ILJU Privacy Policy
Last updated: September 10, 2026
ILJU (“the App”) is operated by 87Lab (“we”, “us”). This policy explains what the App collects, where it goes, and what you can do about it.
Contact: contact@87lab.app
See also our Terms of Use.
Summary
- The App does not make you sign up. It creates an account for you so that your chart, your balance, and the readings you unlocked survive a reinstall or a new phone. Section 4 describes it in full.
- Your birth details, your balance, and the readings you unlocked are kept on your device and copied to our own server in the United States.
- Adding a sign-in is optional: a Google account, your Apple ID on an iPhone, or an email address and password. It is the only way to get your data back on a different phone. Section 4 says what each one gives us.
- When a reading is written, your birth details are sent to our reading service and on to Amazon Bedrock, which hosts the AI model. They are not stored there.
- Face reading and Palm reading, where your version of the App offers them, use one photo you take inside the App. The photo itself is never saved. The written description made from it is kept on your phone, and section 1a explains both.
- You can delete everything we hold, at any time, from our deletion page, and from inside the App in the versions described in section 4. Deletion is immediate and permanent.
- Where your version of the App offers rewarded ads, they are optional and are supplied through Unity LevelPlay. Section 1 says what data that involves.
- If the App crashes, a crash report goes to Sentry. It carries no birth details, no name, no email address, and no IP address. Section 1 says what it does carry.
- Anything you buy goes through the store your phone uses, Apple’s App Store on an iPhone and Google Play on Android, and we never see your card. We keep the receipt that store issues so that we can credit you once and answer a refund dispute. Sections 4 and 8 explain.
- We do not sell your personal data.
1. What we collect, and why
Birth details. The date of birth, birth time (if you know it), sex, and birth city you enter, together with the latitude and longitude of that city, which the App looks up from a list built into it. We need these to calculate your chart. The App does not read your device’s location for this or for anything else.
These details are kept on your device. They are sent to our reading service at api.halallog.com each time a reading is generated, and a copy is kept in your account as described in section 4.
Names you type. The name or label you give a chart is not sent to the reading service: the App strips it out before the request, because it has no effect on the reading. It is part of the account copy described in section 4, so if you would rather we never held it, leave the name blank or use an initial.
Sign-in details. The App works without a sign-in. If you add one, so that your chart can be recognised on another phone, we receive what that sign-in needs. With Google, that is the account identifier and email address Google passes us. With Apple, on an iPhone, that is the user identifier Apple gives us and an email address if Apple sends one. Apple lets you hide your address, and it then sends a relay address instead of your own. We do not ask Apple for your name, and either way the sign-in works, because what recognises you on the next phone is the identifier and not the address. With an email address and password, that is the address and a one-way hash of the password: the password itself travels to our server over an encrypted connection and is not stored, and the hash cannot be turned back into it. To prove the address is yours, our server sends you a six-digit code through our email provider (section 5). The code works for 10 minutes, and the server keeps a fingerprint of it rather than the code. The server also counts wrong password attempts and locks that address for 15 minutes after ten of them. Section 4 says what the account then holds.
In-app activity. A record of your smile balance, which readings you have opened, and basic usage events such as opening the App or unlocking a reading. The balance and the record of what you unlocked are kept on your device and copied to your account (section 4). The usage events go to our analytics provider instead, and they carry no birth details, no names, and no reading text.
Purchases. If you buy units or a membership, the purchase is made through the store your phone buys from: Apple’s App Store on an iPhone, Google Play on Android. That store takes the payment and never shows us your card or bank details. What the App sends to our server is the receipt the store issues for that purchase, which says nothing about how you paid, and the product it was for. Our server asks that store to confirm the receipt, credits your account once it does, and keeps the receipt, the store it came from, the product, and the time. That receipt is what stops one purchase from being credited twice, including when you restore purchases on a new phone, and what we go back to if a refund is disputed. Section 8 says how long it stays.
Technical data at our servers. When your device contacts our service, our servers see your IP address. We use it only to apply rate limits that keep the service available and to detect abuse. It is held in memory for those limits and appears in short-lived server access logs. It is not linked to your birth details and not used to build a profile.
Crash reports. If the App crashes or hits an error it cannot recover from, a report goes to Sentry, our crash reporting provider (section 5). A report holds the error and where in the App’s code it happened, the App version, the device model and operating system version, basic device state at that moment, and a random identifier the reporting library creates when the App is installed, so that repeat crashes on one device can be counted. We do not attach your IP address, your birth details, your name, your email address, or any reading text to it. Our own server sends the same kind of report about its own errors, and never the contents of your requests.
