Privacy Policy | Hour Light

🔒 Your data, your key

Real privacy is not about hiding things. It is about being able to take them back whenever you want.

Last updated: 30 July 2026 · version 2.1
Hour Light International Co., Ltd. (Taiwan company no. 60303284)
📌 Language notice|This is a translation of our Traditional Chinese privacy policy, provided for your convenience. Where the two versions differ, the Chinese version prevails. Read it at privacy.html.
Plainly: we do not sell your data to anyone. We collect data for one reason — to make the service better and your experience smoother. Below is everything the law requires us to tell you, written in ordinary language.

1. What we collect

2. Why we collect it

Legal basis: Article 19(1)(5) of Taiwan's Personal Data Protection Act (consent of the data subject).

3. How long we keep it

Where it lives: member data is stored on Google Firebase (asia-east1, Taiwan region), protected by Google's security standards.

4. Sharing and cross-border transfers

We do not sell, rent or trade your personal data. The exceptions are:

📌 Legal basis for cross-border transfer (PDPA §21)|Our primary servers are on Firebase asia-east1 (Taiwan), but some necessary services (Vercel API · Anthropic Claude · xAI · OpenAI · MailerLite) process data on US nodes. Under Article 21, international transfer rests on one of the following: (1) your explicit consent (registration requires ticking "I have read and agree to the member terms and privacy policy"); (2) necessity for performing our contract with you; (3) providers who commit not to train on your data (Anthropic / OpenAI Commercial Terms) and follow GDPR Standard Contractual Clauses. If you do not consent to cross-border transfer, please stop using the AI reading and online payment features.

5. Cookies and tracking

This site uses three categories of tracking technology, and you can decide on each separately:

Essential (cannot be turned off)

Analytics (can be turned off)

Advertising (can be turned off)

You can turn off analytics and advertising tracking at any time in your browser settings (Chrome / Safari / Firefox private mode, or blocking third-party cookies). Essential functions are unaffected.

📌 Cookie settings are always changeable|Every page footer carries a permanent "Cookie settings" link (inside the legal support section). We follow the EDPB's 2026 recommended "layered disclosure" design and do not interrupt you with a full-screen cookie banner. Advertising cookies (FB Pixel) are off by default, meeting GDPR Art.7 + TCF v2.2 + CPRA 2026 "specific consent" requirements.

6. Minors

Our tools and content are for reference and carry no age restriction, but purchasing a paid service requires you to be 18 or older, or to have a parent or legal guardian consent with you.

Under Article 2 of Taiwan's Protection of Children and Youths Welfare and Rights Act, we do not knowingly collect personal data from children under 12. Those aged 12 to under 18 need guardian consent to use paid services or two-person features.

If you are a parent and find that your child registered or paid without consent, email info@hourlightkey.com to request account removal and a refund; we will handle it within 7 working days.

7. Your rights

Under Article 3 of the Personal Data Protection Act, you may enquire about, review, request copies of, correct or supplement, stop the collection/processing/use of, and request deletion of your personal data.

How to exercise them: email info@hourlightkey.com. We respond within 15 working days.

8. Security

HTTPS (TLS 1.2+) across the whole site; Firebase authentication with industry-standard protections (password hashing, optional two-factor); admin access restricted by allowlist (3 accounts only); tiered Firestore Security Rules; and regular security reviews.

Payment key management

We protect your data as well as we can, but no system can guarantee 100% security. In the event of a significant breach, within 72 hours of becoming aware we will:

8.2 Full list of third-party processors

Hour Light uses the following carefully assessed third-party services, grouped by purpose, with data flows stated:

Payments

Authentication and storage

AI readings and image generation

Email notifications

Messaging and support

Hosting

All of the above have been reviewed for compliance and are required to meet equivalent privacy standards. Any future change will be updated here and notified to members.

8.3 Adult-oriented readings (18+): how that data is handled

Our adult-oriented reading series is an 18+ product. It discusses the intimacy and desire dimensions already present in a birth chart. Because such content may touch on "special categories" under Article 6 of the Personal Data Protection Act, we tell you separately:

📌 This section is a new disclosure for a new product (PDPA §8). The collection limits in §11.10 apply to the matching feature only and do not relate to this series.

