Privacy Policy

1. Who this policy is for

This policy applies to the TaKnow mobile application and its related online services. TaKnow is for adults only: you must be at least 18 and meet any higher age of adulthood or minimum age for using this service that applies where you live. The screening flow described here applies to the adult-policy app update; earlier installed versions may show the previous sign-in flow. In the updated app, age screening takes place before sign-in. The date you enter for screening is checked locally on your device, is held only for that screening, and is not saved or sent to TaKnow's server. You also confirm that you meet the requirements where you live. App language, locale, or App Store content rating does not establish where you live or make you eligible.

After sign-in, TaKnow records your adult-eligibility and Terms/Privacy decisions for your account before the personalized experience begins. Existing users must confirm the adult policy again; a previous 13-or-older confirmation is not sufficient. If you do not meet the requirements, do not use the service. You can still use public Support to request access to or deletion of existing data and help with an Apple purchase. We do not automatically delete an existing account solely because eligibility has not been confirmed.

2. Information we process

  • Account information: a user ID and, depending on how you sign in, an email address, phone number, or identity-provider credential.
  • Apple deletion credential: after Apple sign-in, TaKnow exchanges the one-time authorization code directly with Apple and retains only an AES-256-GCM-encrypted refresh token so it can revoke Apple authorization if you delete the account. The one-time code and plaintext token are not stored or logged.
  • Optional profile information: nickname, birthday, and gender, when you choose to save them separately from age screening. These profile fields are optional. A previously saved birthday may also be checked for age eligibility; the screening itself does not save a birthday.
  • Compliance records: your accept, decline, or withdrawal decision for age eligibility, Terms and Privacy, AI processing, optional analytics and diagnostics, Apple Speech disclosure, and diagnostic export, together with the applicable document version, source, client time, authoritative server time, app version/build, locale, and minimal choice context. Adult-eligibility records contain the eligibility outcome and confirmation of applicable local requirements, not your screening date of birth.
  • Your content: tarot questions, selected cards, conversations, diary notes, and reading history.
  • Account wallet: virtual fish-treat balance, reading entitlements and expiry, check-ins, exchanges, owned items, membership status, and the account-linked ledger used to deliver and reconcile these benefits. Fish treats cannot be withdrawn as money.
  • Apple purchase history: when you use an Apple purchase, signed purchase evidence, product and transaction identifiers, subscription dates and renewal state, delivered benefits, and refund or revocation state. We link verified purchases to your TaKnow account and separate test purchases from real purchases. Apple handles payment; TaKnow does not receive your payment-card or bank-account credentials.
  • Invitation and redemption records: account/customer identifiers, account creation time, membership and new-account eligibility, invitation relationships and codes, redemption qualification, reward amounts, and delivery/retry records when you use these features. Our self-hosted campaign service does not receive your name, email, phone number, tarot questions, diary content, or Apple purchase identifiers.
  • Voice input: short recordings you choose to make for speech-to-text and the resulting transcript.
  • Optional product analytics: if you turn on Analytics & Diagnostics, a limited set of reading-flow and diary actions linked to your account ID. TaKnow does not send your questions, chat messages, diary notes, email address, phone number, or profile fields in analytics events.
  • Optional diagnostics: if you turn on Analytics & Diagnostics, crash, memory, and reliability information linked to your account ID to help maintain the app.
  • Remote app configuration: TaKnow retrieves presentation copy and settings from PostHog whether optional analytics is on or off. When analytics is off, the request uses a reset anonymous app identifier rather than your account ID, sends no product or feature-exposure event, and includes none of your questions, chats, readings, diary content, contact details, or profile fields.
  • Device preferences: language, sound, onboarding state, and an account-scoped local mirror/retry queue for compliance decisions.
  • Service usage counters: your account ID, request category, rolling-window start, and count for AI and diary abuse prevention.
  • Google sign-in signals: if you choose Google sign-in, Google's SDK may process identity attributes and technical signals such as approximate location, a device identifier, and usage data for sign-in functionality and service analytics. TaKnow does not request iOS location permission for this.

3. Why we use it

We use this information to authenticate you, provide readings and conversations, remember your diary and preferences, maintain your wallet, verify and deliver purchases, administer check-ins, exchanges and enabled invitation/redemption rewards, enforce eligibility and your processing choices, convert voice to text, keep the service secure, troubleshoot failures, and comply with account-deletion requests. We do not sell your personal information or use it for cross-app advertising tracking.

