Skip to legal content
duckgu.studio
EN日本語한국어
LodestarPRIVACY

DATA & PRIVACY

Privacy Policy.

How Lodestar handles account, reflection, and subscription data.

Operator
Choi Hansol, sole proprietor registered under the trade name Lodestar and operating the Duckgu Studio brand (Republic of Korea; Business Registration No. 522-36-01755)
Effective date
October 1, 2026
Contact
privacy@duckgustudio.com
Privacy PolicyTerms of UseSupportExcelEscape
Scheduled effective date — October 1, 2026

This version is scheduled to take effect on October 1, 2026. Self-service access is limited to users aged 14 or older; a user who has not reached the age of majority where they live must have permission from a parent or legal guardian. Users under 14 are excluded because no child-account or verified-parental-consent program is offered at launch. The operator is currently exempt from Korean mail-order-sales business reporting because it is registered as a simplified VAT taxpayer. If that status changes or reporting becomes required, the applicable report information will be added. Analytics, marketing email, push notifications, processors, international transfers, consent choices, and store disclosures must match the released configuration before the corresponding feature is activated.

Contents
  1. Information we process
  2. Information kept only on your device
  3. AI and third-party processing
  4. Service providers and overseas processing
  5. Retention
  6. Website sharing, support, and browser storage
  7. Your choices and rights
  8. United States state privacy notice
  9. Age, security, and changes
  10. Contact

Choi Hansol, a sole proprietor registered in the Republic of Korea under the trade name Lodestar and operating the Duckgu Studio brand, operates Lodestar for launch in the United States, Republic of Korea, and Japan. Lodestar is an iOS service for astrology-inspired reflection. This policy explains what Lodestar processes, why it is used, and the choices available to you.

This policy also covers the Lodestar website community and inquiry forms where available. These website features are separate from the current iOS release, in which community sharing is not enabled.

Information we process

AreaInformationPurpose
Account and sign-inFirebase UID and the name and email supplied through Sign in with AppleAuthenticate you, maintain your account, and provide support
AI reflectionsYour reflection input and generated result, with sun-sign and solar-season context, locale, and local dateGenerate responses, show history, and retry interrupted requests
Website public copiesThe title and text you choose to submit, optional sun sign, account link, consent version and time, copy revision, and publication or moderation statusReview a separate copy for publication, record your consent, and manage revisions and withdrawal
Website inquiriesAccount-linked subject, category, original messages and replies, message language, status history, and timestampsAllow you and authorized support staff to follow and resolve your inquiry
Website reports and blocksReported public-copy identifier and revision, reason, staff decision and note, status and timestamps; viewer-specific opaque block identifiersReview reports, record moderation decisions, and hide blocked authors from your signed-in view
Website audit recordsAction, target identifier, staff or member role, a hashed actor reference, and timestamp; no journal or inquiry message textCheck moderation and support actions and protect the service
Subscription accessStoreKit entitlement or transaction identifiers, plan/status, and previously recorded trial timing retained for compatibility, where presentVerify Plus access, reconcile purchases and restorations, and prevent duplicate processing; historical trial data does not grant access
Security and operationApp-integrity signals, essential configuration requests, limited operational logs, per-account counts of AI and safety requests, and rate-limit window timestampsUsed only to protect the service, apply rate limits, and troubleshoot; never used for advertising or location-related purposes
Legacy on-device recordsIf an earlier app version saved a place or lucky-item record, it may remain in protected account-scoped storage on that device. The current version does not create new records of this type or send them to Duckgu Studio servers, Google, or OpenAI.Show the previously saved record read-only until you delete Lodestar’s local account data or the app

Information kept only on your device

Exact date of birth, gender, the local guardian-consent confirmation used for eligible teen access, non-AI notes, and keepsakes are stored only on your device and excluded from device backup. Duckgu Studio does not receive these fields through the normal service flow, and they are not sent to OpenAI.

The current release does not provide map search or nearby-place recommendations, request iOS location permission, collect device coordinates or place categories, send them to Google Maps/Places, use the Google Maps/Places SDK or provider, or create new place records. The location-independent daily lucky item and number remain available and are calculated on your device.

