Privacy Policy

Last updated: July 16, 2026

Yiwen AI (“we”, “us”, operated by Huakai Engine Technology Co., Ltd.) respects your privacy. This policy explains what data we collect, why, how we protect it, and the rights you have over it.

1. Data We Collect

  • Account data: email address, hashed password, display name, and consent preferences you provide at registration.
  • Birth information (sensitive): birth date, birth time, and gender you enter to generate a cultural personality profile. This is processed on our servers to compute your profile, then returned to your browser — we do not persist birth data in our database unless you explicitly save it while signed in.
  • Usage data: feature requests and counts (for quota enforcement), timestamps, and subscription tier at time of use.
  • Referral data: invitation code, inviting account ID, activation and purchase status, reward history, and limited fraud-prevention signals. Invitation URLs do not contain names or email addresses.
  • Billing data: handled by our payment processor Creem. We do not store your full card number; we receive only subscription status and the last four digits / card brand for display.

2. Cookies & Local Storage

We use cookies and browser local storage for authentication, language preference, and feature settings. We do not use advertising or tracking cookies. For a full list and how to manage them, see our Cookie Policy.

3. How We Use Your Data

  • To generate and display your cultural personality profile and related insights.
  • To operate AI chat features (your messages may be processed by our AI provider).
  • To enforce plan quotas and manage your subscription.
  • To attribute invitations, provide non-cash referral benefits, and prevent abuse.
  • To send essential service communications (e.g., billing, security).
  • Marketing emails are sent only if you opt in, and you can unsubscribe anytime.

4. Legal Bases (GDPR)

Where the EU/UK GDPR applies, we process your data on the bases of: your consent (birth data and marketing), performance of a contract (providing the service you subscribe to), and our legitimate interests (security, fraud prevention, service improvement).

5. Data Sharing

We do not sell your personal data. We share data only with processors necessary to run the service:

  • Creem — payment processing, subscription billing, and tax remittance (Merchant of Record).
  • Alibaba Cloud DashScope (Qwen) — AI advisor chat; prompts and conversation history are sent to process your messages. Data may be processed in China.
  • Resend — transactional and marketing emails (daily energy notes, if you opt in).
  • Supabase — PostgreSQL database hosting (Singapore region).
  • Vercel — static site hosting and anonymous analytics (with your cookie consent).
  • Sentry — optional error monitoring (no intentional PII).

International transfer safeguards for these processors are described in Section 6.

6. International Data Transfers (GDPR Chapter V)

Yiwen AI is operated by Huakai Engine Technology Co., Ltd. To run the service, personal data may be processed in countries outside your own, including locations that may not provide the same level of data protection as your home jurisdiction. The main transfers are:

  • Supabase (Singapore) — account, subscription, usage, and application data stored in our database.
  • Alibaba Cloud DashScope / Qwen (China) — AI advisor chat messages and optional profile context sent to generate responses.
  • Vercel (United States and global edge) — website hosting and, with your cookie consent, anonymous analytics.
  • Creem — payment and subscription billing data (Merchant of Record).
  • Resend (United States) — transactional and marketing emails, if you opt in.
  • Sentry (United States) — optional error and performance monitoring.

Where the EU/UK GDPR applies and we transfer personal data to countries without an adequacy decision (including China and the United States), we rely on:

  • Standard Contractual Clauses (SCCs)— the European Commission's SCCs (Decision (EU) 2021/914), and the UK International Data Transfer Addendum where applicable, incorporated into our agreements with processors. Official text: EU Standard Contractual Clauses.
  • Data Processing Agreements (DPAs) — contractual terms with each subprocessor, including confidentiality, security, and assistance with data-subject requests. Processor DPAs / privacy terms:
  • Supplementary measures — TLS encryption in transit, access controls, data minimization (e.g., only necessary profile fields sent to AI), pseudonymous error reporting, and contractual obligations on processors to protect your data.

By using the AI advisor, you acknowledge that chat content may be processed in China by Alibaba Cloud DashScope under the safeguards above. You may email support@yiwen-ai.com to request further information about transfers or copies of relevant contractual safeguards (subject to confidentiality limits).

7. Data Retention

We retain account and profile data while your account is active. Usage logs are retained for up to 12 months for abuse prevention and analytics. Certain billing or tax records held by our payment processor may be retained as required by law even after account deletion.

8. Deleting Your Account

You can delete your account at any time from Account Settings (sign in required). Deletion is permanent and takes effect immediately on our servers.

When you delete your account, we remove:

  • Your account profile (email, name, hashed password)
  • AI chat history and advisor memory linked to your account
  • Purchase and entitlement records on our servers
  • Email leads and usage logs associated with your account

Birth/profile data stored in your browser (session storage) is cleared when you delete your account from Settings on that device.

Important — billing: Deleting your Yiwen AI account does not automatically cancel an active Creem subscription or issue a refund. If you have a paid plan, cancel it first via Manage Billing on the Subscription page before deleting your account.

If you cannot access your account, email support@yiwen-ai.com from the address on your account and request deletion. We will verify your identity and process the request within 30 days.

9. Your Rights

Subject to your jurisdiction (including GDPR and California CCPA/CPRA), you may have the right to access, correct, delete, export, or restrict processing of your data, and to withdraw consent. Export your account data from Account Settings (signed in) or email support@yiwen-ai.com. California residents may also request disclosure of categories of data collected and opt out of any “sale” or “sharing” (we do not sell data).

10. Security

Passwords are stored hashed. Data is transmitted over HTTPS. While we use reasonable safeguards, no method of transmission or storage is 100% secure. Our procedures for responding to personal data breaches are described in Section 11 below.

11. Personal Data Breach Notification (GDPR Arts. 33–34)

We maintain technical and organizational measures to detect, contain, and respond to unauthorized access, loss, alteration, or disclosure of personal data (“personal data breaches”). Where the EU/UK GDPR applies, we follow the notification obligations in Articles 33 and 34:

  • Supervisory authority (Art. 33): If we become aware of a personal data breach, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to your rights and freedoms.
  • Affected individuals (Art. 34): If a breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay. That notice will describe, in clear and plain language, the nature of the breach; the categories and approximate number of records concerned; likely consequences; measures we have taken or propose to take; and how you can obtain further information (including contact details below).
  • Documentation: We record all personal data breaches, including the facts, effects, and remedial actions taken, regardless of whether notification to a authority or individuals is required.

Notification to individuals may not be required where we have applied appropriate technical and organizational protection measures (e.g., encryption), have taken subsequent measures to ensure the high risk is no longer likely, or notification would involve disproportionate effort (in which case we will use a public communication or similar measure).

If you believe your Yiwen AI account or personal data has been compromised, contact us immediately at support@yiwen-ai.com so we can investigate and respond.

12. Children

Yiwen AI is not directed to children under 16. We do not knowingly collect data from children. If you believe a child has provided data, contact us for removal.

13. Changes & Contact

We may update this policy; material changes will be posted here with a new date. Questions? Contact support@yiwen-ai.com.

See also our Terms of Service, Cookie Policy, and Disclaimer.