Privacy Policy
Privacy Policy
Effective date: Pending publication
I Ching is operated by Sprout Technologies INC ("Hexagram.Today," "we," "us," or "our"). This policy explains how we collect, use, disclose, and retain information when you use the I Ching mobile app, website, and related services.
Data collection and privacy controls differ between the native iOS or Android app and the website. The native app uses product analytics and limited campaign measurement as described below. Apple's App Tracking Transparency permission controls access to the iOS advertising identifier and cross-app tracking capabilities. The website uses separate Cookie and advertising measurement choices.
Information Collection and Use
I Ching can be used without an account for some features. If you choose to sign in, we may receive and store account information from your sign-in provider, such as your Supabase user ID, email address, display name, avatar URL, provider identifier, and account creation date.
When you use the oracle feature, the service may process and store the question you enter, the generated hexagram result, a request identifier, an anonymous visitor identifier, and related technical information needed to provide the reading and prevent abuse.
We do not ask you to upload contacts, photos, precise location, or payment card details. A sign-in provider may supply a profile image or avatar URL as part of the account information you authorize it to share. App Store and Google Play subscription purchases are managed by the relevant store and RevenueCat; we receive purchase history and subscription entitlement information needed to unlock, restore, analyze, and support paid features, but we do not receive your full payment-card details.
Technical information may include device type, operating system, browser or WebView details, language, timezone, viewport size, screen size, color scheme, touch capability, cookie availability, and a hashed version of the request IP address.
Log Data
Whenever you use I Ching, in the case of an error or diagnostic event, we may collect data and information through third-party products or our own server logs. This Log Data may include information such as your device name, operating system version, browser or WebView version, the time and date of your use of the service, and other statistics.
Cookies and Local Storage
I Ching uses cookies, local storage, session storage, or equivalent app storage for necessary session state, security, local preferences, consent choices, first-login deduplication, registration-event delivery status, and purchase-event deduplication. Disabling necessary storage may prevent sign-in or other parts of the service from working correctly.
The first-login deduplication record is scoped to the current app installation or browser storage. It may store the sign-in method, event time, retry window, and non-sensitive delivery status for each measurement provider, but it does not store an account ID, email address, authentication token, or advertising identifier.
The iOS app also keeps a separate local purchase-event record containing the account identifier, transaction identifier, and whether a qualifying purchase or trial event has been recorded. This prevents repeated callbacks from reporting the same transaction again. The record itself is not included in those analytics events.
To distinguish a newly created account from a returning sign-in, Supabase keeps a private, account-linked registration claim with its creation time and, when claimed, an opaque OAuth attempt ID. This claim is not sent to measurement providers and is removed when the related account is deleted.
On the website, advertising tags may use first-party storage or recognize advertising attribution information associated with a visit only as allowed by the website choices described below. We may preserve attribution parameters across an OAuth sign-in redirect, but we do not add raw advertising click identifiers to our first-login event payload.
Account Deletion
Signed-in mobile app users can delete their account from Settings. Account deletion removes the Supabase Auth user, profile, saved readings, follow-up messages, account-linked reading history, achievements derived from that history, and account-linked legacy oracle memory rows.
Deleting your account does not automatically cancel an active App Store or Google Play subscription. Store subscriptions must be managed from your Apple ID or Google account.
Service Providers
We use service providers to operate, secure, measure, and improve I Ching. Depending on the platform and feature, these may include:
- Vercel for website hosting and delivery;
- Supabase for authentication, database, and account services;
- Apple and Google for sign-in, app distribution, and store purchases;
- Google Firebase and Google Analytics for product analytics and Google Ads measurement;
- Meta App Events, Meta Pixel, and Meta Conversions API for advertising measurement;
- TikTok App Events and TikTok Pixel for advertising measurement; and
- RevenueCat for purchase processing support, subscription entitlements, and subscription lifecycle reporting to advertising measurement partners.
These providers process information under their applicable agreements and privacy terms. Their roles and retention practices vary by service. You can review the privacy policies of Google, Meta, TikTok, Supabase, Vercel, and RevenueCat.