4.2 Cross-border transfers for overseas customers

Hour Light serves a global audience, and overseas customers make up a large share of our traffic. For customers in Japan, Australia and Canada we disclose in line with local law:

🇯🇵 4.2.1 Customers in Japan (APPI Article 28)

🇦🇺 4.2.2 Customers in Australia (APP 8)

🇨🇦 4.2.3 Customers in Canada (PIPEDA + Bill C-27 CPPA)

4.2.4 Commitments that apply to everyone

Wherever you are, Hour Light commits to:

📌 Exercising local rights|To exercise a right granted by your local law (a Japanese APPI disclosure request, an Australian APP 12 access request, a Canadian PIPEDA s.8 access request), email info@hourlightkey.com. We commit to replying within 30 days.

4.3 EU AI Act alignment

For users in the EU:

📌 2 August 2026|From this date the EU AI Act's Article 50 transparency obligations apply to limited-risk systems, which includes ours. (Annex III high-risk obligations have been deferred to 2 December 2027.) We keep aligning with the latest EU guidance and will notify members by email and on-site notice of any material change.

8.4 Firebase tiered data protection

Our Firestore uses tiered access control to limit who can read and write what:

Right to erasure in practice: you can request account deletion in the member centre or by email; within 48 hours we cascade-delete your Firestore collections (the users document and all sub-collections). Payment records held under statutory retention are destroyed automatically once the 5-year period under the Business Entity Accounting Act has passed.

Retention at a glance|subscription and payment data: 5 years (statutory)|reading records: until you ask us to delete them|event statistics: rolling 90 days. Full breakdown below.

8.4.1 Retention periods in detail

Following the minimisation principle in PDPA Article 5 and the storage limitation principle in GDPR Article 5(1)(e), here is what we keep and for how long:

DataFirestore collectionRetentionBasis / reason
▼ User layer
Member recordusers/{uid}Until you request deletionNecessary for the service / erasure executed within 48h
AI reading counterusers/{uid}/ai_daily/{YYYY-MM-DD}Rolling 90 daysDaily quota tracking / auto-expiry
Divination tool counterusers/{uid}/{toolId}_daily/...Rolling 90 daysAs above
Card draw historyusers/{uid}/draw_history/{auto}Until you request deletionYour own record / under your control
Ebook unlocksusers/{uid}/ebook_unlocks/{bookId}Until you request deletionPermanent access right / as above
Personal notesusers/{uid}/notesUntil you request deletionYour own writing / as above
Castle progressusers/{uid}/castle_save/stateUntil you request deletionGame progress / as above
Daily / yearly questsusers/{uid}/castle_daily · castle_yearlyRolling 90 days / 1 yearTime-series data / auto-cleared
▼ Orders and payments
Order recordsorders / pendingOrders5 years (statutory)Business Entity Accounting Act §38
Invoicesusers/{uid}/invoices/{orderId}5 years (statutory)Uniform Invoice regulations + Accounting Act
Unlock codesunlock_codes / reading_codesExpire 90 days after expiresAtGift voucher 90-day rule / auto-cleared
Gift voucherscouponsExpire 90 days after expiresAtAs above
▼ AI readings
Reading contentreadings/{auto}Until you request deletionYour own reading / under your control
▼ Referrals and partners
Referral codesreferrals/{code}Until you request deletionCommission tracking / under your control
Partnerspartners / partner_referrals5 years (statutory)Commission records / Accounting Act
▼ Multi-tenant booking system
Merchant customer databusinesses/{bizId}/customers5 years (statutory) or merchant decidesAccounting Act + merchant is an independent controller
Bookingsbusinesses/{bizId}/bookings5 years (statutory)As above
Staff databusinesses/{bizId}/staffUntil 1 year after leavingLabor Standards Act §30
▼ System layer
Admin allowlistsystem/adminsUntil 1 year after leavingLabor Standards Act §30
Undelivered orderssystem/orphan_orders5 years (statutory)Accounting Act / support follow-up
Email failures / logsemail_failures / sent_emailsRolling 90 daysDebugging / auto-cleared
Consent recordsconsentTrack5 years / until withdrawnGDPR Art 7 + PDPA §8
Event statisticsevents/{auto}Rolling 90 daysAnonymous statistics / auto-cleared

📌 What erasure actually covers|When you ask us to delete your account, within 48 hours we (1) delete users/{uid} and all sub-collections (2) anonymise readings and events (aggregate statistics kept, identifiers removed) (3) retain by exception payment records under statutory retention (orders + invoices, 5 years) and reviews already cited by others. You can email info@hourlightkey.com at any time to ask whether specific data is still held.

