🔒 Your data, your key
Real privacy is not about hiding things. It is about being able to take them back whenever you want.
Last updated: 30 July 2026 · version 2.1
Hour Light International Co., Ltd. (Taiwan company no. 60303284)
📌
Language notice|This is a translation of our Traditional Chinese privacy policy, provided for your convenience. Where the two versions differ,
the Chinese version prevails. Read it at
privacy.html.
Plainly: we do not sell your data to anyone. We collect data for one reason — to make the service better and your experience smoother. Below is everything the law requires us to tell you, written in ordinary language.
1. What we collect
- What you give us: name, email, date of birth, LINE account (for bookings and member services)
- What the tools generate: birth date, numerology results (calculated on your device; not sent to our servers automatically)
- What is collected automatically: browsing records, device information, IP address (via Google Analytics and Facebook Pixel, to improve the site)
- Paid services: transaction records, invoice details (handled by a third-party payment provider; we never store your card number)
2. Why we collect it
- To provide what you asked for (bookings, online readings, course sign-ups, newsletters)
- To improve how the site works
- To send newsletters or event notices you subscribed to (you can unsubscribe at any time)
- To keep transaction records as required by law
Legal basis: Article 19(1)(5) of Taiwan's Personal Data Protection Act (consent of the data subject).
3. How long we keep it
- Member account data: kept while your account exists; removed from live systems within 48 hours of a deletion request, and fully cleared from backups and offline copies within 30 days
- Transaction records: 5 years, as required by tax law
- Reading results: stored in your browser by default and gone when you clear browsing data; once you log in, some results are stored in the cloud so you can read them across devices
- Site analytics: Google Analytics retains data for 14 months by default
Where it lives: member data is stored on Google Firebase (asia-east1, Taiwan region), protected by Google's security standards.
4. Sharing and cross-border transfers
We do not sell, rent or trade your personal data. The exceptions are:
- When you have explicitly agreed
- When lawfully requested by judicial authorities
- Third-party providers necessary to complete a transaction (payment processing, newsletter platform, AI reading APIs), each required to meet equivalent privacy standards (see §8.2 for the full list)
📌 Legal basis for cross-border transfer (PDPA §21)|Our primary servers are on Firebase asia-east1 (Taiwan), but some necessary services (Vercel API · Anthropic Claude · xAI · OpenAI · MailerLite) process data on US nodes. Under Article 21, international transfer rests on one of the following: (1) your explicit consent (registration requires ticking "I have read and agree to the member terms and privacy policy"); (2) necessity for performing our contract with you; (3) providers who commit not to train on your data (Anthropic / OpenAI Commercial Terms) and follow GDPR Standard Contractual Clauses. If you do not consent to cross-border transfer, please stop using the AI reading and online payment features.
5. Cookies and tracking
This site uses three categories of tracking technology, and you can decide on each separately:
Essential (cannot be turned off)
- Firebase Authentication|keeps you logged in and syncs across devices|without it you cannot log in or pay
Analytics (can be turned off)
Advertising (can be turned off)
- Facebook Pixel (ID: 1333106288588347)|ad performance and retargeting|opt out via Facebook ad preferences or by blocking third-party cookies
You can turn off analytics and advertising tracking at any time in your browser settings (Chrome / Safari / Firefox private mode, or blocking third-party cookies). Essential functions are unaffected.
📌 Cookie settings are always changeable|Every page footer carries a permanent "Cookie settings" link (inside the legal support section). We follow the EDPB's 2026 recommended "layered disclosure" design and do not interrupt you with a full-screen cookie banner. Advertising cookies (FB Pixel) are off by default, meeting GDPR Art.7 + TCF v2.2 + CPRA 2026 "specific consent" requirements.
6. Minors
Our tools and content are for reference and carry no age restriction, but purchasing a paid service requires you to be 18 or older, or to have a parent or legal guardian consent with you.
Under Article 2 of Taiwan's Protection of Children and Youths Welfare and Rights Act, we do not knowingly collect personal data from children under 12. Those aged 12 to under 18 need guardian consent to use paid services or two-person features.
