Mystic Mirror
Privacy Policy
Last updated: June 6, 2026
Mystic Mirror is a self-exploration and divination tool built on deterministic ancient wisdom systems and AI interpretation. This policy explains what personal information we collect, how we use it, and your rights.
Data We Collect
Birth Data
Your date of birth, birth time, and birth location are used to calculate charts (BaZi, Ziwei Doushu, Western astrology, numerology, and related systems). This data is stored in your profile and used only to generate and store your readings. We do not sell or share birth data with third parties for advertising or analytics.
Profiles You Create for Other People
If you create a chart or reading for another person, we may process the name or label you provide, that person's birth date, birth time, birth location, relationship context, and any related questions you submit. Only provide another person's data when you have a lawful reason and permission to do so.
Chat and Reading History
Messages you send to the AI oracle and the interpretations it generates are stored to support continuity across sessions. You may delete this data at any time from your account settings.
Payment Information
Payments are processed by Creem. We do not store full card numbers or raw payment credentials. We retain transaction identifiers, subscription status, and credit balance to deliver entitlements and handle support.
Authentication Identity
Login and identity management is handled by Auth0. We receive a user identifier, email address, and optional display name from your authentication provider. We do not store passwords.
Device and Network Data
Cloudflare and our own systems may process IP address, request metadata, user-agent strings, timestamps, error logs, and security events to route traffic, protect the service, and investigate abuse or reliability issues.
Usage Telemetry
We collect anonymized usage signals (page views, feature interactions, error reports) to improve the product. Telemetry does not include your birth data or chat content.
Sensitive and Inferred Information
Some information we process may be considered sensitive personal information in certain jurisdictions, including precise birth place or coordinates, gender, inferred ethnicity or spiritual/personality profile, and relationship or wellbeing context you choose to enter. We use this information only for the requested reading, account continuity, security, and legally required records.
How We Use Your Data
We use your data to: deliver your personalized readings and interpretations; maintain your credit and subscription entitlements; provide account access and authentication; improve reliability and product quality; and respond to support requests. We do not use your data to train third-party AI models without your explicit consent.
Data Retention
We retain different categories of data for different periods depending on their legal and operational purpose. The table below reflects our internal data retention contract.
| Data type | Retention period | Deletion trigger |
|---|---|---|
| Account & birth profile | Until account deletion | User-initiated account deletion |
| Chat & calculation history | 2 years (730 days) | Account deletion or scheduled expiry |
| Calculation cache | 90 days from last access | Auto-expiry; account or person deletion |
| Payment records | 7 years (legal hold) | Anonymized on account deletion; metadata minimized after 7 years |
| Telemetry & share access logs | 90 days | Auto-expiry; anonymized on account deletion |
| Audit & security logs | 7 years | Retained for legal compliance, not user-deletable |
Subprocessors and AI Providers
We use the following third-party services to deliver Mystic Mirror:
- Auth0 (Okta) — authentication and identity management
- Creem — payment processing, tax compliance, and subscription management
- Stripe — payment processing, refunds, invoices, and subscription management where configured
- Cloudflare — content delivery, DNS, DDoS protection, and backups stored in Cloudflare R2 (Eastern North America region)
- DigitalOcean — application hosting and database infrastructure
- OpenRouter — active AI inference router for interpretation and chat responses. Production routing is restricted to AtlasCloud and Parasail sub-providers, denies provider-side data collection, and disables OpenRouter fallbacks so China-hosted providers and other ignored providers are not used.
- SiliconFlow (siliconflow.cn) — historical China-hosted AI provider entry; disabled for active production routing unless a future consent-gated legal path is approved
- Z.ai — historical China-hosted AI provider entry; disabled for active production routing unless a future consent-gated legal path is approved
- BigModel (bigmodel.cn) — historical China-hosted AI provider entry; disabled for active production routing unless a future consent-gated legal path is approved
AI providers may receive the text of your query and the minimum chart/session context needed to generate the requested interpretation. This may include birth date, birth time, birth place, timezone, names or labels you provide, gender, prior chat context, and derived chart data. We do not send raw payment credentials to AI inference providers.
