Bamgwabi Privacy Policy
Last updated: October 3, 2026
Lumi (the "Company") provides Bamgwabi (bamgwabi.com), a saju and tarot reading service, in compliance with the Personal Information Protection Act and other applicable laws, and processes only the minimum personal information necessary to provide the service.
1. Personal Information We Process and Why
| Category | Data (required or optional) | Purpose |
|---|---|---|
| Kakao login | Kakao account member number (required) | Identify members and maintain their login sessions, retrieve purchased readings, and verify their identity for payment, refund, and other inquiries |
| Google login | Google account identifier (required), email address (required) | Identify members and keep them logged in, display the account in Profile, retrieve purchased readings, and verify identity for payment, refund, and other inquiries |
| Apple login | Apple account identifier (required) — we do not receive your name or email address | Identify members and maintain their login sessions, retrieve purchased readings, and verify their identity for payment, refund, and other inquiries |
| Bamgwabi in the Toss app | User identifier provided to Bamgwabi by Toss (required) | Identify users, retrieve purchased readings, and verify their identity for payment, refund, and other inquiries |
| Information entered while using the service | Your and the other person's dates of birth (required), birth times (required or optional depending on the question—some questions don't ask for it if unknown), genders (required), breakup date (for breakup questions), and selected question and topic (required) | Calculate saju, compatibility, and tarot results, write readings, and let you view results again |
| Saved to your account | The date of birth, birth time (not saved if unknown), and gender most recently entered for yourself—saved when you use the service while logged in | Preselect your date of birth, birth time, and gender on the input screen for your next reading |
| Web reading purchases | Member account ID or guest browser session ID, order number, payment processor transaction number, purchased reading, amount, date and time, and a one-way encrypted value identifying the reading request — required to make a purchase | Verify purchases, provide purchased readings, and respond to payment, refund, and other inquiries |
| Toss app reading purchases | User ID, order number, purchased reading, amount, date and time, and a one-way encrypted value identifying the reading request — required to make a purchase | Verify purchases, provide purchased readings, and respond to payment, refund, and other inquiries |
| iPhone app reading purchases | Account ID or browser session ID, order number, App Store transaction ID, purchased reading, amount, date and time, and a one-way encrypted value identifying the reading request — required to make a purchase | Verify purchases, provide purchased readings, and respond to payment, refund, and other inquiries |
| Android app reading purchases | Account ID or browser session ID, order number, Google Play order number, purchased reading, amount, date and time, and a one-way encrypted value identifying the reading request — required to make a purchase. The purchase token is used to verify the purchase and remains in the device's browser storage along with the information entered for the purchased reading. | Verify purchases, provide and restore purchased readings, and respond to payment, refund, and other inquiries |
| Paid reading storage (logged-in members) | Results of paid readings purchased while logged in — your saju chart, five elements, and reading text (the other person's saju chart and five elements are not stored) | Access readings again in Saved readings on any device for 1 year from the payment date |
| Reviews (from October 8, 2026) | Star rating and one-line review submitted by a user who purchased a reading, date and time submitted, and the order number linked to the review — collected only when submitted (optional) | Collect and display reviews without names, improve the service, and filter out abusive language and advertising |
| Sharing results | The shared result's question, people, main answer, summary, and reading text (excluding dates of birth, birth times, saju charts, and account information) — collected only when shared (optional) | Show the result to anyone with the sharing link |
| One-on-one inquiries | Inquiry type and content, reply email address (required for guests, optional for members), account ID or browser session ID, purchase history at the time of the inquiry (order number, purchased reading, amount, date and time, status), and the conversation if the inquiry came from chat support — collected only when an inquiry is made | Review and respond to inquiries, and process payments and refunds |
| Chat support | Content entered and responses provided during support, account ID or browser session ID — collected only when using support | Respond to inquiries, review support quality, and prevent misuse |
| Data collected automatically | Access logs, device and browser information, cookies, and browser storage (required) | Keep you logged in, save results in Saved readings, diagnose errors, and prevent misuse |
| Visit statistics | Visited page paths, referring sites, browser and device types, loading times, and performance metrics | Aggregate visit statistics that do not identify individuals and improve site performance. Not used for advertising or tracking individuals across sites |
We do not collect resident registration numbers or payment details such as card or bank account information. The payment processor handles payment details for paid readings directly.
