Skip to content
TigerTell

Privacy Policy

Version 2026-09-10 · effective 2026-09-10

1. What we collect

- Account: email address (required), password (hashed; email sign-up only), display name (optional), interface language. If you sign in with Google, we receive your email address and account identifier. - Reading subject - stored only when a reading is generated with an analysis ticket: date of birth, time of birth (or "unknown"), country and city of birth, gender, relationship status, reading language, and an optional label. Gender is used solely to determine the direction of the 10-year luck cycle (daeun). - Payment: order and payment identifiers issued by our payment provider, amount, currency, status, and the hearts credited. We never receive or store your card number, expiry, CVC, or bank account number - the payment window is operated by the payment provider and those details do not pass through our servers. - Service records: heart ledger entries, ticket purchases and redemptions, referral codes and relationships, coupon redemptions, consent records (document, version, timestamp, method), a hash of your IP address for coupon abuse prevention (never the raw address), and any quality report you submit.

2. What decides whether we store it — whether you are signed in

🔴 The line is whether you are signed in. It is not whether you paid.

1. Anything you enter while signed out is not written to our database. Entering birth details without an account to see the eight characters and the free preview works that way: the inputs travel to our server so the chart can be computed, are discarded afterwards, and are held only in your browser session. Closing the browser or switching device means you cannot retrieve them.

2. Anything you enter into our content while signed in is stored, whether or not you paid for that content. The same rule applies to content we add in future - if you are signed in when you type it, assume we keep it.

What we store when you are signed in: the birth details you enter (date of birth, time of birth or "unknown", country and city of birth, gender), anything else that piece of content asks for - for shared-space content, the nickname you choose (up to 3 characters) and an identifier for the space you joined - and the eight-character chart computed from those details. Gender is used solely to determine the direction of the 10-year luck cycle (daeun). How long each is kept depends on the content and is listed in section 6; for shared spaces it is 90 days from the day the space was created, or one year if an extension was purchased, and for content you pay for (saju and compatibility readings) it is one year from the day it was stored. For shared spaces the results themselves (your role, the pairings between people) are not stored; they are recomputed each time the screen opens.

What the other people in that space can see: your nickname, the role computed for you there, and the pairing results. What they cannot see: your email address or display name.

🔴 Anyone in the same space can also open a detailed compatibility reading with you. When they do, your chart data - the eight characters, and the birth date, birth time, birthplace and gender behind them - is carried into their reading. They cannot edit your details.

🔴 What is carried over follows the retention period of the compatibility content - one year - not the 90 days of the space. It remains inside that person's reading after the space is deleted and after you leave, and one year from the day that reading was stored it is deleted automatically and completely (section 6).

🔴 That person can also turn their compatibility reading into a SHARE LINK, which opens without signing in. The shared page shows the name label you chose and the reading text, and both people's eight-character charts are part of what that page receives. 🔴 YOUR BIRTH DATE, BIRTH TIME AND BIRTHPLACE ARE NOT PUT ON THE SHARED PAGE - for a reading that came from a shared space, the option to show them cannot be turned on. But for the reason in the note below, the eight characters alone still narrow the window. Whether sharing is on is decided by the person who bought that reading, and we cannot know how far the link travels.

⚠️ A chart is determined by a birth date and time, so the eight characters alone already narrow the window considerably. We cannot remove that. It is why we tell you this before you join, and why you can simply not join if you would rather not.

The person who created a space can remove participants and delete the space; a participant can leave at any time. In every one of those cases the participation data for that person is deleted immediately. Our administrators may view the nicknames and computed roles in a space only when a user has reported an error in it, only to handle that report; those views are logged, and charts are not included.

This content does not use generative AI. Its sentences are pre-written by us and assembled according to the computed result, so nothing about you is sent to an external AI provider for it.

3. Why we process it, and on what legal basis

Creating and managing your account: (b) performance of a contract

Calculating charts and producing readings: (b)

Selling hearts and analysis tickets; refunds: (b), (c) legal obligation

Paying referral rewards: (b)

Preventing coupon and free-tier abuse: (f) legitimate interests

Product analytics and improvement: (f), or (a) consent where required

Handling enquiries and quality reports: (b), (f)

Retaining transaction records required by law: (c)

We do not send marketing email without separate, explicit consent.

