Skip to main content
Back to Omamori

Omamori Privacy Notice

Version: 2026-10-11 · Last updated: 2026-10-11 · Applies to: the Omamori web app (the "App")

This notice explains what personal data we collect, why, who handles it, how long we keep it, and what rights you have under Thailand's Personal Data Protection Act B.E. 2562 (2019) ("PDPA"). We have tried to write it in plain language.

1. Who we are (data controller)

HyperFlow Co., Ltd. ("we", "us"), Thailand.

Contact for all privacy matters: [email protected]

Data Protection Officer: not appointed. For privacy questions write to [email protected] (to be confirmed with a lawyer whether one is required).

2. What Omamori is, in one paragraph

Omamori is an entertainment and gentle self-reflection app inspired by Japanese shrines and temples. It offers fortune-style activities, a weekly lucky charm, a prayer ritual, and a short personal blessing written by an AI. It does not predict the future and it is not affiliated with any shrine or temple. See the Terms.

3. Data we collect, why, and our legal basis

"Legal basis" is the reason the PDPA allows us to use the data. "Consent" means you said yes and can say no later. "Contract" means we need it to give you the service you asked for. "Legitimate interest" means a reasonable need such as security, balanced against your rights.

DataWhy we use itLegal basis
Email address, mobile number, or Google account ID (whichever you sign in with)Create your account, send sign-in codes, recognise you when you returnContract
Guest account: a generated user ID only (no email, name, or phone number)Let you use the app before creating an account. If you later add Google or an email, the same user ID keeps your dataContract
Security data for sign-in: one-time codes (short-lived), CAPTCHA result, IP address in technical logs, rate-limit countersStop bots and fraud; keep the service safeLegitimate interest
Nickname (up to 16 characters)Address you in the app and in blessingsContract
BirthdayWork out your weekly charm, star sign and Eto (Chinese zodiac animal) and your age checkContract
Blood type (optional)Show a fun personality line. Skip it if you preferConsent
Language and time zoneShow the app in your language and start your charm week at the right timeContract
Consent records (which text, which version, when, yes/no)Prove and respect your choicesLegal obligation / legitimate interest
Age confirmationApply our age rulesContract / legal obligation
Prayers (temple, feeling you chose, week, time)Run the prayer ritual, goshuin (stamp) book and weekly charm "charging"Contract
Blessings (the text shown, whether AI-written or curated, language, model and prompt version, your heart / "not for me" rating)Show your blessing, keep your journal, improve quality, audit our AIContract; legitimate interest (audit and quality)
Short note "what is on your mind" (up to 140 characters)Only if you choose to type it and you agreed: sent to the AI so the blessing fits you. Kept only if you save the blessing to your journalConsent
Journal entries, charms opened, goshuin stampsLet you revisit your history and sync between devicesContract
Saved pictures (only if you tap "Save to my gallery")Store the finished framed picture in your private galleryContract (and consent, because it is your explicit action)
Subscription state (whether you have Plus)Know whether you have Plus. We never see or store your card numberContract; legal obligation (tax records)
Product usage events (which feature was used, without any text you typed)Understand which features work and fix problemsConsent (anonymous usage statistics are off by default)
Error and performance logsFix bugs, keep the service runningLegitimate interest
Product update emailsSend news about OmamoriConsent (off by default)

We do not collect: card numbers, your original photo, face data or face templates, precise location, contacts, or advertising identifiers.

We do not sell your data, share it for advertising, or use advertising trackers.

4. Your photos

The photo frame feature runs entirely on your device (in your browser). Your original photo is not uploaded to us or to anyone. If you tap "Save to my gallery", only the finished, framed picture is uploaded to your private storage. We do not use face recognition or biometric data.

5. AI processing

Personal blessings are written by an AI model that we reach through OpenRouter, an AI gateway service, which passes your request to an AI model company. Every AI blessing is labelled "written by AI". Blessings are for fun and reflection and are not predictions.

What is sent to the AI provider for each blessing request:

What is not sent: your email, Google ID, birthday date, blood type, user ID, photos, payment information, or your full journal.

