 30 days. The question text is also covered by the demand research record described below. |
| Demand Research Record | To analyse demand trends and evaluate new product directions, the question text you type is also kept as a research record. This covers free fortune-stick previews and paid readings, Moon Blocks consultations, decision timing, Qi Men, Mei Hua, the two paths and optional question in Two Roads, the context box in Zi Wei and compatibility readings, the Palmary scenario description, and the opening question in a Yuelao intake (the conversation that follows is not written to it). The record holds only the question text, question type, language, time asked, and a random identifier. Common email, URL, and phone-number patterns are stripped, and no IP address, name, or payment data is attached; text signalling self-harm is never written to this record. Research records are kept for at most 24 months. |
| Birth Details Research Record | The birth date, hour, and sex submitted for Zi Wei / BaZi, compatibility, character-card, or Five Elements crystal readings are also kept as a research record, used to understand user structure (such as how often an hour is supplied, or the spread of birth decades) and to evaluate new product directions. Records are deduplicated per chart, so the same birth details are written once, and carry no name, email, IP address, payment data, or contact details. Kept for at most 24 months. |
| Character Card and Decision-Timing Data | The question, domain, time range, casting hour, card or board identifier, free preview, full reading, and payment state. Decision-timing records are kept for about 7 days; free character-card castings for about 2 hours and paid records for about 30 days. We also keep an anonymous count-and-domain statistic with no identifying data for up to about 400 days; the question text is covered by the demand research record described below. |
| Five Elements Crystal Report Data | The birth date you submit (hour optional), any description of jewellery you already own, language, result identifier, redemption or invite code usage, and payment state. Results are cleared automatically after about 30 days. |
| Fortune-Slip Photos | Where this feature is offered (currently the Chinese-language site), the photo of a fortune slip you upload so the sign number can be read. The image is converted in memory, sent once for AI recognition, and discarded; kaucim.ai does not store the original. The output is a sign number. If recognition fails you can enter the number manually. |
| Yuelao Conversation Data | Relationship context, questions, messages, follow-up dialogue, and any email address you provide to resume the same Yuelao conversation. Used to generate the reading and maintain conversational continuity; not published or used to identify you. |
| Palmary Photo and Reading Data | The palm photo you upload, your selected scenario or question, generated preview or full reading, result identifier, and related payment state. The original photo is sent once for AI analysis and is not stored by kaucim.ai after the request. Your browser may temporarily keep a local copy in sessionStorage so the annotated card can be generated or restored on your device. |
| Kaucim Riso Avatar Photo and Avatar | One adult portrait you upload and the Riso avatar generated from it. Your browser first resizes the original and converts a copy to JPEG. That copy is sent to the AI image provider only for this generation. kaucim.ai does not write the original photo, the likeness notes, or the finished avatar to a database. The avatar remains only in the open browser page and disappears when you reload or close it. |
| Feng Shui Room Photo and Scan Data | The room photo you upload, generated room scan, result identifier, language, and related payment state. The photo is used for the scan, then deleted automatically at the latest within 7 days; paid scans delete the photo once the report is saved. The written report remains available at your private result link while the Service continues to operate. |
| Agent-Initiated Purchase Data | If an AI agent orders on your behalf through our public agent channel, we receive the product parameters it submits (such as a sign number, question, birth details, or room photo), the checkout session identifier, the requesting IP address, and rate-limit counters. We cannot verify the arrangement behind the agent; responsibility for that authorisation sits with the agent's operator (see section 4 of the Terms of Service). |
| Payment Data | Payment information processed via Stripe, Airwallex, or Antom. For iOS in-app purchases, Apple passes us the transaction receipt, anonymous transaction identifier, original subscription transaction identifier, and expiry date. We use these details to verify purchases, process renewals, restore delivery, and withdraw access after a refund. We do not store your credit card numbers directly. |
| Local Storage | Cached unlocked content stored in your browser's localStorage or sessionStorage, including generated analysis reports, Palmary result state, and temporary card-generation data. In the iOS app, the bearer code for a reading pack or subscription entitlement and the sliding 30-day sign-in session are held in your device keychain. Opened Qi Men reports, Zi Wei and BaZi charts, compatibility reports, and journal entries remain on the device. Chart PDFs are created on the device only when you export one, and the temporary file is removed after sharing. |
| Creator and Referral Data | Creator profile: Once your application is approved, we keep your slug, name, email, platform link, primary product line, language, payout method and payout account details, payout preference, and any notes. Kept while the partnership is active; you can email us to request deletion after it ends. |