If you are a parent and find that your child registered or paid without consent, email info@hourlightkey.com to request account removal and a refund; we will handle it within 7 working days.
7. Your rights
Under Article 3 of the Personal Data Protection Act, you may enquire about, review, request copies of, correct or supplement, stop the collection/processing/use of, and request deletion of your personal data.
How to exercise them: email info@hourlightkey.com. We respond within 15 working days.
8. Security
HTTPS (TLS 1.2+) across the whole site; Firebase authentication with industry-standard protections (password hashing, optional two-factor); admin access restricted by allowlist (3 accounts only); tiered Firestore Security Rules; and regular security reviews.
Payment key management
- PAYUNi payment encryption uses AES-256-GCM (HashKey + HashIV with EncryptInfo + AuthTag, SHA-256 signature)
- Keys live in Vercel's encrypted environment variables — never in git, never written to server logs, injected only at serverless runtime
- Key rotation: immediately upon any security incident or personnel change, plus an annual review
- Payment details (card number, CVV) never pass through this platform; PAYUNi transmits them encrypted directly to the issuing bank
- We retain only: merchant order number (MerTradeNo), PAYUNi transaction ID, amount and payment time (5 years, per Article 38 of the Business Entity Accounting Act)
We protect your data as well as we can, but no system can guarantee 100% security. In the event of a significant breach, within 72 hours of becoming aware we will:
- Notify affected users (scope of the breach, likely impact, remediation advice, emergency contact)
- Report to the Personal Data Protection Commission (PDPC), per PDPA §12 and the 2025 amendments (and to the competent authority during the transition period)
- Provide affected users with necessary assistance (account protection, password change guidance, credit monitoring advice)
- Publish progress on our homepage and official LINE account
8.2 Full list of third-party processors
Hour Light uses the following carefully assessed third-party services, grouped by purpose, with data flows stated:
Payments
- PAYUNi (merchant ID U031269167)|handles credit cards, ATM virtual accounts, convenience-store codes, Apple Pay, Google Pay|encryption: AES-256-GCM|licensed third-party payment provider in Taiwan|card details never pass through this platform, PAYUNi sends them encrypted straight to the issuing bank
Authentication and storage
- Firebase (Google)|region: asia-east1 (Taiwan)|handles email/Google login, member data, reading records, subscription status|Firebase Security Rules restrict read and write access
AI readings and image generation
- Anthropic Claude API (US)|generates readings for the Time Cards, chart tools and skin analysis|requests carry no direct identifiers (no email, real name, address or phone)|no training: under Anthropic Commercial Terms your data is not used to train models|transfer basis: your consent (PDPA §21)
- xAI Grok API (US)|(1) wallpaper prompt synthesis (only your chosen theme plus chart results; no PII); (2) generation of adult-oriented readings (18+ only)|data sent for those readings: full chart calculation results (birth date, time, gender and the 37 systems derived from them) plus any nickname you entered for a partner in your own chart library (two-person edition)|no email, address or phone|no training: under xAI API Terms, API data is not used for training by default|transfer basis: your consent (PDPA §21)
- OpenAI gpt-image-1 API (US)|generates wallpaper images|only the synthesised prompt text is sent; no PII|no training by default under the OpenAI API Data Usage Policy
- Google Gemini API (US, Google LLC)|OG image prompt design, backup image analysis, multimodal prompt tasks|only the prompts and images needed for the feature; no PII (email, name, address, phone)|no training: under Google AI for Developers Terms, API-tier data is not used to train models by default|transfer basis: your consent (PDPA §21)
Email notifications
- MailerLite (account ID 2060689, US)|monthly gift notices, delivery of reading reports, event notices|every email carries a one-click unsubscribe link|transfer basis: your consent (PDPA §21)
Messaging and support
- LINE Messaging API (@hourlight official account)|support messages and booking notifications|messages you send are anonymised after 90 days (aggregate statistics retained); staff replies are kept until the account is deleted|never forwarded to third parties
- Discord Webhook (internal operations channel)|forwards feedback you submit and course-viewing anomaly alerts (multi-IP logins) to our internal desk|not public, not forwarded to third parties|retention: rolling 90 days
Hosting
- Vercel (Hobby plan, US nodes, covered by GDPR Standard Contractual Clauses)|runs 10 serverless APIs (payments, AI readings, email, reconciliation)|environment variables encrypted; no user data persisted on the server|minimisation: only the fields strictly necessary cross the border
- GitHub Pages|hosts 1,100+ static front-end pages|no cookies, no behavioural tracking
All of the above have been reviewed for compliance and are required to meet equivalent privacy standards. Any future change will be updated here and notified to members.
