BaZiWar
Privacy Policy
Effective date: May 27, 2026 · Last updated: June 10, 2026
BaZiWar is operated by Luxey Holdings LLC and Ofye Group (collectively, "we," "our," or "us"). Luxey Holdings LLC is a California limited liability company. This Privacy Policy describes how we collect, use, store, share, and protect information when you use the BaZiWar mobile application, baziwar.com, and related services (collectively, the "Service").
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, do not use the Service. This Privacy Policy is incorporated by reference into our Terms of Service.
1. Information We Collect
1.1 Information You Provide Directly
- Account credentials — email address and/or phone number used to create and authenticate your account.
- Profile information — display name, username, and optional profile photo.
- Birth data (your own) — date, time, and location of birth. This information is used solely to calculate your BaZi Four Pillars chart and provide personalized readings and coaching. It is stored securely on your account and is never sold to third parties.
- Target profiles — birth data you voluntarily enter for other individuals ("Targets"). You are solely responsible for ensuring you have appropriate consent, authorization, or lawful basis for entering any third party's birth data. See Section 4.
- Messages and content — messages sent through BaZiWar's direct messaging, group rooms, community features, and content shared with Xia (our AI coaching system).
- Missions and notes — mission data, strategy reports, saved messages, and notes you create within the app.
- Support communications — emails or messages you send to support@baziwar.com.
1.2 Information Collected Automatically
- Device information — device type, model, operating system version, and app version.
- Session and authentication data — login timestamps, session duration, session tokens, and device identifiers used for security and session management.
- Usage data — features accessed, in-app navigation, and interaction patterns, used to improve the Service and diagnose technical issues.
- Error and crash data — diagnostic information generated when the app encounters errors, used solely to improve app stability.
1.3 What We Do Not Collect
We do not:
- Use third-party advertising networks or sell your personal information to advertisers.
- Track you across other apps or websites for advertising purposes.
- Collect your precise GPS location (birth location is entered manually by you).
- Access your device contacts, camera, or microphone without your explicit in-app permission grant.
- Knowingly collect personal information from individuals under 17 years of age.
2. How We Use Your Information
- Create and manage your account, and authenticate your identity.
- Calculate and display your BaZi Four Pillars chart, daily readings, and personalized interpretations.
- Power the Xia AI coaching and strategy system by providing your chart data and conversation history as context for AI responses.
- Enable messaging, community features, and social interactions within the app.
- Process subscription purchases and manage billing through Apple, Google, or Stripe.
- Send account-related communications, including OTP codes, security alerts, and account notifications. We do not send marketing emails without your explicit consent.
- Detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms.
- Analyze aggregate, non-identifying usage patterns to improve and develop the Service.
- Comply with legal obligations, court orders, and regulatory requirements.
3. Artificial Intelligence — Xia and AI Processing
BaZiWar uses OpenAI's API to power Xia, our AI coaching system. When you interact with Xia:
- Your message content and relevant chart context (BaZi pillar data, profile information) are sent to OpenAI for processing to generate a response.
- OpenAI processes this data as a data processor on our behalf, subject to OpenAI's Privacy Policy and data processing agreements.
- As of the effective date of this policy, OpenAI does not use data sent via the API to train its models, pursuant to its API data usage policies.
Important AI disclaimer: AI-generated outputs are for informational and entertainment purposes only. They are not professional, legal, financial, psychological, medical, or other regulated advice.
4. Third Parties and Target Profiles
The Target profile feature allows you to enter birth data for other individuals. You acknowledge that:
- You are solely responsible for obtaining any necessary consent or authorization before entering another person's birth data.
- the Operators store Target birth data associated with your account solely to provide the Target analysis features you request.
- We do not independently verify whether you have consent to enter any individual's birth data.
- If a third party contacts us to request removal of their birth data that you entered, we will evaluate such requests and may remove the data at our discretion.
- You indemnify and hold the Operators harmless from any claim by any individual whose data you entered without appropriate authorization.
5. How We Share Your Information
We do not sell your personal information. We share information only in the following circumstances:
| Recipient | Data Shared | Purpose |
| Supabase, Inc. | Account and user data | Database hosting, authentication, and storage |
| OpenAI, LLC | Message content, chart context | AI response generation via Xia |
| Stripe, Inc. | Billing email, subscription metadata | Payment processing for web checkout subscriptions |
| Apple Inc. | Purchase transactions | App distribution and payment processing (iOS) |
| Google LLC | Purchase transactions | App distribution and payment processing (Android) |
| Resend, Inc. | Email address, message content | Transactional and support email delivery |
| Cloudflare, Inc. | Technical logs, API requests | Website hosting, security, and API infrastructure |
| Law enforcement / courts | As legally required | Compliance with legal process or government requests |
| Successor entity | All data, with notice to you | Merger, acquisition, or sale of assets |
We do not share your birth data, personal chart, or messages with other users of the Service without your explicit action (e.g., you choose to share content in a community room).
6. Data Security
We implement industry-standard security measures including encrypted connections (TLS/HTTPS), row-level security (RLS) in our database, secure session token management, and access controls limiting employee access to user data on a need-to-know basis.
However, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security of your data.
7. Data Breach Notification
In the event of a data breach that is reasonably likely to result in risk to your rights or freedoms, we will notify affected users within seventy-two (72) hours of becoming aware of the breach, or as soon as reasonably practicable, to the extent required by applicable law.
8. Data Retention
- Account data is retained while your account is active and for up to 90 days after account deletion.
- Messages may be retained for the period necessary to deliver them and for a reasonable period thereafter for security auditing and dispute resolution.
- AI conversation logs sent to OpenAI are subject to OpenAI's retention policies.
You may request deletion of your account and associated data at any time by contacting support@baziwar.com or using the in-app Delete Account feature. We will process deletion requests within 30 days, subject to any legal retention obligations.
9. Your Rights — California Residents (CCPA/CPRA)
If you are a California resident, you have the right to know, delete, correct, and limit use of sensitive personal information, and the right to non-discrimination for exercising privacy rights. We do not sell or share personal information for cross-context behavioral advertising.
To exercise these rights, contact support@baziwar.com with the subject line "California Privacy Rights Request." We will respond within 45 days.
10. Users Outside California
Regardless of where you are located, you may contact us at support@baziwar.com to access, correct, delete, or restrict processing of your personal information. We will respond in good faith and to the extent required by applicable law.
11. Children's Privacy
BaZiWar is intended exclusively for users aged 17 and older. We do not knowingly collect personal information from individuals under 17. If we become aware that we have collected such information, we will delete it promptly and terminate the associated account.
12. Third-Party Links and Services
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. The inclusion of any link does not imply endorsement by the Operators.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on baziwar.com, updating the "Last updated" date, or by other appropriate means. Your continued use of the Service after changes take effect constitutes your acceptance of the updated policy.
14. Contact Us
Luxey Holdings LLC and Ofye Group
Attn: Privacy
PO Box 3315, San Felipe Rd Ste 49
San Jose, CA 95135
United States
support@baziwar.com