| Link clicks: A monthly click count for your /r/slug link. We record only a count, never who clicked. | |
Attribution cookie: Clicking a creator link sets a browser cookie named kc_creator_v1 holding only the creator slug and a timestamp, expiring after 30 days. At payment, we write that slug into the order record to calculate commission. | |
| Commission records: Order identifier, product, amount, currency, commission amount, and status. The payer's email is stored only as a hash, used to tell whether this is that user's first payment, and cannot be reversed back into an email address. If a payment is refunded or disputed, the record is marked reversed rather than deleted, as our reconciliation trail. | |
| User-to-user referrals: Once you leave an email after a paid purchase, we generate your referral code and record how many users paid through it, plus any redemption codes issued. User records are kept for about 1 year, the referral-code index for about 2 years, and redemption codes for about 6 months; arriving through a referral link temporarily holds the code in your browser. |
3. How We Use Your Data
- Provide and improve our cultural content interpretation service
- Generate fortune-stick, Moon Blocks, Qi Men, character-card, decision-timing, Mei Hua, almanac, folk-calendar, Zi Wei / BaZi, career, wealth, monthly-flow, compatibility, and related cultural-reference outputs
- Read the sign number from a fortune-slip photo you upload, where that feature is offered, so you can open the matching verse
- Generate and deliver the 2027 annual reading book by email, including sending the pickup link, re-sending it on request, and letting you download it again within the retention window
- Generate Five Elements crystal reports from your birth details and validate redemption or invite codes
- Generate Palmary palm reading previews, full readings, and on-device annotated cards
- Generate a Kaucim Riso Avatar from the adult portrait you upload, then assemble its pin and share image in your browser
- Generate feng shui room scan previews and paid room reports from uploaded room photos
- Provide Yuelao conversation continuity and allow you to resume a prior conversation
- Confirm purchases and restore access to paid reports through the email address given at checkout
- Process your payment transactions (via Stripe, Airwallex, or Antom, or via Apple for iOS in-app purchases)
- Analyse user behaviour to improve AI quality and user experience
- Analyse question themes and demand trends across products to improve existing services and evaluate new product directions
- Analyse the overall distribution of birth details (such as how often an hour is supplied, or the spread of birth decades) to improve product design and evaluate new product directions
- Calculate and pay creator commission, prevent self-purchase and duplicate counting, and reconcile the monthly statement
- Prevent fraud and abuse
- Comply with legal obligations
4. Data Sharing
We share data with the following third parties:
- Stripe, Inc. — Payment processing. Stripe receives your payment information to complete the transaction. See the Stripe Privacy Policy.
- Airwallex (Hong Kong) Limited — Payment processing. Airwallex receives your payment information to complete the transaction. See the Airwallex Privacy Policy.
- Antom (Ant International) — Payment processing. Antom receives your payment information to complete the transaction. See the Antom Privacy Policy.
- Apple Inc. — In-app purchase processing. When you buy inside our iOS app, Apple collects the payment and returns a transaction receipt that we verify before unlocking the content. See the Apple Privacy Policy.
- Resend — Transactional email delivery. When we send a purchase confirmation, a sign-in link, or the annual book's pickup link, your email address and the message content pass through Resend. See the Resend Privacy Policy.
- AI Interpretation Provider — AI interpretation engine. Depending on the product, the data sent to the AI model may include your sign selection and question type, a fortune-slip photo you upload, Moon Blocks question, Qi Men question and board summary, character-card and decision-timing inputs, birth details used for a chart-based report or the annual book, the birth date and jewellery description used for a crystal report, Yuelao messages you submit, a Palmary palm photo and scenario prompt, a Kaucim Riso Avatar portrait, or a feng shui room photo. These inputs are used to generate the requested output and are not published by us.
- Analytics providers — On the production hostname, we use Google Analytics (Google), Microsoft Clarity (Microsoft), and PostHog to understand page views, product-funnel events, and aggregate usage patterns. Microsoft Clarity also records session replays and heatmaps; every input field, and every area that displays a name, birth details, or the question you asked, is masked and does not appear in a replay. Analytics events are used for product operations and measurement, not for selling your personal data.
- Hosting providers — Our cloud hosting service (e.g. Vercel) may process access logs.
- Creator payout services — We pass the payout details needed to pay commission to the payout service you name (FPS, bank transfer, PayPal, or Wise).
Aside from the above, we do not sell, rent, or otherwise disclose your personal data to third parties, except as required by law.
5. Cookies & Local Storage
We may use analytics cookies or similar browser storage on the production Website to measure page views and product-funnel events. We also use the browser's localStorage to cache unlocked paid content so you can return to view it. This local cache is stored on your device.