Advertising data. Where your version of the App offers rewarded ads, it shows them through the Unity LevelPlay SDK. Through that SDK, Unity and the advertising networks its mediation connects may access your device’s advertising ID, your IP address, an approximate location (country or city level) estimated from that IP address, device information, and information about the ads you see and interact with, under their own privacy policies. When an ad is shown, the SDK also tells the App which country it was shown in and what the ad was worth, and the App records those two facts with its usage event for that ad. In the EU, EEA, UK, and Switzerland the App asks you before any of that is personalised, as section 6 describes.
1a. Face and Palm reading photos
How the photo is taken. Face reading and Palm reading are optional. If your version of the App offers them, starting one opens the camera inside the App, and you take a single photo yourself. Nothing happens until you tap the shutter, and you can retake the photo or leave the reading at any time.
The photo itself. It is never added to your photo library and never kept. The camera hands it to the App through a temporary file in the App’s own private cache, which the App deletes as soon as it has read the photo into memory. From then on the App holds it in memory only, and discards it the moment you retake it, go back, or leave the reading. It does not survive closing the App. The written description made from that photo is a different thing, and it does stay on your phone.
Where the photo goes. To write your reading, the App sends that one photo to our reading service, which passes it once to the AI model described in section 3 so the model can describe what it sees. Neither our reading service nor the AI provider stores the photo. The description they send back is not cached on our servers either. The photo is used for that one request and for nothing else.
What comes back, and what stays. The App receives a written description (for example the shape of a face, or the lines on a palm) and the reading built from it. Both are saved on your phone so that you can open them again. Section 8 says how long they stay, and section 9 says how to delete them.
What we do not do with your photo. We do not use it to identify you, to match you against any other photo or person, to build a face template or a face database, or to train any model. We do not ask the model to work out your race, your ethnicity, your religion, your sexual orientation, your politics, or any medical condition from your face. Our reading service also checks each reading before you see it and rejects one that describes your race, your ethnicity, your religion, or your sexual orientation.
2. What we do not collect
We do not collect your phone number, contacts, photo library, microphone, files, or health data, and the App never reads your device’s location services. The only location involved is the rough one the advertising SDK estimates from your IP address, described in section 1. The App has a camera feature, described in section 1a, and that feature is the only reason the camera permission appears in the App’s store listing. Opening the App does not turn the camera on: it turns on only when you start a Face or Palm reading and grant the permission. We hold no password of yours in a form that can be read: if you create an email sign-in, what we keep is a one-way hash of it (section 1). We learn your email address only if you connect a Google account, sign in with Apple and let Apple pass an address on, create an email sign-in (section 4), write to us, or send a deletion request through the web form. We never ask you for your name: the only name we hold is the label you choose to type on a chart.
3. Where your birth details go when a reading is written
Your birth details are sent to our reading service, which calculates the chart and asks an AI model to write the reading. The model is Claude, made by Anthropic, and we run it on Amazon Bedrock, a service of Amazon Web Services, on servers in the United States.
The reading service does not keep your birth details after the reading is written. What it does keep is the finished reading text, saved under a one-way fingerprint computed from the chart facts, so that the same chart does not have to be generated and paid for twice. That stored text is not linked to you, to your device, or to your IP address, and readings for the same chart are shared with everyone who has that chart. What your account keeps is a separate thing, described in section 4.
Our reading service and the AI provider process your birth details on our instructions and for no other purpose. They are not permitted to use them to train models or for their own purposes.
4. Your ILJU account, and what our server holds
What changed, and when. Until August 2026 the App kept everything on your device and had no account of any kind. Starting with the version that introduces account backup, the App keeps a copy of the items below on our own server so that you do not lose them when you reinstall the App or move to a new phone. If your version of the App has no account controls in the Account tab, nothing in this section has started for you yet.
The account you never signed up for. There is no registration to get through. The first time the App saves anything to the server, it generates a random key on your device, and that key is the account. We store a one-way fingerprint of the key, never the key itself, so the key never leaves your phone. It also means that if you lose the phone without having added a sign-in, no one, including us, can identify or reach that copy again.
The sign-in you can add. From the Account tab you can attach a sign-in to that account: a Google account, your Apple ID on an iPhone, or an email address and a password. All of them are optional and none of them unlocks anything. What they change is that we can then recognise you on a different phone and give the copy back. Section 1 says what each one sends us.
What the server holds:
- Your profile: the name or label you entered, sex, date of birth, birth time if you gave one, and the birth city with its latitude and longitude.
- Your balance and what goes with it: smile units, daily grants, your return streak, and how many rewarded ads you have watched today.
- Your ledger: which readings and which dates you have unlocked. This is what stops you from paying twice for something you already opened.
- A copy of the readings you unlocked, stored word for word, so that a reading you already paid for comes back exactly as you first read it. It is fixed at the moment it is stored and is never rewritten afterwards.
