Skip to content

Privacy policy

Last updated: September 2026.

The short version: your readings, your questions, and your notes are stored on your own device. Everything in the app works that way, with no account.

Three features send data off your device, and each one only runs when you ask for it: an AI reflection on a reading, sign-in for sync, and sync itself.

What we store about you

If you never sign in, nothing. There is no record of you on our side at all.

If you sign in to sync across devices, we store:

  • the email address you signed in with;
  • a copy of each reading you sync: its question, any context you wrote, the six line values, its title, and when it was cast;
  • a copy of each journal entry you sync;
  • your passkeys' public keys, if you add passkeys. The private keys stay in your device or security key and never reach us.

We hold no password, because the app never asks for one. Sessions are opaque tokens; we store only their hashes, so a copy of our database would not contain anything that could be used to sign in as you.

Synced readings and journal entries are stored so our server can read them. That is how sync works: the server has to hold the text to give it back to your other device. It is protected in transit and no one else's account can reach it, but it is not encrypted in a way that hides it from us. If that is more than you want, every feature except sync works without an account, and export gives you your own file.

What leaves your device

Three things, each only when you ask.

If you request an AI reflection on a reading, we send that reading's question, the context if you wrote one, and its six line values to our server, which forwards them to the model provider. We do not send your notes, your other readings, or any identifier. The screen tells you this immediately above the button, every time. We do not store the request or the reflection; it is shown on the page and kept nowhere.

If you request a sign-in code, we send your email address to our mail provider so the code can reach you. The message contains no links.

If you press Sync while signed in, we send your readings and journal entries to our server and pull down anything your other devices sent. Sync never runs without you pressing it.

If you do none of these, nothing you write ever leaves your device.

Analytics

There are none. No analytics service, no product measurement, no cookies for measurement. We do not know how many readings you have cast.

Ads

There are ads.

The iPhone app shows a short video ad when you ask for the one free reflection a day. That ad is served by Google AdMob, which is an advertising company and does track. The website shows display ads from Google AdSense. Both pay for the model that writes the reflection, which is the only part of this product that costs money to run.

Three things are true about them and are worth stating plainly:

  • Nothing you write is sent to an advertiser. Your question goes to the model that answers it and nowhere else. The ad network never sees your question, your notes, your journal, or which hexagram you cast.
  • The tracking prompt is a real choice. The iPhone app asks whether you will allow tracking. If you say no, you see a less targeted ad and get exactly the same reflection. Nothing you can do in the app depends on that answer.
  • Everything else has no ads. Casting, the hexagrams, the source texts, the commentary, your history, the map, the learning pages, and your export carry no advertising and are not going to.

We keep one thing to make the daily allowance work: a random identifier for your install or browser, generated on your device. It says nothing about you, it is not an advertising identifier, and all it records is that this install has used today's reflection.

Error reporting

We do not run an error reporting service that could collect your text. Our server's error responses are fixed messages that never contain anything you wrote, and our sign-in endpoints give the same answer whether or not an address has an account, so they cannot be used to check whether someone uses the app.

Your data is yours

You can export everything to a file at any time from the History screen, with or without an account. The file is plain JSON: you can read it without this app, keep it wherever you like, and import it back here or into another browser.

Deleting a reading deletes it and its notes, on this device, on the server, and on your other devices the next time they sync. Signing out ends the session on that device; signing out everywhere ends all of them.

Deleting your account deletes the account, its sessions, and every reading synced to it. On the iPhone this is under Settings while signed in; on the web it is in the sync panel. Readings kept only on your device stay there.

Clearing your browser's site data, or deleting the app, removes the copy on that device.

Children

The app is not directed at children.

Changes

If this policy changes in a way that affects what leaves your device, that change will be visible in the app before it takes effect, not buried in a document.

Contact

For privacy questions, write to me@skumyol.com.