Privacy
Privacy Policy
Your birth details are calculated only in your browser and never sent to our server. Here is how we handle login and contact information.
YJ International (와이제이인터내셔널) ("we") runs Mukwoon (the "Service") and handles your personal information under Korea's Personal Information Protection Act. This policy explains what we handle, where, why and for how long.
1. Birth details used for your chart
Your birth date, birth time and gender are calculated only inside your browser. They are never sent to our server.
So you don't have to type them again, the same details are saved in your browser's storage (localStorage) on your device. We can't see them. Clearing this site's data in your browser deletes them.
If you were born abroad and pick a birthplace (city), we use it only to adjust your birth time for that city's time zone and longitude. It is saved with your birth details in the same browser storage. City search runs on a list inside your browser and is never sent to our server.
1-1. Noble Helper check links
The check link you send a friend from Noble Helper carries only your Day Master character and a set of branch characters (with no positions). It never carries your birth date, time or gender. Your friend's birth details are also calculated only in their own browser and are never sent to you or to us. Analytics never receives this part of the link (the query).
2. What we collect and why
| Type | Items | Purpose | Stored in |
|---|---|---|---|
| Login — Google | Email, name, profile photo | Login and account identification | Firebase Authentication, Firestore |
| Login — Kakao | Kakao member number, nickname, email (if you agree), profile photo | Login and account identification | Firebase Authentication, Firestore |
| Login — Naver | Naver member ID, name (or nickname), email, profile photo | Login and account identification | Firebase Authentication, Firestore |
| Sign-up — email | Email, password | Login, account identification, password reset emails | Firebase Authentication (Firebase encrypts the password; we can never see it) |
| Account record | Login method, sign-up and last login time, time you confirmed you are 14 or older | Account management, age check | Firestore |
| Contact form | Name, email, subject, message, time sent | Reading and answering your message | Firestore, our email inbox (delivered through Resend) |
| Paid plan (only if you paid) | Order number, amount, plan status and period, payment ID | Payment confirmation, monthly billing, cancellation and refunds | Firestore |
| Chat helper (Ink Sage) | Your question (numbers, dates, email and web addresses are masked on your device before sending), screen language, IP address (used only for rate limits, never stored). Questions that suggest a crisis (such as self-harm) are never sent; we show helpline information and count only how many times per day it was shown (no question text, IP or device information) | Finding a matching answer, preventing abuse, improving answers from unanswered questions | Firebase Cloud Functions (finding answers; the IP stays briefly in server memory only), Firestore (only unanswered questions, masked) |
| Result views and interest buttons | How many times the result screen was opened, how many times a "Full report" button was tapped and how many launch-notify sign-ups there were (topic: money, love or career), screen language. Daily counts only (no text, IP, device or account info) | Gauging demand for features in progress | Firestore |
| Visit analytics (Google Analytics) | Page path (without query, except campaign tags utm_* on the first page) and title; actions: landing on the home screen, starting the birth form (not the values), reading depth, the analyze button, reaching the result, result tabs, result card create/share (image, copy link)/save, viewing a compatibility result, drawing tarot cards, login method, language switch; screen language, device type (mobile/desktop), traffic source (referring domain, campaign tags such as utm_source); browser details, approximate region and a cookie ID that Google collects automatically | Usage statistics, improving the Service | Google Analytics |
Logging in is optional. You can use the basic features, including your chart, without an account. Analytics never receives your birth details, email or name, and we attach no user ID. Google signals and ad personalization links are turned off. Card and bank details are handled by the payment provider and are never stored by us. Paid plans are not offered at the moment, so we take no new payment information.
3. Children under 14
Children under 14 may not use the Service. When you sign up or log in, you must confirm "I am 14 or older." Without it, sign-up does not continue. If we learn that we hold information from a child under 14, we delete that account and information without delay.
4. Information kept only on your device
The following stays in your browser and is never sent to our server.
- The birth details you entered, and a random device ID that is never sent anywhere
- Your daily reading, mindset test, tarot and MBTI results, and reminder settings (reminders are shown by your device only)
- An "internal visit" flag, only if an operator turned it on with internal=1 in the address (visits from that device are left out of visit analytics and interest-click stats)
- Which dream dictionary categories you left open, and which full reports you asked to be notified about
- Your language choice, whether you closed the language suggestion bar, your login status (name, email, profile photo and a login token), and your email if you choose "remember email"
- Your cookie choice (if asked in the EU, UK or Switzerland) and this visit's traffic source (cleared when you close the tab)
- Your Ink Sage (chat helper) question count (date, count and the times of questions in the last minute; never the questions themselves)
- Short-lived values for animations and login steps (session storage, cleared when you close the tab)
To delete them, clear this site's cookies and site data in your browser settings. Logging out also clears your login status.
5. How long we keep it
- Account information: until you delete your account. We delete it without delay when you ask.
- Contact messages: 1 year after we finish handling them, then deleted. When you delete your account, messages sent from the same email are deleted too.