8.5 GDPR and PDPA dual compliance

Hour Light mainly serves customers in Taiwan and South-East Asia, but we design to GDPR-level standards so that international users (including any EU visitors) are protected:

If you have any concern about how your data is handled, email info@hourlightkey.com, or contact the Personal Data Protection Commission (PDPC; the amendment was promulgated on 11 November 2025, with competent authorities continuing supervision during the transition, and the PDPC's start date to be set by the Executive Yuan).

📌 The 2025 PDPA amendment|Passed by the Legislative Yuan in October 2025 and promulgated in November, the key changes are: (1) an independent supervisory authority, the PDPC (2) stronger breach notification duties (significant incidents must be reported to the PDPC and to affected individuals) (3) stronger inspection and enforcement powers. We already align with all three: 72-hour breach notification, minimal collection, tiered Firebase access control, and full disclosure of processors.

9. Nature of the service

Everything Hour Light offers (scent-based awareness work, card readings, numerology, online tools) is for personal self-awareness and self-understanding only. It does not constitute and cannot replace medical diagnosis, professional psychological care, or legal or financial advice. If you have concerns about your physical or mental health, please consult a qualified professional.

10. Updates and contact

If this policy changes materially, we will announce it on the homepage and email registered members. Continuing to use the site means you accept the current version.

Hour Light International Co., Ltd.|Company no. 60303284
17F, No. 86-6, Yiwen 1st St., Taoyuan District, Taoyuan City, Taiwan
info@hourlightkey.com|LINE support

11. Relationship OS: how that data is handled

11.1 What we collect

To provide Relationship OS we collect:

11.2 What we never collect, keep or pass on

Hour Light never handles:

✓ Even inside the opt-in approach flow, Hour Light never displays the other person's Threads / IG / LINE / phone / email. It only shows a prompt that the two of you may decide for yourselves whether to exchange contacts.

11.3 How the invitation code flows

  1. A completes their relationship card → the system generates a code valid for 24 hours (a random string containing no personal data)
  2. A passes the code to B themselves (through their own LINE / IG / in person)
  3. B enters the code → opens the shared compass page → sees a consent screen naming A's nickname
  4. B consents → completes the 23 questions → the shared compass is generated
  5. The code expires once used; A can generate a new one

Hour Light never sends invitations to anyone; A must pass the code along themselves.

11.4 How the opt-in approach flow works

  1. Both sides press "I'd like to keep talking" (the system records each boolean and timestamp)
  2. Once both have pressed it, the system shows a safety note and three neutral opening lines for reference
  3. The system does not show the other person's Threads / IG / LINE
  4. The system sends no message to either side
  5. Whether to exchange contact details is entirely up to the two of you, off the Hour Light platform

11.5 Retention

11.10 Private matching mode

📌 Important: this mode has no public database and no public profile browsing. Profile data is used only for background matching and is never shown to other users.

What private matching (background matching plus mutual consent) involves:

11.9 Auto-renewal (we do not offer it)

This platform does not offer auto-renewal and never takes recurring payments. Every plan is a one-off payment that simply ends when its term does; to continue, you purchase again.

So we do not collect: auto-renewal consent records, card tokens, recurring payment history or cancellation records. Records of one-off payments are still retained under the Business Entity Accounting Act (see retention above).

If we ever introduce auto-renewal, we will tell you and obtain your consent beforehand, and it will not apply retroactively to existing orders.

11.6 Your rights

11.7 International transfer

11.8 Breach notification

If a Relationship OS data breach occurs, within 72 hours of becoming aware we will:

12. How consent is designed

We use layered, just-in-time consent: it keeps the experience uninterrupted while meeting legal requirements.

