Privacy Policy
Last updated: September 17, 2026
Master Hachimi (哈基米道长)
Master Hachimi (“the App”), brand Hachimi.ai, is operated by the Hachimi.ai team (“we”, “us”; the operating entity is named in the contact section at the end of this policy). This Privacy Policy explains what data the App processes, why, and your rights.
Please understand how the App works first. You provide two numbers and write the question on your mind; our unified server performs a fixed Mei Hua Yi Shu (Plum Blossom divination) cast, and a third-party AI model then generates the reading in the voice of “Master Hachimi”. Unlike many purely on-device divination utilities, generating a reading necessarily sends your question and the cast to our server, which forwards them to a third-party AI service. The nature of that service, and what we require of it, are set out in section 3. This policy discloses that accordingly.
1. Summary
• Online question casting runs deterministically on our backend. DeepSeek Open Platform receives the question and clarification, scenario, derived hexagram, time index, language and selected context to generate a reading, without the original numbers; the casting instant, time zone and public calendar pillars supply time context. See §3 for the full categories. Offline charts run locally and do not require AI consent.
• What you asked and the reading are stored on our server under an anonymous install identifier, with free-text content kept for at most 90 days, only to improve reading quality (explicit consent before the first actual online reading; using the App means collection under that consent; your recourse is resetting the anonymous identifier under Me → Privacy and data at any time, plus the 90-day automatic deletion; see sections 4 and 5).
• “Master Hachimi’s Memory” (memory episodes and your focus profile) stays only on your device; the server keeps no memory store; at most 3 relevant episodes and 8 active profile evidence entries for the same case travel transiently with a cast request to shape that one reading and are discarded after processing (see section 4).
• We do not sell your data, do not use it for advertising, and do not track you across other apps or websites; we use no advertising identifier or IDFA, and no App Tracking Transparency.
• No account is required to use the App.
2. Data we process
• Your question, the free text you type, is the subject of the divination. It is sent to our server on each cast and forwarded to the third-party AI service to generate the reading; it is also used to improve reading quality; the server stores it under an anonymous install identifier (explicit consent before the first actual online reading; using the App means collection under that consent), with the text kept for at most 90 days before automatic deletion (see section 4). Your reading history, which includes the question, always stays on your device.
• Your chosen scenario, one of find-item, love, career, or open question, selects the reading's focus and tone. It is sent with the question to the server and included in the prompt forwarded to the third-party AI service; it is stored with the event per section 4, and is stored on your device as part of history.
• Two cast numbers and the local time-of-day drive the fixed cast, setting the upper and lower trigrams and the changing line. They are sent with the question to the server; stored with the event per section 4; history is stored on your device.
• Your feedback on a reading (thumbs up / down) flags reading quality so real unsatisfying samples can help improve the readings. It is sent alongside the corresponding cast event (withdrawing consent stops all uploads); it stays in your local history, and the server-side vote contains no text and is kept as anonymous statistics.
• The anonymous install identifier, a random UUID generated on first launch, groups events from the same installation to observe overall quality trends and is never linked to your identity. It is sent with every cast request; its link to stored events is automatically severed after 90 days, and you can reset it under Me → Privacy and data at any time.
• Master Hachimi’s Memory (episodes and your focus profile) lets readings pick up threads you asked about before. Episodes and the profile themselves stay only on your device and are deleted in cascade with your history; while the Memory is on, at most 3 relevant episodes and 8 active profile evidence entries for the same case and the theme profile travel transiently with that cast request and are forwarded to the third-party AI service solely to shape that one reading, then discarded and never stored; the server keeps only content-free counts such as how many episodes a request carried. Turning the Memory off, choosing “no need to remember this one”, or casting via “Asking for someone else” sends no memory at all.
• Reading history, meaning the chart, reading, time, and question, is stored on your device only, so you can review past readings.
• Selected language and settings are app preferences, stored locally on your device.
• Usage statistics (anonymous daily counts) tell us whether features are actually used and whether a new version keeps people coming back. They are daily counts of nine actions from a closed list: opening the App, seeing a reading, collecting a waiting result, going back home mid-ritual, ending a cast, browsing history, using export, and turning Master Hachimi’s Memory on or off, recorded only as “on this day, this action, in this scenario, happened N times”, with no timestamps and none of the text you write. They are uploaded to our server with the anonymous install identifier; retention is described in section 4.
• Crash diagnostics (iOS system mechanism only) help us find and fix defects that crash the App. They are generated after a crash by Apple’s built-in MetricKit framework and contain purely technical information such as the call stack and the OS and App versions, none of your content, and no anonymous install identifier from the moment of collection, so they cannot be linked to any installation. They are uploaded only to our own server; retention is described in section 4.