These analytics cookies are not required for the Website to work. If you are in the European Economic Area, the United Kingdom, Switzerland, or Thailand, they do not load until you choose "Accept" on the cookie banner; choosing "Decline" leaves all three analytics tools unloaded. Clearing this site's browser data withdraws an earlier choice and brings the banner back.
Palmary may also use your browser's sessionStorage to temporarily hold the uploaded palm photo and generated card state during the same browser session. This local copy is used for on-device card generation and recovery; it is not a server-side storage copy held by kaucim.ai.
A Kaucim Riso Avatar original and finished image remain only in the open page. The tool uses localStorage only for a random device identifier that enforces the daily free limit. It contains no photo or likeness information.
Feng shui scans may use temporary server-side storage for the uploaded room photo during the scan and report-generation window, as described above. Fortune-slip recognition uses no server-side storage; the photo is processed in memory once.
Anonymous iOS usage sharing is on by default. You can turn off Share Anonymous Usage Data under Me. Turning it off stops collection immediately, removes the active local installation identifier, and requests deletion of that installation's event history. If the app is offline, it retries the deletion request when a connection returns. Turning sharing on again creates a new random identifier. Deleting the sync account also deletes the current installation's anonymous events first.
6. Data Storage and Security
Your data may be stored outside Hong Kong (including the United States, Singapore, and other regions) as our third-party providers (Stripe, Airwallex, Antom, Vercel, and our AI interpretation provider) operate servers overseas. We take reasonable measures to protect your data but cannot guarantee absolute security of internet transmissions.
Palmary result data is stored for a limited time to support payment verification and unlocking. The original palm photo is not stored by kaucim.ai after the analysis request, but it may be processed by the AI interpretation provider and temporarily retained in your own browser session as described above.
Ordinary Kaucim Riso Avatar uploads never enter a public example gallery, advertisement, or social post. If we show an original-photo and Riso-avatar pair, we use a photo for which we hold the necessary usage rights and separately obtain the pictured adult's explicit written permission for AI transformation and public display. Using the tool does not grant that permission. A stock-model example is labelled as illustrative, and every generated image is identified as AI-generated. You may contact us to stop future display of an example you previously agreed to publish. We will remove it from channels we control within a reasonable time, although we cannot retrieve copies already downloaded, reposted, or cached by others.
Feng shui room photos are retained only for the scan and report-generation window and are deleted automatically at the latest within 7 days. Paid scans delete the uploaded photo once the report is saved.
iOS email verification codes expire after 10 minutes, and app sessions use a sliding 30-day expiry. Once you sign in, reading packs, passes, and Zi Wei, compatibility and Qi Men reports bought on the website with the same email address are synced into the app. You can sign out in the app or use Delete Sync Account to remove account links, full Qi Men reports, Zi Wei and compatibility birth details and reports, linkable analytics events, related research samples, and all app sessions. We keep only the minimum transaction details required for legal, refund, and accounting duties. Deleting the sync account does not cancel an Apple subscription; you must cancel it separately in Apple's subscription settings.
First-party anonymous iOS product events are kept for up to 24 months. Offline events are retried only for 7 days, and the server rejects expired, future, or non-allowlisted fields. Apple's app usage and retention reports cover only devices whose owners agree to share analytics with Apple and that meet Apple's minimum privacy threshold, so some values may be unavailable.
Demand research records, covering the question text you type across products, and birth details research records are kept for at most 24 months. Question text has common email, URL, and phone-number patterns stripped; neither record carries an IP address, name, or payment data.
Other products keep results for: about 7 days for decision-timing readings, about 30 days for crystal reports, about 2 hours for free character-card castings and about 30 days for paid ones, and about 120 days for annual-book job records with delivery markers for up to 90 days. The anonymous decision-timing statistic, which holds only counts and domain distribution, is kept for up to about 400 days. Free Mei Hua castings are kept for about 2 hours and paid records for about 30 days. Fortune-slip photos are not stored server-side. Once a retention window closes the record is cleared and previously unlocked content may no longer load, so download or screenshot anything you want to keep.
7. Your Rights (Under PDPO)
Under the Hong Kong Personal Data (Privacy) Ordinance, you have the right to:
- Access — Request access to the personal data we hold about you
- Correct — Request correction of inaccurate personal data
- Delete — Request deletion of your personal data where reasonable
To exercise these rights, please email support@kaucim.ai. We will respond within a reasonable time.
8. Children's Privacy
The Service is not directed to children under 16. If we become aware that we have collected personal data from a minor, we will take steps to delete it.
9. Policy Updates
We may update this Privacy Policy from time to time. The revised version will be posted on this page with an updated "Last Updated" date.
10. Contact Us
Starry Research Labs Limited
Email: support@kaucim.ai
Website: https://www.kaucim.ai/