LUQI Privacy Policy
This Privacy Policy explains how Synced LLC ("LUQI," "we," "us," or "our") collects, uses, and shares personal information when you use the LUQI mobile application (the "Service"). LUQI is your personal AI Feng Shui master: a calm AI advisor grounded in Feng Shui and Chinese metaphysics that computes your Feng Shui chart from your birth details and gender, gives you daily, monthly, and yearly guidance, and answers your questions one at a time.
Synced LLC is a limited liability company formed in Delaware and operating from Honolulu, Hawaii. For purposes of data protection law, we are the controller of the personal information described in this Policy.
LUQI is intended only for adults 18 years of age and older. Please read this Policy together with our Terms of Service, which govern your use of the Service. If you do not agree with this Policy, please do not use LUQI.
1. Introduction
This Privacy Policy describes the personal information that Synced LLC ("LUQI," "we," "us," or "our") collects through the LUQI iOS application and related services, why we collect it, how we use and share it, and the choices and rights you have. We are a Delaware limited liability company operating from Honolulu, Hawaii, and we act as the controller of your personal information.
LUQI is a mobile app that serves as your personal AI Feng Shui master. After you enter your birth details and gender, the app computes your Feng Shui chart (such as your Chinese zodiac sign, Kua number, lucky directions, and governing element) and produces daily, monthly, and yearly "energy" readings. An AI master answers questions you submit, each as a single, self-contained consultation rather than an ongoing companion chatbot. The app also includes daily guidance, an almanac, and a "Scan" feature that analyzes a photo of your room or space.
This Policy applies to your use of the LUQI app and any features offered through it. It does not apply to any third-party services or websites that we do not control. LUQI is for adults 18 and older. Your use of the Service is also governed by our Terms of Service.
Last updated: August 19, 2026.
↑ Back to top2. Information We Collect
We collect the following categories of personal information, organized by how we obtain it. All of it is created only after you sign in, and it is stored on your own record in our database.
(a) Information you provide to us
- Name. The name you type at the "What should I call you?" step. We store it as you enter it and use it to address you in the app, in certain notifications, and in the context we send to the AI master.
- Date of birth. Stored as a calendar date. We use it to compute your Feng Shui chart and to verify that you are at least 18 years old.
- Birth time (optional). This step is optional, and you can choose "I don't know my birth time." If you provide it, we store it and use it to refine your chart—in particular to derive the "hour pillar" of your BaZi chart. If you skip it, no birth time is stored.
- Birth place (optional). You can pick a city from a built-in list. We store a readable city label (to show back to you) and the time zone for that city, which is what the chart calculation uses. We do not collect GPS coordinates, a street address, or any precise location for your birth place.
- Gender. Used to calculate your chart, where it sets the direction of the luck-pillar sequence. You can choose Female or Male; if you choose a third option, we record a "non-binary" value and then ask which of the two calculation bases to apply. That recorded third value is not used to compute anything and is not sent to the AI.
- Questions and messages you submit to the AI master. The text of the questions you ask (up to 2,000 characters each) and the AI's replies, stored together.
- Daily check-ins and journal notes. A dated entry with mood tags (presets or your own) and a free-text note (up to 4,000 characters).
- Photos of your room or space. For the Scan feature, three photos taken with your device camera, together with the room type and the direction it faces. How these photos are handled is described in "How the AI Works and What We Send to It."
(b) Information we receive when you sign in
- Email address. You do not type this; we receive it from the Google or Apple account you sign in with. If you use Apple's "Hide My Email," we receive and store the Apple relay address (ending in @privaterelay.appleid.com) rather than your real address.
- Sign-in identifiers. A user ID and which provider you used (Google or Apple), received through Firebase Authentication.
(c) Information we collect automatically
- Device time zone. Read automatically from your device's system settings so that daily guidance lines up with your local day. You are not asked for it separately and cannot decline it, and we refresh it each time you open the app.