Your logged-in account stores only one set of the date of birth, birth time, and gender entered for yourself. New entries replace the previous values. The other person's date of birth, birth time, and gender entered for compatibility or other readings are used only to calculate results and are not stored (they are also used solely to create a one-way encrypted value identifying the purchased reading). If you use the service without logging in, the information you enter is not saved to an account.
2. Retention periods
- Member information (account ID and personal information saved to your logged-in account) is deleted 7 days after you request account deletion. Before then, you can cancel the request in your Profile. You can request account deletion through chat support or by contacting us using the details below. Records retained by law (reading purchase records, one-on-one inquiry records, and chat support records) are stored separately from your account. Identifiers in those records (email address, member number, and Apple ID) are masked, and the one-way encrypted value identifying the reading request is deleted. Once account deletion is complete, devices where you were previously logged in are also logged out.
- Reading purchase records (web, Toss app, iPhone app, and Android app) are retained for 5 years under the “Records of payment and supply of goods, etc.” category below, then deleted.
- Paid readings purchased by logged-in members are stored on the server for 1 year from the payment date, then deleted. If a member deletes a reading from Saved readings, it is deleted immediately. If they delete their account, it is deleted when account deletion is complete (7 days after the request).
- Readings purchased by guests are not saved to the server or transferred to a logged-in member's Saved readings. You can view results during the current purchase session. Clearing browser data also removes results remaining on your device.
- Reviews are retained while displayed in the service and deleted immediately if the author requests removal using the contact details below. If a member deletes their account, their reviews are also deleted when account deletion is complete (7 days after the request).
- Shared results are retained for 1 year from the date they are shared, then deleted (if the same result is shared again, the 1-year period starts from that date). To delete a result sooner, send its sharing link using the contact details below.
- One-on-one inquiry and chat support records are retained for 3 years under the “Records of consumer complaints or dispute resolution” category below, then deleted. The reply email address provided in a one-on-one inquiry is retained with the inquiry record for 3 years and is not masked when the member deletes their account.
- However, information that applicable laws require us to retain is kept for the required period, then deleted.
- Records of contracts or contract withdrawals, payments, and the supply of goods, etc.: 5 years (Electronic Commerce Act)
- Records of consumer complaints or dispute resolution: 3 years (Electronic Commerce Act)
- Operational and error diagnostic logs are retained in Cloudflare Workers Logs for up to 7 days. Cloudflare provides aggregate visit statistics for the most recent 6 months.
3. Disclosure to third parties
The Company does not disclose users’ personal information to third parties, except in response to a lawful request under applicable laws.
4. Outsourced processing and overseas transfers
The service runs on overseas cloud infrastructure. We outsource the processing of personal information as follows, and the information is transferred overseas in the process.
| Recipient | Destination country | Data transferred | Purpose | Retention period |
|---|---|---|---|---|
| Cloudflare, Inc. privacyquestions@cloudflare.com | Countries where Cloudflare data centers are located, including the United States | Information processed under Section 1. To draft chat support replies: submitted content (with IDs masked), login method, whether account deletion has been requested, platform (app/web), and purchase history (purchased readings, amounts, dates and times, and status — IDs and order numbers are not sent). Non-identifying visit statistics. | Server hosting, data storage, content delivery, drafting chat support replies, and compiling visit statistics | Until the retention periods in Section 2 expire (deleted when the outsourcing agreement ends) |
| OpenAI OpCo, LLC dsar@openai.com | United States | Saju values calculated from birth date, birth time, and gender; values calculated from entered dates, such as a breakup date; and selected questions and cards (names, contact details, and other information that could identify users are not sent) | Turning calculation results into easy-to-understand readings | Until the purpose of the outsourced processing is fulfilled (subject to the processor's policy) |
Transfers occur as needed over communications networks while the service is in use. Users may refuse overseas transfers, but doing so may make it difficult to use the service. To refuse, contact us using the details below.
5. How we delete information
Electronic files are deleted in a way that prevents recovery. We do not create separate paper documents.
6. Your rights
- You may request access to, correction or deletion of, or suspension of processing of your personal information at any time. Submit your request using the contact details below, and the Company will handle it without delay.
- We do not collect personal information from children under 14. Kakao's consent screen confirms that users are at least 14 when they log in with Kakao. If we learn that personal information belongs to a child under 14, we delete it without delay.
7. Security Measures
- Encryption in transit (HTTPS), limiting access to what's necessary, and storing authentication secrets separately
- Login sessions are maintained using server-signed cookies that page scripts cannot read (HttpOnly).