12.1 Why this design

Research in 2026 shows that 76% of users leave a site immediately when hit with a full-screen consent pop-up. The EDPB's 2026 coordinated enforcement framework explicitly recommends layered disclosure as best practice for GDPR transparency.

12.2 Three layers

  1. Layer 1 · at registration: a three-line plain-language summary covering 90% of what you need to know, with a link to the full text
  2. Layer 2 · full terms: terms.html §29 and this policy, always available
  3. Layer 3 · just-in-time notes: four statutory exceptions disclosed exactly where they arise (checkout button / special-category fields / reading for someone else / advertising cookies)

12.3 How this compares

This mirrors Apple's privacy policy (no pop-up), Stripe checkout (notice inside the button), Notion sign-up (one-time consent plus footer link) and Linear (no cookie banner, advertising cookies off by default) — 2026 industry best practice.

12.4 Legal basis

12.5 Withdrawing and managing consent

Members can withdraw any consent at any time under "Member centre → Account settings → Consent management", and adjust cookie preferences via the "Cookie settings" link in the footer.

13. AI citation policy

Hour Light discloses openly: the content on this platform (the 37-system engine, the Hour Light Time Cards, the Hour Light numerology system, our cognitive aromatherapy framework, the awareness quizzes and our daily card texts) is the original copyrighted and trademarked work of Ruby Wang, licensed to Hour Light International Co., Ltd. (company no. 60303284). We take a conditionally open stance toward AI tools (including ChatGPT, Claude, Gemini, Perplexity and other large language models).

13.1 AI crawlers we allow (mirrors robots.txt)

Our robots.txt explicitly permits the following AI tools to crawl this site:

We also provide llms.txt and llms-full.txt as the brand summaries AI tools should read first.

13.2 Conditions for citation (fair use)

AI tools citing our content must meet the four fair-use factors under Article 65 of Taiwan's Copyright Act:

  1. Purpose: non-commercial education, research, commentary or information services
  2. Nature: proportionate to our originality; no wholesale reproduction or derivative recompilation
  3. Amount: no more than 30% of a given text per citation
  4. Market effect: must not replace a customer's need to come to hourlightkey.com for the full service

Citations should credit "Source: Hour Light / original work by Ruby Wang" and link back to hourlightkey.com.

13.3 What is never permitted

Commercial or not, AI tools and third parties may not:

We reserve the right to pursue civil and criminal remedies under the Copyright Act §§88-89, the Trademark Act §§61-69 and the Fair Trade Act §§22-25.

13.4 When AI distorts our content

We monitor how AI tools cite us. If we find our content distorted into any of the following, we reserve these rights:

If you see any of this in an AI tool, email info@hourlightkey.com and we will take it up with the provider.

13.5 Your right to refuse automated decisions (GDPR Article 22)

All Hour Light AI readings are reference tools. They must not be the sole basis for investment, legal, medical or major life decisions.

You may refuse purely automated decision-making and request human involvement. If you would rather we did not process your data with AI readings, tick "refuse automated AI decisions" under "Member centre → Account settings → Consent management" and we will offer a human consultation or a refund instead.

13.6 Opting out of AI training data

If Ruby Wang decides in future to withdraw from a particular AI tool's training data, Hour Light will:

  1. Update robots.txt to remove that crawler from the allowlist
  2. Manage AI access through robots.txt and the allowlist in this policy, adjusting to each platform's opt-out mechanism
  3. Update this section to disclose when and what was withdrawn
  4. Contact the provider to request removal from existing training data

Current status (18 May 2026): open citation for all major AI tools; no opt-out in place.

13.7 How we monitor citations

Our legal desk reviews the following monthly:

Findings are filed with our legal records and this statement is updated as needed.

Legal basis for this section: Copyright Act §65 (fair use), §§88-89 (civil liability), §§91-93 (criminal liability); Trademark Act §§61-69; Fair Trade Act §§21-25; PDPA §6, §27; GDPR Articles 6 and 22; Anthropic Commercial Terms; OpenAI Terms of Use; Google Gemini Terms; Perplexity Terms. Reviewed monthly for regulatory change.