1. Introduction
memenow LLC (“memenow,” “we,” “us,” or “our”) operates the YinYang Agent platform. This Privacy Policy explains what personal information we collect, how we use it, how long we keep it, and when we share it. It applies when you visit our site, sign in with TikTok Login Kit, purchase memberships through Stripe, or generate BaZi analysis reports. It is also intended to satisfy disclosure requirements for integrations with the TikTok Developer Platform.
2. Information We Collect
We collect the following categories of information:
- Account and Authentication Data: Email address, display name, profile photo, TikTok
open_idand related identifiers, wallet addresses used for sign-in, and OAuth tokens required to authenticate you. - Birth and Analysis Inputs: Date, time, and location of birth, gender, and other details you submit to run BaZi analyses.
- Payment and Transaction Data: Order identifiers, billing country, and payment method metadata processed by Stripe. We do not store full card numbers.
- Usage Data: Logs from Cloudflare Workers, Neon database telemetry, browser type, operating system, IP address, language settings, pages viewed, and actions taken within the Service.
- Security and Abuse-Prevention Data: First-party security cookies, Cloudflare Turnstile verification results, and HMAC-hashed risk signals used to protect the free allowance and account security. We do not store raw Turnstile tokens, raw OAuth authorization codes, wallet signatures, or invasive browser fingerprints.
- Support Communications: Messages, attachments, or feedback you send to privacy@memenow.xyz.
3. How We Use Information
We use the information we collect to:
- Authenticate users via TikTok Login Kit and Google OAuth 2.0 and maintain secure sessions.
- Generate BaZi analyses, Insight Entry surfaces, and saved reports tailored to your inputs.
- Deliver membership features, manage Stripe subscriptions, and send purchase confirmations.
- Monitor Service performance, troubleshoot errors, and protect against abuse or fraud.
- Comply with legal obligations, respond to lawful requests, and enforce our Terms of Service.
- Communicate updates, security alerts, and policy changes relevant to your account.
4. Legal Bases
For individuals located in the European Economic Area or the United Kingdom, we rely on the following legal bases:
- Consent for marketing messages and optional analytics cookies.
- Performance of a contract to provide BaZi analysis and membership services.
- Compliance with legal obligations such as taxation, reporting, and record keeping.
- Legitimate interests in improving the Service, detecting fraud, and ensuring security.
5. Sharing and Third-Party Processors
We share personal information only as needed for the purposes listed below:
- TikTok Login Kit: Authenticate accounts and retrieve basic profile information in accordance with TikTok’s developer login policies.
- Stripe, Inc.: Process payments, manage subscriptions, and detect fraud. Stripe may act as an independent data controller for certain activities.
- Cloudflare, Inc.: Provide hosting, security, and content delivery services for the application and APIs.
- Neon Tech, Inc.: Host the backend PostgreSQL database and connection pooling used by the service layer.
- Service Providers: Vendors who assist with logging, analytics, or customer support under confidentiality agreements.
- Authorities: Law enforcement or regulators when required to comply with legal obligations or protect our rights.
6. Data Retention
We retain personal information for the periods necessary to fulfill the purposes described above:
- Account and authentication records are retained while your account remains active plus up to 24 months.
- BaZi analysis inputs and generated reports are stored for up to 30 days unless you request earlier deletion.
- Transaction records are stored for at least seven years to satisfy accounting and legal obligations.
- Server logs are retained for up to 180 days for security and troubleshooting.
- Security cookies and abuse-prevention counters are retained for short periods appropriate to fraud prevention and free allowance protection.
7. Cookies and Similar Technologies
We use strictly necessary cookies to maintain authentication sessions and prevent fraud. This includes the HttpOnly__Host-yy_abuse_device cookie on HTTPS and yy_abuse_device during local HTTP development. These cookies are used only for security, abuse prevention, and free allowance protection, not for advertising. We may also deploy optional analytics cookies with your consent to understand feature adoption. You can update cookie preferences through browser settings and, where offered, in-product controls.
If you opt in, we use Google Ads services from Google LLC for advertising measurement and consent-mode signals. Google Ads cookies may help retain ad-click parameters and measure conversions such as ad landings, accepted analysis submissions, report generation, sign-ins, and purchases. We do not send BaZi birth inputs, report text, OAuth tokens, Stripe payment details, wallet signatures, or email contents to Google Ads. You can withdraw optional consent through the Cookie preferences control in the footer.
When analytics or advertising consent is denied, Google tags may still send limited cookieless measurement pings for aggregate modeling. These pings can include consent state and basic request or page context, but they do not read or write advertising cookies.
8. Data Security
We implement technical and organizational measures to safeguard personal information:
- HTTPS enforcement across the entire Service and service-binding interactions.
- Encryption at rest for databases and storage provided by Neon and Cloudflare.
- Role-based access controls and multi-factor authentication for administrative tools.
- Routine security assessments aligned with industry guidance.
9. International Transfers
We operate primarily from the United States and may transfer personal information to countries where our processors operate. When required, we implement safeguards such as the EU Standard Contractual Clauses or other lawful transfer mechanisms.
10. Your Rights and Choices
Depending on your location, you may have the right to:
- Request access to the personal information we hold about you.
- Request correction of inaccurate or incomplete information.
- Request deletion of your personal information, subject to legal exceptions.
- Object to or restrict certain processing, including direct marketing.
- Receive a copy of personal information in a portable format.
- Withdraw consent where processing is based on consent.
To exercise these rights, contact privacy@memenow.xyz. We may request identity verification before fulfilling your request. You may also file a complaint with your local data protection authority.
11. California Privacy Rights
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know the categories of personal information collected, request deletion, and opt out of the sale or sharing of personal data. We do not sell personal information as defined by the CCPA. Submit CCPA requests to privacy@memenow.xyz.
12. Children's Privacy
The Service is intended for users aged 18 or older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us data, contact privacy@memenow.xyz so we can delete it.
13. Updates to This Policy
We may revise this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make material changes, we will notify you by email or through the Service and update the “Last Updated” date at the top of this page.
14. Contact Us
If you have questions or concerns about this Privacy Policy, contact:
memenow LLC
Email: privacy@memenow.xyz
Website: https://memenow.xyz
Mailing Address: 16192 Coastal Highway, Lewes, DE 19958, United States
