One Divination · ColorfulMoon
Privacy Policy
2026-09-07 · 2026-09-07Who we are
One Divination is operated by ColorfulMoon. Contact us about privacy and data rights at mgming03@outlook.com. This policy covers the iOS and Android apps and their optional cloud service. Effective date: 7 September 2026.
Your choice: offline or cloud
The core card readings, reflection journal and settings work on your device without an account. Those entries remain on your device unless you expressly enable cloud sync or separately consent to an AI request. An AI request creates an anonymous cloud identity if needed and saves only the selected reading as conversation context; it does not enable whole-journal sync or upload private notes. Viewing an online policy or checking the optional service configuration creates a network request, but does not upload your journal. Disabling cloud sync stops future uploads; use Delete cloud data to erase copies already uploaded.
Data processed on your device
The app stores your chosen language, preferences, consent choices, readings, journal notes and favorites locally. It does not require your real name, email address, date of birth, precise location, contacts, photos or advertising identifier. No advertising or cross-app tracking SDK is included. Device-level backups or exports that you choose are controlled by you and your operating-system provider. Protect exported files because they can contain private reflections.
Where the cloud service operates
ColorfulMoon’s optional cloud service is hosted on Tencent Cloud infrastructure in Singapore (ap-singapore). Reading records and reports that you choose to send are processed and stored there, which may be outside your country. Cloudflare provides DNS, CDN and a TLS reverse proxy for the domain. API and page requests pass through its global network, which processes request contents, IP addresses, connection metadata and security logs to deliver and protect the service. Its processing locations and retention depend on the applicable service terms and settings; see https://www.cloudflare.com/privacypolicy/ and https://www.cloudflare.com/cloudflare-customer-dpa/. The hosting provider may process infrastructure operation and security records under its applicable service terms.
Optional cloud data
After you agree to this policy version and either cloud sync or the selected-reading storage disclosed before AI, the service creates a random user identifier and a secret session token. The service stores a hash of the token, your language, consent version, creation and last-use timestamps, and the reading records that you choose to sync: questions, cards, interpretations, dates, notes and favorites. When only AI is enabled, the selected reading is saved without uploading private notes; previously synced notes are preserved. We use this data to provide sync, retrieve your entries, secure access and fulfill your deletion or export request. Your email is not linked to the anonymous account. The token is the access credential; losing it can prevent access and recovery.
Optional AI and third parties
AI is optional and requires separate, explicit consent. Before you send a request, the app displays the configured AI provider, its privacy notice, processing region and retention description. Only the question, selected cards and the reading context needed for that request are sent to that provider. Private journal notes, session tokens and your cloud identifier are not included. AI may be inaccurate. Avoid entering names, contact details, health information or other sensitive information. The provider may process data outside your country under the disclosed terms. If AI is not configured, no question is sent to an AI provider. Do not use AI if you do not accept the disclosed processing. Withdrawing AI consent prevents future AI requests; it cannot recall a completed request.
Feedback and support
When you report content, we store your chosen category, report text, the AI answer you select to include, optional reading reference and anonymous user identifier to investigate the report. Reports are not automatically forwarded to an AI provider. Support emails contain the address and information you choose to send, and are handled through the operator’s email service. Do not email session tokens.
Retention and deletion
Local entries remain until you delete them or clear the app’s data; removing the app may not remove operating-system backups. Synced data remains until you delete the entry or cloud account, or the cloud account has been inactive for 365 days. Session credentials expire after 90 inactive days. Reports are deleted after 90 days, and immediately with the cloud account. Deleting a cloud account revokes its sessions and deletes associated readings and reports from the live service. The reference service does not create database backups automatically. Any future backup or retention change must be disclosed before deployment. Provider retention for AI is disclosed separately before consent.
Security and technical requests
Production communication requires HTTPS. Access to cloud entries requires a secret token, stored by the app using platform secure storage; the server retains only a cryptographic hash. Database access is restricted to the service account. The service briefly uses the connecting IP address in memory to limit abuse, for up to one hour; it does not retain IP access logs or use them for advertising. Error logs contain a request identifier and error code, not questions, notes, tokens or IP addresses. No service can guarantee absolute security.
Your rights and controls
In You → Data & privacy, you can review privacy information, stop cloud sync, export your data, clear the local journal and delete all cloud data. You can delete individual readings from their journal entry. AI permission is requested separately for each AI action; you can decline later requests or stop sending questions. Local data and cloud data are separate: remove both if you want both copies erased. You may contact mgming03@outlook.com to request access, correction, deletion, consent withdrawal or assistance, and where applicable object, restrict processing, request portability or complain to your local privacy authority. We must verify that you control the anonymous account before acting on an account-specific request; an email address alone cannot identify it. We aim to respond within 30 days, or the shorter period required by applicable law.
Age, purpose and updates
The service is intended for people aged 18 or older and is not designed for children. Readings are for reflection and entertainment, not medical, legal, financial or emergency services. We do not sell personal data or use it for targeted advertising. We will publish policy changes with a new version and seek renewed consent for materially different processing before enabling it. Mandatory privacy rights in your jurisdiction remain unaffected.