← 知命條 款 · Policy
Policy · 條款

款之卷

The slow reading of our terms
Privacy

Privacy Policy

What we keep, and what we release

Privacy Policy

Effective date:

Mingful (知命) respects your privacy. This Policy explains what personal data we collect, how we use it, how long we keep it, and the rights you can exercise. It aligns with the Hong Kong Personal Data (Privacy) Ordinance (PDPO), the EU General Data Protection Regulation (GDPR), and the Personal Information Protection Law of the People's Republic of China (PIPL).

1. What we collect

1. **Account data** — email address, display name and login credentials (passwords, where used, are one-way hashed). You can sign in by email verification code or choose Google or Apple sign-in. Third-party sign-in provides a provider account identifier and any supplied name and email address, which may be an Apple private relay address. We use these to verify identity and link your Mingful account; we do not receive your Google or Apple password. For Apple sign-in, we also retain encrypted refresh credentials for account security and authorization revocation during deletion. 2. **Birth details** — solar or lunar date of birth, time (where known), time zone, birth city, gender, and the name you want in the reading. These are required to compute a BaZi chart. 3. **Optional scan photographs** — face, left palm, and right palm capture are optional. When you choose one, the app uploads the original over encrypted transport through a short-lived presigned URL to private Cloudflare R2. We use it to derive the selected face or palm features. 4. **Payment data** — we never store full card numbers or Alipay/WeChat account details. Stripe and Airwallex process website payments; Apple App Store and Google Play process in-app purchases. We receive transaction identifiers, receipts or purchase credentials, product details, amounts, currencies and subscription status needed to verify purchases. We link purchase records to your Mingful account to provide access, restore purchases and handle refunds. 5. **Usage data** — page views, event clicks, device type, browser, coarse region (IP prefix), and crash reports. Used for product improvement and anti-abuse. 6. **Cookies and similar technologies** — for session state, preferences, and anonymised analytics. 7. **Notification data** — when you enable push, we retain an app installation identifier, push token, linked Mingful account, device platform, language, time zone, reminder time and notification preferences. Delivery status helps prevent duplicates and handle failed delivery. Trial reminders also use your verified email address and the store-verified trial end time.

2. How we use your data

1. To compute and write the reading you ordered. 2. To send daily-report-ready notifications according to your preferences, plus reading-ready notices, receipts, trial-ending reminders and important policy updates. Trial reminders go to your verified email address three days before the trial ends; push reminders are optional. You can manage push in the app and device settings. Declining push does not disable the trial email reminder. 3. To prevent misuse, fraud, and unlawful activity. 4. To improve the product, working from anonymised or aggregated data.

We do **not** sell birth data, photographs, or reading text. We do **not** make them available as training data for any third-party model.

3. How we share data

We share only in these cases:

1. **Essential service providers**, under data processing agreements and on a need-to-know basis: - Google (Gemini models — reading text generation) - Fireworks.ai (vision model — used to read feature shapes when the selected scan workflow requires Deep Read processing) - Supabase (database hosting, Singapore / Hong Kong region) - Cloudflare R2 (private storage for optional scan originals and public share cards; scan uploads use short-lived presigned URLs over encrypted transport) - Stripe, Airwallex (website payments); Apple App Store, Google Play (in-app payments and subscription verification) - Google, Apple (third-party sign-in, if you choose it) - Resend (email delivery) - Google Firebase Cloud Messaging, Apple Push Notification service (push tokens and notification delivery) - Sentry, PostHog (error tracking and anonymised analytics) 2. **Legal compulsion** — in response to a valid order from a competent authority in Hong Kong or in your jurisdiction. 3. **Business transfer** — in the event of a merger, acquisition, or asset sale, with equivalent privacy obligations on the receiving party.

4. Retention

| Category | Default retention | |---|---| | Account data | While account is active | | Birth details | While account is active (needed to re-render your reading) | | Optional face, left-palm, and right-palm originals | Expire 20 hours after capture. Cleanup runs hourly; a 24-hour survivor alert is raised if an expired original remains. | | Derived scan data | Derived data is kept until replacement, source deletion, or account deletion. | | Reading text | While account is active | | Payment records | Seven years (tax and regulatory requirement) | | Usage logs | Twelve months | | Push installations and notification records | While the account is active; installation data is removed on deregistration, and related notification data is removed during account deletion. | | Apple sign-in refresh credentials | Encrypted until account deletion completes; available grants are revoked with Apple before credentials are removed. |

When account deletion reaches a terminal state, object-key rows and owner/recovery identifiers are removed and terminal deletion metadata is de-identified promptly. The remaining status-and-timestamp shell is removed at 30 days. Nonterminal deletion work remains attributable until it can finish safely. Payment records retained for tax compliance are excluded from account-content deletion.

If Apple authorization needs confirmation, the deletion flow asks you to sign in with Apple again. If the credentials needed for revocation are unavailable, it explains how to stop using Sign in with Apple manually in your Apple Account settings and requires your acknowledgement before continuing. We do not mark unconfirmed revocation as successful. Deleting your Mingful account does not cancel an App Store or Google Play subscription; cancel it separately through the store used for purchase.

5. Your rights

Regardless of where you live, you have the right to:

1. **Access** — know what we hold about you. 2. **Rectification** — correct inaccurate data. 3. **Erasure** — request permanent deletion. 4. **Restriction** — pause certain uses. 5. **Portability** — receive a machine-readable export. 6. **Objection** — opt out of marketing communications (each email has a one-click unsubscribe).

EU users (GDPR) may complain to a local data protection authority. Mainland China users (PIPL) may contact the Cyberspace Administration. Hong Kong users (PDPO) may contact the Privacy Commissioner for Personal Data.

To exercise a right, email support@predvix.com. We respond within 30 days.

6. International transfers

Our cloud providers operate in Singapore, the United States, and the EU. Data may cross borders. We rely on Standard Contractual Clauses, encrypted transport, and data minimisation to keep transfers safe.

7. Children

The Service is not intended for users under 18. If we learn we have collected a minor's data, we delete it.

8. Security

1. Transport is HTTPS end-to-end. 2. Scan originals are sent over encrypted transport using a short-lived presigned URL and stored in private Cloudflare R2 with encryption at rest until their 20-hour expiry or earlier source/account deletion. 3. Only authorised engineers can touch individual records, for troubleshooting, with an audit trail. 4. In the event of a breach, we notify regulators and affected users within 72 hours.

9. Cookies and tracking

We use three categories of cookies:

- **Essential** — session state, language preference. - **Analytics** — PostHog pseudonymous events are strictly opt-in and tied to your account preference. Before server delivery, we replace the account UUID with a deterministic HMAC pseudonym; PostHog does not receive the raw account UUID. Withdrawing consent immediately blocks new collection, removes queued device and server events, and de-identifies delivered database audit rows. An external request already in flight when withdrawal commits cannot be recalled, and events previously delivered to hosted PostHog require a separately authorised operator/data-subject deletion workflow. - **Marketing** — **we do not use third-party advertising tracking cookies.**

10. Changes to this Policy

Updates are published on this page; material changes are emailed.

11. Contact

Privacy questions and data-rights requests: support@predvix.com

---

Mingful 知命 · Hong Kong Readings are provided for entertainment and cultural reference only, and do not constitute professional advice.

Last reviewed · 2026-04-20

© 2026 Mingful · 本內容為娛樂參考,不構成醫療、法律或投資建議