- We collect only the minimum data necessary — login collects only account IDs (including email addresses for Google). Birth date, birth time, and gender are used only for the purposes above, not for advertising or marketing messages.
8. Cookies and Browser Storage
We use cookies and browser storage to keep you logged in (for up to 30 days) and save results in Saved readings. You can block them in your browser settings, but this may make it difficult to stay logged in or use Saved readings.
Non-identifying visit statistics
We use Cloudflare Web Analytics to collect statistics on page visits and loading performance. These analytics don’t use cookies, local storage, or browser fingerprinting to identify visitors or track their activity across sites. Names, birth dates, submitted stories, and account identifiers aren’t sent for analytics, and Cloudflare doesn’t record URL query parameters in its analytics.
We don’t use advertising tracking code. Cookies and storage needed for login, purchases, and saving results, as well as consent to send reading information from the app, are separate from the site analytics described above.
9. Privacy Officer
Privacy Officer: Kim Hyun (CEO)
Contact: help@bamgwabi.com
You can also report privacy violations or get advice from the Personal Information Infringement Report Center (privacy.kisa.or.kr; dial 118, no area code needed).
10. Notices
Changes to this policy will be announced in the service at least 7 days before they take effect.
- Initial announcement and effective date: September 28, 2026
- Amendment announced and effective: September 28, 2026 — Reduced the information collected to just the member number for Kakao login and the user identifier provided by Toss within the Toss app. Added storage of the account holder’s birth date, birth time, and gender in their login account, along with payment records. Marked each item as required or optional.
- Amendment announced and effective: September 30, 2026 — Specified that paid readings purchased by logged-in members are stored on the server for 1 year from the payment date (the other person’s saju chart and five elements aren’t stored), while guest purchases are stored only on the device.
- Amendment announced: October 1, 2026 · Effective date: October 8, 2026 — Added optional star ratings and one-line reviews from users who purchased readings.
- Amendment announced and effective: October 1, 2026 — Restricted Saved readings to logged-in members and specified that readings purchased before login are moved to the member’s Saved readings when they log in on that device.
- Amendment announced and effective: October 3, 2026 — Discontinued automatic transfer of guest purchase results to members’ Saved readings and specified that guests can view results during the current purchase session.
- Amendment announced and effective: October 1, 2026 — Opened customer support (one-on-one inquiries and chat support), added inquiry and support records (retained for 3 years) and information transferred overseas to draft chat support replies, and specified that account deletion takes place 7 days after the request and can be canceled from Profile before then.
- Amendment announced and effective: October 1, 2026 — Corrected the deletion timing for a departing member’s saved readings to when account deletion is complete (7 days after the request). Specified that, once deletion is complete, the member’s reviews are deleted, devices that were logged in are logged out, IDs in records kept separately from the account are masked, and values that identify reading requests are removed. Also specified that IDs in content sent to draft chat support replies are masked. Added the conditions for transferring guest-purchased readings to a member’s Saved readings: logging in within 24 hours of purchase without closing the purchase screen.
- Amendment announced and effective date: October 1, 2026 — Added Apple login (only the Apple account identifier is collected; names and email addresses are not collected).
- Amendment announced and effective: October 2, 2026 — Added iPhone app reading purchases (App Store transaction IDs), payment processor transaction IDs for web reading purchases, and breakup dates for breakup questions to the information processed. Added iPhone app purchases to the reading purchase records retained. Specified that the reply email address for one-on-one inquiries is retained with inquiry records for 3 years and isn’t masked upon account deletion. Changed the provider used to draft readings and support replies to OpenAI, and added values calculated from entered dates, account deletion request status, and platform (app/web) for chat support to the information sent. Corrected Cloudflare’s retention period to the periods specified in Section 2.
- Amendment announced and effective: October 2, 2026 — Changed chat support reply drafting to Cloudflare Workers AI and updated the purpose and information sent under the processing outsourced to Cloudflare. OpenAI is used to draft readings.
- Amendment announced and effective: October 2, 2026 — Added result sharing (displaying shared results at a share URL and retaining them for 1 year from the date they’re shared).
- Amendment announced and effective: October 3, 2026 — Added the collection method and retention period for non-identifying site analytics, along with the processor’s contact details. Corrected the retention period for operational and error diagnosis logs to match actual service practices.