🔮
MysticJapanAI Fortune
🔒

Privacy Policy

Last updated: June 8, 2026

Your trust matters to us. This policy explains clearly what data we collect, why we collect it, and how you can control it.

1. Who We Are

MysticJapan AI Fortune ("we", "our", "us") operates the website at https://mystic-iota.vercel.app and provides AI-powered Japanese fortune reading services.

For privacy-related questions, contact us at privacy@mysticjapan.app.

2. Data We Collect

We collect only what is necessary to provide the service:

  • Email address — collected when you sign in via magic link or Google OAuth. Used to identify your account.
  • Date of birth — entered when requesting a fortune reading. Used solely to generate your personalised reading. Not stored permanently unless you request a reading.
  • Name — entered when requesting a reading. Used within the reading generation only.
  • Questions / concerns — optional text you provide for a reading. Stored alongside your reading result.
  • Fortune readings — the generated reading text, stored so you can review past readings in future.
  • Credit balance — the number of reading credits associated with your account.
  • Payment information — processed entirely by Stripe. We never see or store card numbers. We receive only a confirmation of successful payment and the tier purchased.

3. How We Use Your Data

  • To authenticate you and maintain your account session.
  • To generate personalised AI fortune readings based on your birth date and name.
  • To send magic link emails for passwordless sign-in (transactional only — no marketing emails).
  • To process payments and update your credit balance.
  • To store your reading history so you can reference past readings.
  • To maintain and improve the service (anonymised usage patterns only).

We do not sell your personal data, share it with advertisers, or use it for any purpose other than operating this service.

4. Third-Party Services

We use the following trusted third-party providers. Each has their own privacy policy:

Supabase

Provides our database and authentication infrastructure. Your account data (email, credit balance, reading history) is stored on Supabase-hosted PostgreSQL servers in the United States.

Stripe

Processes all payments. When you purchase credits, your card details are entered directly into Stripe's secure form and never transmitted to our servers. Stripe stores payment data under PCI-DSS compliance.

Anthropic (Claude API)

Powers fortune reading generation. Your name, birth date, and optional question are sent to Anthropic's API to generate the reading. Anthropic does not use API inputs to train models by default.

Vercel

Hosts the application. Standard access logs (IP address, request path, timestamp) are retained for security and debugging.

5. Cookies and Local Storage

We use the following browser storage mechanisms:

  • Authentication cookies — set by Supabase after sign-in to maintain your session. These are essential for the service to function and cannot be disabled while signed in.
  • Session storage — used temporarily to pass fortune form data and results between pages within a single browser session. Cleared automatically when the browser tab is closed.

We do not use advertising cookies, tracking pixels, or third-party analytics cookies.

6. Data Retention

  • Account data — retained for as long as your account is active.
  • Reading history — retained indefinitely so you can reference past readings. You may request deletion at any time.
  • Deleted accounts — all personal data is permanently removed within 30 days of an account deletion request.

7. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access — request a copy of the personal data we hold about you.
  • Correction — request correction of inaccurate data.
  • Deletion — request deletion of your account and all associated personal data.
  • Data portability — request an export of your reading history in a machine-readable format (JSON).
  • Objection — object to processing of your data in certain circumstances.

To exercise any of these rights, email privacy@mysticjapan.app with "Data Request" in the subject line. We will respond within 30 days.

8. Data Security

We take reasonable technical and organisational measures to protect your data:

  • All data is transmitted over HTTPS/TLS.
  • Database access is protected by Row Level Security (RLS) — each user can only access their own data.
  • API keys and credentials are stored as environment variables, never in source code.
  • Payments are handled entirely by Stripe — we have no access to card data.

No method of transmission or storage is 100% secure. If you become aware of any security issue, please contact us immediately at privacy@mysticjapan.app.

9. Children's Privacy

MysticJapan is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For significant changes, we will notify users via email. Continued use of the service after changes constitutes acceptance of the updated policy.

11. Contact Us

For any privacy-related questions, requests, or concerns:

MysticJapan AI Fortune

Email: privacy@mysticjapan.app

Website: https://mystic-iota.vercel.app