Legal & Compliance

Privacy Policy

Last updated: August 18, 2026
This Privacy Policy explains how SPYLL (https://spyll.id) collects, uses, stores, and protects your personal information when you access and use our personality profiling web application.

1. Information We Collect

SPYLL collects information you provide directly when taking the profiling quiz, including: name/preferred name, email address, date of birth, time of birth, birthplace, gender, and quiz responses.

When you choose to sign in with Google (Google OAuth), we receive basic profile details from Google including your full name, email address, and profile picture avatar.

We also store limited technical session data (such as secure session tokens and local storage) strictly required to keep your authentication state and profile access safe.

2. How We Use Your Data

Collected information is used to: (a) calculate and generate your personalized reading based on BaZi, Zi Wei Dou Shu, and modern psychology; (b) authenticate and manage your user account; (c) store and provide ongoing access to your blueprint report whenever you sign in; and (d) process transactions or voucher access.

Your birth date, time, and birthplace are utilized solely for astrological chart calculations and SPYLL internal personality mapping models.

3. Google User Data & Limited Use Disclosure

Data obtained via Google OAuth (such as your verified email address and basic profile) is used exclusively for account authentication and linking your report history to your Google account.

SPYLL does not sell, rent, or transfer user data obtained through Google APIs to third parties for advertising, third-party marketing, or data monetization purposes.

SPYLL's use and transfer of information received from Google APIs to any other app adheres strictly to the Google API Services User Data Policy, including the Limited Use requirements.

4. Data Storage and Security

User data is stored on secure cloud database infrastructure with industry-standard encryption protocols (HTTPS/TLS) in transit and role-based access control.

We apply technical and organizational security practices to prevent unauthorized access, tampering, or data disclosure.

5. Third-Party Data Processing

We do not sell personal data to any third party.

Data is only processed by trusted infrastructure vendors essential for SPYLL operations, such as hosting and database providers (e.g. Supabase), AI generation APIs for report synthesis, and secure payment processors.

All service providers are bound by strict confidentiality obligations and process information solely under SPYLL instructions.

6. User Rights, Data Retention, and Deletion

You have the right to review, update, or request permanent deletion of all personal data and report history stored on SPYLL.

You can also revoke SPYLL's access permissions to your Google account at any time via your Google Account Permissions settings (https://myaccount.google.com/permissions).

To request full deletion of your account and data, email our support team at [email protected].

7. Updates to This Policy

SPYLL may update this Privacy Policy periodically to reflect service evolutions or legal requirements. The latest revision date will always be indicated at the top of this page.

8. Contact Us

If you have questions, feedback, or requests regarding privacy and personal data protection, please contact the SPYLL team at [email protected].

Questions regarding these terms?[email protected]