Privacy Policy
Effective Date: September 16, 2026
1. Who Operates This Service
Your I Ching is an independent, one-person project. In this policy, “we”, “our”, and “us” refer to that project and its operator. The operator is the controller of your personal data. Contact options for personal-data requests, when configured, are shown in Section 10. This page describes the information the current service handles and the specific outside services to which it sends information. It does not claim a corporate team or a compliance program that is not present in the current operation.
2. Information the Service Handles
Account Information
If you create an account with email and password, you provide a name, email address, and password credential. Better Auth maintains the account and session records. If Google sign-in is enabled and you choose it, the service can receive the name, email address, profile image, and authentication records Google returns for that sign-in.
Reading Information
A reading record contains the question you submit, an optional scenario tag, the six cast results, the resulting hexagram snapshot, the AI-generated interpretation, and any follow-up conversation. Private questions are not placed on public pages or share cards.
Session Information
Authenticated session records can include an IP address and user-agent value. For an anonymous casting session, the application can store a one-way salted hash of the request IP for observability; it does not persist the raw IP in the anonymous-session record.
Anonymous Session Cookie
Before you create an account, we set an anonymous session cookie named anon_sid to track your free-reading quota and to associate any reading you cast anonymously with that browser. This cookie is httpOnly (not accessible to page scripts), is scoped to this site only, and lasts approximately 180 days. If you later log in or create an account, readings linked to your anonymous session are merged into your account.
Reader Feedback
After a completed reading, we collect feedback from completed readings to understand the Service and improve it. The feedback form does not copy your question, hexagram, interpretation, email address, or account identity into the feedback record.
Support Correspondence
When you email support, we receive your email address, message, and the correspondence needed to respond to your request.
You may submit feedback without agreeing to public display. If you choose public display, your feedback and reader-chosen display name may be considered after manual review by an administrator. Administrators may approve or reject feedback, but cannot edit or rewrite its body or display name.
Approved public feedback is displayed exactly as submitted in its original language. We do not translate, interpret, or rewrite it.
You can withdraw feedback or revoke public-display permission using the feedback controls on the associated reading. Either action removes feedback from public eligibility immediately. To request deletion of feedback, email support@youriching.com.
Payment Records
If you buy follow-up capacity or a subscription, the application stores the amount, currency, product, payment status, Waffo order id, and the entitlement attached to your account. The detailed payment flow is described below.
Platform Traffic Measurement
Our hosting platform, Vercel, provides privacy-friendly, cookie-less traffic and performance measurement (Vercel Web Analytics and Speed Insights). It reports aggregated page views, referrers, device type, and page-performance metrics. It does not set a cookie and does not build a cross-site profile of you.
Product Usage Events
We also record a small number of first-party product usage events — for example, a reading being cast or a checkout being started — to our own database. Each event is tagged only with the event name, a timestamp, and the account or anonymous session it belongs to. Events never include your question text, and your email address is not attached to an event. A completed purchase separately triggers the Google Ads conversion tag described next, which does carry a hashed form of the account email.
Advertising Conversion Measurement (Google Ads)
When you complete a purchase, a click identifier stored in a first-party cookie, readable by page scripts, for about 90 days is used to confirm the Google Ads conversion measurement tag fired for that purchase. That confirmation carries the purchase amount, the currency, an opaque order reference we generate ourselves — not your name and not any internal identifier for your account — and a SHA-256 hash of the email on your account, computed inside your browser before it leaves the page.
Because the tag loads as part of the page, Google also receives the same request-level information any web request carries — your IP address, browser information, and the address of the page you are on — whenever the tag runs. On a reading result page, that address contains only an opaque identifier, never the question text; the admin dashboard and the email-verification and password-reset pages do not load the tag. Ad personalization is turned off for every visitor.
3. How the Information Is Used
The current application uses these records to:
- Create and authenticate an account and let you update its display name
- Create, interpret, retain, and retrieve your readings
- Apply free-reading, follow-up, and subscription limits
- Open a checkout and apply a completed purchase to your account
- Send account verification, password-reset, and subscription-renewal messages
- Send the daily hexagram email to addresses subscribed through the newsletter form
- Check account or anonymous-session ownership before returning private reading data
4. Named Outside Processing
Payment Processing (Waffo Pancake)
Payment for a one-time purchase of follow-up capacity, and payments for subscriptions, are processed by Waffo Pancake, our third-party payment processor, on Waffo's own hosted checkout page. The one-time product applies only to the current reading's follow-up capacity and includes no new cast. Your card number and other full payment credentials are entered directly into that Waffo page — our servers never receive, transmit, or store your card number or other full payment credentials.
