Trust
Security & Privacy.
Your birth data and chart are personal. Here's plainly how they're protected, who can see them, and what rights you have — no legal boilerplate.
How your data is protected
Encrypted in transit
Every connection between your device and BaZiWar runs over TLS/HTTPS — the same standard used for banking and healthcare apps.
Row-level database security
Our database enforces row-level security (RLS) — your account can only ever read its own data, enforced at the database layer, not just the app.
Need-to-know access
Employee access to user data is limited to what's needed to operate and support the Service — not open by default.
Secure sessions
Login sessions use secure token management, not long-lived passwords floating in requests.
Full technical and legal detail lives in our Privacy Policy.
Who can see your chart
Your birth data and BaZi chart are yours. We don't sell personal information, and we don't share it for cross-context advertising. Data goes to a short list of service providers (Supabase for the database, OpenAI for Xia's coaching, Stripe for billing, Cloudflare for infrastructure) strictly to operate the Service — under contracts that limit what they can do with it. Full list in our CCPA and Privacy pages.
Age requirements
BaZiWar account eligibility is 13 and up, consistent with COPPA. We do not knowingly collect personal information from children under 13 — if we learn an account belongs to a child under 13, we delete it and the associated data. Full detail in our Child Safety Standards.
Your rights, wherever you are
United States
California residents have specific rights under CCPA/CPRA. See CCPA Rights.
European Union & UK
EU, UK, and Swiss residents have rights under GDPR — access, correction, deletion, portability, and more. See GDPR Rights.
Everywhere else
Our Privacy Policy applies globally, and we honor deletion and access requests from any BaZiWar user regardless of region.
Questions
Reach us at support@baziwar.com, or see our full FAQ.