8.3 Adult-oriented readings (18+): how that data is handled
Our adult-oriented reading series is an 18+ product. It discusses the intimacy and desire dimensions already present in a birth chart. Because such content may touch on "special categories" under Article 6 of the Personal Data Protection Act, we tell you separately:
- Purpose|to generate a reading for you from the birth data you provide.
- Categories of data|birth date, hour, gender, and the chart results derived from them; the two-person edition also includes the birth data and nickname you entered for the other person in your own chart library. We do not collect — and never ask about — your actual sex life, sexual history, orientation or health data. The reading is derived from a chart, not a record of your private life.
- Processing|chart results are sent to xAI Grok API (US) to generate the reading (see §8.2); the result is stored in Firebase Firestore (asia-east1) for you to read in your member area. Never used for marketing, never disclosed, never used to train models.
- Retention and deletion|you may request deletion of any such reading at any time; we delete it promptly and keep no copy. Email hourlightkey@gmail.com.
- Separate consent|purchase requires your separate, explicit consent (PDPA §6 I (6), §7). Declining does not affect any other service.
- Limits of the two-person edition|it is for spouses or partners only, and is written from your perspective and the interaction between you; we make no assertions about the sex life of a third person who has not consented. The system also gates relationship and age: if the other person is under 18, generation is refused and fully refunded.
- No medical or therapeutic claims|this reading (including any scent suggestions) is not a medical service, has no therapeutic effect and makes no medical claims, and cannot replace a physician, psychologist or sex therapist. If something is troubling you, please seek professional help.
📌 This section is a new disclosure for a new product (PDPA §8). The collection limits in §11.10 apply to the matching feature only and do not relate to this series.
4.2 Cross-border transfers for overseas customers
Hour Light serves a global audience, and overseas customers make up a large share of our traffic. For customers in Japan, Australia and Canada we disclose in line with local law:
🇯🇵 4.2.1 Customers in Japan (APPI Article 28)
- Receiving country|Taiwan (Hour Light International Co., Ltd., company no. 60303284, 17F, No. 86-6, Yiwen 1st St., Taoyuan District, Taoyuan City)
- Data protection regime in Taiwan|the Personal Data Protection Act as amended (passed October 2025) with oversight by the PDPC
- Third-party processors|Anthropic (US) / xAI (US) / OpenAI (US) / Vercel (US) / Google Firebase (asia-east1, Taiwan region preferred)
- Purpose|Time Card readings / chart tools / AI readings / wallpaper generation / skin analysis
- Legal basis|APPI Article 28 on cross-border transfer (amended June 2021, effective April 2022; formerly Article 24), plus the duty to inform you about the receiving country when obtaining consent (country name, its data protection regime, the recipient's safeguards)
- Consent|registration requires ticking "I have read and agree to the member terms and privacy policy"; the transfers and receiving-country information in this section form part of that policy
🇦🇺 4.2.2 Customers in Australia (APP 8)
- Disclosure|your personal information will be disclosed to Hour Light International Co., Ltd. (Taiwan) and 4 US AI service providers
- Notice of likely overseas disclosure|under APP 1.4(f)(g) and APP 5.2(i)(j), we notify you of this at the point of collection
- APP 8 notice|once your data leaves Australia, some APP protections may not apply; Hour Light nonetheless commits to Taiwan's PDPA and the transparency principles of GDPR Articles 13/14
- Reasonable steps|(1) Anthropic Commercial Terms (no training) (2) tiered Firebase access control (3) AES-256-GCM payment encryption (4) 72-hour breach notification
