Skip to main content
HACHIMI AI

Privacy Policy

Last updated: July 21, 2026

Master Hachimi (哈基米道长)

Master Hachimi (“the App”), brand Hachimi.ai, is operated by the Hachimi.ai team (“we”, “us”; the operating entity is named in the contact section at the end of this policy). This Privacy Policy explains what data the App processes, why, and your rights. Please understand how the App works first. You provide two numbers and write the question on your mind; our unified server performs a fixed Mei Hua Yi Shu (Plum Blossom divination) cast, and a third-party AI model then generates the reading in the voice of “Master Hachimi”. Unlike many purely on-device divination utilities, generating a reading necessarily sends your question and the cast to our server, which forwards them to a third-party AI service. The nature of that service, and what we require of it, are set out in section 3. This policy discloses that accordingly.

1. Summary

• The cast turns your numbers into a hexagram, a fixed computation performed off-device; the reading is generated by a third-party AI service. Your question, chosen scenario, the two cast numbers, and time-of-day are sent to our server for casting; thereafter only your question, chosen scenario, the resulting hexagram, and time-of-day are forwarded to the third-party AI service to generate the reading. The two cast numbers are not sent to that third-party service. • What you asked and the reading are stored on our server under an anonymous install identifier, with free-text content kept for at most 90 days, only to improve reading quality (a single explicit consent on first launch; using the App means collection under that consent; your recourse is resetting the anonymous identifier in Settings at any time, plus the 90-day automatic deletion; see sections 4 and 5). • “Master Hachimi’s Memory” (memory episodes and your focus profile) stays only on your device; the server keeps no memory store; at most 3 relevant episodes travel transiently with a cast request to shape that one reading and are discarded after processing (see section 4). • We do not sell your data, do not use it for advertising, and do not track you across other apps or websites; we use no advertising identifier or IDFA, and no App Tracking Transparency. • No account is required to use the App.

2. Data we process

• Your question, the free text you type, is the subject of the divination. It is sent to our server on each cast and forwarded to the third-party AI service to generate the reading; it is also used to improve reading quality; the server stores it under an anonymous install identifier (a single explicit consent on first launch; using the App means collection under that consent), with the text kept for at most 90 days before automatic deletion (see section 4). Your reading history, which includes the question, always stays on your device. • Your chosen scenario, one of find-item, love, career, or open question, selects the reading's focus and tone. It is sent with the question to the server and included in the prompt forwarded to the third-party AI service; it is stored with the event per section 4, and is stored on your device as part of history. • Two cast numbers and the local time-of-day drive the fixed cast, setting the upper and lower trigrams and the changing line. They are sent with the question to the server; stored with the event per section 4; history is stored on your device. • Your feedback on a reading (thumbs up / down) flags reading quality so real unsatisfying samples can help improve the readings. It is sent alongside the corresponding cast event (withdrawing consent stops all uploads); it stays in your local history, and the server-side vote contains no text and is kept as anonymous statistics. • The anonymous install identifier, a random UUID generated on first launch, groups events from the same installation to observe overall quality trends and is never linked to your identity. It is sent with every cast request; its link to stored events is automatically severed after 90 days, and you can reset it in Settings at any time. • Master Hachimi’s Memory (episodes and your focus profile) lets readings pick up threads you asked about before. Episodes and the profile themselves stay only on your device and are deleted in cascade with your history; while the Memory is on, at most 3 relevant episodes and the theme profile travel transiently with that cast request and are forwarded to the third-party AI service solely to shape that one reading, then discarded and never stored; the server keeps only content-free counts such as how many episodes a request carried. Turning the Memory off, choosing “no need to remember this one”, or casting via “Asking for someone else” sends no memory at all. • Reading history, meaning the chart, reading, time, and question, is stored on your device only, so you can review past readings. • Selected language and settings are app preferences, stored locally on your device. • Usage statistics (anonymous daily counts) tell us whether features are actually used and whether a new version keeps people coming back. They are daily counts of nine actions from a closed list: opening the App, seeing a reading, collecting a waiting result, going back home mid-ritual, ending a cast, browsing history, using export, and turning Master Hachimi’s Memory on or off, recorded only as “on this day, this action, in this scenario, happened N times”, with no timestamps and none of the text you write. They are uploaded to our server with the anonymous install identifier; retention is described in section 4. • Crash diagnostics (iOS system mechanism only) help us find and fix defects that crash the App. They are generated after a crash by Apple’s built-in MetricKit framework and contain purely technical information such as the call stack and the OS and App versions, none of your content, and no anonymous install identifier from the moment of collection, so they cannot be linked to any installation. They are uploaded only to our own server; retention is described in section 4. We do not collect: your name, email, contacts, photos, precise location (GPS), or any advertising identifier (IDFA). The App does not use App Tracking Transparency because it performs no cross-app tracking. “Time-of-day” means your device's current clock hour, used to determine the changing line; it is not GPS positioning. On health and finances: the App does not read HealthKit, medical records, bank accounts, or any structured health or financial data, and never asks you for any. But what you write is free text, and you may well mention your body, a diagnosis, your salary, or a debt in it. Those words are handled as part of your question, on exactly the same terms as any other free text in this section: forwarded per section 3 to generate a reading, retained and deleted per section 4. So write only what you want to write; you do not owe the App a detail you would rather keep.

