Effective 2026-10-06 · version 19 (v18 2026-10-02 · v17 2026-10-01 · v16 2026-09-27 · v15 2026-09-26 · v14 2026-09-26 · v13 2026-09-21 · v12 2026-09-20 · v11 2026-09-19 · v10 2026-09-10 · v9·v8·v7·v6 2026-09-08 · v5·v4·v3 2026-09-07 · v2 2026-09-06 · v1 2026-08-25)
The Korean version is the governing text. This is a translation for convenience — if the two ever disagree, the Korean page prevails. The app is called 포츈해커 in Korean and 4tuneHacker in every other language; both names mean this same app.
| Information | Where it is stored | Stored on a server |
|---|---|---|
| The on/off setting for using your location in today's time periods (on by default) | The app's database on your phone — a setting, separate from any coordinates | Only if usage statistics are on — just the on/off state is included in statistics (never coordinates or permission status; §6-1). Not included in backups or shares |
| Your current location, if you allow it — used to apply solar time to today's time periods | Handled only in phone memory. The longitude is rounded to 0.1° and kept for at most 15 minutes on that screen; never stored permanently | No — the app never sends it anywhere, and it is not included in statistics, backups or shares |
| Birth details you choose to send — public display name, Gregorian birth date and birth time (or unknown) | The message or clipboard you choose and the recipient's device | Not sent to our server — your messaging service may store the message under its own policy. §3-1 |
| Your birthday, birth time and label | Your phone (the app's database) | No |
| Your full name written in Hangul (family name included), if you register it — for a reference reading of the name's sound | Your phone — stored separately from your display label. The name reading also runs on the device | No — not included in invitations, public share links, images or usage statistics. It is included in automatic backups and backups you export yourself |
| The label, birthday, time and tags of people you add | Your phone (the app's database) | No |
| A random per-person identifier, and the sentences, situations, tones, usage notes, how-you-used-it and timestamps of the conversation helper, plus its general-mode setting | Your phone — used to link a person to their private notes and to restore a backup | No — not included in public share links, images or usage statistics. Included in automatic backups and backups you export yourself. |
| The most recently copied conversation example | Your phone — one per friend, deleted on the next visit once 7 days have passed since copying | No — copying is separate from a usage note and is not included in backups |
| The label, birthday and time a friend enters through an invitation | Relay server until acknowledgement or expiry, then the inviter's phone (in the review list until the inviter adds, ignores or reports it) | Encrypted in transit — the server copy is deleted when the inviter's app receives it; anything not received is deleted automatically after at most 7 days · ignoring or reporting deletes it from the phone at once |
| The result card made by "Share a link" — temperament, inner nature, zodiac animal, elements, score, label (or initials) and graph layout | Server (share link) | Yes — no birthday or birth time is included. §5 |
| App usage statistics — screen names and dwell time, action names and bucket values, bucketed people and group counts, how many days you opened today's chemistry, whether notifications are on, build number, OS version (major version on iOS, API level on Android), device type, text size, app version, platform, language, approximate country, a hashed identifier and a timestamp | Server — Umami, which we run ourselves | Yes — sent only if you turn on the first-run switch, which is off by default, and a consent record is created. Nothing is sent before onboarding finishes. A previous install saved as on with no consent record is treated as off. §6 |
| Website (pillaxy.com) visits — page address, where you arrived from, approximate country, browser type | Server (the analytics tool we run ourselves) | Yes — counted without cookies. Personal link identifiers and result values inside the address are stripped before sending. §6-2 |
| Install identifier (a random UUID for this app installation) | Your phone | Its raw value is stored with a share link to mark its issuer (§5). If you enable usage statistics, our server receives the raw value and sends a persistent secret-keyed hash to Umami. It is not a name or account, but it links records from the same app installation, so we disclose it as linked to a device (§6). |
Temperaments, chemistry and scores shown in the app are all computed on your phone; nothing is sent to a server in order to compute them.
Optional use of location — In Settings → "Today's time periods" you can turn "Use current location for time periods" on or off; the default is on. While it is on, the app checks your location when you open "My chart today", and asks for the while-in-use location permission if you have not decided yet. It never re-asks automatically after you decline once — change it in your device's app settings. Once a valid fix is obtained the lookup ends, and latitude, accuracy and the measurement time are used only to check validity. The rounded longitude and the expiry information are deleted when you turn the setting off, leave the screen, send the app to the background, after the 15-minute expiry, or when the device date or time zone changes. While the setting is on, one fresh lookup happens when you return to the screen or after expiry; nothing is looked up in the background. Only the on/off setting is stored on the device: no movement history is built, and the location is never sent to geocoding, map or weather services. How the operating system's own location services behave follows your device settings and those services' policies. You can use the app with the device clock alone without allowing location.
