ILJU

ILJU Privacy Policy

Last updated: September 10, 2026

ILJU (“the App”) is operated by 87Lab (“we”, “us”). This policy explains what the App collects, where it goes, and what you can do about it.

Contact: contact@87lab.app

See also our Terms of Use.

Summary

1. What we collect, and why

Birth details. The date of birth, birth time (if you know it), sex, and birth city you enter, together with the latitude and longitude of that city, which the App looks up from a list built into it. We need these to calculate your chart. The App does not read your device’s location for this or for anything else.

These details are kept on your device. They are sent to our reading service at api.halallog.com each time a reading is generated, and a copy is kept in your account as described in section 4.

Names you type. The name or label you give a chart is not sent to the reading service: the App strips it out before the request, because it has no effect on the reading. It is part of the account copy described in section 4, so if you would rather we never held it, leave the name blank or use an initial.

Sign-in details. The App works without a sign-in. If you add one, so that your chart can be recognised on another phone, we receive what that sign-in needs. With Google, that is the account identifier and email address Google passes us. With Apple, on an iPhone, that is the user identifier Apple gives us and an email address if Apple sends one. Apple lets you hide your address, and it then sends a relay address instead of your own. We do not ask Apple for your name, and either way the sign-in works, because what recognises you on the next phone is the identifier and not the address. With an email address and password, that is the address and a one-way hash of the password: the password itself travels to our server over an encrypted connection and is not stored, and the hash cannot be turned back into it. To prove the address is yours, our server sends you a six-digit code through our email provider (section 5). The code works for 10 minutes, and the server keeps a fingerprint of it rather than the code. The server also counts wrong password attempts and locks that address for 15 minutes after ten of them. Section 4 says what the account then holds.

In-app activity. A record of your smile balance, which readings you have opened, and basic usage events such as opening the App or unlocking a reading. The balance and the record of what you unlocked are kept on your device and copied to your account (section 4). The usage events go to our analytics provider instead, and they carry no birth details, no names, and no reading text.

Purchases. If you buy units or a membership, the purchase is made through the store your phone buys from: Apple’s App Store on an iPhone, Google Play on Android. That store takes the payment and never shows us your card or bank details. What the App sends to our server is the receipt the store issues for that purchase, which says nothing about how you paid, and the product it was for. Our server asks that store to confirm the receipt, credits your account once it does, and keeps the receipt, the store it came from, the product, and the time. That receipt is what stops one purchase from being credited twice, including when you restore purchases on a new phone, and what we go back to if a refund is disputed. Section 8 says how long it stays.

Technical data at our servers. When your device contacts our service, our servers see your IP address. We use it only to apply rate limits that keep the service available and to detect abuse. It is held in memory for those limits and appears in short-lived server access logs. It is not linked to your birth details and not used to build a profile.

Crash reports. If the App crashes or hits an error it cannot recover from, a report goes to Sentry, our crash reporting provider (section 5). A report holds the error and where in the App’s code it happened, the App version, the device model and operating system version, basic device state at that moment, and a random identifier the reporting library creates when the App is installed, so that repeat crashes on one device can be counted. We do not attach your IP address, your birth details, your name, your email address, or any reading text to it. Our own server sends the same kind of report about its own errors, and never the contents of your requests.

Advertising data. Where your version of the App offers rewarded ads, it shows them through the Unity LevelPlay SDK. Through that SDK, Unity and the advertising networks its mediation connects may access your device’s advertising ID, your IP address, an approximate location (country or city level) estimated from that IP address, device information, and information about the ads you see and interact with, under their own privacy policies. When an ad is shown, the SDK also tells the App which country it was shown in and what the ad was worth, and the App records those two facts with its usage event for that ad. In the EU, EEA, UK, and Switzerland the App asks you before any of that is personalised, as section 6 describes.

1a. Face and Palm reading photos

How the photo is taken. Face reading and Palm reading are optional. If your version of the App offers them, starting one opens the camera inside the App, and you take a single photo yourself. Nothing happens until you tap the shutter, and you can retake the photo or leave the reading at any time.

The photo itself. It is never added to your photo library and never kept. The camera hands it to the App through a temporary file in the App’s own private cache, which the App deletes as soon as it has read the photo into memory. From then on the App holds it in memory only, and discards it the moment you retake it, go back, or leave the reading. It does not survive closing the App. The written description made from that photo is a different thing, and it does stay on your phone.

Where the photo goes. To write your reading, the App sends that one photo to our reading service, which passes it once to the AI model described in section 3 so the model can describe what it sees. Neither our reading service nor the AI provider stores the photo. The description they send back is not cached on our servers either. The photo is used for that one request and for nothing else.

What comes back, and what stays. The App receives a written description (for example the shape of a face, or the lines on a palm) and the reading built from it. Both are saved on your phone so that you can open them again. Section 8 says how long they stay, and section 9 says how to delete them.