- 2024 reforms|we do not rely on contract alone, and align with the strengthened accountability principles of Australia's 2024 reforms
🇨🇦 4.2.3 Customers in Canada (PIPEDA + Bill C-27 CPPA)
- Transfer out of Canada|your personal information will be transferred to Taiwan (Hour Light International Co., Ltd.) and the US (4 AI providers)
- Foreign authority access|courts and agencies in Taiwan and the US may access your data under their own laws. We assist only under a lawful warrant (per Taiwan's Communication Security and Surveillance Act) and notify you where feasible under PDPA §12
- Safeguards|(1) contractual protection (PIPEDA Principle 4.1.3) (2) continuing accountability for data with US processors (3) data processing agreements aligned with recipients
- Bill C-27 CPPA|we align with the incoming CPPA requirements on cross-border accountability, contractual safeguards and transparent disclosure
- Contacting the OPC|if you have concerns about cross-border processing you may contact the Office of the Privacy Commissioner of Canada (priv.gc.ca)
4.2.4 Commitments that apply to everyone
Wherever you are, Hour Light commits to:
- Minimal collection (we do not collect real names, addresses, phone numbers or national ID numbers)
- Tiered Firebase access control (asia-east1, Taiwan region preferred)
- Full third-party disclosure (4 US AI providers + Vercel + Firebase + MailerLite)
- 72-hour notification for significant breaches (PDPA §12 as amended + GDPR Articles 33-34)
- No training on your data (Anthropic Commercial Terms)
- Transparency: we email members before any material change in processing
- Support in Chinese and English at info@hourlightkey.com
📌 Exercising local rights|To exercise a right granted by your local law (a Japanese APPI disclosure request, an Australian APP 12 access request, a Canadian PIPEDA s.8 access request), email info@hourlightkey.com. We commit to replying within 30 days.
4.3 EU AI Act alignment
For users in the EU:
- Classification|Hour Light AI readings (Time Cards / 37 systems / skin analysis) fall under limited risk and minimal risk. They are not Annex III high-risk systems (no education scoring, proctoring, HR decisions, credit scoring, law enforcement, migration or justice)
- Not a prohibited practice under Article 5|our readings are not used for crime-risk prediction, social scoring or manipulative AI
- Article 50 transparency|(1) every AI reading is labelled as AI-generated (2) you always know you are interacting with AI (3) AI-generated images carry an AI disclosure footer
- Your decision stays yours|readings are for self-awareness only; the final decision is always yours, aligned with the GDPR Article 22 right regarding automated decisions
- Complaints|EU customers may complain to their local data protection authority, or email info@hourlightkey.com
📌 2 August 2026|From this date the EU AI Act's Article 50 transparency obligations apply to limited-risk systems, which includes ours. (Annex III high-risk obligations have been deferred to 2 December 2027.) We keep aligning with the latest EU guidance and will notify members by email and on-site notice of any material change.
8.4 Firebase tiered data protection
Our Firestore uses tiered access control to limit who can read and write what:
- User data (users/{uid}, reading records, subscription status)|read: you plus an admin allowlist (3 accounts)|write: you, or an authenticated backend API
- Order data (pendingOrders, orders, reading_codes)|read: admins only|write: payment callback backend only
- Event statistics (events)|read: admins only|anonymous statistics
Right to erasure in practice: you can request account deletion in the member centre or by email; within 48 hours we cascade-delete your Firestore collections (the users document and all sub-collections). Payment records held under statutory retention are destroyed automatically once the 5-year period under the Business Entity Accounting Act has passed.
Retention at a glance|subscription and payment data: 5 years (statutory)|reading records: until you ask us to delete them|event statistics: rolling 90 days. Full breakdown below.
