bori.life

Privacy Policy

Last updated · August 4, 2026

01Who we are

Bori ("we", "us") is an AI companion that reads Korean saju — your birth chart — and talks it through with you. This policy explains what we collect when you use bori.life, why we collect it, who processes it on our behalf, and how you can get it deleted.

Questions about anything here? Email ceo@subject0bject.com.

02What we collect

  • Account — your email address. You sign in with Google or with a magic link sent to your inbox; either way Firebase Authentication holds the credential, not us. We never see or store a password.
  • Birth details — date of birth, time of birth (optional — you can say you don't know it), solar or lunar calendar, gender, and birth city together with its coordinates and time zone. These are the inputs the chart is computed from; without them there is no reading.
  • People you add — if you ask Bori about someone else, the name, relationship, and birth details you enter for them. These are entries in your account, not accounts of their own.
  • Conversations — the messages you send Bori, Bori's replies, and the readings generated for you, so the conversation is still there when you come back.
  • Daily check-ins — the one answer you give to Bori's daily check-in question, and the date you gave it.
  • Paws wallet — your credit balance and a ledger of grants, spends, and reversals (amounts, timestamps, and the payment ID of a purchase). We never receive or store card numbers, CVV, or bank details — those go directly to our payment provider.
  • Settings — your home time zone (so "today" means your today), whether you opted in to Bori's emails, and whether your advisors may start a conversation on their own.
  • Technical data — your IP address, used only to rate-limit abuse of the free chart and the free preview. For the chart it is held in server memory for a rolling hour and never written to our database; for the preview we store a salted one-way hash of it — never the address itself — and that record expires after three days. Blocked requests are also noted in our server logs.
  • Before you sign up — if you try a reading as a guest, the birth details and chart stay in your own browser's local storage and are discarded after 24 hours. They reach our servers only as the calculation request itself, and become part of an account only if you choose to sign up and claim them.

We do not ask for your real name, address, or phone number. If a purchase requires a billing address, it is collected and held by our payment provider.

03Why we use it

  • To compute your chart and generate your readings, daily guidance, and Bori's replies.
  • To keep your conversation, people, and wallet balance available across sessions and devices.
  • To process purchases of Paws and to honor refunds.
  • To send you service email you asked for, and — only if you opted in — Bori's emails: the weekly note and the occasional note from an advisor who has something to tell you. Every marketing email carries a one-click unsubscribe link, and you can also flip the setting off under My.
  • To prevent abuse of our servers and of the free daily message allowance.
  • To meet tax, accounting, and other legal obligations.

04Your data is not used to train AI models

We do not use your conversations, birth details, or check-ins to train, fine-tune, or improve any AI model. Your data is sent to our AI provider only to produce your own response, in the moment you ask for it, and under enterprise terms that prohibit that provider from using it to train its models. We do not sell your personal information, and we do not share it with advertisers or data brokers.

05Who processes your data

We rely on the following providers. Each acts under its own terms and security commitments:

  • Google Firebase — authentication, the Firestore database that holds your account, server functions, and website hosting.
  • Google Cloud Vertex AI — runs the models that write your readings and Bori's replies. Your inputs are sent for that request and are not used to train models (Section 4).
  • Google reCAPTCHA Enterprise — used through Firebase App Check to tell real browsers from automated abuse. It inspects signals about your browser and device on protected requests.
  • Dodo Payments — our Merchant of Record. It runs checkout, handles card data, collects VAT and sales tax, and issues refunds.
  • Resend — delivers our email (welcome mail and, if you opted in, Bori's emails: the weekly note and notes from your advisors).
  • Google Analytics 4 — product analytics, used to see which parts of the service work, in two layers. Its own automatic measurement (page views, referrer, approximate location) starts as soon as the script loads outside the EEA and UK, and stops setting cookies the moment you decline; inside the EEA and UK it runs without cookies until you accept. Separately, the events we define ourselves — signing up, finishing onboarding, chat activity, hitting the paywall, buying Paws — are only sent to Google Analytics after you accept the cookie banner, wherever you are. We do not enable its advertising features.

Some illustrations in the app and in our emails are AI-generated.

06Cookies and browser storage

  • Strictly necessary — keeping you signed in, remembering your cookie choice, and holding a guest chart for up to 24 hours. These are always active; the service cannot work without them.
  • Abuse prevention — storage set by reCAPTCHA Enterprise through Firebase App Check. The rate limits on the free chart and preview run entirely on our servers and store nothing in your browser; they work from your IP address as described in Section 2.
  • Analytics — set by Google Analytics 4's own automatic measurement: denied by default in the EEA and UK until you accept, allowed by default elsewhere until you decline. The events we generate about your own use of Bori are sent only after you accept, wherever you are.

We use no advertising or retargeting cookies. You can change your choice at any time using "Cookie settings" in the footer — choosing Decline there withdraws consent immediately, wherever you are.

07How long we keep it, and how to delete it

Your account data is kept while your account exists. You can delete it yourself, at any time — go to My → Danger zone → Delete my account & data and type DELETE to confirm. That immediately and permanently erases your profiles, the people you added, your conversations, your readings, your check-ins, your wallet balance and ledger, your sign-in account, and any billing address our payment code had stored. It cannot be undone, and any unspent Paws are gone with it.

Two things intentionally survive deletion:

  • Purchase records — order and payment records are retained for five years to satisfy bookkeeping and tax obligations. Dodo Payments separately keeps its own transaction records as Merchant of Record.
  • Anonymous chart caches — a generated preview may be cached against a hash of the birth details it was computed from, so an identical chart is not recomputed. That cache holds no name, no email, and no account reference, and cannot be traced back to you.

Guest data that never became an account expires from your browser by itself after 24 hours, and is cleared when you sign out.

08Your rights

Wherever you live, you can use the self-serve deletion above. Depending on your jurisdiction — including the GDPR in the EEA and UK, and the CCPA/CPRA in California — you may also request access to your personal information, correction of it, a portable copy of it, restriction of or objection to certain processing, and withdrawal of any consent you gave. Email ceo@subject0bject.com and we will respond within 30 days. We do not sell or share personal information as those terms are defined under California law, and we do not discriminate against anyone for exercising these rights. EEA and UK users may also complain to their local data protection authority.

09International transfers

We run on Google Cloud, and our providers operate in regions that may sit outside your country of residence, including the United States. Where the law requires it, those transfers rely on the Standard Contractual Clauses or an equivalent safeguard offered by the provider.

10Children

You must be at least 13 to use Bori for yourself. Our birth form checks the date you enter before anything is calculated or stored: if it shows you are under 13, we stop right there and keep nothing. You must be at least 18 to buy Paws.

Adding a profile for someone else — a child, a partner, a friend — is a different thing and is allowed at any age, because that person is not using the service: you are looking up a chart, and the entry lives in your account under your control. By adding it you confirm you are entitled to provide those details. Delete a person any time from the People tab, or remove everything at once by deleting your account.

If you believe a child under 13 has created an account, email ceo@subject0bject.com and we will delete it.

11Security

Traffic is encrypted in transit, data is encrypted at rest by Google Cloud, and database rules restrict every document to its owner so one account cannot read another's. No system is perfect; if we ever discover a breach affecting your data, we will notify you and the relevant authority as the law requires.

12Changes

We may revise this policy. Material changes will be posted here with a new "Last updated" date, and continued use after that constitutes acceptance.

13Contact

ceo@subject0bject.com

THIS IS KOREAN SAJU — NOT ASTROLOGY
The 24 Archetypes
PrivacyTermsRefund policy

Bori is for entertainment and self-reflection. Not medical, legal, or financial advice.

© 2026 Bori