3. Third-party AI reading (core feature · App Store Guideline 5.1.2(i))

To generate the “Master Hachimi” reading, on each cast the App sends your question, chosen scenario, the cast, and the time-of-day to our own server (a thin proxy; client device-integrity attestation is planned, see section 7). The server performs the fixed cast and then forwards the hexagram, your question, and the chosen scenario to a third-party AI service to generate the reading text. What matters is not which AI model is behind the scenes, but how it handles your content. The nature of, and our commitments about, any service we use are set out at the end of this section. • Explicit permission: Before your first cast, the App shows a consent screen that clearly states what will be sent and the recipients (our server + the third-party AI service), and also discloses that what you ask will be used to improve reading quality (the event storage described in section 4). Nothing is sent without your consent. • Revocable: You can withdraw consent at any time in Settings. After withdrawal the App sends no further data and therefore cannot generate new readings (the product has no offline reading mode); your existing local history is unaffected. Withdrawing consent also stops all event and feedback uploads. • The provider acts as a service provider: the third-party AI service processes the content as a service provider / data processor to provide the reading service to us, and we have required that it not use your content to train its own models (see the end of this section). • Minimization: we send the third-party AI service only what is needed to generate the reading (your question + chosen scenario + cast + time-of-day). We do not send your identity, device identifiers, or location to it. Once enabled, the device-attestation token used for anti-abuse will be sent only to our server, never to the third-party AI service, and will not be used for tracking. The nature of the third-party AI service, and our commitments: we use only a reputable commercial, paid-tier third-party AI service (an enterprise paid API, never a free tier or a consumer-grade product). Only your question, chosen scenario, hexagram, and time-of-day are forwarded to it. The service processes this content as our service provider (data processor), solely to provide the reading service and for no other purpose; we have required that it not use your content to train or improve its models, and required that it not sell personal data, not use it for targeted advertising, and not build user profiles. What matters is not which model is behind the scenes. We may change such a service or use more than one (for example, to route requests) as our needs evolve, and the standards above apply uniformly to every such service; as long as those standards still hold, the consent you have given remains valid and this policy does not need to change.