Native App Analytics and Advertising Measurement
In the native iOS and Android apps, Google Firebase product analytics and the permitted Meta and TikTok measurement events operate by default. Product analytics helps us understand service reliability, aggregate feature usage, app launches, screen and product interactions, subscription status, successful interactive sign-ins, and new account registrations.
Meta and TikTok receive their SDK-provided install, activation, or launch events and a limited set of app events for the first successful sign-in on an installation and a server-confirmed new account registration. Our native app code sends only the event name for these sign-in and registration events. It does not attach our Firebase analytics payload or custom business parameters.
Our sign-in and registration advertising events do not include your oracle questions or readings, generated interpretations, email address, name, authentication tokens, raw account identifier, raw advertising click identifier, or purchase data. Provider SDKs may still process technical fields they collect under their documented behavior, such as app and operating-system versions, timestamps, device or installation identifiers, and advertising identifiers when platform permission allows them.
We use Google, Meta, and TikTok measurement to understand app installs, first successful sign-ins, and new account registrations. We also use RevenueCat and Meta for subscription advertising measurement as described below. We do not use our integrations to personalize the in-app experience, show third-party advertisements inside I Ching, or send purchase events to TikTok.
For iOS subscription measurement, RevenueCat sends subscription lifecycle and purchase events to Meta through the Conversions API. These events may include product identifiers, amounts converted to USD, currency, transaction-related event identifiers, a hashed RevenueCat app user identifier, IP address, user-agent information, and permitted device and app information. We use this information to measure advertising results, attribute eligible conversions, and support campaign optimization. RevenueCat remains our source for transaction and subscription entitlement records; Meta determines advertising attribution. Older app versions may also report purchase activity through Meta's automatic SDK collection while we complete the transition to RevenueCat for subscription reporting.
Our RevenueCat project is shared across platforms. Eligible Android or web purchase lifecycle events processed by that project may also be delivered through the shared Meta integration. The website pixel controls below apply to those pixels and do not control this separate server-side subscription reporting.
App Tracking Transparency on iOS
Apple's App Tracking Transparency permission applies only to the native iOS or iPadOS app. When the app first becomes active and the permission has not been determined, I Ching may request Apple's system permission. Access to sign-in, casting, readings, subscriptions, or any other core feature is not conditioned on granting that permission.
Before permission is granted, or when it is denied or restricted, I Ching does not access the iOS advertising identifier and does not use another identifier to bypass your tracking choice. Firebase product analytics and permitted Meta and TikTok events may still be sent without IDFA. RevenueCat may also deliver eligible subscription events to Meta with tracking permission recorded as not authorized. These events may include Meta's app-scoped anonymous identifier, the vendor identifier, and a hashed RevenueCat app user identifier, subject to applicable platform restrictions. Hashing an identifier does not make it anonymous or grant permission to track. Eligible advertising may also be measured through privacy-preserving, aggregate systems such as SKAdNetwork or AdAttributionKit and through restricted platform modeling. These methods do not provide us with a guaranteed, user-level attribution record.
If permission is granted, the advertising identifier may be used by Google, Meta, or TikTok for permitted attribution, reporting, and fraud prevention. We keep advertising personalization disabled in this phase. You can change the system permission through iOS Settings.
Advertising ID on Android
The Android app declares the standard Google Play Advertising ID permission. When available, Google, Meta, or TikTok may use the Android Advertising ID for permitted attribution, reporting, and fraud prevention. Android does not display Apple's ATT permission.
If you delete or restrict the Advertising ID through Android or Google settings, the identifier becomes unavailable or is replaced with a zero value. I Ching does not create another persistent device identifier to bypass that choice. Permitted product analytics and limited event reporting may continue without an available Advertising ID.
Website Analytics, Advertising Measurement, and Consent
Website product analytics and advertising measurement are enabled by default. Google web measurement follows Google Consent Mode. Meta Pixel and TikTok Pixel may load and send permitted events on eligible website environments unless you turn off Advertising Measurement. If you turn it off, those pixels remain disabled or stop sending future events controlled by I Ching.
