Omamori Privacy Notice
Version: 2026-10-11 · Last updated: 2026-10-11 · Applies to: the Omamori web app (the "App")
This notice explains what personal data we collect, why, who handles it, how long we keep it, and what rights you have under Thailand's Personal Data Protection Act B.E. 2562 (2019) ("PDPA"). We have tried to write it in plain language.
1. Who we are (data controller)
HyperFlow Co., Ltd. ("we", "us"), Thailand.
Contact for all privacy matters: [email protected]
Data Protection Officer: not appointed. For privacy questions write to [email protected] (to be confirmed with a lawyer whether one is required).
2. What Omamori is, in one paragraph
Omamori is an entertainment and gentle self-reflection app inspired by Japanese shrines and temples. It offers fortune-style activities, a weekly lucky charm, a prayer ritual, and a short personal blessing written by an AI. It does not predict the future and it is not affiliated with any shrine or temple. See the Terms.
3. Data we collect, why, and our legal basis
"Legal basis" is the reason the PDPA allows us to use the data. "Consent" means you said yes and can say no later. "Contract" means we need it to give you the service you asked for. "Legitimate interest" means a reasonable need such as security, balanced against your rights.
| Data | Why we use it | Legal basis |
|---|---|---|
| Email address, mobile number, or Google account ID (whichever you sign in with) | Create your account, send sign-in codes, recognise you when you return | Contract |
| Guest account: a generated user ID only (no email, name, or phone number) | Let you use the app before creating an account. If you later add Google or an email, the same user ID keeps your data | Contract |
| Security data for sign-in: one-time codes (short-lived), CAPTCHA result, IP address in technical logs, rate-limit counters | Stop bots and fraud; keep the service safe | Legitimate interest |
| Nickname (up to 16 characters) | Address you in the app and in blessings | Contract |
| Birthday | Work out your weekly charm, star sign and Eto (Chinese zodiac animal) and your age check | Contract |
| Blood type (optional) | Show a fun personality line. Skip it if you prefer | Consent |
| Language and time zone | Show the app in your language and start your charm week at the right time | Contract |
| Consent records (which text, which version, when, yes/no) | Prove and respect your choices | Legal obligation / legitimate interest |
| Age confirmation | Apply our age rules | Contract / legal obligation |
| Prayers (temple, feeling you chose, week, time) | Run the prayer ritual, goshuin (stamp) book and weekly charm "charging" | Contract |
| Blessings (the text shown, whether AI-written or curated, language, model and prompt version, your heart / "not for me" rating) | Show your blessing, keep your journal, improve quality, audit our AI | Contract; legitimate interest (audit and quality) |
| Short note "what is on your mind" (up to 140 characters) | Only if you choose to type it and you agreed: sent to the AI so the blessing fits you. Kept only if you save the blessing to your journal | Consent |
| Journal entries, charms opened, goshuin stamps | Let you revisit your history and sync between devices | Contract |
| Saved pictures (only if you tap "Save to my gallery") | Store the finished framed picture in your private gallery | Contract (and consent, because it is your explicit action) |
| Subscription state (whether you have Plus) | Know whether you have Plus. We never see or store your card number | Contract; legal obligation (tax records) |
| Product usage events (which feature was used, without any text you typed) | Understand which features work and fix problems | Consent (anonymous usage statistics are off by default) |
| Error and performance logs | Fix bugs, keep the service running | Legitimate interest |
| Product update emails | Send news about Omamori | Consent (off by default) |
We do not collect: card numbers, your original photo, face data or face templates, precise location, contacts, or advertising identifiers.
We do not sell your data, share it for advertising, or use advertising trackers.
4. Your photos
The photo frame feature runs entirely on your device (in your browser). Your original photo is not uploaded to us or to anyone. If you tap "Save to my gallery", only the finished, framed picture is uploaded to your private storage. We do not use face recognition or biometric data.
5. AI processing
Personal blessings are written by an AI model that we reach through OpenRouter, an AI gateway service, which passes your request to an AI model company. Every AI blessing is labelled "written by AI". Blessings are for fun and reflection and are not predictions.
What is sent to the AI provider for each blessing request:
your nickname;
your star sign and Eto (worked out from your birthday; your birthday date itself is not sent);
your language, the time of day, today's luck summary and this week's charm;
the feeling you picked and the temple;
short summaries of your last five blessings (so we do not repeat ourselves);
your short note, only if you turned on the "send my short note to the AI" consent and typed one.
What is not sent: your email, Google ID, birthday date, blood type, user ID, photos, payment information, or your full journal.
