Privacy notice
Chinese I Ching is operated by an individual based in China.
Effective date: 2026-10-05
Privacy contact: support@thechineseiching.com
Children
This service is not directed to children under 14. We do not request birthdays or add an age-verification form.
On your device
Your optional question, notes and unfinished throws stay in browser storage. They are not submitted in our reading, payment or analytics requests. Clearing storage or changing devices may remove them; recovery codes do not sync them.
Our application
An essential random session cookie identifies your readings and access. The server stores a hash of the session token, CSRF token, six line values, reading IDs, immutable text snapshots, and access/recovery records. Payment records retain internal and provider order identifiers, product/version, currency, amount and verified status. Recovery codes are stored as hashes and submitted only in a protected request body.
Rate limiting stores a session-based key, count and time window. The application does not persist full IP addresses, arbitrary URLs, questions, notes, passwords, card numbers or CVC. The public review deployment is configured for Fly.io, which processes connection and network metadata to deliver the service. Fly documents 7-day searchable application logs. This application does not log reading questions, notes or payment credentials. Retention of other provider network metadata has not been confirmed.
Payments and third parties
No payment SDK or checkout is loaded by the public review site. If later enabled, Waffo receives necessary order references and handles payment details on its service. Our webhook inbox stores only allowlisted order/payment/refund fields for verification and retry, not the whole raw buyer payload. See Waffo privacy policy. PayPal direct checkout is disabled at launch.
Analytics and storage
Optional first-party funnel analytics are disabled in this release candidate. No advertising, session replay or third-party analytics is added. Essential session cookies are set for up to one year. Server records currently have no scheduled automatic deletion; backups also require controlled retention. We do not promise an automatic deletion period that is not implemented.
Your requests
Contact us to request access or deletion through the support channel above. We must verify ownership without asking for card credentials or passwords. Records necessary for legal obligations or resolving transactions may need to be retained. Do not send private recovery codes in ordinary email. Application records have no scheduled automatic deletion. Review backups retain 7 daily and 4 weekly copies plus a pre-upgrade recovery point on the same storage volume. Contact support for verified access or deletion requests.