If an earlier app version saved a place or lucky-item record, it may remain on that device. The current version displays previous records in read-only form, does not collect new location data or create place records, and does not send them to Duckgu Studio servers, Google, OpenAI, or another external provider. Those records are deleted when you delete Lodestar’s local account data or the app.

If you voluntarily include any of this information in an AI-reflection prompt, it becomes part of the reflection input described above.

The current release does not include an advertising SDK and does not request or display ads. Lodestar does not sell personal information or share it for cross-context behavioral advertising. If advertising is considered later, Duckgu Studio will update the applicable policy and terms, provide advance notice, and obtain consent or provide opt-out controls where required by law before activation. Any future ads must remain non-personalized; must not target minors; must not use journal or AI content, birth information, or sensitive information for targeting; and may appear only to eligible free users on neutral screens, never on AI or journal input and result screens, crisis, account, purchase, or legal screens.

Firebase Analytics and Performance SDKs are not included in the current release. Analytics and optional marketing email or push notifications are currently inactive. They may be enabled only after the policy, consent and opt-out controls, age protections, international-transfer disclosures, and store disclosures are updated to match the implemented configuration. Marketing messages will use a separate opt-in where required, and every marketing email will provide an unsubscribe method and the operator’s postal address.

AI and third-party processing

The Firebase backend sends AI-reflection input and necessary context to OpenAI. OpenAI requests set `store:false`, so generated responses are not stored as API application state; this setting does not by itself disable abuse-monitoring logs. OpenAI API inputs and outputs are not used to train or improve OpenAI models unless Duckgu Studio explicitly opts in. Duckgu Studio has not confirmed that Zero Data Retention or Modified Abuse Monitoring is enabled for the production project. Under the default setting, OpenAI may retain content in abuse-monitoring logs for up to 30 days; longer retention may occur where required by law or reasonably necessary to protect the services or third parties from harm.

Service providers and overseas processing

Apple processes App Store payments and sign-in data when you use Sign in with Apple. Google Firebase provides authentication, database, functions, app attestation, and remote configuration. Firebase Analytics and Performance SDKs are not included in the current release. The Crashlytics SDK is linked, but automatic crash-report collection and symbol upload are disabled. Crash information may be kept locally on the device, but this release does not send it to Firebase. Remote Config is fetched only after the combined Privacy Policy and Terms agreement gate.

Firebase and OpenAI may process information outside your country, including in the United States. The primary Firestore database is currently in the United States. We will provide the information and safeguards required by applicable law before relying on consent or another lawful transfer mechanism.

Analytics, marketing email, and push notifications are currently inactive. Their data categories, receiving legal entities, countries, transfer timing and method, retention, safeguards, age restrictions, consent, and opt-out controls will be confirmed and this policy and the available choices will be updated before activation.

  • Google Firebase: authentication, database, server functions, app integrity, and remote configuration
  • OpenAI: AI-reflection generation
  • Apple: Sign in with Apple
  • Apple StoreKit: subscription and transaction processing
  • No advertising provider is active in the current release. Any future provider, data flow, transfer location, and retention period will be disclosed before activation.
  • Google Workspace: support and privacy email handling

Retention

InformationRetention
Account and AI-reflection historyUntil the account is deleted
Website public copies, consent, and moderation statusUntil the account is deleted. Public display ends when you withdraw the copy, it is hidden or removed through moderation, or your account is deleted.
Website inquiry conversations and status history3 years after the inquiry is closed, or earlier if the account is deleted
Website reports and staff decision recordsUntil the reporting account is deleted
Website author blocksUntil you unblock the author or delete your account
Website moderation and support audit records3 years after creation, or earlier if the account to which the record belongs is deleted
Interrupted-request retry cacheNo longer than 2 hours
Subscription, payment, supply, and transaction evidence5 years, or longer where required for an active dispute or by law
Customer inquiries3 years after the inquiry is closed
Routine operational logsNormally 90 days
Security-incident and audit records3 years after creation, or longer where needed for an active incident or legal claim
OpenAI abuse-monitoring logsUp to 30 days by default; potentially longer where required by law or reasonably necessary to prevent harm
On-device notes and legacy recordsUntil you delete Lodestar’s local account data or the app

Website sharing, support, and browser storage

Private journals in the iOS app are never automatically made public. Website sharing requires a separate copy that you choose and explicitly consent to publish. Authorized staff review the current copy before publication; a revised submission requires renewed consent and review. The public view contains only the approved title and text, optional sun sign, public-copy identifier, revision, and publication time. It does not expose your authentication UID. Withdrawal stops further public access through the service, but cannot recall copies or screenshots that someone else already saved.

