Effective August 4, 2026 · Draft template — not legal advice. Have a licensed attorney review against your actual data flows before launch.
Account information: if you create an account, your email address and a salted, hashed version of your password — we never store the password itself and cannot recover it. Reading content: the question you ask, the spread you choose, the cards you draw, the reading generated for you, and any follow-up questions you ask about it. Payment information: your email address and subscription status. Payments are handled entirely by Stripe; we never see or store your card number. Technical information: your IP address, used only to limit how many free readings can be requested per hour, and a randomly generated session identifier stored in a cookie. Profile information, all of it optional and all of it offered after your first reading, never before: a name or nickname for the oracle to address you by, what brought you to the cards, your preferred voice and reading length, and your date of birth. We use the date of birth for two things only — confirming you meet the minimum age in our Terms, and marking your birthday in a reading. We do not use it for astrology, and we do not derive a star sign or birth chart from it. If you are not signed in, none of this leaves your browser.
To generate your readings, keep you signed in, process subscription payments, maintain your reading journal, address you by name, confirm you meet our minimum age, and prevent abuse of the free tier. Where you have given a name or said what brought you to the cards, those are included in the text sent to our AI provider so the reading is written for you rather than for anyone. We do not sell your data, and we do not use your questions or readings to train AI models.
This depends on whether you are signed in. If you use the Service without an account, your reading history, free-reading status, and preferences stay in your browser's local storage on your own device and are never saved to our server. Your question and drawn cards still pass through our server on the way to the AI provider that writes the reading, but we do not retain them. If you create an account, your readings are saved to our server so they follow you between devices; each saved entry includes your question, the spread, the cards drawn, and the reading's closing summary. Your account details and subscription status are always stored on our server.
The Service depends on four providers, each processing data under its own privacy policy. Stripe handles checkout, card processing, and subscription billing. OpenAI generates your reading text — the question you ask and the cards you draw are sent to its API for that purpose. Cloudflare provides our hosting, database, and content delivery, and processes your IP address as part of serving and protecting the site. Meta receives advertising events from the pixel described in section 5, together with your IP address and the Meta cookies already in your browser.
We set one cookie of our own: a session identifier that keeps you signed in to your account and membership. It is HttpOnly (unreadable by scripts), Secure, and expires after 60 days. We also run the Meta (Facebook) advertising pixel, which sets its own cookies and reports to Meta when you view a page, begin a reading, create an account, or complete a purchase, so we can measure and target our advertising. That means Meta can recognise you across other sites that use it. You can limit this through your Meta ad preferences, or block it with a browser setting or content blocker — the Service works normally either way. We also use your browser's local storage to remember your free-reading status, voice and depth preferences, your daily card, and — if you are not signed in — your reading journal. Local storage stays on your device and can be cleared at any time through your browser settings.
Session records expire automatically 60 days after you sign in. The hourly counters used to rate-limit free readings expire within one hour and are not retained beyond that. Account details, saved journal entries, and subscription records are kept until you ask us to delete them; we may retain billing records for longer where tax or accounting law requires it. Anything held only in your browser's local storage is deleted when you clear it.
Depending on where you live — for example under the GDPR or the CCPA — you may have the right to access, correct, export, or delete your data, or to object to its processing. We do not yet offer self-service deletion in the app: email us at the address below and we will action your request. You can cancel your subscription yourself at any time through the billing portal, which is separate from deleting your data.
The Service is not directed to anyone under 16, in line with the minimum age in our Terms of Service, and we do not knowingly collect their data. If you believe someone under 16 has given us personal information, contact us and we will delete it.
We may update this policy from time to time. Material changes will be posted here with an updated effective date.
Privacy questions or data requests: [support@yourdomain.com].