Trust

Security & Privacy.

Your birth data and chart are personal. Here's plainly how they're protected, who can see them, and what rights you have — no legal boilerplate.

How your data is protected

Encrypted in transit

Every connection between your device and BaZiWar runs over TLS/HTTPS — the same standard used for banking and healthcare apps.

Row-level database security

Our database enforces row-level security (RLS) — your account can only ever read its own data, enforced at the database layer, not just the app.

Need-to-know access

Employee access to user data is limited to what's needed to operate and support the Service — not open by default.

Secure sessions

Login sessions use secure token management, not long-lived passwords floating in requests.

Full technical and legal detail lives in our Privacy Policy.

Who can see your chart

Your birth data and BaZi chart are yours. We don't sell personal information, and we don't share it for cross-context advertising. Data goes to a short list of service providers (Supabase for the database, OpenAI for Xia's coaching, Stripe for billing, Cloudflare for infrastructure) strictly to operate the Service — under contracts that limit what they can do with it. Full list in our CCPA and Privacy pages.

Age requirements

BaZiWar account eligibility is 13 and up, consistent with COPPA. We do not knowingly collect personal information from children under 13 — if we learn an account belongs to a child under 13, we delete it and the associated data. Full detail in our Child Safety Standards.

Your rights, wherever you are

United States

California residents have specific rights under CCPA/CPRA. See CCPA Rights.

European Union & UK

EU, UK, and Swiss residents have rights under GDPR — access, correction, deletion, portability, and more. See GDPR Rights.

Everywhere else

Our Privacy Policy applies globally, and we honor deletion and access requests from any BaZiWar user regardless of region.

Questions

Reach us at support@baziwar.com, or see our full FAQ.