- Payment and plan records: 5 years, as required by Korea's Act on Consumer Protection in Electronic Commerce, then deleted.
- Unanswered Ink Sage (chat helper) questions (masked): used to improve answers and deleted within 1 year. IP addresses are not stored.
- Information on your device: until you delete it.
- Visit analytics data: kept and then deleted under the Google Analytics data retention setting (2 months by default).
6. Sharing with third parties
We don't share your personal information with third parties, except when the law requires it through due process (for example, a lawful request from investigators).
7. Service providers
| Provider | What they do for us | Information involved |
|---|---|---|
| Google LLC (Firebase) | Account login (Firebase Authentication), web hosting, server functions (Cloud Functions), database (Firestore) | Account information, contact messages, payment records, access logs |
| Resend, Inc. | Delivering contact messages to our inbox | Name, email, subject and message |
| Google LLC (Google login) | Login with your Google account | Email, name, profile photo |
| Kakao Corp. | Login with your Kakao account | Kakao member number, nickname, email, profile photo |
| NAVER Corp. | Login with your Naver account | Naver member ID, name or nickname, email, profile photo |
| Google LLC (Google Analytics) | Visit analytics (usage statistics) | The visit analytics items in section 2 |
Our fonts load from Google Fonts and jsDelivr, so your connection details (such as your IP address) may reach those services when a page opens.
8. Transfers outside Korea
Our database (Firestore) and server functions run in the Seoul region, Korea (asia-northeast3). The following may be handled outside Korea.
| Recipient · country | Items | When and how | Purpose | Kept for |
|---|---|---|---|---|
| Google LLC · USA and Google’s global infrastructure | Account information (email, name, profile photo, password), access logs | Sent over the network when you sign up, log in or open a page | Account login, web hosting | Until you delete your account |
| Resend, Inc. · USA | Contact name, email, subject, message | Sent over the network when you send a message | Delivering your message to our inbox | Under Resend’s retention policy |
| Google LLC · USA (AdSense) | Ad cookies, device and browser details, visit history | When you open a page with ads | Showing ads | Under Google’s policies |
| Google LLC · USA (Google Analytics) | The visit analytics items in section 2 (including a cookie ID) | Sent over the network when you open or use a page | Usage statistics, improving the Service | Under the Google Analytics retention setting (2 months by default) |
If you don't want this, you can skip login and the contact form, and block analytics and ad cookies in your browser. Your chart still works.
9. Ads and cookies
Mukwoon shows ads through Google AdSense. Google may use cookies to show ads based on your visits and interests. Learn more in How Google uses information for ads, and turn off personalized ads in Google Ad Settings.
We use Google Analytics for usage statistics. It tells visits apart with cookies (such as _ga). It never receives your birth details, email or name. You can block cookies in your browser or use the Google Analytics opt-out add-on.
If you visit from the EU/EEA, the UK or Switzerland, we ask for your consent before using analytics and ad cookies. Until you choose, analytics and ad storage stay off, and everything still works if you decline. To choose again, clear this site's data in your browser.
10. Your rights
- You can ask to see, correct, delete or stop the processing of your personal information at any time.
- Deleting your account: log in, then open the profile menu at the top → Delete account → Delete account. Your Firebase Authentication account, your account record on our server and contact messages sent from the same email are deleted right away. Payment records we must keep by law are the only exception. On the same screen you can also clear the birth details and results saved on this device.
- For your security, you can delete your account only within 5 minutes of logging in. If it has been longer, you'll be asked to log in again, and the delete screen opens again after you do.
- If you have an active monthly plan, cancel it first.
- If the button doesn't work for you, email joun90@gmail.com from your account email and ask us to delete your account.
- You can also disconnect Kakao or Naver login in that service's account settings (connected services).
- You can log out from the profile menu at the top of the screen.
11. How we delete information
When the retention period ends or the purpose is fulfilled, we delete the information without delay. Electronic files are deleted so they can't be restored.
12. How we protect it
- All connections are encrypted with HTTPS.
- Passwords are encrypted and kept by Firebase Authentication. We never store passwords ourselves.
- Your browser never reads our database directly. Only server functions that check your login read and write data.
13. Privacy officer
- Officer: Jeon Young-Jae (전영재), Representative of YJ International (와이제이인터내셔널)
- Contact: joun90@gmail.com
14. Getting help
For advice or reports about privacy violations, you can contact these Korean agencies.
- Personal Information Infringement Report Center: privacy.kisa.or.kr / 118 (in Korea)
- Personal Information Dispute Mediation Committee: www.kopico.go.kr / 1833-6972
- Supreme Prosecutors' Office: www.spo.go.kr / 1301 (in Korea)
- Korean National Police Agency: ecrm.police.go.kr / 182 (in Korea)
15. Changes to this policy
If this policy changes, we will post the change on this page at least 7 days before it takes effect.
- Company: YJ International (와이제이인터내셔널) · Representative: Jeon Young-Jae (전영재) · Business registration no. 569-10-02302
Effective date: October 5, 2026