8.4.1 Retention periods in detail
Following the minimisation principle in PDPA Article 5 and the storage limitation principle in GDPR Article 5(1)(e), here is what we keep and for how long:
| Data | Firestore collection | Retention | Basis / reason |
| ▼ User layer |
| Member record | users/{uid} | Until you request deletion | Necessary for the service / erasure executed within 48h |
| AI reading counter | users/{uid}/ai_daily/{YYYY-MM-DD} | Rolling 90 days | Daily quota tracking / auto-expiry |
| Divination tool counter | users/{uid}/{toolId}_daily/... | Rolling 90 days | As above |
| Card draw history | users/{uid}/draw_history/{auto} | Until you request deletion | Your own record / under your control |
| Ebook unlocks | users/{uid}/ebook_unlocks/{bookId} | Until you request deletion | Permanent access right / as above |
| Personal notes | users/{uid}/notes | Until you request deletion | Your own writing / as above |
| Castle progress | users/{uid}/castle_save/state | Until you request deletion | Game progress / as above |
| Daily / yearly quests | users/{uid}/castle_daily · castle_yearly | Rolling 90 days / 1 year | Time-series data / auto-cleared |
| ▼ Orders and payments |
| Order records | orders / pendingOrders | 5 years (statutory) | Business Entity Accounting Act §38 |
| Invoices | users/{uid}/invoices/{orderId} | 5 years (statutory) | Uniform Invoice regulations + Accounting Act |
| Unlock codes | unlock_codes / reading_codes | Expire 90 days after expiresAt | Gift voucher 90-day rule / auto-cleared |
| Gift vouchers | coupons | Expire 90 days after expiresAt | As above |
| ▼ AI readings |
| Reading content | readings/{auto} | Until you request deletion | Your own reading / under your control |
| ▼ Referrals and partners |
| Referral codes | referrals/{code} | Until you request deletion | Commission tracking / under your control |
| Partners | partners / partner_referrals | 5 years (statutory) | Commission records / Accounting Act |
| ▼ Multi-tenant booking system |
| Merchant customer data | businesses/{bizId}/customers | 5 years (statutory) or merchant decides | Accounting Act + merchant is an independent controller |
| Bookings | businesses/{bizId}/bookings | 5 years (statutory) | As above |
| Staff data | businesses/{bizId}/staff | Until 1 year after leaving | Labor Standards Act §30 |
| ▼ System layer |
| Admin allowlist | system/admins | Until 1 year after leaving | Labor Standards Act §30 |
| Undelivered orders | system/orphan_orders | 5 years (statutory) | Accounting Act / support follow-up |
| Email failures / logs | email_failures / sent_emails | Rolling 90 days | Debugging / auto-cleared |
| Consent records | consentTrack | 5 years / until withdrawn | GDPR Art 7 + PDPA §8 |
| Event statistics | events/{auto} | Rolling 90 days | Anonymous statistics / auto-cleared |
📌 What erasure actually covers|When you ask us to delete your account, within 48 hours we (1) delete users/{uid} and all sub-collections (2) anonymise readings and events (aggregate statistics kept, identifiers removed) (3) retain by exception payment records under statutory retention (orders + invoices, 5 years) and reviews already cited by others. You can email info@hourlightkey.com at any time to ask whether specific data is still held.
8.5 GDPR and PDPA dual compliance
Hour Light mainly serves customers in Taiwan and South-East Asia, but we design to GDPR-level standards so that international users (including any EU visitors) are protected:
- Data minimisation|we collect only what the service needs
- Purpose limitation|data is used only for the stated purposes (generating readings, subscription notices, anonymous statistics)
- Data portability|you can request an export of your data (JSON), handled within 15 working days
- Right to be forgotten|you can request deletion of your account and all data, executed within 48 hours
- Transparency|we email members before any material change in processing
- Taiwan PDPA|we follow the duty to inform (§8), purpose limitation (§19) and data subject rights (§27)
If you have any concern about how your data is handled, email info@hourlightkey.com, or contact the Personal Data Protection Commission (PDPC; the amendment was promulgated on 11 November 2025, with competent authorities continuing supervision during the transition, and the PDPC's start date to be set by the Executive Yuan).
