Privacy policy
By DailyAstro · Last updated 2026-09-10
Birth profiles stay on your device; membership has separate server records. Scoring still runs in your browser. Pages load Google Fonts; when membership is enabled, the app also connects to Clerk for login. AI receives computed scores and rules only when you press its button, without names or raw birth dates.
This English page is a translation provided for convenience. If it differs in any way from the Chinese original at 私隱政策, the Chinese text prevails.
What we collect
Clerk handles login details and necessary session cookies. Stripe handles payments, subscriptions and required billing details. We do not receive or store full card numbers. When membership is enabled, the app checks login status automatically; payment starts when you choose a plan. Signing in does not sync birth profiles by itself; a member can turn on Profile sync (section 5 under Outbound connections).
Cloudflare D1 stores member IDs, Stripe customer/subscription/invoice IDs, membership status, credit grants, AI request IDs, the explanation kind (today / wealth / date / compatibility / start date), content hashes, dates, completion status and reply text for accounting and recovery. Apart from the profiles a member chooses to mirror with Profile sync (section 5), we do not store raw requests, names or birth dates in D1 or write request contents to application logs. Replies remain until you erase them, one at a time or all at once, on the membership page; you can reread saved replies there, and asking about the same result again returns the saved reply without spending another credit. Usage and billing records are retained separately and are not deleted by clearing browser data.
What is stored on your device
The following is kept in your browser's localStorage and stays on this machine, in this browser:
| Key | Contents |
|---|---|
da_profiles | The names you gave yourself, family members, friends and candidates, their birth dates, an optional birth time, and optionally a gender and a birth place (a city, used only for the ascendant) |
da_active_profile | Which profile you currently have selected — a profile ID, or the marker meaning “everyone”, and nothing else |
da_settings | A DeepSeek / Gemini API key you typed in yourself (optional, see section 2), a Google Client ID, your AI model choice, and the domains you marked as 「我最關心」 (wealth / career / love / health / travel / study) |
da_tarot | Tarot: the random seed behind the daily card, and your last 30 draws (date, spread, question, cards) |
da_yijing | I Ching: your last 30 castings (date, method, question, line values or numbers, hexagram numbers) |
da_sync | The Profile sync switch, the time of the last sync, and deletions not yet pushed (profile id and time) |
da_explain_cache | AI reply caches separated by signed-in account, up to 60 entries. Regenerating after clearing them uses credits under your plan. |
da_explain_pending | Request IDs waiting for recovery, to prevent duplicate charges on retry. No raw birth details. |
da_reply_ticks | Which action items you ticked on an AI reply card — position numbers only, never sent anywhere. |
da_history | Records migrated from the old version (v1). This version adds no new records: what you see on the profiles page is what the old version left behind, and you can delete them one by one. If you never used the old version, this key never appears. |
calendarEventIds | The IDs of events added to Google Calendar through the app, kept only so it knows which ones you added; deleting them means deleting them in Google Calendar yourself (the app has no delete button) |
Two more are left over from the old version: baziHistory and baziSettings. If you used the old version, the new one reads them once, the first time it reads records or settings, and moves the contents into da_history / da_settings above. Once moved, we do not delete the original two keys — they stay on your machine until you clear this site's data in your browser yourself.
The chart (the four pillars) is never stored; it is derived from the birth date each time. localStorage does not sync anywhere and does not follow you to a second machine.
Outbound connections
In normal use, only the following requests leave your machine:
1. Google Calendar (optional, started by you)
You first have to enter your own Google Client ID and press “connect Google Calendar”. Only then is Google Identity Services (accounts.google.com) loaded for authorisation, with a scope limited to calendar.events. When you press “add to calendar”, what is sent is the date you picked: the date, the hour range, the day master, and the event title and description. The birth date itself is not sent. You can revoke the authorisation in your Google account at any time.
2. AI explanation: forwarded through our server (optional, you press the button)
When you press AI explanation or AI deep analysis, your browser sends the computed result to /api/explain. The natal-chart tab and the daily card send, respectively: the four pillars with ten gods, 納音, life stages, 命宮/身宮 and the luck-cycle stems and branches (direction as a boolean); the 紫微 palaces, stars and transformations; the sun sign, today's house and moon phase; today's pillar, pattern, element and almanac lines; for the annual reading, the year's stem-branch, ten god, branch relations, 太歲 relation, luck-cycle stem-branch, month pillars and 紫微 year palace; for the recommendation grid, the six domain verdicts, scores and signal lines; for the 奇門 hour chart, the hour, the 局, the nine cells, the pattern verdicts and the directions; for feng shui, the year and month flying-star boards and the 八宅 directions (the 命卦 is one trigram looked up from birth year and gender; neither is sent) — again no name, birth date, age or gender. A tarot reading sends the spread, your question (60 characters at most) and the drawn cards (name, orientation, keywords), and nothing from any chart; an I Ching reading likewise sends only the hexagrams, moving lines and question. The Western chart sends each body's sign, degree and house, the ascendant and today's transit aspects, plus the time-zone offset; never the birth instant and never the city. Name numerology sends only the stroke counts, the five grid numbers and their elements, never the characters you typed (the name is not stored either); synastry sends the aspects, overlays and score; the event picker sends the event, the window, your settings and the rule hits of the candidate days, with every participant written as 「參與者」 and no birth data. After checking membership and allowances, the server forwards it to DeepSeek with the site key (Gemini is also supported as a fallback). Site-funded AI requires an active membership and sufficient allowance; you do not need your own key.
