Legal
Privacy Policy
Fireway Studio processes information needed to provide Mystic East. Free results, purchases, external payments and optional analytics are explained below.
Responsibility and rights
Mystic East is operated by Fireway Studio. Representative Kim Donghoon handles privacy requests. Contact: fireway365@gmail.com, +82 10-2434-8245.
You or an authorized representative may request access, correction, deletion, restriction, withdrawal or a copy. We verify requests using minimum information such as the order email, respond within legal deadlines and explain any lawful retention restriction.
Data and purposes
Free results calculate submitted birth date, time/unknown-time choice, location and timezone. Free requests are not stored as purchase reports in our database. This tab’s sessionStorage may prefill checkout; it is cleared on tab closure or paid report load.
Purchases collect name, email, gender, birth details, optional occupation/relationship status/concern, language, product, referral information, payment/refund status and results from forms/payment notices for calculation, delivery, private access and support. Gender is needed for current chart calculation. We do not store full card numbers.
We record acceptance time, interface language, document version, displayed wording and payment-transfer acceptance. Connection IP, browser and errors may be processed for delivery, security and rate limiting. Support uses your email and message.
Necessary processing relies on your service request and contract performance. Payment sharing/overseas transfer and optional analytics have separate consent. Purchase is not consent to marketing emails.
Retention
Reports and birth data remain while we provide private-link access or until deletion is processed. Deletion ends access and recovery support. Unpaid information is deleted after checkout/support closes; inactive orders are reviewed after 30 days.
Korean e-commerce retention: contract/withdrawal and payment/supply records five years; complaints/disputes three years; advertising six months. Only necessary statutory data remains. Birth details and full reports are not retained merely as transaction evidence.
Analytics choices are saved for 180 days. PostHog event retention may be one year on free plans or seven years on paid plans. Withdrawal stops future collection; contact support to delete existing data. Provider periods follow below.
Processors, transfers and refusal
Supabase, Vercel, Anthropic and Resend provide storage, hosting, writing and email. Necessary overseas processing/storage is disclosed under Article 28-8(1)(3) of Korea’s Personal Information Protection Act where applicable. Independent Dodo payment processing and optional PostHog analytics use separate consent.
Encrypted transfers occur on use of each function. Recipients, contacts, locations, data, purpose/timing and retention follow below. Request stopping transfers or deletion through support. Refusing necessary storage, AI or delivery limits paid reports; declining analytics does not limit service.
Supabase — storage
Supabase Pte. Ltd.; privacy@supabase.io. Database: Tokyo, Japan (ap-northeast-1); company: Singapore. Purchases, birth data, reports and consent receipts are stored/retrieved from ordering, for the service/statutory periods above and until deletion. Backups expire under provider cycles; the DPA explains support/subprocessors.
Vercel — hosting
Vercel Inc.; privacy@vercel.com. US and global infrastructure processes pages, APIs and security. Visits include connection details, requests/responses and errors; calculation/purchase requests include submitted inputs. Retention follows request handling, log/backup cycles and necessary legal/security retention.
Anthropic — writing
Anthropic, PBC; privacy@anthropic.com. Necessary birth/chart data, optionally supplied occupation/relationship status/concern and output are processed through its US API during generation. Card data and order email are not sent for writing. Ordinary API input/output is typically deleted within 30 days, subject to legal/usage-policy exceptions.
Resend — delivery
Plus Five Five, Inc. (Resend); support@resend.com. Name, email, report link and delivery status are processed in the US when sending. Standard-plan email/log retention is 30 days; enterprise configuration, account closure, backups and legal retention may differ.
Dodo — payment sharing and overseas transfer
Recipients: Dodo Payments Inc. (United States) and Dodope Payments Limited (United Kingdom). Contact: support@dodopayments.com.
Data: name, email, order identifier, product and payment information. Dodo collects card, billing and connection details on its checkout. We do not send birth details or report text.
Encrypted transfer occurs when opening checkout for payment, tax, refunds, fraud prevention and disputes. Dodo independently processes information as the payment seller.
Retention: the service relationship, applicable legal retention and limitation periods, two months after the limitation period, and active legal claims. See Dodo’s Privacy Policy for details.
You may refuse this sharing and overseas transfer. Paid checkout cannot then proceed; free results remain available. Contact us or Dodo to withdraw. Statutory transaction records may still be retained.
Analytics, cookies and refusal
PostHog Inc.; privacy@posthog.com. Only if allowed, US analytics receives public-page views, clicks, referral information, cookie identifiers and hashed order analytics identifiers. Birth details, email, report text and private URLs are excluded. Session recording and automatic click collection are disabled. Retention follows the plan periods above.
Refuse/withdraw with Analytics preferences in the footer, or clear/block browser cookies/storage. Contact support for other-device withdrawal or deletion of transmitted data. Vercel visit analytics also runs only when allowed.
Fonts and support email
Google LLC font requests may transfer IP, browser and request details to US or other Google infrastructure, excluding birth data. Support uses Gmail, so email/messages may be processed in US or other Google facilities until the matter closes and statutory dispute retention expires.
Deletion and safeguards
On purpose completion or deletion requests, we separate statutory records and remove other data from the database/associated storage. Electronic files use deletion intended to prevent recovery; paper copies are shredded. Backups expire under their cycles and deletions are reapplied after restores.
We use server-only permissions, encrypted transmission, administrator authentication and access restrictions. Keep report links out of public channels.
Complaints and updates
Korean privacy channels include KISA (118) and the Personal Information Dispute Mediation Committee (1833-6972).
Legal Updates records changes, reasons and application dates. Material changes to purposes, recipients or consent are notified beforehand; new consent is obtained where required.
Version 2026-10-05