- Activity timestamps. Automatic markers such as when you last opened the app, last added a journal entry, and last ran a scan; when your account was created; when we last sent you a notification; and a trial-reminder time.
- Push-notification tokens. If you grant notification permission, we store a token for each device you enable so we can deliver notifications; turning notifications off in the app removes that device's token.
- Usage analytics. Screens viewed and in-app events, collected via Google Analytics for Firebase, as described below.
- Subscription and purchase status. Your subscription state, received through RevenueCat and Apple.
- Technical and diagnostic data. Device type, app version, the IP address inherent to your requests, and any crash data, collected via Firebase.
(d) Information we derive
- Your computed chart and readings. From your birth date, your birth time and its time zone (when provided), and your gender, we derive your Feng Shui profile (such as your Chinese zodiac sign, Kua number, element, and favourable directions) and your full BaZi natal chart, along with your daily, monthly, and yearly readings and a pre-computed almanac for the current and next year. You can read these; the app cannot overwrite them.
3. What We Do Not Collect
To be clear about the boundaries of our data practices, we do not collect the following:
- Precise or GPS location. We do not collect your device's latitude, longitude, or position. For your birth place we keep only a city label and its time zone, never coordinates or a street address. The Scan feature asks for location permission but reads only the compass heading—the direction a room faces—and never your position; the on-device permission prompt states this directly.
- Payment card details. All payments are processed by Apple. We never see or store your card numbers.
- Advertising identifiers and cross-app tracking. We use no advertising SDK, no advertising identifier (IDFA), and no analytics other than Google's Firebase Analytics, and we do not present an App Tracking Transparency prompt, because we do not track you across other companies' apps or websites.
- Data from users under 18. The app is restricted to adults, and we do not knowingly collect or retain personal information from anyone under 18 for use of the Service. If someone who turns out to be under 18 enters a date of birth during onboarding, we use it only to block sign-up; we do not create a profile, send anything to the AI, or retain that date of birth. See the Children and Age Restriction section for details.
4. How We Use Your Information
We use the personal information described above for the following purposes:
- Compute your chart and readings. To calculate your Feng Shui profile and your daily, monthly, and yearly readings.
- Generate AI guidance and Scan analysis. To produce the AI master's answers and the analysis of the room or space photos you submit to the Scan feature.
- Operate, secure, and improve the Service. To run the app, maintain its security and integrity, debug and diagnose issues, and improve features.
- Manage subscriptions. To provide, renew, and administer your subscription and entitlements.
- Send notifications. To deliver the push notifications you have enabled, such as daily almanac notes, an occasional re-engagement message based on your chart, and a reminder before your free trial ends.
- Analytics and diagnostics. To understand how the app is used and to monitor performance and stability.
- Safety and crisis protocol. To detect signals of self-harm or crisis and respond by showing crisis resources, as described in the Safety and Crisis Resources section below.
- Comply with law. To meet legal obligations and to establish, exercise, or defend legal claims.
5. How the AI Works and What We Send to It
The AI master's guidance, its answers to your questions, and the Scan analysis are generated by Google's Gemini model (gemini-2.5-flash) through Google Vertex AI. This runs inside our own Google Cloud project using our own credentials—it is not the consumer Gemini app and not a separate third-party AI service.
What we send for an AI consultation. When you ask the AI master a question, we send Vertex AI: your name, as you entered it; your derived chart (for example your zodiac sign, Kua number and element, favourable directions, the year's reigning influences, today's rating, upcoming favourable and cautionary dates, your four BaZi pillars—including the hour pillar whenever you have provided a birth time—your day master and its strength, your elemental balance, and your current luck pillar); a plain statement of whether your birth time is known or not, so the absence of a birth time is itself disclosed to the model; the mood tags from your three most recent check-ins; and your question, as you typed it.
What we do not send. We do not send the raw birth inputs themselves—your date of birth, your birth time, your birth city, or its time zone—nor your stored gender, the recorded non-binary value, your email address, your internal account ID, or the free-text note from your journal. Only values derived from your birth data are sent, never the raw birth inputs. No conversation history is included; each question is a single, standalone request.