4. Entering someone else's birth details

The service is designed to let you analyse other people - a partner, a friend, a family member. When you do: you are responsible for having the right to enter that person's details; the data we hold contains no name, contact detail, or other direct identifier of that person, so we do not know who they are; you can delete the entry at any time, and deleting your account deletes it too. If the person themselves asks us to delete it, contact us at the address in section 13 and we will act on it.

5. How the AI sees your data

Readings and chat answers are generated through OpenAI, L.L.C.'s API. What we send depends on the content. For saju and compatibility readings:

- Sent: the computed chart (the eight characters, element and Ten God distributions, sinsal, luck-cycle year ranges), the reading language, the gender value used for the luck-cycle direction, and a coarse relationship-status bucket. - Not sent: your name, your email address, your account identifier, your city of birth, and your date and time of birth themselves. Where a reading addresses you by name, the AI writes a placeholder token; your actual name is substituted at display time, in your browser. The stored text contains no real name. Note that a birth *year* may be inferable from luck-cycle year ranges. - Generated text is stored and reused for anyone whose chart, language, and conditions hash to the same value. It carries no identifier of any person.

🔴 In content where you write your own questions (saju AI chat), what we send is different: your question is sent as you wrote it. - Sent: the text of your question, the text of your earlier questions in the same conversation together with a summary of each answer, and the computed chart described above. - Not sent: your name, your email address, your account identifier, and your date and time of birth themselves. - ⚠️ But whatever you put in the question itself is sent as written. We do not screen the contents of a question in advance. Please do not write names, contact details, health information, or anything else you would rather not disclose. - The conversation - your questions and the AI's answers - is stored so that you can reopen it. Each message is kept for one year from the day that message was written, after which it is deleted automatically and completely. - 🔴 This conversation is never reused for anyone else's result. Unlike the readings above, it stays in your own room.

Readings are entertainment and reflection content. They are not automated decisions producing legal or similarly significant effects within the meaning of GDPR Art. 22.

6. How long we keep it

Account, hearts, tickets, referrals, coupons, consent records: Until you delete your account

Birth details you entered for an analysis (date and time of birth, birthplace, gender, relationship status): 🔴 ONE YEAR from the day they were stored, or sooner if you delete your account - after that they are deleted automatically and completely and the result can no longer be opened. Re-reading does not extend the year

Coupon abuse attempts (IP hash): 90 days

Payment records: 5 years, as required by Korean e-commerce law; the account identifier is detached

Quality reports you submit: Kept anonymised - on account deletion the account identifier is detached and only the report text remains, as the basis for correcting a faulty reading

Computed charts and generated reading text: Kept indefinitely - they contain no personal identifiers and serve other users' cached readings

What you enter into our content while signed in (birth date and time, gender, birthplace and so on): 🔴 the period depends on the content, and the screen that asks for the information tells you that content's retention period and asks you to confirm it before anything is stored - for example, information in shared-space content (nickname, birth details, chart) is kept for 90 days from the day the space was created, or one year if an extension was purchased, after which the space and everything in it is deleted automatically and completely

That participation data is also deleted immediately, regardless of the period above, when you leave the space or the person who created it deletes it

Results you paid for (saju readings, compatibility readings) and the chart data inside them: 🔴 ONE YEAR from the day they were stored, or sooner if you delete your account - after that they are deleted automatically and completely and cannot be opened again. RE-READING DOES NOT EXTEND THE YEAR - 🔴 this can include another user's chart data, which is what happens when you obtain a compatibility reading with someone you met in a shared space (section 4a). During that year it is not deleted when that person leaves the space or the space itself is deleted

Records we must keep by law, even after you delete your account:

Statute Act on Consumer Protection in Electronic Commerce / Record Contracts and withdrawal of subscription / Period 5 years

Statute " / Record Payment and supply of goods/services / Period 5 years

Statute " / Record Consumer complaints and dispute resolution / Period 3 years

Statute " / Record Advertising and labelling / Period 6 months

Statute Protection of Communications Secrets Act / Record Service access logs / Period 3 months

7. Who else processes it

Processor Supabase, Inc. / Role Database, authentication, and delivery of sign-up / password-reset email / Country Singapore (AWS ap-southeast-1)

Processor Vercel, Inc. / Role Hosting and application runtime / Country United States

Processor OpenAI, L.L.C. / Role Reading generation / Country United States

Processor Korea PortOne Inc. / Role Payment gateway integration and settlement checks / Country Republic of Korea (no transfer abroad)

Processor Kakao Pay Corp. / Role Domestic wallet payments / Country Republic of Korea (no transfer abroad)

Processor KG Inicis Co., Ltd. / Role Domestic card payments / Country Republic of Korea (no transfer abroad)

Processor Eximbay Co., Ltd. / Role Payments on cards issued outside Korea / Country Republic of Korea (no transfer abroad, though the authorisation itself passes through the issuing bank and the international card network)

🔴 These payment processors collect the payment instrument themselves - card number, expiry, CVC. That data never reaches our servers and is never disclosed to us.