📌 The 2025 PDPA amendment|Passed by the Legislative Yuan in October 2025 and promulgated in November, the key changes are: (1) an independent supervisory authority, the PDPC (2) stronger breach notification duties (significant incidents must be reported to the PDPC and to affected individuals) (3) stronger inspection and enforcement powers. We already align with all three: 72-hour breach notification, minimal collection, tiered Firebase access control, and full disclosure of processors.
9. Nature of the service
Everything Hour Light offers (scent-based awareness work, card readings, numerology, online tools) is for personal self-awareness and self-understanding only. It does not constitute and cannot replace medical diagnosis, professional psychological care, or legal or financial advice. If you have concerns about your physical or mental health, please consult a qualified professional.
10. Updates and contact
If this policy changes materially, we will announce it on the homepage and email registered members. Continuing to use the site means you accept the current version.
Hour Light International Co., Ltd.|Company no. 60303284
17F, No. 86-6, Yiwen 1st St., Taoyuan District, Taoyuan City, Taiwan
info@hourlightkey.com|LINE support
11. Relationship OS: how that data is handled
11.1 What we collect
To provide Relationship OS we collect:
- The nickname you choose (up to 8 characters; we suggest not using your real name)
- Your answers to the 23-question relationship quiz
- Timestamps for invitation codes generated or received
- The shared compass result (both types, rhythm comparison, sticking-point analysis)
- The "I'd like to keep talking" status (a boolean for each side)
- Your member UID (to identify your account; never shown to the other person)
- Membership entitlement status (to unlock the opt-in approach flow)
11.2 What we never collect, keep or pass on
Hour Light never handles:
- The other person's Threads account
- The other person's Instagram account
- The other person's LINE ID or account
- The other person's phone number
- The other person's email (unless they are already a member, in which case matching happens on internal UIDs only and is never shown to the other side)
- Any private conversation between you (for example after you add each other on LINE)
- Any record of you meeting, calling or interacting privately
✓ Even inside the opt-in approach flow, Hour Light never displays the other person's Threads / IG / LINE / phone / email. It only shows a prompt that the two of you may decide for yourselves whether to exchange contacts.
11.3 How the invitation code flows
- A completes their relationship card → the system generates a code valid for 24 hours (a random string containing no personal data)
- A passes the code to B themselves (through their own LINE / IG / in person)
- B enters the code → opens the shared compass page → sees a consent screen naming A's nickname
- B consents → completes the 23 questions → the shared compass is generated
- The code expires once used; A can generate a new one
Hour Light never sends invitations to anyone; A must pass the code along themselves.
11.4 How the opt-in approach flow works
- Both sides press "I'd like to keep talking" (the system records each boolean and timestamp)
- Once both have pressed it, the system shows a safety note and three neutral opening lines for reference
- The system does not show the other person's Threads / IG / LINE
- The system sends no message to either side
- Whether to exchange contact details is entirely up to the two of you, off the Hour Light platform
11.5 Retention
- Shared compass results: 12 months (from the last visit by either side; members may keep them permanently on their memory wall)
- "I'd like to keep talking" status: 90 days (after which it lapses and must be expressed again)
- After 12 months without a visit: automatically anonymised (aggregate statistics kept, identifiers removed)
- You can clear your side at any time via "disconnect the shared compass" in the member centre
- Auto-renewal consent records: we do not offer auto-renewal, so no such data exists
- Payment history: 7 years (Business Entity Accounting Act)
- Cancellation-of-auto-renewal records: not applicable, as we do not offer auto-renewal
- Voluntary platform support contributions: 5 years (stored in events, with amount, timestamp and PAYUNi transaction ID)
11.10 Private matching mode
📌 Important: this mode has no public database and no public profile browsing. Profile data is used only for background matching and is never shown to other users.
