Mingli Paipan

Effective: September 5, 2026

Privacy Policy

This policy explains how Mingli Paipan processes chart, payment, license, and AI report data.

1. Scope and operator

Mingli Paipan operates the website at lee.locker. Questions about this policy or personal data may be sent to [email protected].

2. Data processed locally

Basic Bazi and Zi Wei Dou Shu chart calculations run primarily in your browser. Birth information, chart history, interface preferences, and saved license keys may be stored in browser local storage. Clearing browser data may remove these records.

Basic local chart calculations work without an account. Full free AI consultation answers require signing in to claim the available allowance. Without account sync, saved records remain on your device except for data you submit to AI services or payment processing as described in sections 3 and 4.

2A. Optional account

You may create an optional account to keep purchases and saved records across devices. You can sign in with a single-use email link or a supported identity provider such as Google or LINE. We store your email address when one has been verified and attached, the provider and stable provider-side identifier for linked sign-in methods, one-time sign-in tokens, and session records. LINE sign-in requests only OpenID and basic profile access; we use its verified ID-token identifier and do not request your LINE email address. Sign-in tokens and session identifiers are stored only as irreversible hashes; anyone who obtained a copy of the database could not use them to sign in as you.

While signed in, we store on our servers the records you choose to keep with your account, which may include birth date, time, gender, calendar type, and birth location, together with saved charts, compatibility results, and AI reports you have generated. Birth details are sensitive personal information; we store them only to provide this synchronisation and never sell or share them for advertising.

Signing in with the email address used for a purchase also links the license keys issued to that address to your account. This is the same trust model as the existing self-service key recovery: whoever controls the mailbox can obtain the keys sent to it.

You can export everything associated with your account as a single file, and you can delete your account at any time from the account page. Deletion is permanent and removes your account, its synchronised charts and reports, its sessions, and the links between your account and any license keys. Purchase and license records themselves are retained as described in section 6 so that refunds, disputes, and legal obligations can still be handled; after deletion they are no longer associated with any account. We also retain one irreversible hash derived from your sign-in identity (your email address, or the provider-side identifier for social sign-in) for the sole purpose of preventing a deleted account from being re-created to claim the free AI consultation allowance again; after deletion it is no longer linked to any account.

2B. Cookies

We use no advertising or cross-site tracking cookies. Signing in sets two strictly necessary cookies: a session cookie that keeps you signed in (not readable by page scripts), and a small flag that tells the page you are signed in so it can skip an unnecessary request for visitors who are not. Signing out clears both. Visitors who never sign in receive no cookies from us.

3. AI report data processing

When you actively request a paid AI report, the chart text, requested report type, selected language, and license key are sent over HTTPS to our Cloudflare-hosted backend. The chart text and instructions are then sent to the configured third-party AI provider to generate the report. Do not submit information about another person unless you have permission to do so.

Reports generated through the consultation system are encrypted before temporary server storage and expire after 24 hours. Saved browser copies and account-synchronised copies have separate lifecycles as described in sections 2 and 2A.

When you ask a question about a paid report, the selected report, its chart text, your question, and prior answers in that Report Conversation are sent to the consultation system and configured AI provider. This content is encrypted before persistent storage and deleted seven days after the last successful answer, or earlier when you use the delete control. The number of Report Questions already used is retained separately to enforce the purchased allowance.

3A. Private consultation data

When you use free or paid AI consultation, birth details, chart facts, questions, selected report attachments, and responses are sent over HTTPS to our Cloudflare-hosted consultation system and configured chart and AI providers. Consultation content is encrypted before persistent storage, used to deliver and resume the service and to review and improve consultation quality, and automatically deleted 90 days after the last activity; you may delete it earlier in the consultation interface. Payment and license records follow the separate retention terms below.

Paid consultations additionally keep a small advisor memory so you do not have to reintroduce yourself each time: your most recently confirmed birth details and a short excerpt of your last few questions and conclusions. It is encrypted with the rest of your consultation data, is never created for the free trial chat, expires 180 days after your last consultation, and can be erased at any time with "Make the advisor forget this" in the consultation interface.

4. Payments and licenses

Payments are processed by Creem as Merchant of Record. We do not receive or store complete card details. To deliver and support purchases, our backend may store a license key, product identifier, checkout and order identifiers, purchase email when supplied by Creem, status, creation time, and daily usage counters. When a purchase email is available, that address and your license key are passed to our email provider once, to deliver the receipt; the interface language you checked out in is carried through the payment metadata so the receipt is sent in that language.

Starting a purchase sends our backend the address to return you to after payment (so the correct report panel reopens) and the product being purchased; when creating the Creem checkout session, we forward that same return address, a checkout/order identifier we generate, and the product identifier, so Creem’s checkout record and related access logs may include the return address. To understand which pages and channels lead to purchases, the checkout session may also carry anonymized traffic-source tags: the path of the page you first landed on (never its query string), a coarse referrer category (such as “search” or “forum”), and any utm campaign labels present in the address you arrived from. These tags contain no birth data and no personal identifiers. That return address only ever contains the page location and payment-status markers — never your birth date, time, gender, calendar type, birthplace coordinates, city, or comparison partner nickname, even if those appeared in your browser’s address bar through the link-sharing feature. Basic chart calculations run primarily in your browser. Account sync and user-requested free or paid AI services process data as described in sections 2A, 3 and 3A; creating a checkout does not itself submit your birth details for AI processing.

5. Service providers

  • Cloudflare — hosting, serverless functions, storage, security, and anonymous traffic and performance analytics (aggregate usage events and Core Web Vitals measurements, without user identifiers).
  • Creem — checkout, payment processing, tax handling, receipts, refunds, and fraud prevention.
  • Configured AI provider — generation of paid reports and consultation responses from submitted chart and conversation text.
  • Resend — delivery of the purchase receipt email containing your license key, when a purchase email is available. Sent only after a completed purchase; no marketing email.
  • Google, GitHub, and LINE — optional account authentication. LINE receives the OAuth/OIDC request and returns a verified stable user identifier and basic profile authorization; Mingli Paipan does not request the LINE email scope.

6. Retention, security, and choices

We retain server-side purchase and license records for as long as reasonably necessary to provide access, prevent abuse, resolve disputes, and meet legal obligations. Local browser data can be removed through the application or browser settings. No internet service is completely secure; we use reasonable technical safeguards but cannot guarantee absolute security.

Account data is retained until you delete your account. Expired sign-in tokens and sessions are cleared automatically. Deleting your account permanently removes it along with everything synchronised to it; see section 2A for what this does and does not cover.

7. Contact and updates

Contact [email protected] to request assistance concerning your data. We may update this policy when our services or providers change; the effective date shown on this page will be revised.