Privacy Policy
Last updated: 23 August 2026
This policy explains what KanminLabs collects, why it is used, where it may be processed, how long it is kept, and how to exercise privacy choices.
Who we are
This service operates under the KanminLabs business name. The privacy contact is support@kanminlabs.ai. This policy describes how we handle personal information across our website, mobile applications, support, and subscriptions.
Information we collect
Account information: name, email address, account identifier, sign-in method, profile image, and login-security information.
Reading information: birth date and time, gender selection, birth or current location, coordinates, relationship type, another person’s details that you are authorized to submit, questions, saved Case and Cast times, eight-system chart data, chat history, deterministic previews, separately requested Personality, Career, Relationship, and Annual reports, and saved results. For signed-in users, explicit first-person statements may be saved as unconfirmed Memory candidates for review.
Billing and usage information: subscription and payment status, transaction references, purchased-credit balance and activity, and free-use counters. We also collect limited device, request, security, error, and—only with your permission—aggregate product-usage information. Card details are handled by Stripe; we do not receive or store full card numbers.
AI quality and safety reports: if you report an output, we collect the selected reason and an optional short note after automated contact-detail redaction. We retain only limited references and generation information needed to review the report—not the question, birth data, chart context, or complete AI output.
Why we collect and use it
We use information to authenticate accounts, calculate and generate readings, answer questions, save history, synchronize subscriptions, provide support, prevent fraud and abuse, troubleshoot, maintain security, meet legal and accounting duties, and enforce our terms.
If required information is not provided, the relevant chart, account, saved-history, location, or payment feature may not work. Optional fields can be left blank where the interface allows.
Long-term Memory is consent-based and is available only when that feature is enabled. AI predictions and prior assistant answers are not treated as user facts. A candidate is excluded from AI context until you explicitly confirm it. Where Memory controls are available, you can deny, correct, or withdraw facts there; otherwise contact support@kanminlabs.ai for help. Withdrawn and superseded records are retained only for integrity and are not supplied to AI.
When we improve the service, we use only aggregate product analytics that you have allowed and minimized reliability, security, abuse-prevention, and safety records. We do not use private birth details, precise locations, questions, chats, readings, or saved reports to train general-purpose AI models. Information needed to answer an AI request is sent to the configured AI provider to provide that request, as described below.
Service providers and overseas processing
We use service providers for hosting and data storage, sign-in and account functions, location search, payments, AI processing, mobile-app delivery, reliability and security monitoring, and email or customer support. The providers you see or choose are named: sign-in is offered through Apple and Google, web payments are processed by Stripe, and optional analytics, only if you allow it, is sent to Google Analytics 4 and PostHog. Each provider receives only the information reasonably needed to perform its function and is subject to contractual and privacy obligations.
Optional product analytics is off by default: no analytics event is collected or sent to Google Analytics 4 or PostHog unless you choose Allow analytics. You may later change or withdraw that choice through Anonymous analytics settings on the Account page. We do not include birth details, precise locations, names, email addresses, account or payment identifiers, questions, chats, readings, report text, or URL query strings in analytics events. Automatic interaction capture and session replay are disabled. Sentry operates separately for minimized reliability and security diagnosis, with configured data filtering and without session replay.
Because these providers and their subprocessors operate internationally, information may be processed outside Australia, including in the regions configured for our provider accounts and other locations used by their subprocessors. Those locations can change. We assess available provider safeguards and take reasonable steps required by applicable law for overseas disclosures.
We may also disclose information where required by law, to protect users or the service, or as part of a business transaction subject to appropriate safeguards. We do not sell personal information.
Retention and deletion
Account profiles, saved charts, question Cases, Cast bundles, Case chat history, and Memory evidence are retained while the account remains active or until deletion is requested. Guests keep only the latest question Cast locally on their device. Providers may retain limited security logs under their policies.
For a signed-in natal reading, we may keep a temporary completed-response copy for up to 31 days to replay the same request after a connection failure, securely save a result you choose, and prevent duplicate allowance or Credit use. Replay depends on the same device or browser profile retaining its opaque retry identifier. The copy expires automatically, is separate from results you choose to save, and is deleted sooner when account deletion completes.
Operational and security logs are kept only as long as reasonably needed for reliability, fraud prevention, and incident response. Payment, tax, dispute, and fraud-prevention records may be retained for the period required by law, commonly up to seven years for Australian business records.
Minimized AI quality events and content reports expire after no more than 365 and 180 days respectively. Deleting a signed-in account also deletes the quality and report records linked to that account's one-way actor identifier.
After account deletion completes, we retain a one-way deletion-safety marker for 45 days solely to stop delayed requests or payment notifications from recreating deleted app data. It contains no direct account identifier or profile information and is not used for personalization. If deletion cleanup is still pending, the marker remains until the request is resolved and then is removed or changed to the 45-day period.
Use the Account page to initiate account deletion. We delete or de-identify associated app data unless retention is legally required, and remove reusable payment profiles and payment methods after billing is clear while retaining only required transaction records. First cancel every active subscription and wait until it is confirmed not to renew; any renewing subscription blocks deletion. Deleting immediately after cancellation ends remaining paid access and does not automatically issue a refund; statutory rights remain unaffected.
Security
We use encrypted connections, access controls, authentication safeguards, monitoring, and restricted administrative access to protect information. No system is completely secure; contact us immediately if you suspect misuse.
Access, correction, complaints, and choices
You may request access to or correction of personal information, delete saved charts or your account, or object to a use that is not necessary to provide the service. Email support@kanminlabs.ai. We may verify identity. We will respond within any period required by applicable law and otherwise as soon as reasonably practicable.
For a privacy complaint, describe the issue and desired resolution. We will investigate and explain our response. If unresolved and the Australian Privacy Act applies, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au.
Children and automated outputs
Accounts are not intended for children under 13. Users aged 13 to 17 self-confirm during account creation or use that they already have parent or legal guardian permission. A parent or guardian may contact us about access, correction, or deletion. We apply age-oriented output restrictions, but do not rely on readings to make legal or similarly significant decisions about a person.
Software and AI automatically calculate charts, enforce access limits, detect abuse patterns, and generate entertainment content. These processes affect service content or access but are not intended to determine legal rights, eligibility for essential services, employment, credit, health treatment, or similar high-impact interests.
Changes and contact
We may update this policy when practices, providers, or laws change. Material changes will be notified in the service or by email where practicable. Questions: support@kanminlabs.ai.