Datenschutz
Last updated: 9 September 2026
This policy explains what we collect, why we collect it, who we send it to, how long we keep it, and how you control it. It is written around the data flows that actually happen in the product, not from a template.
One thing to know up front: to produce a reading, your profile details and the text you type are sent to a third-party large language model provider; to convert a birth place into coordinates, that place name is sent to a third-party geocoding provider. See section 3.
1. What we collect
1.1 Account information
- Email address or phone number (for sign-in and account recovery)
- Password (stored as an irreversible hash — we cannot see the plaintext)
- Display name and bio (optional, provided by you)
- The avatar you pick (only from FateCode's built-in avatar library — custom or uploaded images are not supported; all we record is which one you chose)
1.2 Profile information
This is the core data of the service, and the most sensitive part of it:
- Name or label
- Gender
- Date and time of birth (to the minute)
- Place of birth, and the longitude and latitude resolved from it
- Notes, tags and relationships you attach to a profile
1.3 Usage content
- The analyses you request and the directions you choose
- The full text of consultation conversations
- The reports generated for you
- Credit balance and consumption records
1.4 Device and log data
- IP address, device model, OS version, app version
- Access times, API call records, error logs
- If the app crashes: the error stack trace along with the app version, OS version and device model at the time. This is written to your device when the crash happens and uploaded the next time you open the app, so that we can locate and fix the fault.
1.5 What we do not collect
We do not collect your contacts, your photo library, GPS location, call logs or SMS content, and we do not read the list of apps installed on your device. Avatars can only be chosen from FateCode's built-in avatar library — custom or uploaded images are not supported, the app never requests photo library permission, and it never reads your photos. The service carries no third-party advertising SDKs, does no cross-site tracking, and gathers no page-view or tap analytics.
2. Why we need the birth place and its coordinates
This is the item most often misunderstood, so it gets its own section.
Charting does not run on clock time. It runs on true solar time — the time the sun actually crosses the local meridian. A country may keep a single standard time zone across a wide span of longitude, and the gap between local true solar time and the clock can exceed an hour.
One degree of longitude is roughly four minutes of true solar time. The hour pillar in BaZi is divided into two-hour branches, so that gap is easily enough to move the hour pillar into the adjacent branch — and for births near the midnight boundary, to change the day pillar as well. Once the hour or day pillar changes, the ten-god structure, the shen sha and the start of the luck cycles all change with it, and the reading becomes a different reading.
So the birth place is not a biographical detail we collect out of curiosity: it is a required input to the charting algorithm. Without it we cannot produce a correct chart. We use it solely for this time correction — never to infer where you live, where you travel, or anything else about you.
3. Who we send information to
We do not sell your information. The following third parties handle some of it in order for the service to work:
3.1 Large language model provider
What is sent — the chart output for a profile (pillars, stars, shen sha and so on), name and gender, the analysis direction you chose, everything you type in a consultation, and enough prior messages to preserve context.
Why — readings are generated by a language model, and this is its input. Without it there is no reading.
Constraints — under the provider's enterprise terms this content is processed on our behalf only, for the purpose of returning your reading, and may not be used to train or improve their models or for any other purpose. We do not sell, trade or otherwise provide this content to any third party for advertising purposes.
Even so, once sent, this content enters a third party's processing pipeline. Please do not type sensitive information you would not want a third party to process (national ID numbers, bank details, medical records and the like).
3.2 Geocoding provider
What is sent — the birth place text you enter (for example "Hangzhou, Zhejiang").
Why — to resolve the place name into coordinates for the true solar time correction described in section 2.
What is not sent — account details, names, birth times and reading content are never sent to the geocoding provider.
3.3 Infrastructure providers
Hosting, databases, object storage and email delivery are provided by cloud vendors. They may technically have access to stored data in the course of running that infrastructure, and may not use it for anything else.
3.4 Legal requirements
We may disclose information where the law clearly requires it, where a judicial authority requests it through due process, or where it is necessary to protect someone's vital interests. Unless prohibited, we will make reasonable efforts to notify you first.
4. How we use information
- To compute charts, generate reports and support consultations (the core purpose)
- To maintain your account, verify identity and recover access
- To calculate credit consumption and balance
- To diagnose faults, analyse crashes, and improve algorithms and prompts
- To send service notifications (analysis complete, system announcements)
- To prevent abuse, scraping and attacks
We do not use your profiles or conversations for ad targeting, and we do not sell them to data brokers.
5. How long we keep it, and how to delete it
5.1 Retention
- Profiles and reports — until you delete them or close your account
- Conversations — the same
- Logs — typically 90 days, for troubleshooting and security auditing
- Transaction and credit records — longer, as required for accounting and audit
5.2 Deleting a profile
Deleting a profile deletes its chart data, the analysis reports generated from it, and the consultations attached to it. This cannot be undone — please confirm before proceeding. If the profile had been shared with other users, that sharing ends at the same time.
5.3 Closing your account
On closure, all profiles, reports, conversations and personal details under the account are deleted or anonymised. Credits already consumed are not refunded, and any remaining balance is cleared. Records we are legally required to retain (such as transaction history) are kept in de-identified form for the statutory period.
5.4 Content already sent to third parties
Content already sent to the language model provider is retained in their systems under their own policies, and we cannot delete it on your behalf. This is why section 3.1 asks you not to enter sensitive information.
6. Your rights
You can:
- Access your account details and all your profiles
- Correct information entered wrongly (fix a birth time and the chart is recomputed)
- Delete an individual profile, an individual conversation, or your whole account
- Export your profiles and reports (by asking us)
- Withdraw consent by ceasing use and closing your account
Exercising these rights is free. For anything you can do in the app (access, correction, deletion), please go ahead directly. For anything needing our help (export, difficult deletions), contact us using section 10 and we will respond within a reasonable time.
7. Security
We protect your data by:
- Encrypting traffic with HTTPS
- Storing passwords as salted, irreversible hashes
- Restricting database access on a least-privilege basis
- Keeping audit logs of sensitive operations
No system is perfectly secure, however. Please use a strong password unique to this service rather than one reused elsewhere.
8. Minors
The service is intended for users aged 18 and over, and we do not knowingly collect personal information from anyone under 18.
That said, you may create a profile for a family member who is a minor. In that case you must be their guardian, or have the guardian's consent. If we discover that we have collected a minor's information without valid consent, we will delete it promptly.
9. Changes to this policy
We may update this policy. For material changes — to how data is used, who it is shared with, or how long it is kept — we will give advance notice through in-app notification or email rather than quietly changing the date. The "last updated" date at the top reflects the current version.
10. Contacting us
For questions about this policy, to exercise any right in section 6, or to request deletion of your data, email us at contact@fatecode.com, or use any of the other channels listed in the "Contact us" section of our homepage.
A separate public page explains how to delete your account and data yourself, including the cooling-off period and how to cancel the request: https://www.fatecode.com/account-deletion.