What private matching (background matching plus mutual consent) involves:
- Collected: six profile fields (nickname / age band / region / what you are looking for / short bio + Threads ID) plus match-notification records, accept/decline/block/report actions, and edit history (90 days)
- Shown to the other user: on a successful match, only each other's Threads ID. Nickname, age, region and bio are never disclosed
- Limits on compatibility analysis: it must never disclose either person's birth date, chart, quiz answers, cards, match reasoning or full report. It may only offer interaction rhythm, getting-along notes, communication suggestions, boundary reminders and safe next steps
- Never collected (permanently prohibited): LINE / IG / FB / phone / email (your registration email is never published) / real name / full address / employer / special-category data under PDPA §6 (health, politics, religion, sexual orientation)
- Retention: a profile inactive for 1 month leaves the matching pool automatically; if you opt out you can restore within 30 days, after which identifiers are permanently deleted (aggregates kept); match notifications 12 months; reports 5 years; block lists permanently (you can undo them)
- Your rights: query, correct or delete your matching profile at any time; leave the pool at any time; block any matched person at any time; request full account deletion, handled within 30 days
- Cross-border: Firestore asia-east1 (Taiwan). Not transferred to the EU or China; available to users in Taiwan only
11.9 Auto-renewal (we do not offer it)
This platform does not offer auto-renewal and never takes recurring payments. Every plan is a one-off payment that simply ends when its term does; to continue, you purchase again.
So we do not collect: auto-renewal consent records, card tokens, recurring payment history or cancellation records. Records of one-off payments are still retained under the Business Entity Accounting Act (see retention above).
If we ever introduce auto-renewal, we will tell you and obtain your consent beforehand, and it will not apply retroactively to existing orders.
11.6 Your rights
- Access: query your Relationship OS data at any time
- Correction: request correction if anything is wrong
- Deletion: request permanent deletion (timing varies by data type; generally within 30 days)
- Restriction: ask us to stop processing your related data at any time
- Withdrawal of consent: withdraw at any time, without affecting lawful processing before withdrawal
- Requests via LINE @hourlight
11.7 International transfer
- Relationship OS data is stored on Firebase (Google Cloud asia-east1, Taiwan)
- Not transferred to the EU, and not to servers inside mainland China
- US OpenAI / Anthropic APIs process only your quiz answers for analysis; no personal data is retained and no models are trained on it
11.8 Breach notification
If a Relationship OS data breach occurs, within 72 hours of becoming aware we will:
- Notify affected users (scope, likely impact, remediation advice)
- Report to the competent authority under PDPA §12
- Provide free assistance (account protection, password change guidance)
12. How consent is designed
We use layered, just-in-time consent: it keeps the experience uninterrupted while meeting legal requirements.
12.1 Why this design
Research in 2026 shows that 76% of users leave a site immediately when hit with a full-screen consent pop-up. The EDPB's 2026 coordinated enforcement framework explicitly recommends layered disclosure as best practice for GDPR transparency.
12.2 Three layers
- Layer 1 · at registration: a three-line plain-language summary covering 90% of what you need to know, with a link to the full text
- Layer 2 · full terms: terms.html §29 and this policy, always available
- Layer 3 · just-in-time notes: four statutory exceptions disclosed exactly where they arise (checkout button / special-category fields / reading for someone else / advertising cookies)
12.3 How this compares
This mirrors Apple's privacy policy (no pop-up), Stripe checkout (notice inside the button), Notion sign-up (one-time consent plus footer link) and Linear (no cookie banner, advertising cookies off by default) — 2026 industry best practice.
12.4 Legal basis
- Taiwan Personal Data Protection Act §15, §19, §27
- Taiwan Consumer Protection Act §19 (right to withdraw from distance sales)
- GDPR Articles 6, 7, 13
- EDPB 2026 Coordinated Enforcement Framework
- ICO layered privacy notice guidance
- US CPRA 2026 symmetry principle
- IAB Europe TCF v2.2
12.5 Withdrawing and managing consent
Members can withdraw any consent at any time under "Member centre → Account settings → Consent management", and adjust cookie preferences via the "Cookie settings" link in the footer.
13. AI citation policy
Hour Light discloses openly: the content on this platform (the 37-system engine, the Hour Light Time Cards, the Hour Light numerology system, our cognitive aromatherapy framework, the awareness quizzes and our daily card texts) is the original copyrighted and trademarked work of Ruby Wang, licensed to Hour Light International Co., Ltd. (company no. 60303284). We take a conditionally open stance toward AI tools (including ChatGPT, Claude, Gemini, Perplexity and other large language models).