Scan photos. For a Scan, your three photos are uploaded to our own Google Cloud Storage, retrieved by our server, and sent to Vertex AI for analysis together with your Kua number, group, element, zodiac, favourable directions, and the room's type and facing direction. The photos are deleted from our storage immediately after the analysis runs—whether it succeeds or fails, and also if the request is turned away before any analysis—so they are transient and are not retained on our servers. The saved Scan result contains no image, and the app cannot read the photos back from storage. Note that when you take the photos, copies are written to the app's cache on your own device; those are not proactively deleted by the app and remain until iOS reclaims the space or you delete the app.
No-training commitment. Per Google Cloud's AI/ML Privacy Commitment and Vertex AI data-governance terms, Google does not use the prompts and inputs we send, or the responses generated, to train or fine-tune Google's foundation or AI models without permission. This is a no-training commitment, not a promise that Google never stores or sees the data: Google may process and briefly retain inputs and outputs to operate the service and for abuse monitoring, in accordance with its terms.
Vertex AI processing for LUQI occurs in the United States. AI-generated guidance is for reflection and entertainment and is not professional, medical, legal, financial, or psychological advice.
↑ Back to top6. Service Providers and Sub-Processors
We rely on a small set of service providers (sub-processors) to operate LUQI. Each receives only the data needed for its role, and may process personal information on our behalf under contract. They are:
- Google Firebase / Google Cloud. Provides authentication, the Firestore database, file storage for your Scan photos, serverless functions, and analytics. Your data is stored on Google Cloud in the United States.
- Google Vertex AI (Gemini). Receives your name, your derived chart facts, your recent check-in tags, and your question—or, for a Scan, your photos with the relevant chart facts—in order to generate a response, as described above. This processing occurs in the United States.
- RevenueCat. Manages your subscription entitlements. We send it only your account ID and your analytics instance ID, which lets it link purchase records to your account; we do not send it your name, email, birth data, gender, chart, or journal content.
- Apple. Provides Sign in with Apple and processes all in-app purchases and payments. We also hold an Apple refresh token on our server for a single purpose—revoking your LUQI sign-in at Apple when you delete your account, as Apple requires; it is not readable by any app, including yours, and is sent back to Apple only at deletion. Push notifications are delivered through Apple's push service (APNs); most carry no personal data, but the re-engagement notification can include chart details such as your zodiac sign, Kua element, and personal wealth direction, and the trial-ending reminder includes your name.
We do not use any email service provider, because the app does not send email; the trial reminder and other prompts are delivered as push notifications, not emails.
Other disclosures
Legal and compliance. We may disclose personal information if we believe it is reasonably necessary to comply with a law, regulation, legal process, or governmental request; to enforce our Terms of Service; to detect, prevent, or address fraud, security, or technical issues; or to protect the rights, property, or safety of LUQI, our users, or the public.
Business transfer. If we are involved in a merger, acquisition, financing, reorganization, or sale of all or part of our assets, personal information may be transferred as part of that transaction, subject to this Policy or a successor policy with comparable protections.
↑ Back to top8. Data Retention
We keep personal information only as long as we need it for the purposes described in this Policy.
- Account data. Information associated with your account—such as your name, date of birth, birth time and place (when provided), gender, and computed chart—is kept for the life of your account.
- AI interactions and check-ins. The questions and answers in your AI history, your check-ins and journal notes, and your Scan results are kept until you delete the individual item or your account, whichever comes first. (Scan photos are deleted from our servers immediately after analysis, as described above; only the text result is stored.)
- Deletion on account closure. When you delete your account, we destroy your account record and its contents, except for the narrow legal-hold archive and the safety records described below, and subject to the routine cycling-out of backups.