- If you add a sign-in: for Google, the account identifier Google gives us and the email address on that account; for Apple, the user identifier Apple gives us and the address Apple passes on, which may be a relay address or nothing at all; for an email sign-in, the email address and the one-way hash of your password described in section 1. We use them to recognise you on a new phone and to show you in the App which sign-in is connected. The only email we send is the sign-in code you ask for, and it goes to the address you typed. We do not send marketing email, we do not write to you at an address a sign-in provider gave us, and we do not use your address for advertising.
- If you buy something: the receipt described in section 1, which is what the App Store or Google Play issued for that purchase, which of the two it came from, the product it was for, and when it was verified.
- If you send a deletion request through the web form: the contact detail and the message you write.
Where the server is. It is our own machine, operated by 87Lab, running in the United States. It answers at api.halallog.com. That address is ours, not another company’s: our other app runs on the same machine, and the name has stayed with it. No third party receives your account data, apart from the email provider that delivers your sign-in code (section 5).
What the server does not hold. Your device key itself, your password in any readable form, and any payment details: card and bank details stay with the App Store or Google Play, and the receipt we keep does not contain them.
What we do not do with it. The account copy exists to give your data back to you. We do not use it to profile you, to advertise to you, or to train any model, and we do not share it with anyone.
5. Service providers
- Amazon Web Services (Amazon Bedrock), United States. Hosts the AI model that writes your reading. Receives your birth details for that purpose. If you use Face or Palm reading, also receives that one photo for the request that produces the description. Stores neither.
- Amazon Web Services (Amazon Lightsail), United States. Hosts our own server, the one described in section 4. Amazon supplies the machine, and only we read what is on it.
- Apple (Sign in with Apple). If you choose to sign in with your Apple ID on an iPhone, Apple confirms to us that the Apple ID is yours and passes us its user identifier, with an email address if you let it, under Apple’s own privacy policy.
- Apple (App Store). Takes the payment for anything you buy in the App on an iPhone, under Apple’s own terms and privacy policy, and confirms to our server that a receipt it issued is genuine.
- Google (Sign in with Google). If you choose to connect an account, Google confirms to us that the account is yours and passes us its identifier and email address, under Google’s own privacy policy.
- Google (Google Play). Takes the payment for anything you buy in the App on an Android phone, under Google’s own terms and privacy policy, and confirms to our server that a purchase token it issued is genuine.
- Resend (Plus Five Five, Inc.), United States. Sends the sign-in code email described in section 1. Receives your email address and that one message.
- PostHog, United States. Product analytics. Receives anonymous usage events only. No person profile is created and no birth details are sent.
- Sentry (Functional Software, Inc.), United States. Crash reporting. Receives the crash reports described in section 1, from the App and from our own server. No birth details, names, email addresses, or reading text are sent.
- Unity Technologies (LevelPlay). Serves the rewarded ads described in section 1, together with the advertising networks its mediation connects, and processes advertising data under its own privacy policy.
6. Legal bases (for people in the EU, EEA, and UK)
- Providing the reading you asked for, and keeping and restoring your chart, balance, and readings: performance of a contract with you (GDPR Article 6(1)(b)).
- Rate limiting, abuse prevention, and keeping the service available: our legitimate interests in operating a secure service (Article 6(1)(f)).
- Anonymous product analytics: our legitimate interests in understanding how the App is used (Article 6(1)(f)).
- Connecting a Google account, signing in with Apple, or creating an email sign-in: your consent, given by choosing to add it (Article 6(1)(a)). You can withdraw it by deleting your account as described in section 9.
- Verifying a purchase, crediting it, and keeping its receipt: performance of a contract with you (Article 6(1)(b)) and, once you delete your account, our legitimate interests in preventing fraud and answering refund disputes (Article 6(1)(f)).
- Crash reports: our legitimate interests in finding and fixing faults in the App and in our service (Article 6(1)(f)).
- Personalised advertising, where it applies: your consent, given through the choice the App offers the first time you watch a rewarded ad (Article 6(1)(a)). Refusing is a real option: you still see an ad and you still earn the same reward. Section 9 says how to change your answer.
- Taking and processing a Face or Palm photo to write the reading you asked for: your consent, given when you start the reading and grant the camera permission (Article 6(1)(a)). You can withdraw it at any time: stop taking readings, revoke the camera permission in your device settings, and delete any reading already written, as section 9 describes.
We do not ask you for, and do not want, information about your health, your religion, your politics, or your sexual orientation. Please do not enter any.
7. International transfers
Our own server and the providers above are in the United States, so wherever you are, your data is handled there. For people in the EU, EEA, or UK, the transfers to those providers are made under the transfer safeguards they offer, which include the European Commission’s Standard Contractual Clauses and, where applicable, the EU to US and UK to US Data Privacy Framework. You can ask us for details at the address above.