Your Rights
Depending on your location, you may have the right to: access a copy of your data; correct inaccurate information; delete your account and associated data; export your data in a portable format; withdraw consent for optional data uses; opt out of sale or sharing where applicable; and limit the use of sensitive personal information where applicable. To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
California Privacy Notice
This section is intended for California residents and explains how Mystic Mirror handles personal information under CCPA/CPRA.
Sensitive personal information categories
Mystic Mirror may process sensitive personal information such as precise birth place or coordinates, gender, relationship context, and inferences from BaZi, Ziwei Doushu, astrology, numerology, tarot, I Ching, or related systems. We use these categories to provide requested readings, preserve account history, secure the service, and maintain required records.
Sale or sharing
We do not sell personal information for money. We do not share birth data, chart data, or chat content for cross-context behavioral advertising. Transfers to AI inference providers are used to generate requested interpretations and require service-provider or contractor terms before regulated-market launch; until those terms are fully executed, this remains an implementation dependency.
Limit use of sensitive personal information
You may ask us to limit use of sensitive personal information to what is necessary to provide requested readings, maintain security, and meet legal obligations. Contact [email protected] with the subject line "Limit SPI".
Global Privacy Control
We honor browser-based opt-out preference signals such as Global Privacy Control when they are detected by this browser or by request headers. You can also review or change cookie and privacy choices from Account > Data & Privacy.
AI-Generated Content and AI Providers
Interpretations, oracle responses, and insight text on Mystic Mirror are generated by AI language models. The interface includes an AI-generated content notice. These outputs are for self-reflection and exploration. They are not predictions, professional diagnoses, or authoritative statements about your life, health, finances, or relationships.
Inputs sent to AI providers
When you request an AI interpretation, we may send your user message, selected chart data, birth date, birth time, birth place, timezone, latitude/longitude where available, names or labels you provide, gender, relationship context, prior chat context, and derived divination profile needed for the response. We do not send raw card numbers or payment credentials.
Providers and locations
Current AI inference routing uses OpenRouter as the active inference router, restricted in production to AtlasCloud and Parasail sub-providers with provider-side data collection denied and OpenRouter fallback disabled. SiliconFlow, Z.ai, and BigModel remain listed only as historical China-hosted entries and are disabled for active production routing unless a future consent-gated legal path is approved. Auth0, Creem, Stripe, Cloudflare, and DigitalOcean may also process account, payment, hosting, or network data from the United States or global infrastructure.
Consent and legal basis
AI processing is used to perform the reading or chat feature you request. For jurisdictions that require explicit consent for AI-provider processing or cross-border transfer, the intended mechanism is a granular consent gate covering AI processing and cross-border transfer before the first AI interpretation. Until that consent gate and provider contracts are fully implemented, this notice identifies the intended consent path and remaining implementation dependency.
Opt-out and withdrawal
You may opt out of AI interpretation by not using AI-powered readings or chat features, and you may contact [email protected] to withdraw consent for optional AI processing. Withdrawal does not undo processing that already occurred lawfully, but it will limit future access to AI-powered features.
Automated decisions
Mystic Mirror does not use AI output to make legal, financial, employment, housing, credit, insurance, healthcare, or similarly significant decisions about you. Divinatory and reflective outputs are generated for self-exploration and do not determine your rights or access to essential services.
Cross-Border Data Transfer
Mystic Mirror operates globally. Your data may be processed by subprocessors located outside your country. Backups are pinned to Cloudflare R2 ENAM (Eastern North America) and stay in the United States. Application hosting is currently documented as DigitalOcean infrastructure in the United States. For EEA or UK personal data transfers where required, the intended transfer mechanism is the European Commission Standard Contractual Clauses under Commission Implementing Decision (EU) 2021/914, using the applicable module for the parties' roles. For Singapore personal data transfers where required, the intended mechanism is the PDPC Model Contractual Clauses or another legally enforceable mechanism providing comparable protection. AI inference is currently documented around OpenRouter with production routing restricted to AtlasCloud and Parasail sub-providers, provider-side data collection denied, and OpenRouter fallback disabled. Historical China-hosted AI providers remain disabled for active production routing unless a future consent-gated legal path is approved. If you are in the EU, Singapore, Canada, California, or another jurisdiction with transfer restrictions, please contact us before using AI interpretation features.