• Derived summary of the selected chart profile (natal year/month/day/hour pillars, day master, yin/yang, strength, pattern, seasonal balancing elements, gender, and ten-year age band): Lets the reading use the chart background explicitly selected for that question: Transiently: forwarded through our backend to DeepSeek; profile name, birth details and location are not sent: Used for that reading and not stored as a profile library; the complete profile stays on the device and in system-managed backups
Company servers do not receive chart-profile names, birth details or locations, email, contacts, photos, precise location (GPS), or any advertising identifier (IDFA). Names, birth details and birthplaces you choose to enter in the profile library are used for on-device chart calculation and may be included in system-managed device backups; when a profile is selected for a question, only the derived summary listed above is sent. The App does not use App Tracking Transparency because it performs no cross-app tracking.
On health and finances: the App does not read HealthKit, medical records, bank accounts, or any structured health or financial data, and never asks you for any. But what you write is free text, and you may well mention your body, a diagnosis, your salary, or a debt in it. Those words are handled as part of your question, on exactly the same terms as any other free text in this section: forwarded per section 3 to generate a reading, retained and deleted per section 4. So write only what you want to write; you do not owe the App a detail you would rather keep.
3. Third-party AI readings and consent
Our backend receives your current question and clarification, scenario, two numbers, precise casting time and time zone, language, random installation and request identifiers, consent version, and necessary authentication and entitlement fields to cast, prevent abuse, and provide readings. Optional memory and chart context described below are included when enabled or selected.
3.1 Recipient and data sent
The recipient is DeepSeek Open Platform (DeepSeek). It receives the current question and clarification, scenario focus, output language, derived hexagram and time index, plus the frozen casting instant, IANA time zone, local civil time, public year/month/day/hour pillars, actual UTC offset and calendar rule version.
When memory is enabled and not paused for the selected case, it also receives safety-filtered statistics, up to three past questions, summaries, themes, elapsed days, hexagram numbers and feedback outcomes for that case. Up to eight active profile evidence entries include their topic, content, statement or inference basis, elapsed days and correction status. A selected chart supplies its locally computed natal year/month/day/hour pillars, day master, yin/yang, strength, pattern, seasonal balancing elements, gender and ten-year age band, plus personal Da Yun status, pillars, interval boundaries, fixed birth-clock offset, input precision, calculation rules and engine versions.
Original cast numbers, case-library names, birth details and locations, installation or request IDs, authentication tokens, subscription credentials, consent records and local feedback notes are not forwarded as fields. Anything entered in the question or clarification is sent as written. Processing and retention follow the applicable provider terms and account settings. Changes to recipients, fields or purposes require updated disclosure and renewed consent.
Natal pillars, personal period boundaries and birth-clock offsets may narrow down a birth-time range even though no raw birth date or time is sent.
3.2 Permission and withdrawal
Without a question, casting produces only a deterministic result. It does not call DeepSeek, use memory profiles or require AI consent.
The first-launch guide has a single Get Started button and does not grant permission for online readings. When you first request an online reading, the App explains the data, purposes and recipient, DeepSeek, and offers Agree and Enable Online Readings or Not Now. Once accepted, the same disclosure version is not requested again. Online reading requests are not sent without permission.
In Me > Privacy & Data > Privacy Policy, you can open the full policy and see your permission status. If you have agreed, the bottom of the page offers Stop Online Readings and Withdraw Consent. It has no enable button when permission is absent. Withdrawal stops new AI-reading requests, usage receipts and feedback uploads. The App ends its active session and keeps your input draft; late responses are not saved to history. Requests already sent cannot be guaranteed to stop remotely, and existing server records remain subject to their retention periods. You may still explicitly submit a content report.
Withdrawal does not delete local history or affect offline charts and local data. To use online readings again, explicitly choose Agree and Enable Online Readings when requesting a reading.
4. Backend and data retention
• The Company operates a unified backend to receive cast requests, run the deterministic cast, and forward to the third-party AI service. To improve reading quality, this backend stores cast events as a pseudonymous minimal set: each cast's question, chosen scenario, hexagram, and reading are stored in the Company's own database together with the anonymous install identifier (using the App means collection under the explicit consent given before an online reading — there is no separate switch; if you do not consent, the sending features are simply not used). Your controls are: online-reading consent (revocable, see §3.2) + resetting the anonymous identifier at any time (past events are immediately unlinked from your installation) + the 90-day automatic deletion.
• 90-day rolling deletion: the question text, any clarification, the full reading text, and the link to the install identifier are automatically deleted or severed by a daily scheduled task once a record is 90 days old; after that, the database keeps only anonymous statistical rows containing no free text (such as scenario distribution, response latency, and feedback rates) for long-term quality trends.
• Quality-evaluation samples: a small number of thumbs-down readings may be selected as internal evaluation material — before use they must be manually rewritten and de-identified (turned into semantically equivalent synthetic cases; your original wording is not kept verbatim), and only the rewritten version enters the evaluation set.
• No third-party analytics: all of the above runs on the Company's own infrastructure; we integrate no third-party analytics, advertising, or crash-reporting SDKs.
• Purposes (explicit and limited): improving reading quality with real failure samples, making follow-up questions and question understanding more accurate, and refining how different scenarios are handled. Never for advertising, profiling, or sale. ("Profiling" here means advertising / marketing user profiles; it is distinct from the on-device "focus profile" of §4.1 — see the disambiguation there.)