13.1 AI crawlers we allow (mirrors robots.txt)
Our robots.txt explicitly permits the following AI tools to crawl this site:
- GPTBot (OpenAI) / ChatGPT-User
- ClaudeBot (Anthropic) / anthropic-ai
- PerplexityBot
- Google-Extended (Gemini) / Applebot-Extended
- cohere-ai / Bytespider / CCBot
- FacebookBot / Meta-ExternalAgent
We also provide llms.txt and llms-full.txt as the brand summaries AI tools should read first.
13.2 Conditions for citation (fair use)
AI tools citing our content must meet the four fair-use factors under Article 65 of Taiwan's Copyright Act:
- Purpose: non-commercial education, research, commentary or information services
- Nature: proportionate to our originality; no wholesale reproduction or derivative recompilation
- Amount: no more than 30% of a given text per citation
- Market effect: must not replace a customer's need to come to hourlightkey.com for the full service
Citations should credit "Source: Hour Light / original work by Ruby Wang" and link back to hourlightkey.com.
13.3 What is never permitted
Commercial or not, AI tools and third parties may not:
- Copy the Hour Light Time Cards' names, palette, structure or reading logic wholesale
- Copy our numerology system's formulas, H.O.U.R. four-number definitions or twelve-house mapping wholesale
- Copy the 37-system integration architecture as their own AI reading product
- Use "Hour Light" or our other marks as their own service name, or in any way that misleads customers
- Recompile, adapt or create derivative works from our content without licence
- Distort our content into medical diagnosis, clinical counselling or guaranteed fortune-changing — all of which we explicitly disclaim
We reserve the right to pursue civil and criminal remedies under the Copyright Act §§88-89, the Trademark Act §§61-69 and the Fair Trade Act §§22-25.
13.4 When AI distorts our content
We monitor how AI tools cite us. If we find our content distorted into any of the following, we reserve these rights:
- Claims of "treatment", "diagnosis" or "medical" → we ask the provider to correct it immediately and log it as compliance evidence
- Claims of "guaranteed change of fortune" or "guaranteed prediction" → as above
- Claims of clinical psychological counselling → as above
- Fabricated testimonials or fabricated partnerships → as above, plus public correction where necessary
If you see any of this in an AI tool, email info@hourlightkey.com and we will take it up with the provider.
13.5 Your right to refuse automated decisions (GDPR Article 22)
All Hour Light AI readings are reference tools. They must not be the sole basis for investment, legal, medical or major life decisions.
You may refuse purely automated decision-making and request human involvement. If you would rather we did not process your data with AI readings, tick "refuse automated AI decisions" under "Member centre → Account settings → Consent management" and we will offer a human consultation or a refund instead.
13.6 Opting out of AI training data
If Ruby Wang decides in future to withdraw from a particular AI tool's training data, Hour Light will:
- Update robots.txt to remove that crawler from the allowlist
- Manage AI access through robots.txt and the allowlist in this policy, adjusting to each platform's opt-out mechanism
- Update this section to disclose when and what was withdrawn
- Contact the provider to request removal from existing training data
Current status (18 May 2026): open citation for all major AI tools; no opt-out in place.
13.7 How we monitor citations
Our legal desk reviews the following monthly:
- Changes in AI Search Console citation counts (61 in the current 90 days)
- The quality of AI citations for our core terms (Hour Light numerology / 37 systems / Hour Light Time Cards / H.O.U.R.)
- Any distortion, infringement or trademark misuse
Findings are filed with our legal records and this statement is updated as needed.
Legal basis for this section: Copyright Act §65 (fair use), §§88-89 (civil liability), §§91-93 (criminal liability); Trademark Act §§61-69; Fair Trade Act §§21-25; PDPA §6, §27; GDPR Articles 6 and 22; Anthropic Commercial Terms; OpenAI Terms of Use; Google Gemini Terms; Perplexity Terms. Reviewed monthly for regulatory change.