Website Meta events for a first successful sign-in or new account registration may include only a low-cardinality authentication method such as Apple or Google. TikTok website events do not include our custom business parameters. Neither pixel is intended to receive oracle content, authentication tokens, raw account identifiers, or raw advertising click identifiers from these events.
The educational site at 101.hexagram.today does not offer optional measurement, does not display this choice, and does not activate Google Analytics, Meta Pixel, or TikTok Pixel.
With Advertising Measurement allowed, we can keep Meta browser and click identifiers in this tab and share them with RevenueCat before checkout, along with the website origin and browser user agent. Anonymous context expires after 30 minutes; we reject identifiers older than 90 days. This does not define RevenueCat or Meta retention. Withdrawing the browser choice clears this tab’s matching context and stops new optional collection. It does not delete data already received by providers or stop server subscription reporting to Meta.
Manage optional measurement
Changes apply to future optional browser measurement. Advertising personalization remains disabled.
Your Privacy Choices
Native-app and website controls are separate and are not synchronized merely because you use the same account. On iOS, you can review or change Apple's tracking permission in system Settings. On Android, you can delete or restrict the Advertising ID through Android or Google settings. On the website, you can use the controls above and your browser's controls to manage optional cookies and site storage.
Changing a setting applies to future collection or sharing controlled by that setting. It does not automatically delete information previously sent to a provider. Provider-level deletion and retention are governed by the provider's policy and available request mechanisms. You may also delete your I Ching account as described above or contact us with a privacy request.
App Store and Google Play Privacy Disclosures
Our App Store privacy responses, iOS privacy manifests and privacy report, and Google Play Data safety responses are intended to describe the same practices as this policy and the behavior of the released app. Depending on the platform and features you use, disclosed categories may include contact information, account and device identifiers, purchase history, user content, product interaction and other usage data, advertising data, diagnostics, and other technical data.
Purchase history and account or device identifiers may be linked to a user through an account or device. When data is used for cross-app advertising measurement with ATT permission, relevant categories may also be used for tracking. This assessment includes third-party processing and is not limited to the presence of an advertising identifier. The Android disclosure identifies Advertising ID use for advertising or marketing measurement. The final binary's SDK privacy manifests and permissions may describe additional SDK-collected technical data even when I Ching does not add that data to its own event payloads.
Data Retention
We retain account and oracle information for as long as needed to provide the service, maintain security, comply with legal obligations, resolve disputes, and enforce agreements. Local consent and deduplication records remain on the device or browser until they are changed, cleared, or the app is uninstalled.
Account deletion removes the account-linked information described above, subject to limited records that may need to be retained for security, fraud prevention, legal compliance, or transaction records. It does not delete records independently retained by an app store, advertising platform, analytics provider, or other service provider under its own obligations. Aggregated or de-identified information may be retained where it no longer identifies you.
Clipboard, AI Prompts, and External Links
I Ching may let you copy a generated prompt or open third-party AI services such as Claude or ChatGPT. If you choose to send your question or prompt to another service, that third party processes the content under its own privacy policy and terms.
I Ching only writes to the clipboard when you choose an action such as copying a prompt or opening a prepared prompt in another app or website.
Security
We value your trust in providing us your information, and we use commercially acceptable means of protecting it. However, no method of transmission over the internet or method of electronic storage is 100% secure and reliable, and we cannot guarantee absolute security.
Links to Other Sites
I Ching may contain links to other sites or apps. If you click on a third-party link, you will be directed to that site or app. We strongly advise you to review the Privacy Policy of these destinations. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
Children's Privacy
I Ching is not directed to anyone under the age of 13. We do not knowingly collect personally identifiable information from children under 13 or knowingly send their information for advertising measurement. If we discover that a child under 13 has provided us with personal information, we will delete it from our servers. If you are a parent or guardian and you are aware that your child has provided us with personal information, please contact us.
Changes to This Privacy Policy
We may update our Privacy Policy from time to time. You are advised to review this page periodically for any changes. The effective date above identifies the current version. Where required, we will provide additional notice or request permission before materially different processing begins.
Contact Us
If you have any questions, requests, or suggestions about this Privacy Policy, contact Sprout Technologies INC at clay@sprout.place.