To open a Waffo checkout session and let Waffo Pancake attribute the resulting payment back to your account, we send Waffo only the information a payment requires: your account email address (to prefill the checkout form and receipt), an identifier for which product you are purchasing and, when the product adds follow-up capacity to a specific existing reading, that reading's id, and your internal account id (so we can credit the purchase once Waffo notifies us it succeeded). We do not send Waffo your password, your birth date, or any reading content.
After a payment completes, we store a payment record — the amount, the product purchased, its status, and Waffo's own order id — together with the resulting entitlement (an active subscription or follow-up capacity bound to a specific reading). This record never includes your card number or other full payment credentials. See our refund policy for cancellation and refund terms.
AI Interpretation Processing
To generate the reading for a hexagram you cast, your question text and the cast hexagram data are sent from our servers to our upstream interpretation provider, the Huangji Engine, which uses its built-in AI model, DeepSeek, to produce the interpretation. We do not send your email address, name, raw birth date, or IP address to the Huangji Engine or DeepSeek — only your question text, a scenario tag, and the hexagram snapshot are transmitted for this purpose.
Transactional Email (Resend)
When the service sends an account-verification, password-reset, or subscription-renewal email, it sends the recipient email address and that message to Resend for delivery.
The newsletter form in the site footer signs you up for one daily email, sent each morning (US Eastern time) starting the morning after you subscribe, containing that day's hexagram — the same hexagram shown on the Daily I Ching page. When you subscribe, we store the email address you enter, the time you subscribed, a random unsubscribe token that identifies your subscription, and, once sending begins, the date of the most recent daily email delivered to you. The welcome message and each daily message are sent through Resend in the same way as the emails above. If a Resend Audience is configured for this deployment, the address is also added there as a Resend contact and marked unsubscribed when you leave. Every email we send you includes an unsubscribe link; opening it marks your subscription unsubscribed, records the time you did so, and stops the daily email. The subscription record is kept in that state so that subscribing again reactivates it instead of creating a new one.
Optional Google Sign-In
If Google sign-in is configured and you choose it, Google processes the sign-in and returns the account details authorized by that flow. Email-and-password sign-up does not use Google.
Advertising Measurement (Google)
Google receives the purchase-confirmation and page-load information described above under Advertising Conversion Measurement (Google Ads) as the operator of that measurement tag. We have enabled Google's restricted data processing setting, which Google states limits its own use of that data. Google's privacy notice for its advertising products is published at https://business.safety.google/privacy/.
5. Data Security
The application uses authenticated sessions and ownership checks before returning account reading data. Anonymous readings are associated with the anonymous-session cookie held by the same browser. Production web traffic and the named provider requests use HTTPS/TLS.
No method of transmission over the Internet or electronic storage is completely secure, so this policy does not promise absolute security.
6. Data Retention
Your questions, the hexagrams you cast, and the resulting AI-generated interpretations ("readings") are retained permanently so that you — or, for an anonymous session, the same browser session — can look back at past readings at any time. We do not automatically delete readings after a fixed period. If you want a specific reading deleted, contact the site operator, and we will process your request.
The browser-cookie lifetime described above is not a promise that every related database record is deleted on the same date. The current application has no automatic deletion schedule for account or payment records.
7. Your Choices and Possible Privacy Rights
Depending on where you live and the circumstances, applicable privacy law may give you rights concerning personal information. Those can include asking what information is held, asking for access, correction, or deletion, obtaining a copy, or objecting to or restricting some uses. This policy describes how to contact the operator; it does not determine whether any particular law applies to the service or to a specific request.
In the product, you can update your account display name, sign out, and clear site cookies in your browser. Clearing the anonymous-session cookie removes that browser's link to its anonymous session but does not itself delete server-side reading records. See the Cookie Policy for the cookies used by the current service.
We do not sell your personal information.
8. Children
The Service is not intended for anyone under 18, and we do not knowingly collect personal information from anyone under 18.
9. Changes to This Policy
When this page changes, the revised text and effective date will be posted here. This page does not promise a separate email-notification program for policy changes.
10. Contact
Questions about this policy and requests for access, correction, or deletion should go directly to the site operator through the contact channel shown below when one is available.
Email support@youriching.com.