Privacy
Short version: your birth data never leaves your device. Accounts store an email and a password hash. You can delete either at any time.
Last updated 2026-10-10 · applies to fengshuicalculator.com
1. Charts and birth data — local only
Chart computation runs entirely in your browser via WebAssembly. Birth date, time, and site coordinates are kept in your browser's local storage and are never transmitted to us. You can verify this yourself: open DevTools → Network while computing a chart — it issues zero requests. This is an architectural property, not a policy promise (see Methodology §6).
Retention: local chart data persists in your browser until you clear it. There is nothing on our servers to delete.
2. Accounts — what we store when you sign up
- Email address and a password hash (scrypt; we never store the password itself).
- Session records (random token hash, expiry) and, for paid subscribers, subscription status synchronized from Stripe (plan, period end, Stripe customer/subscription IDs).
- An append-only audit record for account-affecting decisions, containing only abstract rule identifiers and hashes — never chart content or birth data (see Methodology §5).
Retention: for the life of the account. To delete your account, email a deletion request from the account address: the user row is removed with cascade to sessions and reset tokens; audit entries are hash-chained and retained in stripped form (rule IDs only, no personal data). Self-service deletion endpoint is on the roadmap — until then requests are handled manually.
3. What we never do
- We do not sell, rent, or share personal data; there is no advertising tracker on this site.
- We do not send your birth data anywhere — there is no server-side path that could receive it.
- We do not infer or generate conclusions about religion, health, or investments from your birth data (GDPR Art. 9 sensitivity — see Methodology §5).
4. Payments
Subscriptions are processed by Stripe. We receive only the subscription status and identifiers; card details are held by Stripe alone and never touch our servers or database.
5. Emails
Currently the only transactional email is the password-reset link (sent on explicit request; the link token is stored hashed and single-use). Marketing emails: none — there is no mailing list.
6. Consent
By creating an account you consent to the storage described in §2. Charts computed without an account involve no data transmission and require no consent.
Questions or deletion requests: see the verify page for how to reach us with verifiable context (include your chart's input_digest).