4. Service providers

Information may be processed by providers that support a specific app function:

  • Supabase for authentication and the account-scoped compliance audit trail.
  • Tencent Cloud for the TaKnow API and encrypted database hosting.
  • Apple or Google when you select their sign-in service. Google sign-in may process the identity attributes and technical signals described above.
  • Apple App Store for in-app payments, purchase verification, subscription management, and purchase/refund notifications when purchases are offered. Apple processes payment information under its own policies.
  • Self-hosted OfferKit for invitation and redemption eligibility, referral/customer records, code qualification and reward events. This service runs separately from the TaKnow application database and receives only the campaign information listed above.
  • Apple Speech when you choose voice input. TaKnow does not send voice audio to its own backend.
  • Doubao to generate tarot classifications, readings, and conversations.
  • PostHog US Cloud for product analytics, crash diagnostics, and remote app configuration. TaKnow disables session replay, automatic screen and element capture, surveys, and push-notification capture.
  • Feishu/Lark for the optional support-request form. The form processes only the support details you choose to submit and the technical information needed to operate the form.

These providers receive only the information needed for the function they perform. TaKnow requires service providers to protect personal information consistently with this policy and applicable law, and does not authorize them to use it for unrelated purposes.

5. Storage and retention

Account and tarot content is retained while your account remains active, unless you delete an item earlier. Compliance decisions form an append-only, versioned account history and are retained for the account lifetime. Raw voice audio is used for recognition and is not stored in TaKnow's application database. Service counters keep one current row for each account and request category, overwrite the rolling window as it advances, and are deleted with the account. An encrypted Apple revocation token, when present, is retained only while the account is active and is revoked and deleted during account deletion. PostHog analytics and diagnostic records are retained under the project's provider retention settings until they are deleted through the provider process or account deletion. Remote-configuration payloads and their device cache contain no user-authored content. Local preferences remain on your device until removed by the app or operating system.

Wallet, account-linked purchase history, and application-side campaign records are retained to maintain your balance, deliver benefits, reconcile renewals or refunds, and prevent duplicate rewards while your account is active. These records are removed from the live TaKnow application database when you delete your account. Separately hosted OfferKit customer, referral, and redemption records are not automatically erased by the current in-app deletion workflow. You may use Support to request deletion of retained campaign records. Deleting a TaKnow account does not delete purchase records held by Apple or cancel an Apple subscription. Apple controls retention of its records under its own policies.

6. Account deletion

You can permanently delete your account inside TaKnow: open Profile → Settings → Delete Account. The request deletes your TaKnow database record and its related sessions, messages, readings, diary history, compliance audit history, and account-linked wallet, purchase and application-side campaign records, then deletes your authentication account. For current Apple accounts, the server first revokes the retained Apple authorization token; older Apple accounts that predate secure token capture receive instructions to revoke access in Apple ID Settings. The app also clears its local session and keychain entry, account-specific choices, cookies, caches, local files, onboarding data, stored diagnostic logs, and local PostHog identity and queued analytics. Before the account and authentication records are removed, the server also asks PostHog to delete the person associated with your account ID and queues deletion of that person's historical events. This stops future account-linked analytics and removes provider-hosted history through PostHog's deletion process. Account deletion cannot be undone. Separate OfferKit campaign records require a Support request as described above. If you have an Apple subscription, manage or cancel it in your Apple account settings to prevent future renewal charges; you can still delete your TaKnow account immediately. See the public account deletion guide.

7. Your choices

Age screening does not save your date of birth. You may skip optional profile fields, decline microphone or speech permission, decline or later withdraw AI processing, turn optional Analytics & Diagnostics on or off without losing core functionality, choose whether to export local diagnostic logs, edit supported profile details, or delete your account. Turning Analytics & Diagnostics off stops product-event and diagnostic collection but does not disable the anonymous remote-configuration request needed to deliver app presentation settings. Permission settings can also be changed in iOS Settings.

8. Security and international processing

TaKnow uses HTTPS/WSS transport, authorization headers, access controls, and server-only credentials. The production API and application database run on Tencent Cloud, while Supabase Auth and the selected PostHog project are hosted in the United States. PostHog, Apple, Google, and Doubao may process information in other locations. This means information can be processed outside your country. Where required, we use contractual and other appropriate legal safeguards. No system can guarantee absolute security, but we limit access and the data sent to each provider.

9. Your privacy rights

Depending on where you live, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. Use the public Support page to submit a request. We may need to verify that the request concerns your account before acting on it. You may also complain to the data-protection authority available in your region.

These support and privacy-request options remain available if you cannot confirm adult eligibility. If you or a parent or guardian believes that an ineligible person has an account, contact Support to request account restriction or deletion. Do not send a password, one-time code, access token, or identity document through the public form.

10. Changes and contact

We may update this policy when the app or applicable requirements change. The effective date above will be revised. For a privacy question or request, use the public Support page or the Feedback option in TaKnow Settings.