What we do not do with your photo. We do not use it to identify you, to match you against any other photo or person, to build a face template or a face database, or to train any model. We do not ask the model to work out your race, your ethnicity, your religion, your sexual orientation, your politics, or any medical condition from your face. Our reading service also checks each reading before you see it and rejects one that describes your race, your ethnicity, your religion, or your sexual orientation.

2. What we do not collect

We do not collect your phone number, contacts, photo library, microphone, files, or health data, and the App never reads your device’s location services. The only location involved is the rough one the advertising SDK estimates from your IP address, described in section 1. The App has a camera feature, described in section 1a, and that feature is the only reason the camera permission appears in the App’s store listing. Opening the App does not turn the camera on: it turns on only when you start a Face or Palm reading and grant the permission. We hold no password of yours in a form that can be read: if you create an email sign-in, what we keep is a one-way hash of it (section 1). We learn your email address only if you connect a Google account, sign in with Apple and let Apple pass an address on, create an email sign-in (section 4), write to us, or send a deletion request through the web form. We never ask you for your name: the only name we hold is the label you choose to type on a chart.

3. Where your birth details go when a reading is written

Your birth details are sent to our reading service, which calculates the chart and asks an AI model to write the reading. The model is Claude, made by Anthropic, and we run it on Amazon Bedrock, a service of Amazon Web Services, on servers in the United States.

The reading service does not keep your birth details after the reading is written. What it does keep is the finished reading text, saved under a one-way fingerprint computed from the chart facts, so that the same chart does not have to be generated and paid for twice. That stored text is not linked to you, to your device, or to your IP address, and readings for the same chart are shared with everyone who has that chart. What your account keeps is a separate thing, described in section 4.

Our reading service and the AI provider process your birth details on our instructions and for no other purpose. They are not permitted to use them to train models or for their own purposes.

4. Your ILJU account, and what our server holds

What changed, and when. Until August 2026 the App kept everything on your device and had no account of any kind. Starting with the version that introduces account backup, the App keeps a copy of the items below on our own server so that you do not lose them when you reinstall the App or move to a new phone. If your version of the App has no account controls in the Account tab, nothing in this section has started for you yet.

The account you never signed up for. There is no registration to get through. The first time the App saves anything to the server, it generates a random key on your device, and that key is the account. We store a one-way fingerprint of the key, never the key itself, so the key never leaves your phone. It also means that if you lose the phone without having added a sign-in, no one, including us, can identify or reach that copy again.

The sign-in you can add. From the Account tab you can attach a sign-in to that account: a Google account, your Apple ID on an iPhone, or an email address and a password. All of them are optional and none of them unlocks anything. What they change is that we can then recognise you on a different phone and give the copy back. Section 1 says what each one sends us.

What the server holds:

Where the server is. It is our own machine, operated by 87Lab, running in the United States. It answers at api.halallog.com. That address is ours, not another company’s: our other app runs on the same machine, and the name has stayed with it. No third party receives your account data, apart from the email provider that delivers your sign-in code (section 5).

What the server does not hold. Your device key itself, your password in any readable form, and any payment details: card and bank details stay with the App Store or Google Play, and the receipt we keep does not contain them.

What we do not do with it. The account copy exists to give your data back to you. We do not use it to profile you, to advertise to you, or to train any model, and we do not share it with anyone.

5. Service providers

6. Legal bases (for people in the EU, EEA, and UK)

We do not ask you for, and do not want, information about your health, your religion, your politics, or your sexual orientation. Please do not enter any.

7. International transfers

Our own server and the providers above are in the United States, so wherever you are, your data is handled there. For people in the EU, EEA, or UK, the transfers to those providers are made under the transfer safeguards they offer, which include the European Commission’s Standard Contractual Clauses and, where applicable, the EU to US and UK to US Data Privacy Framework. You can ask us for details at the address above.

8. How long we keep things

9. Your rights, and how to delete everything

Depending on where you live, you have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict some processing, and to withdraw consent. Here is how each one works in practice.

For anything else, or if you want us to act on a request at our end, write to contact@87lab.app. We will answer within 30 days. You also have the right to complain to your local data protection authority.

If you are a California resident: we do not sell or share your personal information as those terms are defined by California law, and we do not use it for cross-context behavioural advertising without your consent.

10. Children

ILJU is for adults aged 18 or over. It is not directed to children and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us personal data, write to us and we will delete it.

11. Security

Data sent between the App and our service is encrypted in transit using HTTPS. Your account key is held on your device and only its one-way fingerprint reaches us, and a password you set is stored only as a one-way hash. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

12. Changes

We may update this policy. When we do, we will change the date at the top. If the change is material, we will tell you in the App.

13. Contact

87Lab
contact@87lab.app