Legal
Privacy Policy
Last updated 16 September 2026
Your birth date, time, and place are the whole basis of your reading. This page says plainly what we do with them — and what we don't.
Who we are
Kairo publishes personalised Korean Saju readings at askkairo.ai. Kairo is operated from South Korea, which means the people who run it are there; the servers that hold your data are described below. For privacy questions, corrections, or deletion requests, write to hello@askkairo.ai and we will respond within 30 days.
The person responsible for personal information at Kairo is our Privacy Officer (Founder), reachable at hello@askkairo.ai. That is the address to use for any request about your data, wherever you live.
What we collect
When you order a reading, the form asks for your date of birth, time of birth (or a note that it is approximate or unknown), city of birth, the gender you were born as, the name that should appear on the report, and the email address the report should be sent to. If you order a Compass reading, you also describe the decision you want read. The form also has one optional tick-box asking whether we may email you occasionally about Kairo; if you tick it, we record that you did and when.
Payment is handled entirely by Gumroad, the merchant of record for every Kairo order. We never see or store your card number. Gumroad passes us the order details and the email address attached to the payment so we can match your payment to your reading.
We also record how you arrived — the advertising or referral tags on the link you followed, and the page you landed on — so we can tell which channels are worth paying for. Our hosting provider records the country your request came from at the network level. If you choose to leave a review, that two-letter country code is stored with your review and shown as a flag next to it. You are never asked to share your location.
Because your reading is a digital product delivered electronically, we also keep a delivery record. When your report email is sent we store the sending service’s message ID and the delivery events it reports back — accepted, delivered, opened; the email contains a standard invisible open-tracking image, which is how “opened” is known. When your reading page or its PDF is opened, we log the date and time, the network (IP) address, and the browser type of that visit. These records exist to prove your reading reached you if a payment dispute ever arises. They are not used for advertising or analytics and are not shared with anyone except, if a dispute occurs, the payment provider handling it.
Free readings
Kairo also offers a free reading. You enter your date, time, and city of birth, and we calculate and show your chart before asking for anything. To open the written part of that reading we ask for your email address, which is where we send it. That is the only thing required.
Separately, there is an optional tick-box — empty unless you tick it — asking whether we may also email you about new Kairo readings, offers, and seasonal notes. That is marketing email. Your reading opens whether or not you tick it, and ticking it is never a condition of anything. Every marketing message carries a one-click unsubscribe link, and you can also simply reply and say stop.
We store your email address, the birth details you entered (date, time or a note that it is unknown, city, and the coordinates and time zone that city resolves to), the archetype your chart resolved to, the advertising or referral tags on the link you arrived by, and — if you ticked the optional box — the fact and exact time that you gave that permission. These records are kept separately from orders. We do not ask for your name, and no payment information is involved. Nothing here is sold or shared for anyone else’s marketing.
We keep a free-reading record for as long as the permission stands. If you unsubscribe, we stop emailing you and keep only what is needed to honour that — or delete the record entirely if you ask. One email to hello@askkairo.ai is enough.
Why we use it
Your birth details are used to calculate your Four Pillars chart and to write your report. Your name is used to address the report to you. Your email address is used to deliver that report, to answer you if you write to us, and once — a few days later — to ask how the reading was.
If, and only if, you ticked the optional box when you ordered, we may also email you now and then about new Kairo readings and features. That is separate from your order, it is never a condition of receiving your reading, and every one of those emails carries a one-click unsubscribe link. You can also simply reply and say stop. If you never ticked the box, you will not receive them.
We do not use your birth details, your chart, or the contents of your reading for advertising. We do not sell your personal information, and we do not share it with anyone except the service providers listed below, who process it on our instructions in order to run the service.
Advertising and analytics
Kairo advertises on Meta (Facebook and Instagram), and to know whether those ads are worth running we have to be able to connect an ad click to an order. Two things do that, and we would rather describe them plainly than bury them.