8. How long we keep things
- On your device: until you delete your chart in the App or uninstall it.
- Face and Palm reading photos: not retained. The photo exists only in the App’s memory while you are taking the reading. It is destroyed as soon as your reading is written. If you retake the photo or leave the reading first, it is destroyed then. In every case it is gone no later than the moment the App closes. It passes through the App’s private cache only for the instant it takes to read it, is never added to your photo library or sent to a backup, and neither we nor the AI provider keeps a copy once that one request has finished.
- The written description made from a Face or Palm photo: kept on your phone until you delete your chart in Settings or uninstall the App. It is not sent to our own server and is not part of the account copy described in section 4.
- Your account copy on our server: until you delete it. There is no automatic expiry and no fixed retention period. If you stop using the App and never ask us to delete the copy, it stays. Section 9 says how to delete it.
- Generated reading text in the shared cache: kept so it can be reused, and not linked to you. The cache holds a fixed number of readings, and once it is full the oldest one is dropped to make room. Text written for a particular day is dropped once that day has passed. None of this touches the copy of your own unlocked readings kept in your account, which stays until you delete it.
- Server access logs containing IP addresses: a short period for security and troubleshooting, then deleted.
- Deletion requests sent through the web form: we keep the contact detail and message so we can act on the request and have a record that we acted. Ask us and we will delete that record too.
- Sign-in codes and the sign-in tokens they produce: each stops working 10 minutes after it is issued.
- Email sign-in details: your email address and the hash of your password are kept for as long as that sign-in exists. Section 9 says how they are removed.
- Purchase receipts: kept after you delete your account, because a refund or a billing dispute can be raised after a deletion and the receipt is the only record we have of the purchase. There is no automatic expiry for them yet. Write to us if you want to know what we hold.
- Analytics events: retained by our analytics provider under its standard retention period.
- Crash reports: retained by Sentry under its standard retention period, then deleted.
9. Your rights, and how to delete everything
Depending on where you live, you have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict some processing, and to withdraw consent. Here is how each one works in practice.
- Delete everything, from inside the App. In Settings, “Delete my chart” is one control and it clears both copies at once: your birth details, your saved people, your readings, and your balance on this phone, and the backup copy of all of it on our server, including any Google, Apple, or email sign-in connected to it. For an email sign-in that means the email address and the hash of your password go too. It is immediate and permanent, and we cannot undo it.
- Uninstalling the App clears the phone only. The backup copy on our server stays until you delete it, either from inside the App before you uninstall, or from the page below.
- Delete a Face or Palm reading. The reading and the description it was built from are kept on your phone. Deleting your chart in Settings removes them, and so does uninstalling the App. There is no server copy to delete: neither the photo nor the description is ever stored on our server.
- Delete the server copy without the App, at ilju-app.vercel.app/delete/. If you connected a Google account, signing in with that same account on that page proves the data is yours and deletes it on the spot. The page cannot yet check an Apple or an email sign-in, so those go through the form on the same page: it takes your request and we handle it by hand. If you added no sign-in at all, the form is also the only way, with the honest limitation that an account nothing is connected to carries nothing that tells us which record is yours.
- What deletion does not remove. The shared reading text described in section 3 stays, because it is filed under a fingerprint of the chart facts, is not linked to you or your device, and is shared with everyone who has the same chart. Receipts for anything you bought stay, for the reason section 8 gives. Short-lived server access logs and crash reports expire on their own schedule. And if you signed in with Apple, your Apple ID keeps its own note that you once used it here, because that note is held by Apple and not by us: you remove it on your iPhone, in Settings, under your name and then Sign in with Apple.
- Correct or get a copy. Edit your birth details in the App at any time, which replaces the server copy the next time it syncs. For a copy of what we hold, or for anything else, write to us.
- Advertising. You can reset or delete your advertising ID, and turn off ads personalisation, in your device settings. If the App asked you about personalised ads, you can change your answer at any time with the Personalised ads switch in the App’s Settings. Off means generic ads, and refusing costs you nothing: you still see an ad and you still earn the same reward.
For anything else, or if you want us to act on a request at our end, write to contact@87lab.app. We will answer within 30 days. You also have the right to complain to your local data protection authority.
If you are a California resident: we do not sell or share your personal information as those terms are defined by California law, and we do not use it for cross-context behavioural advertising without your consent.
10. Children
ILJU is for adults aged 18 or over. It is not directed to children and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us personal data, write to us and we will delete it.
11. Security
Data sent between the App and our service is encrypted in transit using HTTPS. Your account key is held on your device and only its one-way fingerprint reaches us, and a password you set is stored only as a one-way hash. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Changes
We may update this policy. When we do, we will change the date at the top. If the change is material, we will tell you in the App.
13. Contact
87Lab
contact@87lab.app