4. Backend and data retention

• We operate a unified server to receive cast requests, run the fixed cast, and forward to the third-party AI service. To improve reading quality, this server stores cast events as a pseudonymous minimal set: each cast's question, chosen scenario, hexagram, and reading are stored in our own database together with the anonymous install identifier (using the App means collection under the single explicit consent given on first launch; there is no separate switch; if you do not consent, the sending features are simply not used). Your controls are: the first-launch consent (revocable, see section 3) + resetting the anonymous identifier at any time (past events are immediately unlinked) + the 90-day automatic deletion. • 90-day rolling deletion: the question text, any clarification, the full reading text, and the link to the install identifier are automatically deleted or severed by a daily task once a record is 90 days old; after that, only anonymous statistical rows containing no free text remain (scenario distribution, response latency, feedback rates) for long-term quality trends. • Quality-evaluation samples: a small number of thumbs-down readings may be selected as internal evaluation material; before use they must be manually rewritten and de-identified (turned into semantically equivalent synthetic cases, never keeping your original wording verbatim), and only the rewritten version enters the evaluation set. • No third-party analytics: all of the above runs on our own infrastructure, with no third-party analytics, advertising, or crash-reporting SDKs. Purposes are explicit and limited: improving reading quality with real failure samples, making follow-up questions and question understanding more accurate, and refining how different scenarios are handled; never for advertising, profiling, or sale. • Master Hachimi’s Memory (on-device memory): episodes and your focus profile stay only on your device; the server keeps no memory store. Each reading is distilled on your device into a “memory episode” (a theme plus a one-line gist, including any outcome or note you add); deleting a history record deletes its episode with it. When you cast, at most 3 relevant episodes (including the original question, clipped to 200 characters on-device) and the theme profile travel with that request and are forwarded to the third-party AI solely to shape that one reading, then discarded and never stored; the server-side event keeps only content-free counts such as how many episodes the request carried. Turning the Memory off, choosing “no need to remember this one”, or casting via “Asking for someone else” sends no memory at all. The “focus profile” here is a theme tally computed only on your device; unrelated to the advertising / marketing profiling that “never for profiling” above refers to; the server never aggregates a profile of you. • Cast admission and daily counts: to connect one cast to the reading that follows it, and to enforce the daily cast limit, the server stores an admission record containing only the anonymous install identifier, a timestamp, and a status; it is deleted automatically after at most 8 days. The daily count is just a number per day and is kept for 2 days. Neither contains anything you wrote. • Retention of usage statistics and crash diagnostics: the daily usage counts are kept long-term as anonymous statistics containing no free text, to observe overall trends; the activity records used to estimate next-day and seven-day return are kept under the anonymous install identifier for at most 8 days, after which a daily task strips the identifier, leaving only identifier-free per-day headcounts. Raw crash diagnostics are deleted automatically after 90 days, with only identifier-free daily counts kept long-term. Both stay entirely on our own infrastructure, are never sent to any third party, and are never linked or joined with the cast events described in section 2. • A cast stopped by a safety topic: if what you write touches on a crisis, physical or mental health, or financial hardship, the App switches to a static page of information and generates no reading. In that case we store neither your question nor any generated text; only the admission record described above exists, and it still expires within 8 days. • Readings you report: when you report a reading in the App, the reported reading text, your reason, and an optional note are uploaded so a human can review them and tighten our limits. That queue is deleted automatically after 30 days and never contains your original question. Nothing is uploaded unless you report. • Short-lived data that stays on your device: a draft you have not cast yet is kept for at most 30 days, and a cast that was started but not yet read is kept for at most 7 days; both are then cleared automatically. Both live in a directory excluded from system backups; the question you are in the middle of asking should not be copied into an old backup you no longer control. • Reading history and memory episodes do travel in system backups: they live in the App's regular data area, so they are included in the encrypted, system-managed backup on iOS or Android. That exists so your history survives a new phone. It is not cloud sync by us; we cannot see backup contents, and there is no account. “Delete on-device data” in Settings clears this device's copy; it cannot delete backups already held by Apple or your Android vendor, which you must remove yourself in the system's backup management. • Reading history is stored only on your device. Deleting a record or deleting the App removes it; we provide a “Delete all history” action in Settings. • Retention on the third party: the third-party AI service retains and processes the content it receives under its own terms (we have required that it not use your content to train its models; see section 3). To request deletion of content already sent to it, contact us at voice@hachimi.ai and we can initiate a request on your behalf.

5. Your rights

Depending on where you live (EU/EEA under GDPR, California under CCPA/CPRA, Hong Kong under PDPO, and others), you have rights to access, correct, and delete your personal data, to object to or restrict processing, and to withdraw consent at any time. • Withdraw consent: turn off the third-party AI reading consent toggle in Settings (see section 3); after withdrawal nothing further is sent and no new events are stored. • Access / portability / deletion: the App has no account; server-side events are keyed only to a resettable anonymous install identifier that we cannot link back to you, so we cannot provide per-person access to or export of server-side copies. The reading history on your device is fully under your control; you can view and delete it in-app. Uploaded event text is kept for at most 90 days and then automatically deleted per section 4, and resetting the identifier in Settings immediately unlinks past events from your installation. • GDPR: the lawful basis for sending your question and cast to the third-party AI is your consent, which you may withdraw at any time. • CCPA/CPRA: we disclose your question only for a business purpose to the third-party AI service acting as a service provider, which is not a “sale” or a “share” for cross-context behavioral advertising. • PDPO (Hong Kong): we collect only data needed for the App's function, use it only for that purpose, and apply transport encryption (TLS) to all network calls (device attestation is planned). For any request or question, contact us using the details below; we will respond within the time limits required by applicable law.

6. Age

The App is intended for users aged 13 and older. It is not directed to children under 13 and does not knowingly collect personal data from them. The store age rating, the in-app wording, and this policy all say the same thing.

7. Security

All network calls use standard HTTPS/TLS; client device-integrity attestation (App Check / App Attest) to deter abuse is planned (not yet enforced at launch). Upstream AI service keys are held only on our server and are never shipped to or embedded in the client.

8. Changes

We may update this policy; the “Last updated” date will change. Material changes will be surfaced in the App.

9. Contact

Yuenchuk Investment Limited, Hong Kong Email: voice@hachimi.ai