Article 1 (Purpose)
Article 2 (Personal Information Collected)
The Company collects the following personal information to provide the Service.
1. At signup
- Required: Email address
- Optional (provided by social-login providers when applicable): Name, profile image, display name
2. When using Tarot readings
- The question text entered by the member
- Selected spread and cards
3. When using Astrology readings
- Date of birth, time of birth, place of birth (longitude/latitude), gender
4. When using AI Chat
- The message text entered by the member
5. At payment
- Payment ID, amount, payment method type, timestamp
- Card numbers, bank account numbers, and other sensitive payment data are held by payment processors (Lemon Squeezy, Toss Payments, Kakao Pay) and are not stored by the Company.
6. Automatically collected
- IP address, access logs, device/browser information, cookies
Article 3 (Methods of Collection)
The Company collects personal information through the following methods:
- Direct input by the member during signup and use of the Service
- Information provided through social-login providers (Kakao, Google, Apple, Facebook), with the member's consent
- Information automatically generated during use of the Service
Article 4 (Purposes of Use)
The collected personal information is used for the following purposes:
- Member management: providing membership-based service, identity verification, fraud prevention
- Service delivery: generating tarot/astrology reading results and AI chat responses
- Mora (virtual asset) transactions: crediting, debiting, and refunding Mora
- Payment processing: single, subscription, and package payments
- History of readings and chat: making them available for the member to revisit and continue
- Service improvement: statistical analysis and development of new features
Article 5 (Retention and Use Period)
As a general rule, the Company destroys personal information without delay once the purpose of collection and use has been achieved. However, where retention is required by applicable laws, information is kept as follows:
- Records relating to contracts or withdrawal of subscription: 5 years
- Records relating to payment and supply of goods or services: 5 years
- Records relating to consumer complaints or dispute handling: 3 years
- Access logs: 3 months
In addition, to prevent re-registration of the same account after withdrawal, the Company retains a minimum identifier (such as an email hash) for 30 days after withdrawal, after which it is automatically destroyed (see Article 13 of the Terms of Service).
Article 6 (Disclosure to Third Parties)
As a general rule, the Company does not disclose members' personal information to third parties. The following are exceptions:
- When the member has given prior consent
- When required by law, or when investigative authorities request information through the procedures and methods set out in law for investigative purposes
Article 7 (Processing Entrusted to Third Parties)
The Company entrusts the processing of personal information to the following parties to improve the Service:
- Supabase Inc. (USA): database management, authentication, file storage
- Vercel Inc. (USA): web hosting and serverless function execution
- Lemon Squeezy (USA, Merchant of Record): international (USD) payment processing
- Toss Payments (Korea): single payments and recurring billing keys
- Kakao Pay (Korea): single payment processing
- OpenAI, L.L.C. (USA): generation of tarot/astrology reading results and AI chat responses. The Company transmits input data such as the member's question, birth information (for astrology), and chat messages.
Article 8 (Social-Login Authentication)
The Company is integrated with the following social-login providers for member authentication. This is not entrustment of personal information; it is an authentication flow conducted with the member's explicit consent.
- Google LLC
- Apple Inc.
- Meta Platforms, Inc. (Facebook)
- Kakao Corp.
During social login, the Company receives the minimum information needed to identify the member, such as email, display name, and profile image, from the relevant provider. Additional personal information is collected only when the member enters it directly.
Article 9 (International Transfer of Personal Information)
The Company transfers personal information to overseas processors among those listed in Article 7. Pursuant to Article 28-8 of the Korean Personal Information Protection Act, details of the international transfer are as follows:
- Items transferred: Email, reading inputs (for astrology: date/time/place of birth and gender; for tarot: question text and selected cards), AI chat messages, service usage logs
- Recipients: Supabase, Vercel, Lemon Squeezy, OpenAI
- Country of transfer: United States
- Purpose of transfer: data storage, authentication, hosting, payment, generation of reading/chat responses, and other operations essential to providing the Service
- Retention and use period: until the member withdraws or the entrustment ends (items required by law to be retained are kept for the legally mandated retention period)
Article 10 (Automated Decision-Making)
The Company uses automated systems, including large language models (LLMs), to perform the following:
- Generating tarot reading results: an LLM produces an interpretation based on the member's question and selected cards.
- Generating astrology reading results: an LLM produces a chart interpretation based on the member's birth information.
- Generating AI chat responses: an LLM produces responses based on the member's messages.
Members have the following rights with respect to automated decision-making:
- The right to request information about how the member's personal information is used in automated processing
- The right to express an opinion regarding the processing
- The right to object to the result of automated processing
To exercise these rights or for related inquiries, please contact hermora.tarot@gmail.com.
Article 11 (Member Rights and How to Exercise Them)
Members may view, modify, or delete their personal information at any time and may request deletion of their personal information by withdrawing membership.
- View and modify personal information: directly on My Page, or by emailing hermora.tarot@gmail.com.
- Account withdrawal: directly on My Page (processed within 3 business days).
- Withdrawal of consent: by emailing hermora.tarot@gmail.com.
- After withdrawal, the same account cannot be re-registered for 30 days; during this period, an identifier such as an email hash is retained.
- Under the Korean Personal Information Protection Act and related laws, members may request deletion of their personal information; the Company will process such requests without delay.
Article 12 (Use of Cookies)
Article 13 (Security Measures)
The Company takes the following measures to ensure the security of personal information:
- Encryption of personal information: sensitive data such as passwords is stored encrypted
- Technical measures against hacking and similar threats
- Minimization of personnel handling personal information and ongoing training
- Establishment and operation of an internal management plan for personal information protection
Article 14 (Data Protection Officer)
The Company designates a Data Protection Officer to oversee personal information processing and to handle complaints and provide remedies in connection with personal information processing, as follows:
- Name: Park Jae-ho (박재호)
- Title: CEO
- Email: hermora.tarot@gmail.com
Article 15 (Remedies for Infringement of Rights)
For remedies for infringement of personal information rights, members may apply for dispute resolution or counseling with the following Korean authorities:
- Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
- Korea Internet & Security Agency — Privacy Infringement Report Center: 118 (privacy.kisa.or.kr)
- Supreme Prosecutors' Office Cybercrime Investigation Division: 1301 (www.spo.go.kr)
- Korean National Police Agency Cyber Bureau: 182 (cyberbureau.police.go.kr)
Article 16 (Amendments to This Privacy Policy)
Effective Date
- Company: ChartIQ
- CEO: Jaeho Park
- Business Registration No.: 794-29-01712
- Telecommunications Business Report No.: 2025-Hwaseong-Dongtan-0919
- Address: Unit 1201, Bldg 101, 295 Dongtanjiseong-ro, Hwaseong-si, Gyeonggi-do, South Korea
- Email: hermora.tarot@gmail.com