What is sent: your day master's heavenly stem and its element, the earthly branches of your chart, and for the chosen day its date, day pillar, score, band and golden hour, each scoring rule with its points, and that day's almanac 宜/忌 terms. A compatibility request also sends the other person's day master and branches. It does not include your name or a family member's name, and it does not include the raw birth date. This is filtered twice — once before sending (in the browser) and once after receiving (on the server) — and both layers copy only the fields on an allow-list, discarding everything else.
Raw requests are not written to the database or application logs; replies and usage records are stored as described above. Cloudflare keeps its infrastructure connection records under its own policy. KV keeps short-lived IP counters, removed after about a day, for additional abuse protection: approximately 8 requests per IP per 10 minutes and 30 per day. Those counters are not precise member balances. D1 checks membership credits and daily limits in one write; daily allowances reset at 00:00 UTC (08:00 Hong Kong). A separate site-wide daily attempt cap includes failed attempts to limit provider costs.
Once data reaches DeepSeek or Google it is governed by their privacy policies, which are outside our control.
Profiles → Settings can still hold your own API key. It is used directly from your browser to api.deepseek.com or generativelanguage.googleapis.com only when the server answers no_key (that deployment has no site key) or membership_unavailable (that deployment has no membership service). You pay the provider for that use. A signed-in member who is refused is never switched to their own key, and your own key is not used to bypass membership credit or daily limits.
3. Fonts
Pages load the Noto Serif TC / Noto Sans TC font files from fonts.googleapis.com and fonts.gstatic.com. The browser makes this request automatically; it carries no personal data, but it does let Google see your IP address — the same as on any other site that uses Google Fonts.
And that is all: no Google Analytics, no Meta Pixel, no A/B testing tool, no ad network, no error-reporting service, no session recording.
4. Membership login and payment
Clerk (opens in a new tab) provides login and Stripe (opens in a new tab) provides payment and subscription management. Clerk processes member login data under our service contract and this site’s privacy policy. Stripe also processes payment data under its privacy policy. Providers may process data in different regions.
5. Profile sync (optional, off by default)
The membership page has a switch, “Sync my profiles to this account”, off by default. When it is on, this device's profile table — name, role, birth date, birth hour, gender, birth place (a city), archived flag, and each profile's last-modified time — is sent through /api/member/profiles to the member_profiles table of the membership database (Cloudflare D1), tied to your login account; other devices signed in to the same account with sync on receive the same roster. When one profile was changed on both sides, the newer edit wins; a profile deleted on one device tells the others through a deletion record (profile id and time, kept 90 days). These copies are never used for AI explanations (the AI still receives no names or birth dates) and are not written to application logs. When you turn sync off you choose whether to delete the server copies or keep them; deleting your login account deletes them.
Export (.ics / JSON)
“Export .ics” and Profiles → Backup → “Export profiles (JSON)” both assemble the file inside your browser and download it. Nothing goes over the network. The JSON backup contains only the profile table (name, role, birth date, birth hour, gender, archived flag) — no API keys, settings, history or AI cache. “Import JSON” is likewise read only in the browser and only adds people you do not already have; the welcome screen's “Have a backup? Import JSON” is the same feature. “Download saved explanations (JSON)” on the membership page is also assembled in the browser, from your own replies already shown on that page.
How to delete your data
- Delete individual profiles or records on the app's Profiles page.
- With Profile sync on, “Turn off and delete” on the membership page removes the profile copies from D1; deleting your login account removes them too.
- Clearing browser site data removes local profiles, settings and caches.
- We cannot restore erased local birth profiles. The membership page can erase server AI reply text and your local member cache; this does not cancel a subscription or erase usage/billing records.
- Manage subscriptions in Stripe. Deleting your login account stops subscriptions and erases saved server reply text; accounting metadata is retained for reconciliation and abuse prevention. Clearing browser data does not delete an account.
- Events already added to Google Calendar live in your own Google account; delete them in Google Calendar.
Children
Paid membership is for adults. You may create local profiles for children in your household; those birth details also remain in your browser (unless you turn on Profile sync).
Policy updates
The September 2026 membership version adds login, billing, usage and reply records; 10 September 2026 adds optional Profile sync (Outbound connections, section 5). The old description of having no accounts or database no longer applies. We will update this page and its date when data flows change. You can inspect requests to /api/explain in the Network tab and local data in the Application tab of your browser developer tools.