Legal-hold archive (three years)
Immediately before your data is destroyed on account deletion, we write a narrow archive that we retain for three years (36 months). Its sole purpose is the establishment, exercise, or defence of legal claims—the exception to the right of erasure recognised under GDPR Article 17(3)(e) and the comparable exception under the CCPA. A scheduled job runs daily and permanently deletes archives once they pass the 36-month window.
What the archive keeps: your account ID, name, email, and sign-in provider; your date of birth (kept for the single purpose of evidencing that the 18-and-over age check was met at signup); your account-creation, AI-consent, and deletion timestamps and the consent version; a short subscription summary (first-seen date, last-seen date, and entitlement IDs—not your full billing record); and the full transcript of every AI consultation (question, answer, status, model, and timestamp).
What the archive does not keep: your birth time, your birth place and time zone, your gender, your computed natal chart, your cached readings, your journal entries, and your Scan results and photos. Those are destroyed.
An honest limitation. The archived AI answers are the model's original replies, kept unchanged, so a reply may still restate chart details that were originally derived from your birth time. Destroying the structured chart does not guarantee that such details are absent from a retained transcript. If you clear consultations from your own history before deleting your account, they are not archived, because the archive is written from what exists at the moment of deletion—so clearing your history first genuinely reduces what is kept. The archive is deliberately tied to you rather than anonymised (its whole purpose is to connect a transcript to the person making a claim), and it cannot be reached by anyone through the app, including you.
Records kept for safety
Two kinds of safety records live outside your account record, are not deleted when you delete your account, and have no set expiry: a crisis-resource log and any moderation reports you file. Both are described in "Safety and Crisis Resources." Neither contains your birth data, chart, or journal notes, and the crisis log does not contain the text of your message.
↑ Back to top9. Security
We use reasonable administrative and technical safeguards designed to protect personal information against unauthorized access, use, alteration, and disclosure. The Service runs on Google Cloud infrastructure, and we rely on the security controls that infrastructure provides, along with measures such as access controls and authentication.
We want to be honest about the limits of security: no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You also play a part by keeping your sign-in method and device secure. We do not claim any particular security certification, and nothing in this Policy should be read as such a claim.
↑ Back to top10. Safety and Crisis Resources
LUQI is not a crisis service, a medical or mental-health provider, or a substitute for professional care, and it does not monitor your messages in real time or provide emergency intervention.
Crisis backstop. Every question you type to the AI is checked against a fixed self-harm and crisis pattern list before it is sent anywhere. If it matches, your question is not sent to Google at all; instead the app stores a fixed supportive reply and shows crisis resources—the U.S. 988 Suicide & Crisis Lifeline, and findahelpline.com for people outside the U.S. This check runs before any subscription check, so someone in distress is never shown an upsell.
What we log. When the crisis backstop fires, we write a record to a separate monitoring log for safety and regulatory-reporting purposes. That record contains only your account ID, the consultation ID, a source marker, and a timestamp—not the text of your message. To be transparent: this log is not readable by you, it is not deleted when you delete your account, and it has no set expiry. (The text of your question is stored separately on your own consultation record, and that text is deleted when you delete the item or your account.)
Reporting a reply. If you report an AI reply, we store a moderation report containing your account ID, the message ID, and up to 5,000 characters of the AI's reply (not your own question). These reports are create-only—no one can read, edit, or delete them through the app—and they are not deleted when you delete your account.
If you are in crisis or think you may be in danger, please get help right away. In the United States, you can call or text 988 to reach the 988 Suicide & Crisis Lifeline, call 911, or contact your local emergency services. If you are outside the United States, please contact your local emergency number or a local crisis line, or visit findahelpline.com.
↑ Back to top11. Children and Age Restriction (18+)
LUQI is intended only for adults 18 years of age and older. During onboarding, we present a neutral age screen and use the date of birth you enter to confirm you are at least 18. If the date of birth indicates you are under 18, onboarding is blocked: we use that date of birth only to perform the age check, we do not create a profile, we do not send anything to the AI, and we do not retain the date of birth you entered.
