Privacy Policy: Reckoned Yet?

Effective date: August 28, 2026

We collect only what is needed to read your chart and run the conversation. We do not ask for an email, a password, or a tracking profile. We don't sell data. Your raw birth details stay on your device. Only derived chart context (never your raw birth info) is sent to our servers to generate readings and dialogues.

1. What we collect and process

No account, no tracking. The app does not ask for your email address, phone number, or password. On first launch, we create an anonymous account token: a random identifier unique to your device. This identifier stays in your device's secure storage and keeps your chat history across sessions. On the web app, this token and your profiles live in your browser's storage for app.reckoned.app; clearing site data removes them. You may sign in with Apple, Google, or an email link to keep purchases and history across browsers and devices.

Birth data per profile (device-local). Your birth date, time, time zone, city, longitude, and gender stay on your device or in your browser. In the iOS app they live in the app's private storage; in the web app they live in the browser's local storage for this site, unencrypted, readable only by pages on app.reckoned.app. This data is never sent to our servers, stored in cloud databases, or shared with third parties. Deleting the app, clearing site data, or Settings → Delete removes it.

Profile metadata (device-local). Display names you assign to profiles (for example, "Me" or "Partner") are stored only on your device.

Conversation messages and daily readings (server-side). The questions you send to the AI, the follow-up replies, and the context of drawn Guanyin Lots are sent to our backend database and stored there, keyed only to your anonymous token.

Derived chart context (server-side, transient). When you request a reading, ask a follow-up question, or draw a Guanyin Lot, your device converts your local birth fields into a text string of chart data (stems, branches, ten gods, luck pillars, and daily elements). We send this derived chart context, never your raw birth date or precise birthplace, to our backend and to third-party AI models to generate the response.

Subscription and quota state (server-side). Your purchase status (free tier, subscription tier, or top-up queries) and daily usage counters are tracked on our servers against an anonymous subscriber identifier. Payment processing is handled by Apple (iOS app, through your Apple ID) or by Stripe (web app). When you buy on the web, Stripe receives your payment details, billing country, and email address; we receive only a customer reference, the product bought, and its status.

Aggregate telemetry (server-side, de-identified). Performance indicators, latency metrics, and error rates are logged for app maintenance. Your anonymous device token is salted and SHA-256 hashed before it reaches our telemetry databases, so the logged value cannot be linked back to your session.

Sign-in identity (optional, opt-in). If you link Apple, Google, or an email address to keep your purchases and history across devices, the provider shares a unique identifier for this app and an email address (Apple lets you mask it). Google may also share a display name. We use this only to keep your purchases and history available across devices and to send sign-in links you request. We do not send marketing email, and we do not cross-reference this identity with the AI model or any third-party databases.

2. What we never collect

We do not ask for any of these.

3. How your data is used

To draw your chart. All BaZi calculations run locally on your device. No server is contacted to compute your chart.

To generate AI readings and Oracle lots. When you start a dialogue or draw a lot, the derived chart context and text history are sent to a third-party AI provider's API to return the interpretation. No personal identifiers, emails, or device keys are sent with this request.

To enforce quotas. Quota records are checked on our servers to manage usage. We do not inspect the content of your prompts to do this.

4. Sensitive-category data handling

Because birth charts can reveal private philosophical or spiritual leanings (which may qualify as special-category personal data under frameworks such as GDPR Article 9), we keep this data isolated:

5. Third-party data subprocessors

We use a small set of subprocessors:

The app asks for your permission before anything is shared with the AI provider: your first reading is preceded by an in-app disclosure, and AI readings stay off unless you agree. Your chart itself is computed on your device.

We do not run advertising scripts or third-party behavioral analytics SDKs. For our full subprocessor list, contact support.

6. Data retention and erasure

Device-local storage: Erased when you delete the app or choose "Delete account & charts" in Settings.

Server-side storage: Retained, in anonymized form, to support your chat continuity. Tapping "Delete account & charts" triggers an immediate database wipe that replaces sensitive records with null values and completes within 30 days.

Telemetry: Aggregated system data is kept indefinitely for long-term health monitoring, and is not linked to any identifiable user.

7. Your rights, regional scope, and device portability

You can access, correct, or erase your records directly inside the app. The export path is the in-app "Export my readings" option in Settings, because we hold no email or other personal identifier to verify an external export request against. If you are in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your local supervisory authority. All backend services run on US East cloud nodes under Standard Contractual Clauses (SCCs) where international transfers apply. This app does not support or operate within mainland China.

Anonymous histories and balances live where they were created. Signing in (Apple, Google, or email) lets you recover purchases and server-side history on another browser or device; birth profiles are never uploaded, so you re-enter them. App Store subscriptions also transfer through Apple's receipt system.

8. Children

This app is not directed at children under 13. We do not knowingly collect data from children under 13. You must be at least 13 to use it. If you believe a minor is using the app, please contact support and we will guide them through the deletion process.

9. Changes to this policy

If we make a material change (new data collected, new sub-processor, change in retention), we will update the effective date at the top of this page and post a notice in the app for active users. Continuing to use the app after a material change takes effect constitutes acceptance.

10. Contact

Operated by Boxuan Cui, who is the data controller for the personal data described in this policy. Direct all inquiries, erasure verification requests, or due diligence questions to [email protected].