• A cast stopped by a safety topic: if what you write touches on a crisis, physical or mental health, or financial hardship, the App switches to a static page of information and generates no reading. In that case we store neither your question nor any generated text; only the admission record above exists, and it still expires within 8 days.
• Short-lived on-device data: input drafts expire after 30 days and are removed on the next read. They are stored in a directory excluded from system backups. Active readings and retry state exist only in memory; after the process exits they are not automatically restored or resent.
• Reading history and memory episodes do travel in system backups: they live in the App's regular data area, so they are included in the encrypted, system-managed backup on iOS or Android, so that your history survives a new phone. This is not cloud sync by us:we cannot see backup contents, and there is no account. "Delete on-device data" in Settings clears this device's copy; it cannot delete a backup Apple or your Android vendor already holds. You remove those yourself (iPhone: Settings → your name → iCloud → Manage Account Storage → Backups; Android: the backup section of system settings, or Google One).
• Reading history is stored only on your device. Deleting a record or deleting the App removes it; we provide a "Delete all history" action in Settings.
• Retention and deletion on the third-party AI service: DeepSeek retains and processes received content under its applicable service terms and account settings. To request deletion of content already sent to the service, contact us at the address below; we can help initiate a request, although content sent without an identity linkage may not be individually locatable.
4.1 Hachimi's Memory (per case)
• Each case has separate memories and a profile. Unassociated casts do not build a shared profile. Online readings may propose evidence grounded in the current input; the device checks sources, expiry and conflicts before assigning entries to that case. Inferences are not established facts. Entries can be viewed, corrected or deleted; memory can be paused per case or disabled globally.
• Only the active, same-case context listed in §3.1 is sent transiently for a reading. Expired or conflicting evidence and entries whose sources were deleted or set aside are excluded. Feedback notes are not sent. Company servers do not store memory content or build a case-memory library. No memory profile is sent without an associated case, with memory disabled, or while the case is paused.
• Deleting a case normally preserves its historical name snapshot in reading history and clears linked memory. Its history can then be explicitly cleared from the deleted-case history filter. Deleting a history record removes its memory and evidence that loses its source. Local deletion does not delete existing external backups or previously sent server records.
• These profiles support readings for the selected case, not advertising, marketing or cross-app tracking.
4.2 Membership and subscription
• Apple handles payment; we never see it: membership is purchased in-app through Apple's in-app purchase. Your name, email, card, and billing address are handled entirely by Apple. We neither receive nor store any of it.
• All we receive is a purchase identifier: to verify your entitlement, the backend receives and briefly caches the purchase identifier Apple issues (an opaque originalTransactionId-style ID that does not link back to your real identity), and uses it only to tell whether you are a member. It is not written into the cast-event store of §4 and is never tied to anything you wrote.
• Membership follows the app store: on iOS your membership belongs to your Apple Account and comes back through Apple after a new device or a reinstall. The App needs no account and creates none. It does not carry over to Android, which is counted by that store on its own.
• Paying changes no chart: casting and chart results are byte-for-byte the same whether or not you are a member. Membership opens finer time layers, the professional BaZi sheet, and more AI readings a day. Nothing else.
5. Your rights
Depending on where you live (EU/EEA under GDPR, California under CCPA/CPRA, Hong Kong under PDPO, and others), you have rights to access, correct, and delete your personal data, to object to or restrict processing, and to withdraw consent at any time.
• Withdraw consent: choose Stop Online Readings and Withdraw Consent at the bottom of Me > Privacy & Data > Privacy Policy (see §3).
• Access / portability / deletion: the App has no account; server-side events are keyed only to a resettable anonymous install identifier that we cannot link back to you, so we cannot provide per-person access to or export of server-side copies. The reading history on your device is fully under your control; you can view and delete it in-app. Uploaded event text is kept for at most 90 days and then automatically deleted per section 4, and resetting the identifier under Me → Privacy and data immediately unlinks past events from your installation.
• GDPR: the lawful basis for sending your question and cast to the third-party AI is your consent, which you may withdraw at any time.
• CCPA/CPRA: third-party AI disclosure provides the reading you request. The Company does not sell your data or use it for cross-app advertising tracking. See §3 for provider processing.
• PDPO (Hong Kong): we collect only data needed for the App's function, use it only for that purpose, and apply transport encryption (TLS) to all network calls (device attestation is planned).
For any request or question, contact us using the details below; we will respond within the time limits required by applicable law.
6. Age
The App is intended for users aged 13 and older. It is not directed to children under 13 and does not knowingly collect personal data from them. The store age rating, the in-app wording, and this policy all say the same thing.
7. Security
All network calls use standard HTTPS/TLS; client device-integrity attestation (App Check / App Attest) to deter abuse is planned (not yet enforced at launch). Upstream AI service keys are held only on our server and are never shipped to or embedded in the client.
8. Changes
We may update this policy; the “Last updated” date will change. Material changes will be surfaced in the App.
9. Contact
Yuenchuk Investment Limited, Hong Kong
Email: voice@hachimi.ai