Legal
Privacy Policy
We take your privacy seriously. This policy explains exactly what data we collect, why we collect it, and how it is protected.
Last updated: 22 July 2026
1. Who We Are
ReadMyLove ("we", "us", "our") operates the platform at readmylove.id. We are the data controller responsible for your personal data collected through this Service.
For privacy inquiries, contact us at: support@readmylove.id
2. Data We Collect
Account data
- Email address — required to create an account and sign in
- Password — stored as a secure, irreversible hash; we never see your plain-text password
- Account creation date
Birth data (for consultation generation)
- Full name — used for personalising the consultation text
- Date of birth — day, month, year
- Time of birth — hour and minute (24-hour format)
- Place of birth — city/country (used to contextualise consultations; we do not resolve this to GPS coordinates)
- Gender — optional; used only to personalise your guidance
Token and order records
- Token balance — the number of consultation tokens on your account
- Order records — token purchases or grants, with an order reference, the number of tokens and a timestamp
Consultation history
The full text of consultations you generate is saved to your account so you can revisit them. This includes the input data and the AI-generated output.
Account and payment records
- Your usage history (consultations requested and generated)
- Payment order references (for reconciliation and support)
- We do not collect or store payment credentials. No payment gateway is connected yet, so no payment data exists. When paid plans launch, processing will be handled directly by a licensed payment gateway provider and we will only receive a transaction reference confirming a successful payment.
Technical data
- IP address (stored with each consultation for fraud prevention and rate limiting)
- Basic request logs (timestamps, endpoints accessed)
What we do NOT collect
- We do not use tracking pixels, behavioural analytics, or advertising cookies
- We do not collect social media profiles or third-party identity data
- We do not record audio or video
3. How We Use Your Data
To provide the Service
Your birth data is used solely to calculate your metaphysical chart and generate your AI consultation. It is passed to the AI model to produce the consultation text and then stored in your consultation history.
Account management
Your email and password are used to authenticate you and allow you to access your account and consultation history across devices.
Payment processing
No payment gateway is engaged at present, so no data is shared with one. When paid plans launch, your email address will be shared with the payment gateway provider as part of the transaction, and no other personal data will be shared with them.
Security and fraud prevention
IP addresses and request logs are used to enforce rate limits, detect abuse, and investigate security incidents.
Service communications
We may email you for account-related purposes only (password reset, account notifications). We do not send marketing emails without explicit consent.
AI model processing
Consultation generation requires sending your chart data (name, birth details, calculated chart parameters) to our AI model provider, OpenRouter. This data is used solely to generate your consultation and is subject to OpenRouter's data processing terms. No data is used to train third-party AI models without consent.
4. Data Storage and Security
Your data is stored in Supabase, a secure cloud database platform with infrastructure hosted in the EU. Supabase applies industry-standard security practices including encryption at rest and in transit (TLS).
Access to your data is restricted to authorised systems using service-role credentials. Your data is never accessible to the public or exposed through unsecured interfaces.
Passwords are hashed using bcrypt and are never stored in readable form. We cannot retrieve your password, only reset it.
Despite our security measures, no internet transmission is 100% secure. We cannot guarantee absolute security of data transmitted to or from the Service.
5. Third-Party Services
We use the following third-party services to operate ReadMyLove:
Supabase (database & authentication)
Stores your account, birth data and consultations. Supabase Privacy Policy ↗
OpenRouter (AI model routing)
Routes consultation generation requests to third-party AI language model providers. Your chart data is transmitted to OpenRouter to generate consultations. OpenRouter Privacy Policy ↗
Payment gateway (payment processing)
Once paid plans launch, a licensed Indonesian payment gateway provider will handle all payment transactions via bank Virtual Account transfer and QRIS. No such provider is engaged today. Your bank and payment credentials are processed directly by them, we never see them.
We do not sell, rent, or otherwise share your personal data with any third party for marketing, advertising, or commercial purposes.
6. Data Retention
We retain your data for as long as your account is active. Specifically:
- Account data — retained until you delete your account
- Consultations and birth data — retained until you delete your account
- Payment records — retained for 5 years for accounting and legal compliance purposes, even after account deletion
- IP address logs — retained for 90 days
7. Your Rights
You have the following rights regarding your personal data:
Right to access
You can view all consultations associated with your account at any time through the "My Consultations" section of the app.
Right to deletion
You can permanently delete your account and all associated data through Settings → Delete Account in the app. This action is immediate and irreversible. Payment records are retained for legal compliance as noted above.
Right to correction
You can update your password through the Settings section. To update your email address, contact us at support@readmylove.id.
Right to portability
To request a copy of your data in a structured format, contact us at support@readmylove.id. We will respond within 30 days.
Right to object
You may object to our processing of your data at any time by contacting us. In most cases, objection will require account deletion as your data is necessary to provide the Service.
8. Children's Privacy
The Service is not intended for users under the age of 17. We do not knowingly collect personal data from children. If you believe a child has registered an account, please contact us and we will promptly delete it.
9. Cookies
ReadMyLove does not use tracking cookies. We use localStorage in your browser to store your session token (login credential) so you remain signed in across visits. This is a functional necessity, not a tracking mechanism, and does not contain personal data beyond the authentication token.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes by updating the "Last updated" date above. Continued use of the Service after changes are posted constitutes acceptance of the revised Policy.
11. Contact
For any privacy-related questions, data requests, or concerns:
Email: support@readmylove.id
We aim to respond to all privacy enquiries within 5 business days.