We do not knowingly collect personal information from anyone under 18, and certainly not from children under 13 (within the meaning of the Children's Online Privacy Protection Act, or COPPA). If we learn that we have collected personal information from someone under 18, we will delete that information and terminate the account. If you believe a minor has provided us with personal information, please contact us at support@superb.capital so we can take appropriate action.
↑ Back to top12. Access, Correction, and Deletion
You can access and correct much of your information directly in the app—for example, by updating your name, birth details, or gender in the profile editor. Changing a chart-relevant detail recalculates your chart and readings. You can also delete individual journal entries, individual past AI consultations, and individual Scan results yourself.
In-app account deletion. You can delete your account from within the app, in keeping with Apple's requirement that apps offering account creation also offer in-app deletion. Deletion is initiated only by you, always acts on your own account, and runs in a fixed order: your Scan photos are removed from storage; the legal-hold archive described in "Data Retention" is written; your account record and everything in it—profile, computed chart, cached readings, journal entries, AI consultations, Scan results, and usage counters—is deleted; your subscription record is deleted; your Apple sign-in token is revoked at Apple and deleted; and your authentication account is deleted last.
What deletion does not remove. As explained in "Data Retention," the narrow 36-month legal-hold archive and the safety records described in "Safety and Crisis Resources" live outside your account record and are not removed by account deletion. Information may also persist briefly in routine backups before it cycles out.
If you need help exercising any of these choices, contact us at support@superb.capital.
↑ Back to top13. Your California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the "CCPA"), gives you the following rights:
- Right to know and access the categories and specific pieces of personal information we have collected about you.
- Right to delete personal information we have collected from you, subject to exceptions.
- Right to correct inaccurate personal information.
- Right to opt out of the sale or sharing of personal information. As stated above, we do not sell or share personal information.
- Right to limit the use of sensitive personal information. See the note below on why this right is not triggered.
- Right to non-discrimination for exercising any of your rights.
About "sensitive personal information." Your date of birth and gender are personal information, and gender and age may also fall within the CCPA category of "characteristics of protected classifications under California or federal law." However, neither is statutory "sensitive personal information" as defined in California Civil Code section 1798.140(ae), and we do not collect precise geolocation. We recognize that the Feng Shui chart we compute, and the guidance built on it, could be viewed as relating to religious or philosophical beliefs, which is an enumerated category of sensitive personal information. The right to limit the use of sensitive personal information attaches where such information is used to infer characteristics about a consumer. We do not use any such information to infer characteristics about you for any purpose beyond delivering the Feng Shui Service you request, and we never use it for the secondary purposes the limit-use right is designed to restrict (such as cross-context behavioral advertising or profiling unrelated to the Service). For these reasons, we do not collect or process any category of "sensitive personal information" in a manner that triggers the right to limit its use, and we do not offer a corresponding link. If our practices ever change, we will update this Policy and provide any choices required by law.
How to submit a request. Email us at support@superb.capital. We will respond within 45 days, and may extend that period by up to an additional 45 days (for a total of up to 90 days) where reasonably necessary, with notice to you. We will take reasonable steps to verify your identity before fulfilling a request, such as matching information you provide against information we hold; for requests seeking specific pieces of personal information, we may apply a more stringent verification standard. Requests to know or access are generally limited to twice per 12-month period. You may use an authorized agent to submit a request on your behalf; we may require the agent to provide proof of authorization and may verify your identity directly.
Notice at Collection
We collect the following categories of personal information: identifiers (such as a display name, sign-in user ID, and any name or email received from your sign-in provider); characteristics of protected classifications under California or federal law (such as gender and age, derived from your date of birth); internet or other electronic network activity information (usage analytics and diagnostics); commercial information (subscription and purchase status); visual information (the photos you submit to the Scan feature); and other information you provide (date of birth, birth time and birth place (both optional), gender, your questions and messages, and your check-ins and journal notes), along with the Feng Shui profile we derive from your birth details and gender. We collect this information for the purposes described in "How We Use Your Information." We disclose personal information for business purposes to the service providers described in the "Service Providers and Sub-Processors" section (for example, cloud hosting, AI processing, and subscription management). We do not sell or share personal information. We retain personal information as described in "Data Retention."