Safety check: before and after a blessing, text may also be checked by a safety step (rules and a smaller AI model) to catch crisis language. If the note suggests you may be in danger, we show a caring message with helpline information instead of a blessing.
Tip: you can use a nickname that is not your real name. Please do not type sensitive details (health, money, other people's names) in the note.
Training: we do not use your content to train any AI model. We ask our AI providers not to use API inputs to train their models; their own terms and data policies apply to the requests they receive.
Logs: our AI request logs keep a hash and a category, not your note text, for 30 days.
Fallback: if the AI is unavailable, over its limit, or fails a safety check, you receive a pre-written (curated) blessing and nothing from you is sent.
No decision that significantly affects you is made automatically. The AI only writes words; it does not decide anything about your account or any payment.
6. Who handles your data (processors) and transfers abroad
We use these service providers to run Omamori. They process data on our instructions.
| Provider | What for | Data | Location |
|---|---|---|---|
| Supabase | Sign-in, database, private file storage | Account, profile, journal, prayers, blessings, saved pictures | Singapore |
| Vercel | Hosting and delivering the App | Technical request data (IP address, device info), app traffic | Global edge network; app functions run in Singapore |
| OpenRouter, and the AI model company it routes to | Writing personal blessings and the safety check | Only the items listed in section 5 | United States (and possibly other countries) |
| Hostinger | Sending sign-in codes and (if you agree) product emails | Your email address and message | Hostinger's mail servers (location depends on the plan; may be outside Thailand) |
| Cloudflare (Turnstile) | Bot protection when requesting codes, only if switched on | Technical browser signals | Global |
| Only if you choose "Continue with Google" | Your Google account email and ID | Global | |
| Sentry | Error reports (without personal text), only if switched on | Technical error data | Depends on the Sentry account region |
| Stripe | Taking payment for Plus on Stripe's own secure page. We never see or store your card number | Payment and billing data, plus the email and account ID we pass so we can match your payment | Global (United States and other countries) |
Some of these providers are outside Thailand. When we send personal data abroad we do so only where the PDPA allows it, for example under data processing agreements and appropriate safeguards, or with your consent where required.
7. How long we keep data
| Data | Retention |
|---|---|
| Account, profile, journal, prayers, blessings, stamps, consent records | While your account is active; deleted or anonymised within 30 days after you delete your account |
| Guest accounts that were never used | Removed after 60 days of inactivity (a guest account with no data in it). A guest account with your omamori or journal in it is kept until you delete it |
| Saved gallery pictures | Until you delete them or your account (removed immediately where possible, within 30 days at most) |
| Product usage events | 13 months, and with no user ID once an account is deleted |
| AI request logs (hash and category only) | 30 days |
| Sign-in codes | Minutes (they expire after 10 minutes) |
| Technical and security logs | 90 days |
| Payment and tax records | As the law requires (accounting records are generally kept for 5 years) |
| Backups | Removed on the normal backup cycle, |
8. Your rights
Under the PDPA you may:
Access your data and ask for a copy;
Export / port your data in a readable format (Settings > Export my data, a JSON file);
Correct data that is wrong (you can edit your profile in the App);
Delete your data (Settings > Delete my account);
Object to or restrict some uses of your data;
Withdraw consent at any time (Settings > Privacy). Withdrawing does not affect what we did before, and the parts of the App that need that consent may stop working;
Complain to the Personal Data Protection Committee (PDPC) of Thailand if you believe we have not followed the PDPA.
To use a right, use the App settings or email [email protected]. We aim to reply within 30 days. We may ask you to confirm who you are first.
9. Children and young people
You must be at least 13 to use Omamori. Users under 18 may use the free app; paid plans, if launched, are for adults only. We do not send personalised marketing to under-18s. If you are under the age of majority in Thailand, please ask a parent or guardian before using the App. If we learn that a child under 13 has an account, we will delete it.
10. Security
We use encryption in transit, row-level access rules so each account can only read its own data, secrets kept on the server, rate limits and CAPTCHA on sign-in, and logs that avoid personal text. No system is perfectly secure. If a breach is likely to risk your rights and freedoms, we will notify the PDPC within 72 hours of learning of it, and notify you where the law requires.
11. Cookies and similar technologies
We use only what is needed to keep you signed in and remember your language and theme. We do not use advertising cookies. If you accept anonymous usage statistics, we count feature use without free text.
12. Changes
If we change this notice in a way that matters, we will tell you in the App and, where the law requires, ask for your consent again. The version is recorded in your consent history.
13. Contact
HyperFlow Co., Ltd. · [email protected]