BLACKMORE

Legal

Privacy Policy

In effect from September 23, 2026

1. What we collect — Email address (to identify the account), the photographs the User uploads, date and time of birth, sex, and country and city of birth (only where the fortune reading is used; the time of birth may be left as unknown), and a name for the card (optional). Sex sets the direction of the ten-year cycles and the country and city of birth set the true-solar-time correction, so both are needed for the chart; the name appears only on the card and is not used in any calculation. We also process basic photo-check results (quality status and measurements), creation and privacy consent records, order records, payment records (payment method details are held by the payment provider; the Company does not store card numbers), and service usage records. Under Article 22-2 of the Personal Information Protection Act, the Company does not collect the personal data of children under the age of 14.

2. Why we use it — To generate images, to produce the fortune and face reading and the card that carries them, to process orders, handle payments and refunds, prevent abuse, respond to enquiries, and compile usage statistics to improve the Service. We do not use it for any other purpose.

2-1. Usage statistics and sales by post — We use a feature provided by Vercel Inc. (United States) for general screen-use statistics, without sending order numbers, email addresses or photo URLs. Separately, a first-party cookie records the post identifier, source channel, medium, campaign, landing path, language and arrival time so we can understand which posts lead to visits and purchases. It expires after 30 minutes of inactivity; the latest valid source in that session is fixed to the order. General attribution details are deleted with the original order contents. For purchase and refund performance by post, only the post identifier, channel and language are kept separately with transaction records for up to five years from creation of each transaction record, then removed by daily cleanup. Photos, birth details, reading text, email addresses and access tokens are not copied into these performance records, and photo or result retention is not extended. Marketing receives totals by date, product, currency and source, rather than customer-level records.

2-2. Optional birthday emails — Only after the User separately agrees to promotional emails and retention, and confirms through the email sent to them, do we send one yearly birthday note based on the day stem with news about the experience. Consent is not required to buy, sign in or view a result. We separately keep the email address, solar birthday month/day, calculated day stem, language, calculation version, consent version and time, schedule and annual delivery-attempt record. We do not copy the original birth year, time, place, photos or paid reading text into this subscription. Lunar birthdays use the month/day of the solar date converted in the year of birth; February 29 is observed on February 28 in non-leap years. Unconfirmed requests become due for deletion after 24 hours. Confirmed subscriptions last for up to two years after confirmation, or until unsubscribe or deletion of an account with the same email address. Sending stops at expiry and daily cleanup deletes the record, retrying failed deletions. The unsubscribe link in each email deletes subscription data without login. We cannot remotely remove emails already being sent or delivered to an inbox. The mail service processes the recipient email address and message to deliver it. This optional subscription does not extend the retention of photos or existing readings below.

3. How long we keep it — Photographs, intermediate images and results in Company storage, and their associated birth details, names, measurements, four pillars and judgements, follow these periods. (1) Paid Face & Chart: 14 days from portrait completion; for a paid order whose creation has not finished, 14 days from payment. (2) Other saved birth-chart, face-reading and compatibility readings: 14 days from creation of the reading record. (3) Uploaded photographs not linked to any order: 48 hours from upload. (4) The reference face, basic photo-check results, birth details and name of a Face & Chart request that is not paid for: 48 hours from the request. After these periods, data is removed by the daily scheduled deletion task; failed deletions are retried. The Company does not extend retention in exchange for promotional consent or similar permission. Contract and payment records are held separately for five years as required by the Electronic Commerce Act. Because the results include a portrait generated from the User's own face, these limits keep us from holding them longer than needed. Files the User has downloaded belong to the User and are not removed by the Company's deletion tasks. Temporary browser photos and unpaid drafts follow section 3-0 below; external provider retention follows section 4-2.

3-0. Temporary Face & Chart storage — A smaller source photo prepared before payment is kept temporarily in the browser storage on the User’s device. It is removed when the browser confirms that the reference face is ready, or on the next site visit after it has been held for 24 hours. Automatic deletion while the site is not open is not guaranteed. When the User asks for the reference face to be drawn, birth details, the name if provided, basic photo-check results and consent records are saved in the Company database so the order can resume, and the reference face drawn from the photograph is shown at a small size before payment. A request that has neither been paid nor produced a reading record, together with its reference face, becomes due for scheduled deletion 48 hours after the request was made. After payment, reference faces and results follow the applicable product retention period in section 3.

3-1. Sharing results — Results are private to their owner by default. When the User selects Create a share link on the result screen, a page and preview image containing the generated portrait, office and grade become available to anyone with the link and to external services that fetch link previews. Downloading a share image alone does not create a public link. The shared page excludes names, birth details, Four Pillars, attribute scores, full readings, source photographs and internal reference faces. Company share links stop working when sharing is stopped or the original result retention period ends; share records are removed when results are purged or by scheduled cleanup. The Company cannot remotely delete files already downloaded or images cached or saved by other services. The Company does not independently reuse the User’s photographs or results in homepage promotions, social media or advertising.