Safety check: before and after a blessing, text may also be checked by a safety step (rules and a smaller AI model) to catch crisis language. If the note suggests you may be in danger, we show a caring message with helpline information instead of a blessing.

Tip: you can use a nickname that is not your real name. Please do not type sensitive details (health, money, other people's names) in the note.

Training: we do not use your content to train any AI model. We ask our AI providers not to use API inputs to train their models; their own terms and data policies apply to the requests they receive.

Logs: our AI request logs keep a hash and a category, not your note text, for 30 days.

Fallback: if the AI is unavailable, over its limit, or fails a safety check, you receive a pre-written (curated) blessing and nothing from you is sent.

No decision that significantly affects you is made automatically. The AI only writes words; it does not decide anything about your account or any payment.

6. Who handles your data (processors) and transfers abroad

We use these service providers to run Omamori. They process data on our instructions.

ProviderWhat forDataLocation
SupabaseSign-in, database, private file storageAccount, profile, journal, prayers, blessings, saved picturesSingapore
VercelHosting and delivering the AppTechnical request data (IP address, device info), app trafficGlobal edge network; app functions run in Singapore
OpenRouter, and the AI model company it routes toWriting personal blessings and the safety checkOnly the items listed in section 5United States (and possibly other countries)
HostingerSending sign-in codes and (if you agree) product emailsYour email address and messageHostinger's mail servers (location depends on the plan; may be outside Thailand)
Cloudflare (Turnstile)Bot protection when requesting codes, only if switched onTechnical browser signalsGlobal
GoogleOnly if you choose "Continue with Google"Your Google account email and IDGlobal
SentryError reports (without personal text), only if switched onTechnical error dataDepends on the Sentry account region
StripeTaking payment for Plus on Stripe's own secure page. We never see or store your card numberPayment and billing data, plus the email and account ID we pass so we can match your paymentGlobal (United States and other countries)

Some of these providers are outside Thailand. When we send personal data abroad we do so only where the PDPA allows it, for example under data processing agreements and appropriate safeguards, or with your consent where required.

7. How long we keep data

DataRetention
Account, profile, journal, prayers, blessings, stamps, consent recordsWhile your account is active; deleted or anonymised within 30 days after you delete your account
Guest accounts that were never usedRemoved after 60 days of inactivity (a guest account with no data in it). A guest account with your omamori or journal in it is kept until you delete it
Saved gallery picturesUntil you delete them or your account (removed immediately where possible, within 30 days at most)
Product usage events13 months, and with no user ID once an account is deleted
AI request logs (hash and category only)30 days
Sign-in codesMinutes (they expire after 10 minutes)
Technical and security logs90 days
Payment and tax recordsAs the law requires (accounting records are generally kept for 5 years)
BackupsRemoved on the normal backup cycle,

8. Your rights

Under the PDPA you may:

To use a right, use the App settings or email [email protected]. We aim to reply within 30 days. We may ask you to confirm who you are first.

9. Children and young people

You must be at least 13 to use Omamori. Users under 18 may use the free app; paid plans, if launched, are for adults only. We do not send personalised marketing to under-18s. If you are under the age of majority in Thailand, please ask a parent or guardian before using the App. If we learn that a child under 13 has an account, we will delete it.

10. Security

We use encryption in transit, row-level access rules so each account can only read its own data, secrets kept on the server, rate limits and CAPTCHA on sign-in, and logs that avoid personal text. No system is perfectly secure. If a breach is likely to risk your rights and freedoms, we will notify the PDPC within 72 hours of learning of it, and notify you where the law requires.

11. Cookies and similar technologies

We use only what is needed to keep you signed in and remember your language and theme. We do not use advertising cookies. If you accept anonymous usage statistics, we count feature use without free text.

12. Changes

If we change this notice in a way that matters, we will tell you in the App and, where the law requires, ask for your consent again. The version is recorded in your consent history.

13. Contact

HyperFlow Co., Ltd. · [email protected]