Singapore Privacy Addendum
This addendum is intended for Singapore users under the Personal Data Protection Act 2012 (PDPA) and should be read together with the rest of this Privacy Policy.
PDPA s.20 openness: policies and practices
Under PDPA s.20 and the PDPC Accountability/Openness guidance, we make information about our personal data policies, practices, and complaint process available in this Privacy Policy. The data categories, purposes, retention table, subprocessor register, AI disclosure, and cross-border transfer sections describe how we collect, use, disclose, retain, protect, and transfer personal data. For more detail, review those sections on this page or contact us at [email protected].
PDPA s.21 access and correction
Singapore users may request access to personal data we hold about them, information about how it has been used or disclosed within the relevant lookback period required by PDPA s.21, and correction of inaccurate personal data. Use /account/data for self-service export, deletion, and correction controls, or contact [email protected] if the account page cannot handle the request.
PDPA s.13 consent and withdrawal
Where we rely on consent under PDPA s.13, you may withdraw consent with reasonable notice. Use the ConsentGate choices and account settings at /account to disable optional AI-provider processing, marketing, or other optional data uses where available. Withdrawal does not undo processing that already occurred lawfully, but we will stop the affected optional collection, use, or disclosure after processing the withdrawal and explaining any product consequences.
PDPA s.26 cross-border transfers
For Singapore personal data transferred outside Singapore, PDPA s.26 requires comparable protection through prescribed or legally enforceable mechanisms unless an exception applies. Where applicable, Mystic Mirror intends to use the PDPC Model Contractual Clauses, ASEAN Model Contractual Clauses for Cross Border Data Flows, or another legally enforceable transfer mechanism. Current subprocessors and AI-provider locations are described in the subprocessor register and cross-border transfer section.
PDPC complaints and internal contact
Please contact us first at [email protected] so we can review and respond to your concern. Singapore users may also lodge data protection or DNC complaints with the PDPC through the official portal at https://www.pdpc.gov.sg/Complaints-Reviews-and-Investigations/Complaints or the current PDPC complaints page at https://www.pdpc.gov.sg/complaints-and-reviews.
Do Not Call Registry
Mystic Mirror does not send marketing SMS or telemarketing calls in Singapore. If that changes, we will update this section, check applicable Singapore telephone numbers against the DNC Registry where required, honor clear opt-outs, identify the sender, and comply with the PDPA DNC provisions and PDPC guidance before sending marketing calls, text messages, or faxes.
Mandatory data breach notification
For Singapore notifiable data breaches under the PDPA 2020 amendments, Mystic Mirror will assess suspected data incidents without undue delay and, where notification is required because the breach is likely to result in significant harm or is of significant scale, notify the PDPC as soon as practicable and no later than 72 hours / three calendar days after determining that the breach is notifiable. Where individual notice is required, we will notify affected users as soon as practicable, at the same time as or after notifying the PDPC.
Rights of Third Parties Whose Data Was Uploaded by Others
If you discover that another Mystic Mirror user uploaded your personal data (e.g., birth date, time, place) without your consent, you have the right to request access, correction, or deletion of that data. Email [email protected] with: (a) your name, (b) any identifying details that may match the uploaded record (date / location / who likely uploaded), and (c) the action you want — access, correction, or deletion. We will respond within 30 days under PDPA s.21 / s.22 (Singapore) and equivalent rights under GDPR Art.15-17 / CCPA Section 1798.105. We may need to verify your identity before acting.
Contact
For privacy questions or rights requests, contact us at [email protected]. For general support, use [email protected].
You can opt out of marketing communications at any time by contacting support or using the unsubscribe link in any marketing email.