When a friend enters their birthday through your invitation link, that content travels over an encrypted connection (HTTPS), rests briefly on the relay server, and is deleted the moment the inviter's app fetches it. Anything the app never fetches is deleted automatically after 7 days. The relay server does not read or use that content for any other purpose.
The friend's input page carries the same notice, and the form is submitted only after the friend checks the consent box.
The app (1.0.1 build 27 or later) does not save a received reply as a person right away. It keeps the reply in the "Friend replies to review" list on Home, and the reply becomes a person only when the inviter taps Add. Ignore deletes it from the phone at once; Report deletes it from the phone and opens an email to us (§8). The review list is not included in backup files.
The inviter can close an invitation link at any time with Make a new link in "Add a friend". A closed link can no longer send details, and any server copy sent through it that has not been delivered yet is deleted together with it, with anything left over removed automatically within 7 days at the latest. Closing a link without an internet connection takes effect on the server the next time you open the app online.
When you choose to send your own details, the app first shows your public display name, Gregorian birth date and birth time (or unknown). Sharing sends this text and an app link containing the same information to the messaging app you choose. Copying puts it on your clipboard. The link is encoded, not encrypted. Our server does not relay or store this message.
The recipient reviews the details before adding them to their phone. The Hangul name registered for name readings is excluded, as are person identifiers, conversation records and backup credentials. Messages and clipboard contents may also be kept by your device or chosen service. Deleting your information in this app does not delete those copies; ask the recipient to delete them separately.
When you tap "Share a link" on a compatibility or group screen, only the result values — temperament, inner nature, zodiac animal, elements, score, label (or initials) and graph layout — are stored on the server and a
pillaxy.com/share/… address is created. No birthday or birth time is included, and a link alone cannot be used to work a birthday back out.
# in the address, and image files, stay fixed.To learn which features are used so we can fix the app, we send a screen name when a screen opens and an action name with its bucket value when you take one of the predefined actions. Screen and action records are kept briefly on the device and sent in batches; a usage summary (heartbeat) is sent separately, once a day. The app sends statistics requests only to pillaxy.com, and our server forwards only the allowed items to the Umami instance we run ourselves.
Only the 14 screen names below are counted. Changing which person or group a screen shows, or returning to the app on the same screen, does not add another screen view. Movement inside a sheet is not counted as a screen view either. When a screen opens, the app may also send the previous screen's name, or a special entry path such as just launching the app, arriving from a notification, or arriving from a deep link.
What we send
| Category | Contents |
|---|---|
| 14 screens | Onboarding · Graph · Group · People · My chart · Settings · Shape detail · Today's chemistry · My chart today · Compatibility · Person sheet · Person add/edit · Conversation helper · Conversation history |
| Screen dwell time | When you leave a screen or the app goes to the background, we send how long you stayed on it as a range (under 3s / 3–10s / 10–30s / 30s–1m / 1–3m / 3m or more) together with which screen it was. |
| App open & session length | Whether the app opened as a cold start or resumed from the background (a warm start), and, once it goes back to the background or the screen turns off, how long it stayed in the foreground as a range (under 10s / 10–30s / 30s–1m / 1–3m / 3–10m / 10–30m / 30m or more). |
| Sheet opens | Which of 9 fixed bottom-sheet types you opened, and nothing else — group select · building a share card · notification time · group management · language select · today's chemistry partner select · leaving a conversation-helper note · exporting a graph image · cluster detail. |
| Entry & navigation sources | Opening the app from today's chemistry notification · opening it from a "Tell a friend my birthday" link (no other kind of deep link is recorded in this version) · where a person was opened from (Graph, Group, People or another screen) · where a compatibility page was opened from (Graph, Group, Today's chemistry, a person sheet, or another screen) · where "My chart today" was opened from (the home screen or another screen — never directly from a notification) · which shape-detail category was opened (temperament, inner nature or chemistry — never which specific item you looked at) |
| Tutorial & onboarding | Starting the tutorial (first automatic run or replaying it from Settings) · progressing through its steps (add a friend, relationship graph, add a group, people list) · which step you skipped it from · choosing whether to use sample data · finishing the tutorial · resetting it in Settings · finishing first-time setup (creating a new chart or restoring a backup) |
| Invitations | Accepting the request to open the "Add a friend" sheet · successfully storing a new invite inbox on the device (including Make a new link; reuse of an existing link excluded) · attempting to share a prepared invite link |
| Sharing | Attempting to share a prepared URL (compatibility/group; creating the link is not counted separately) · attempting to share after building an image file (compatibility/group/graph) · attempting to share "Tell a friend my birthday" details directly (§3-1; this version records only sharing, not copying) |