The first is the Meta pixel, which runs on our pages and sets cookies (named “_fbp” and “_fbc”) identifying your browser and, if you came from an ad, that specific click. It tells Meta when a page is viewed, when an order form is opened, and when checkout is started. The second is that when an order completes, our server sends Meta a purchase event containing the amount, the product, and your email address hashed — put through SHA-256 into a fixed string that Meta can compare against its own hashed records but cannot read back into your address. Your birth details are never part of either.
To see how people move through the site we use PostHog, served through our own domain, which counts page views and a small number of events such as “opened the order form” and “started checkout”. Session recording is switched off, so PostHog does not replay what you typed or where you moved your mouse.
If you would rather not be measured this way, browser tracking protection or an ad blocker will stop the pixel and the analytics script, and Kairo works normally without them — nothing on this site requires them to load. Meta's own ad settings let you limit how your activity off Meta is used. The purchase event is sent from our server, so blocking in the browser does not prevent it; if you want that one removed after the fact, email us and we will ask Meta to delete it.
If you are in Quebec
Quebec law requires that technologies which identify, locate or profile you are switched off by default. If you visit from Quebec, neither the Meta pixel nor the PostHog analytics script is loaded at all until you choose. A banner asks once, accepting and declining are equally easy, and declining leaves the site fully working. Your choice is remembered in your own browser, and clearing your browser data asks again.
Who processes your data
Running Kairo requires a small number of providers, each handling one part: Gumroad (payment and receipts, as merchant of record), Vercel (website hosting), Render (the service that generates your report), Supabase (the database and file storage where your order and report are kept), Resend (sending your delivery email), Anthropic (the language model used to compose the writing in your report from your calculated chart), PostHog (the site analytics described above), and Meta (advertising measurement, receiving only the hashed email and order value described above). Each receives only what it needs for its own step.
Your information is handled across borders as a matter of course. Kairo is operated from South Korea, and the providers above store and process data in the United States — Gumroad, Vercel, Render, Supabase, Resend, Anthropic, PostHog and Meta — and in South Korea, where our own working files sit. Each provider is engaged on terms that require it to protect what it holds and to use it only for the step we engaged it for. If you want to know where a specific piece of your data sits, ask and we will tell you.
How long we keep it
The PDF file of your report is kept for 180 days from delivery, so that you can download it again during that window. On the day after it expires the PDF file is deleted from our storage automatically. Your reading page — the link in your delivery email — and the text behind it stay available after that; it is the file, not the reading, that is removed. Records we are required to keep for accounting and tax purposes are retained by Gumroad under their own policy. If you have given us marketing permission, we keep the record of that permission for as long as it stands, and we will ask you to confirm it again rather than assume it forever. Free-reading records follow the rule described under “Free readings” above. You can ask us to delete your order, your reading page, and your birth details at any time by emailing us — we will confirm once it is done.
Your choices
You can ask for a copy of the data we hold on you, ask us to correct it, or ask us to delete it. You can withdraw marketing permission at any time, either from the link in any such email or by writing to us. You can also ask us not to send the single follow-up email that asks how your reading was. One email to hello@askkairo.ai is enough for any of these; you do not need to explain why.
If you are in Quebec, you can also ask us to send you the information you gave us in a structured, commonly used electronic format, or to pass it on to someone else — we will provide it as a machine-readable file.
If you are not satisfied with how we handle a request, you can complain to the privacy regulator where you live: the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, the Office of the Australian Information Commissioner, or the Personal Data Protection Commission in Singapore. We would rather you wrote to us first, but that route is yours either way.
If something goes wrong
If personal information we hold is lost or exposed in a way that could cause you real harm, we will notify you and the relevant regulator as quickly as we can, and tell you plainly what happened, what was involved, what we have done about it, and what you can do. We keep an internal record of every such incident, including ones that did not meet the threshold for notification.
Children
Kairo readings are sold to adults, and the free reading is for adults too. Please do not use Kairo if you are under 18. We do not knowingly collect information from children; if you believe a child has given us their details, write to us and we will delete them.
Changes
If this policy changes in a way that affects what we do with your data, we will update the date at the top of this page. Material changes will be described here rather than made quietly. A change here never gives us permission we did not already have for data we already hold — if we ever want to use your information for something new, we will ask you.