Processor Google LLC / Role Google sign-in; analytics / Country United States

We do not sell personal information and we do not share it with third parties for their own purposes. We disclose it only with your consent or where a law or a lawful order from an investigating authority requires it. Where personal data of EEA/UK users leaves that area, we rely on the European Commission's Standard Contractual Clauses or another transfer mechanism permitted under Chapter V of the GDPR.

8. Cookies and local storage

- Strictly necessary: an authentication session cookie keeps you signed in. Blocking it prevents login. - Browser session storage: free-tier inputs are held there until you sign up or pay, and are cleared when you close the tab. An authentication token may also be held in browser storage to keep you signed in - always sign out when using a shared computer. - Analytics: we may use Google Analytics 4. We do not send it any account identifier. You can refuse it through your browser settings or Google's opt-out add-on. - Acquisition source: the domain of the site that linked you here, and any campaign parameters in the address, are held in browser session storage and used only to count how many people signed up from each source. If you sign up with a Google account, the same value is kept in a cookie for ten minutes while you are away at Google, and is deleted as soon as the sign-up is processed. It is never stored against your account - all we can see is the total per source. Closing the tab clears the temporary value.

9. Your rights

You may request access to, correction of, or deletion of your personal data; ask us to restrict or stop processing; withdraw consent where consent is the basis; obtain a portable copy; and object to processing based on legitimate interests. Use the account settings, or write to us (section 13). We respond without undue delay and in any case within the period the applicable law allows.

What deleting your account actually does - please read before you do it:

- Erased immediately: account details; every birth input you saved (date, time, place, gender, relationship status); heart ledger; tickets; referral relationships; coupon history; consent records. - Retained: the computed charts and the generated reading text. These carry nothing that points to you, and other users with identical charts are already reading them. Your link to them is severed. - Retained: payment records, for the statutory period, with your account identifier detached. - Retained, anonymised: any quality report you filed. The account identifier is detached and only the report text remains, used solely to correct a faulty reading. Please do not put identifying details in a report. - ⚠️ Deletion is irreversible, and you lose access to readings you paid for.

10. Children

We do not knowingly accept users under 14 (PIPA), or under the age set by their country between 13 and 16 where the GDPR applies. If we learn we hold such data, we delete it without delay.

11. If there is a breach

If personal data is lost, stolen, or disclosed, we will notify affected users without undue delay - within 72 hours absent justifiable cause - under Art. 34 of the PIPA, telling you what data was involved, when and how it happened, what you can do to limit harm, what we are doing about it, and where to reach us. Where the scale requires it we also report to the Personal Information Protection Commission or KISA. For users covered by the GDPR we notify the supervisory authority and, where required, the data subjects under Arts. 33 and 34.

12. Security

TLS in transit; passwords stored only as one-way hashes; row-level security in the database so an account can reach only its own rows; separated administrative privileges with an audit log; IP addresses stored only as hashes; and no payment instrument data on our systems at all.

13. Contact, and how to complain

Business registration no.: 483-12-02701

Data Protection Officer: Lee Jooyoung - the owner acts as DPO under Art. 32(2) of the PIPA Enforcement Decree

Email: tigertellit@gmail.com

Phone: +82-506-853-7881

Postal address: 6, Hangeulbiseok-ro 48-gil, Nowon-gu, Seoul, Republic of Korea

Korean users may bring a complaint to the Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972) or the Privacy Infringement Report Centre (privacy.kisa.or.kr, 118). EEA/UK users have the right to lodge a complaint with their national supervisory authority.

14. Changes

We may revise this policy when the law, our vendors, or the service changes. We will post the new version and its effective date in the service, give at least 7 days' notice before changes that materially affect your rights, and ask you to accept the new version where the change is significant.