↑ Back to top14. EEA and UK Users (GDPR / UK GDPR)
If you are in the European Economic Area (EEA) or the United Kingdom (UK), the EU General Data Protection Regulation (GDPR) and the UK GDPR apply to our processing of your personal information. The controller is Synced LLC, 1111 Dillingham Blvd, Honolulu, HI 96817, support@superb.capital.
Lawful bases
- Performance of a contract (Art. 6(1)(b)). For creating and maintaining your account, providing the core Service, and delivering the AI features you request.
- Legitimate interests (Art. 6(1)(f)). For analytics, security, and product improvement. Where we rely on legitimate interests, we balance them against your rights and interests.
- Consent (Art. 6(1)(a)). For optional features you choose to turn on, such as push notifications; you can withdraw at any time by turning them off.
Special category data
Some information we process, such as your Feng Shui chart and the guidance built on it, may reveal or be used to infer religious or philosophical beliefs, which is a special category of data under Article 9. Special-category data requires both a lawful basis under Article 6 and a separate condition under Article 9. For this information we rely on the relevant Article 6 basis (such as performance of a contract or our legitimate interests) together with your explicit consent under Article 9(2)(a), given through a separate, unbundled opt-in. Because the core Feng Shui chart inherently involves such data, we obtain this explicit-consent opt-in at onboarding before the chart is computed; the Article 9(2)(a) explicit consent sits alongside, and does not replace, the Article 6 basis. You can withdraw this consent at any time, which stops further such processing but does not affect the lawfulness of processing carried out before withdrawal.
International transfers
We are based in the United States and process personal information there. For transfers from the EEA to the US, we rely on the EU-US Data Privacy Framework where the recipient is certified, and otherwise on the EU Standard Contractual Clauses together with a transfer impact assessment. For transfers from the UK to the US, we rely on the UK Extension to the Data Privacy Framework where applicable, and otherwise on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the SCCs. These mechanisms cover our US-based sub-processors, including Google Cloud and Google Vertex AI.
Your rights
Subject to applicable law, you have the rights of access, rectification, erasure, restriction of processing, data portability, objection to processing, and to withdraw consent at any time where processing is based on consent. To exercise these rights, contact us at support@superb.capital.
You also have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner's Office (ICO). In the EEA, you may contact the supervisory authority in your country of residence, place of work, or where the alleged infringement occurred.
EU and UK representatives (Article 27). We have not yet designated a representative in the European Union or the United Kingdom under Article 27 of the EU GDPR and the UK GDPR. Until a representative is appointed, individuals in the EEA or the UK may contact us directly about our processing of their personal information at support@superb.capital, and may also lodge a complaint with their supervisory authority as described above.
We retain personal information for the periods described in "Data Retention."
↑ Back to top15. International Users and Data Location
LUQI is operated from the United States. Regardless of where you use the Service, your personal information is processed and stored in the United States and on Google Cloud, including the AI processing performed by Google Vertex AI. By using LUQI, you understand that your information will be transferred to and processed in the United States, which may have data-protection laws that differ from those of your country. Where required, we put in place appropriate safeguards for such transfers, as described in the EEA and UK section above.
↑ Back to top16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this Policy. If we make material changes, we will provide additional notice as appropriate, for example through the app or by email. We encourage you to review this Policy periodically. Your continued use of the Service after an update takes effect means you accept the revised Policy.
↑ Back to top17. Contact Us
If you have questions, requests, or concerns about this Privacy Policy or our handling of your personal information, please contact us:
Synced LLC
1111 Dillingham Blvd
Honolulu, HI 96817
Email: support@superb.capital