Munyeo

Munyeo Privacy Policy

Last updated: 2026-09-12

  1. Controller. Cabotine (카보틴), 14F, 100 Mokdongjungangnam-ro, Yangcheon-gu, Seoul, Republic of Korea. Privacy contact: support@munyeo.app. Data Protection Officer / 개인정보 보호책임자: Yewon Kim (김예원), support@munyeo.app.
  2. What we collect and why.
    DataWhenPurposeLegal basis (GDPR)Retention
    Account identifier (Apple/Google ID token, e-mail)You sign inAccount, sync with companion app, couponsContractUntil account deletion + 30 days
    Birth date; optional birth time, birthplace, sex; a label you choose (for you or another person)You create a profile while signed inCalculate readings you requestContract (yours); your responsibility for others' consentUntil you delete the profile or account. Guests: stored only in your browser, not on our servers
    Compatibility invite: your birth details (and a label)You create a compatibility invite linkCalculate the compatibility reading once the other person completes itContract (yours); the other person's consent is your responsibilityYour birth details, until the reading is generated; both labels, until the invite is purged (expiry + 1 day, at most 15 days). The other person's birth details are used for the calculation only and are not stored
    Order metadata (product, tier, price, payment reference, status)You purchaseDeliver, support, accountingContract; legal obligation (tax)Statutory retention (Korea: 5 years for e-commerce records)
    Reading metadata (product, topic, language, time) and journal lines you saveYou get a reading / save a lineShow your history, sync to the appContractUntil deletion. Reading body text is not stored in our database; a copy of the generated reading text and any PDF (paid tiers) is kept in our file storage for 30 days so the same reading can be shown again, or while your account exists if signed in. Guest readings (derived results, your question, the generated text) are kept on our servers for 30 days; guest birth details are not stored on our servers
    Your resonance marks and wish-fulfilled marks (no wish text)You mark themYour journal; anonymized countsContract; legitimate interest (aggregate counts)Until deletion; aggregates kept indefinitely
    Push token, device identifier (companion app)You enable notifications / sign in on the appNotifications; abuse preventionConsent; legitimate interestUntil you disable or delete
    Salted hash of your IP address (stored with free readings and compatibility invites)You request a free reading or create a compatibility invite linkAbuse prevention (daily free-reading and invite limits)Legitimate interestCleared after 90 days; guest readings are deleted after 30 days; invite copies are purged with the invite (expiry + 1 day, at most 15 days)
    Launch notification list: e-mail, browser language, salted hash of your IP addressYou sign up on the coming-soon pageSend one launch-announcement e-mail; abuse preventionConsentUntil the launch e-mail is sent + 90 days; if no e-mail is sent, 12 months from sign-up; the unsubscribe link in the e-mail removes you within a day
    Technical logs (IP, user agent, timestamps)You use the siteSecurity, error diagnosisLegitimate interest90 days
    Anonymous wish stories you opt in to shareYou opt inDisplay on MunyeoConsentUntil you withdraw

    We do not use third-party advertising or analytics SDKs.

  3. How readings are generated. Your exact birth date and time are processed by our own calculation code. Only the derived results (e.g., pillars, planetary positions, card draws) and your question text are sent to language-model providers to compose the reading. Providers used: OpenAI API and Anthropic Claude API via Cloudflare AI Gateway; they do not receive your name, e-mail, birth date, or profile labels.
  4. Who else processes your data. Hosting and database: Supabase (United States, us-east-1); edge/CDN/files: Cloudflare; payments: Dodo Payments as merchant of record (they collect your payment details directly — we never see card numbers); e-mail delivery: Supabase Auth via Resend (sign-in links and account e-mails). Data may be processed outside your country; transfers rely on the providers' standard contractual clauses as applicable. Korea: see §9 for overseas transfer notice.
  5. Cookies and storage. Strictly necessary cookies (session, language) and browser storage for guest profiles. No advertising cookies. A consent banner is shown where required.
  6. Your rights. Access, correction, deletion, portability, restriction, objection, and withdrawal of consent, via support@munyeo.app or in-app settings. Account deletion is processed within 30 days; transaction records are kept for the statutory period. You may complain to your local supervisory authority (Korea: PIPC; EU: your national DPA).
  7. Children. Munyeo is not directed to children under 16 and does not knowingly collect their data. Purchases require 18+.
  8. Security. Encryption in transit and at rest, row-level access controls, least-privilege keys, no reading text in our database (30-day file-storage copies only).
  9. Notice for Korean users (개인정보 보호법). 수집 항목·목적·보유기간은 위 표와 같으며, 출생시각·출생지는 선택 항목입니다. 국외 이전: Supabase(미국)·Cloudflare(글로벌)·결제사 Dodo Payments — 이전 목적은 서비스 제공·결제, 보유기간은 위 표와 동일. 개인정보 보호책임자: 김예원(support@munyeo.app). 이용자는 열람·정정·삭제·처리정지를 요구할 수 있습니다.
  10. Changes. We post updates here with the date; material changes are notified in-app or by e-mail.

Operator: Cabotine (카보틴), sole proprietorship, Republic of Korea · Business Registration No. 106-38-52134 · Mail-order Business Report No. 2026-Seoul Yangcheon-0788 · Contact: support@munyeo.app