| People & groups | Successfully saving one new person (entered by hand / added from an invitation reply) · successfully saving a new group · editing a person · deleting a person · renaming a group · deleting a group · changing which group a screen (Graph/Group/People) shows. Ignoring or reporting a reply and closing an invitation link are not counted as any action. Receiving a duplicate, saving your own chart during onboarding, restoring a backup, adding the development sample, re-adding an existing group, creating the default groups and merging a backup are not counted as any of these actions. None of the edit, delete or group-change records say which person or group it was. |
| Backup | Attempting to share after building a backup file · completing a backup import (counted even when no new person was added; cancellation and read, parse or apply failures excluded) |
| Conversation helper | Showing the first example · successfully copying a sentence · successfully saving a new note that you actually used it · opening the conversation history screen · successfully saving a new note that you reused an earlier sentence. Only these 5 action names are sent — never the situation, tone, sentence, counterpart, note text or note identifier. Editing or restoring a note is not counted as saving a new note. |
| Feature actions | Switching the relationship graph style between the classic graph and temperament clusters · turning a relation-line type on or off · tapping a person node on the graph · the moment you first type a non-empty search term after entering the People screen (once per visit; the search text itself is never sent) · deleting a link in Settings → My share links |
| Setting changes | Saving a display name · turning "use current location for time periods" on or off · changing a calculation option · changing the notification time — for location use, whether it was turned on or off is sent (never coordinates or permission status). For other settings, only which kind of setting changed is sent, never the new value. |
| Notifications & language | Turning today's notification from OFF to ON (permission denials and pending states excluded) / successfully turning it from ON to OFF · completing the save and apply of a different language preference in Settings (auto/ko/en/ja/zh/es). Re-selecting the same value, the initial language detection and the development language override are not counted. |
| Usage summary (once a day) | Bucketed count of people added (0 / 1–5 / 6–15 / 16+) and a finer range (0 / 1 / 2–3 / 4–5 / 6–10 / 11–20 / 21–50 / 51+) · bucketed group count (0 / 1 / 2–3 / 4+) and a finer range (0 / 1 / 2 / 3 / 4–5 / 6+) · how many of the last 7 days including today you opened today's chemistry (0–7) · whether today's notification is on and, if so, its time band (morning, day, evening or night) · whether sample data from the tutorial is still present · tutorial progress (not started / in progress / done) · whether your language follows the device or was chosen manually · the current relationship-graph style (classic graph or temperament clusters) · whether "use location" for today's time periods is on or off (the setting only — never your actual location or its permission state) · whether you have set a display name (yes/no only, never the value) · whether you have registered a Korean name for the name reading (yes/no only, never the value) · bucketed count of share links you created (0 / 1 / 2–5 / 6+) · bucketed count of saved conversation notes (0 / 1–5 / 6–20 / 21+) · a range for days since install (0 / 1–6 / 7–29 / 30–89 / 90+ / unknown — this field only carries a real value for installs from this app version onward; earlier installs always send "unknown") |
| Common fields | App version and build number · platform (ios/android/web) and its OS version (the major version on iOS, the API level on Android) · phone or tablet · the language in effect (ko/en/ja/zh/es) · a text-size range (small/medium/large/extra-large) · an approximate country derived from the connecting IP (when one is determined). The "auto" language preference means following the device language; the common language field is always one of the five languages actually applied. |
| For aggregation | The install identifier as hashed by our server · a timestamp |
That is 46 action names in total (of 48 defined, minus the 2 reserved for report interest and preview, which have no payment feature behind them yet). A share, invite or backup event means an attempt to start; it is not a record confirming that anything reached another person or that a save completed. Copying a conversation does not mean it was used, and a usage note is the user's own self-report. Turning notifications on is likewise a settings change and does not mean a notification was delivered. Some records may be missing because of network errors and rate limits. For fields with a fixed list of allowed values — entry source, sheet type, shape-detail category and the like — we send only one value from that list, and a value that is technically allowed but not actually produced by this app version is not sent, as noted in the table above.
The server reserves two names, for report interest and preview (report_interest · report_preview). No name is reserved for payment. This version of the app has no place that sends them, so they are not collected. We will update this policy before the actual feature ships.
To know which pages get read, the website counts visits with an analytics tool we run ourselves (Umami, umami.jdsnl.com). It is not a third-party vendor's tool like Google Analytics, and visit records do not go to any ad company. This policy page is counted the same way.