Website inquiries are stored in Firebase and linked to your account. The conversation is available to you and authorized support staff, not to other members or the public. We preserve the original messages, replies, their language, and the status history. If staff write a translated response, it is a separate language-tagged reply and does not replace the original. The website does not automatically send inquiry text to a third-party translation service or AI provider.

A report records the public copy and revision reported, your reason, and the staff decision, note, status, and timestamps. These records are available to authorized moderation staff, not the public. Blocking uses an opaque identifier specific to the signed-in viewer; the block list does not expose the blocked author’s authentication UID. Audit records contain action and identifier metadata, not private journal or inquiry message text.

The website uses Firebase Authentication with browser-tab session persistence to maintain your sign-in and apply your blocks as you navigate within that tab. Live journal and inquiry contents are not persisted by the website in localStorage or sessionStorage. Website requests also use Firebase App Check with Google reCAPTCHA Enterprise for abuse protection.

Your choices and rights

Where applicable, you may request access, correction, deletion, restriction, or withdrawal of consent through privacy@duckgustudio.com. We may need to verify your identity before acting.

From Profile, you can permanently delete your Lodestar account and the account-scoped data on that device, including legacy records.

Deleting your Lodestar account does not cancel an Apple App Store subscription. Cancel it separately in your Apple account settings. Minimal records may remain where retention is required by law.

United States state privacy notice

For United States residents, the categories processed are the identifiers, account information, commercial or subscription records, Internet or device activity, user-provided reflection content, and inferences described above. Sources are you, your device, Sign in with Apple, StoreKit, and the service providers listed in this policy. We use and disclose these categories for the stated service, safety, security, support, transaction, and legal purposes.

During the preceding 12 months, Lodestar has not sold personal information or shared it for cross-context behavioral advertising, and the current release does not show ads. We do not offer a financial incentive for personal information and do not knowingly sell or share personal information of users under 16. If advertising is considered later, it will not use sensitive information, birth information, or AI and journal content for targeting, and the required notice, consent, and opt-out controls will be provided before activation.

Depending on your state and whether the relevant law applies, you may have rights to confirm processing, access, correct, delete, or obtain a portable copy of personal information; to opt out of sale, targeted advertising, or certain profiling; to limit certain sensitive-data uses; to use an authorized agent; to appeal a denied request; and to receive service without unlawful discrimination. Submit a request or appeal to privacy@duckgustudio.com. We will verify requests as appropriate and explain any denial and available appeal route. If an opt-out practice is introduced, Lodestar will provide the required control and honor applicable recognized universal opt-out signals before activating it.

Age, security, and changes

The minimum age is 14. If you have not reached the age of majority where you live, you may use Lodestar only with permission from a parent or legal guardian. Users under 14 may not create an account or use the service because no child-account or verified-parental-consent program is offered at launch. If we learn that an under-14 user provided information, we will restrict the account and take reasonable steps to delete the information as required.

We use reasonable technical and organizational safeguards, but no online service can guarantee absolute security. Material changes will be announced in the app or on the service website before they take effect.

Contact

Operator: Choi Hansol, sole proprietor registered under the trade name Lodestar and operating the Duckgu Studio brand (Republic of Korea; Business Registration No. 522-36-01755)

Representative: Choi Hansol

Business address: Unit B02, 373-8 Bongcheon-ro, Gwanak-gu, Seoul 08750, Republic of Korea

Public telephone: +82-10-5594-0555

Privacy: privacy@duckgustudio.com

Support: support@duckgustudio.com

Questions about this document?

privacy@duckgustudio.com

Email us
Back to Duckgu Studio© 2026 Duckgu Studio