4. Processors and overseas transfer — Creating images requires photographs to be sent to the generation provider. (1) fal.ai (United States) and OpenAI (United States) process reference photographs, generated results and creation requests for image generation. A smaller Face & Chart source photo passes through the Company's servers to the provider and is not kept as a file in Company storage. (2) Vercel Inc. (United States) processes order information and reading results to operate the Service (web servers and the database connection). (2-1) Cloudflare, Inc. (United States) stores generated reference faces, portraits and share-card images in its object storage (R2). Company-held data follows the periods in section 3. Generated Face & Chart reference faces and portraits are held in Company storage. This differs from the source photo, which is not kept there. (2-2) jsDelivr (CDN, cdn.jsdelivr.net) and Google Cloud Storage (storage.googleapis.com) deliver the face-measurement program and model files to the browser and process IP addresses and browser information during those downloads. (3) Dodo Payments — overseas merchant of record for fortune and face-reading products; order, contact and payment information for payment, tax and refund processing. The contracting entity, processing countries and retention terms are described at checkout and in the Dodo privacy policy. Toss Payments (Republic of Korea) — payment and refund records of past hanbok photograph orders that used this method. Hanbok photograph orders are no longer sold; these records are kept for the period required by applicable law. (4) Google LLC (United States) — used for automatic quality checks on hanbok photograph orders, a product we no longer sell. None of the products we sell today send photographs or results to Google. External provider retention and model-training terms are described in section 4-2. The User may refuse overseas transfer, but image creation and payment services that require it cannot then be provided.

4-1. Processing on your device and on our servers — Your browser downloads the face-measurement program and model files from jsDelivr (CDN, cdn.jsdelivr.net) and Google Cloud Storage (storage.googleapis.com), sending those providers your IP address and browser information. Photographs are not sent as part of these file downloads. The basic photo check and geometric measurement of the generated reference face run in the User’s browser. The reference face is made before payment by sending the photograph to the generation provider and is shown in the browser at a small size; the full-size reference face is sent to the browser for measurement after payment. Measurements (26 indicators and percentiles) and the date and time of birth, sex, and country and city of birth entered by the User are sent to the Company’s servers for judgement and chart calculation. A free calculation without a separate save or purchase request does not create a stored reading record. Asking to save a reading or proceed with a purchase stores the relevant input and reading or order draft. Not storing a reading record during a free calculation does not mean that no visit, security, consent or other service records are processed.

4-2. External provider retention — The Company’s storage deletion period does not apply automatically to data held by external providers. Their retention, deletion and model-training practices follow the applicable API policies and contract terms. The Company asks fal to expire generated files on its CDN 24 hours after creation and to disable dashboard storage of request and response bodies. Requests and responses may contain photograph reference URLs or image data. Applicable periods depend on the provider, API and account settings; the Company does not guarantee deletion by every provider immediately after generation, or exclusion from model training by every provider. Provider terms are described in the Media Expiration section of fal’s official documentation, OpenAI’s API data-processing documentation and each provider’s privacy policy.

5. No model training — The Company does not use the User’s photographs or generated results to train artificial intelligence models, and does not sell them to third parties. External provider terms are separately described in section 4-2.

5-1. No biometric identification — The Company uses photographs and facial references created during generation for the image creation and face measurement the User requests. We do not match faces against another person’s biometric data, verify identities or use photographs to identify the User or anyone else. Facial reference data held by the Company is deleted under the applicable product period in section 3; temporary browser photos are removed under section 3-0.

6. Your rights — The User may request access to, correction of, deletion of, or suspension of processing of personal data at any time. After signing in, open Account at the bottom of Your gallery and use Delete account to request direct deletion of photographs, results and account information held by the Company. Failed deletion is not marked complete and can be retried. Payment records subject to statutory retention are excluded, but their identifying link to the account is removed. Account deletion does not remotely delete temporary photos on another device, files downloaded by the User or data held by external providers. Temporary photos on other devices follow section 3-0; provider-held data follows section 4-2. For other access, correction, deletion or processing-suspension requests, contact the address below. Even without a request, Company-held data follows the periods and scheduled deletion procedure in section 3.

7. Safeguards — Portraits and reference-face files are stored at unguessable random URLs and can be opened by anyone who knows the URL. Sending the URL to someone also gives them access to the file. Share cards receive a public URL only when the User enables sharing. We apply technical and administrative protections including separation of access privileges and logging of administrator access.

8. Privacy contact — The channel that handles privacy matters and complaints is Customer Enquiries (hanbok@theblackmore.shop). The name of our privacy officer is shown under Business information at the foot of every page.

Privacy Policy — BLACKMORE