Privacy Policy
Last updated: March 18, 2026
1. Who we are
Tarot Ink is a mobile application for personalized tarot readings, custom deck creation, and daily card practice. The service is operated by:
Tarot Ink
[Impressum details will be added before public release]
Email: hello@tarotink.app
For the purposes of the EU General Data Protection Regulation (GDPR), Tarot Ink is the data controller responsible for your personal data.
2. What we collect and why
We only collect data that is necessary to provide and improve the service. Below is every category of personal data we process, along with its purpose and legal basis under GDPR Article 6.
| Data | Purpose | Legal basis |
|---|---|---|
| Email address | Account creation, authentication, service communications | Contract performance (Art. 6(1)(b)) |
| Display name, handle, avatar | Profile, social features | Contract performance (Art. 6(1)(b)) |
| Birth date, birth time, birth location | Astrological chart and Human Design calculations for personalized readings | Explicit consent (Art. 6(1)(a) and Art. 9(2)(a)) |
| Reading questions and conversation history | Generating personalized tarot readings; building reading history for continuity | Contract performance (Art. 6(1)(b)) |
| Card draw history | Daily card practice, reading records | Contract performance (Art. 6(1)(b)) |
| Deck customization preferences | Generating custom card artwork | Contract performance (Art. 6(1)(b)) |
| Device tokens (push notifications) | Sending notifications you have opted into | Consent (Art. 6(1)(a)) |
| Usage events, device type, app version | Analytics, crash diagnostics, service improvement | Legitimate interest (Art. 6(1)(f)) |
Special category data
Birth data provided for astrological and Human Design calculations may reveal or relate to philosophical or spiritual beliefs. Under GDPR Article 9, this is treated as special category data. We process it only with your explicit consent, which you provide when you choose to enter your birth details in the app. You can withdraw this consent at any time by deleting your birth data from your profile -- the astrological features will simply become unavailable.
Data you choose not to provide
Most data is optional. If you choose not to provide birth details, astrological features will not function, but the core app -- readings, deck creation, daily card pulls -- works without them. An email address is required for account creation.
3. AI processing and disclosure
Tarot Ink uses artificial intelligence to generate tarot readings and card artwork. This section explains exactly what that means for your data.
What is AI-generated
- Tarot card readings and interpretations
- Custom card artwork for your decks
- Personalized reading insights based on your history and profile
All AI-generated content in Tarot Ink is clearly produced by automated systems, not by human readers or artists. This disclosure is made in accordance with the EU AI Act (Article 50).
What data is sent to AI services
When you request a reading, the following may be sent to Google Gemini (our AI provider): your question, selected cards, relevant reading history, and -- if you have provided them -- your birth chart details. When you generate card artwork, your style preferences and deck description are sent.
How AI providers handle your data
We use Google Gemini under a paid API agreement with a Data Processing Addendum. Under these terms, Google does not use your data to train its models. Google acts as a data processor under GDPR, processing your data only as instructed by us to deliver the service.
Automated decision-making
AI-generated readings constitute automated processing that produces personalized content. However, these readings are provided solely for entertainment and personal reflection -- they do not produce legal effects or similarly significant effects on you (GDPR Article 22). You always have the right to contact us if you have questions about how automated processing affects you.
4. Third-party services
We share your data only with the services necessary to operate Tarot Ink. We do not sell your data. Here is every third-party service that receives personal data:
| Service | Data shared | Purpose | Location | Safeguard |
|---|---|---|---|---|
| Google Gemini | Reading questions, card selections, birth chart data, style preferences | AI-generated readings and card artwork | United States | EU-US Data Privacy Framework; Standard Contractual Clauses; Data Processing Addendum |
| Supabase | All account and application data | Database, authentication, file storage | United States | Standard Contractual Clauses; Data Processing Addendum |
| LocationIQ | Birth location text (city/country) | Geocoding for astrological calculations | European Union | EU-based processing |
| PostHog | Usage events, device type, app version | Product analytics | European Union | EU-hosted instance |
| Expo (Apple/Google) | Push notification tokens | Delivering push notifications | United States | Platform terms; Standard Contractual Clauses |
5. International data transfers
Some of our service providers are based in the United States. When personal data is transferred outside the European Economic Area (EEA), we ensure adequate protection through one or more of the following mechanisms:
- EU-US Data Privacy Framework -- for US providers certified under the framework (e.g., Google LLC), following the European Commission's adequacy decision of July 10, 2023.
- Standard Contractual Clauses (SCCs) -- EU Commission-approved contractual terms that bind the data importer to EU-level data protection standards.
- Data Processing Addendums -- additional contractual commitments from our providers regarding data handling, security, and breach notification.
You may request a copy of the relevant safeguards by contacting us at the address below.
6. Data retention
We retain your data only as long as necessary for the purposes described above. Specific retention periods:
| Data | Retention |
|---|---|
| Account data | Until you delete your account |
| Reading history | Until you delete your account or individual readings |
| Generated card images | Until you delete the card or your account |
| Birth/astrology data | Until you remove it from your profile or delete your account |
| Analytics data | Anonymized after 24 months |
| Server logs | 90 days |
When you delete your account, we permanently remove all associated personal data within 30 days. Some anonymized, aggregated data (e.g., total reading count) may be retained for service analytics but cannot be linked back to you.
7. Your rights
Under the GDPR, you have the following rights regarding your personal data:
- Access (Art. 15) -- request a copy of all personal data we hold about you.
- Rectification (Art. 16) -- correct inaccurate data. You can update most data directly in the app.
- Erasure (Art. 17) -- request deletion of your data. You can delete your account directly in the app, which removes all personal data.
- Restriction (Art. 18) -- request that we limit processing of your data in certain circumstances.
- Data portability (Art. 20) -- receive your data in a structured, machine-readable format.
- Objection (Art. 21) -- object to processing based on legitimate interest. We will stop unless we demonstrate compelling grounds.
- Withdraw consent (Art. 7(3)) -- where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
To exercise any of these rights, email us at hello@tarotink.app. We will respond within 30 days.
If you believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection supervisory authority. In Germany, this is your state's Landesdatenschutzbeauftragter.
9. Children
Tarot Ink is not intended for children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has provided us with personal data, please contact us and we will delete it promptly.
10. Changes to this policy
We may update this privacy policy from time to time. If we make material changes, we will notify you through the app or by email at least 30 days before the changes take effect. The "Last updated" date at the top of this page indicates when the policy was most recently revised. Continued use of the service after the effective date constitutes acceptance of the updated policy.
11. Contact
For any questions about this privacy policy or how we handle your data:
Email: hello@tarotink.app