/share/… · /i/…) are collapsed into a single bucket,
and everything after # in the address is removed entirely. After ? only the five campaign markers (utm_source · utm_medium · utm_campaign · utm_term · utm_content), the language lang (ko/en/ja/zh/es) and the style style (ko/en) are allowed. Campaign values are allowed only as 1–32 characters of lowercase letters, digits, underscores and hyphens; we do not additionally inspect the meaning of values in that shape to detect and strip personal information. Everything else is removed, and the page title — which could carry a label — is never sent at all. For addresses that came from an external site we keep only the source, such as the domain, and drop the path and query.Usage statistics are processed on the basis of your consent — you consent by turning on the switch, on the onboarding screen or in Settings, and finishing onboarding, and you can withdraw at any time in Settings (§6).
The "Add a friend" web relay, "Tell a friend my birthday" direct sharing, and creating a share link are processing to perform the exact feature you asked for by tapping the button on that screen. They do nothing unless you take that action, and we use them for no other purpose (§3, §3-1, §5).
Reporting — report an unwanted invitation reply with "Report" in the review list, and a share page with "Report this page". The report email is prefilled only with the label and the date received, never a birth date or time. We aim to review reports within 24 hours.
You can request to access, correct, delete, restrict processing of, or port the information we hold, or withdraw consent.
Some processing runs on the global network of Cloudflare, Inc., headquartered in the United States.
The analytics tool that stores usage statistics (Umami) is run directly by the operator in Korea, separately from Cloudflare, and is not transferred abroad.
4tuneHacker is run by a single operator, who serves directly as the person responsible for personal information protection. Questions, access or deletion requests, and complaints about this policy or how personal information is processed go to the contact above; reply times follow Section 8.
Under the California Consumer Privacy Act / CPRA, we have collected the following categories of information over the past 12 months.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. You have the right to know, to delete and to correct, and the right to non-discrimination for exercising these rights. See §8 for how to exercise them.
4tuneHacker is not directed to children. We ask that anyone under 14 not turn on the usage-statistics switch without a guardian's consent (§6). If we learn that a child's personal information was collected, we delete it without delay.
Automatic backup is on by default from app version 1.0.2, build 30. After setup, the app saves a backup in its private storage on the first eligible launch or return from the background each device-local day. It keeps the latest seven backups. No backup is created on days when you do not open the app, so copies may remain for more than seven days. Backups include saved people's birth details and labels, your optional Hangul name, groups, saved conversation records and modes, and invitation-link credentials. Pending friend replies, tutorial sample data, recently copied items and usage-statistics consent records are excluded.
Deleting a person or record does not remove it from earlier automatic backups. Use “Delete all automatic backups” in Settings, or turn automatic backup off, to delete the app's copies. If deletion fails, the app shows an error and retries on a later launch. Deleting the app removes its internal copies. Exported files and copies in operating-system backups must be managed separately.
Automatic backup does not send backup contents to our servers. On iPhone, copies may be included in an iCloud or Finder device backup, depending on your settings; this is separate from app cloud synchronization. Android system backup and device transfer exclude the app's data. Exporting a file sends it to the destination or service you choose.
The app can also export your data to a file in case you change devices. You create and keep that file yourself. The most recently copied item is excluded from backups. Nothing is transmitted to a 4tuneHacker server by the backup feature.
A registered name is deleted by tapping "Remove the registered name" on the edit screen for your own chart and saving. Backup files you already exported have to be deleted separately. Restoring a backup never overwrites an existing name; it fills one in only when the same person identifier has none.
App data is held in the operating system's per-app sandbox (iOS, Android), protected by the device lock and OS-level encryption. Communication with the relay server is always encrypted with HTTPS.
We do not provide or sell personal information to third parties, and we do not use it for advertising or marketing. The servers and databases behind invitation relay and share links, and the relaying of app statistics, run on Cloudflare infrastructure (see §9 for the scope of the international transfer). Storage and aggregation of app and web usage statistics are handled by the Umami instance we run ourselves (umami.jdsnl.com). Statistics remaining from before the migration are deleted from the former D1 store under the existing periods (§6-1), and outside the purposes in §3, §5 and §6 above we neither keep nor use any data.
When features grow and the information we handle changes — for example, purchase records keyed to an install identifier once paid features arrive — we update this page first and raise the effective date and version. Birth details are not stored on our server except for the consented invitation relay described in §3.
style to the allowed web query items.If you have a question about this policy or about how data is handled, or you want something deleted, write to us. The app has no accounts, so we have no way to identify you — include only what is needed for us to answer.
For things you can do inside the app right away, such as deleting a share link or a person, see §4 first, and see §8 for how to exercise a right such as access or correction.