tarot~ink
Legal

Privacy Policy

Last updated: March 18, 2026

1. Who we are

Tarot Ink is a mobile application for personalized tarot readings, custom deck creation, and daily card practice. The service is operated by:

Tarot Ink

[Impressum details will be added before public release]

Email: hello@tarotink.app

For the purposes of the EU General Data Protection Regulation (GDPR), Tarot Ink is the data controller responsible for your personal data.

2. What we collect and why

We only collect data that is necessary to provide and improve the service. Below is every category of personal data we process, along with its purpose and legal basis under GDPR Article 6.

DataPurposeLegal basis
Email addressAccount creation, authentication, service communicationsContract performance (Art. 6(1)(b))
Display name, handle, avatarProfile, social featuresContract performance (Art. 6(1)(b))
Birth date, birth time, birth locationAstrological chart and Human Design calculations for personalized readingsExplicit consent (Art. 6(1)(a) and Art. 9(2)(a))
Reading questions and conversation historyGenerating personalized tarot readings; building reading history for continuityContract performance (Art. 6(1)(b))
Card draw historyDaily card practice, reading recordsContract performance (Art. 6(1)(b))
Deck customization preferencesGenerating custom card artworkContract performance (Art. 6(1)(b))
Device tokens (push notifications)Sending notifications you have opted intoConsent (Art. 6(1)(a))
Usage events, device type, app versionAnalytics, crash diagnostics, service improvementLegitimate interest (Art. 6(1)(f))

Special category data

Birth data provided for astrological and Human Design calculations may reveal or relate to philosophical or spiritual beliefs. Under GDPR Article 9, this is treated as special category data. We process it only with your explicit consent, which you provide when you choose to enter your birth details in the app. You can withdraw this consent at any time by deleting your birth data from your profile -- the astrological features will simply become unavailable.

Data you choose not to provide

Most data is optional. If you choose not to provide birth details, astrological features will not function, but the core app -- readings, deck creation, daily card pulls -- works without them. An email address is required for account creation.

3. AI processing and disclosure

Tarot Ink uses artificial intelligence to generate tarot readings and card artwork. This section explains exactly what that means for your data.

What is AI-generated

  • Tarot card readings and interpretations
  • Custom card artwork for your decks
  • Personalized reading insights based on your history and profile

All AI-generated content in Tarot Ink is clearly produced by automated systems, not by human readers or artists. This disclosure is made in accordance with the EU AI Act (Article 50).

What data is sent to AI services

When you request a reading, the following may be sent to Google Gemini (our AI provider): your question, selected cards, relevant reading history, and -- if you have provided them -- your birth chart details. When you generate card artwork, your style preferences and deck description are sent.

How AI providers handle your data

We use Google Gemini under a paid API agreement with a Data Processing Addendum. Under these terms, Google does not use your data to train its models. Google acts as a data processor under GDPR, processing your data only as instructed by us to deliver the service.

Automated decision-making

AI-generated readings constitute automated processing that produces personalized content. However, these readings are provided solely for entertainment and personal reflection -- they do not produce legal effects or similarly significant effects on you (GDPR Article 22). You always have the right to contact us if you have questions about how automated processing affects you.

4. Third-party services

We share your data only with the services necessary to operate Tarot Ink. We do not sell your data. Here is every third-party service that receives personal data:

ServiceData sharedPurposeLocationSafeguard
Google GeminiReading questions, card selections, birth chart data, style preferencesAI-generated readings and card artworkUnited StatesEU-US Data Privacy Framework; Standard Contractual Clauses; Data Processing Addendum
SupabaseAll account and application dataDatabase, authentication, file storageUnited StatesStandard Contractual Clauses; Data Processing Addendum
LocationIQBirth location text (city/country)Geocoding for astrological calculationsEuropean UnionEU-based processing
PostHogUsage events, device type, app versionProduct analyticsEuropean UnionEU-hosted instance
Expo (Apple/Google)Push notification tokensDelivering push notificationsUnited StatesPlatform terms; Standard Contractual Clauses

5. International data transfers

Some of our service providers are based in the United States. When personal data is transferred outside the European Economic Area (EEA), we ensure adequate protection through one or more of the following mechanisms:

  • EU-US Data Privacy Framework -- for US providers certified under the framework (e.g., Google LLC), following the European Commission's adequacy decision of July 10, 2023.
  • Standard Contractual Clauses (SCCs) -- EU Commission-approved contractual terms that bind the data importer to EU-level data protection standards.
  • Data Processing Addendums -- additional contractual commitments from our providers regarding data handling, security, and breach notification.

You may request a copy of the relevant safeguards by contacting us at the address below.

6. Data retention

We retain your data only as long as necessary for the purposes described above. Specific retention periods:

DataRetention
Account dataUntil you delete your account
Reading historyUntil you delete your account or individual readings
Generated card imagesUntil you delete the card or your account
Birth/astrology dataUntil you remove it from your profile or delete your account
Analytics dataAnonymized after 24 months
Server logs90 days

When you delete your account, we permanently remove all associated personal data within 30 days. Some anonymized, aggregated data (e.g., total reading count) may be retained for service analytics but cannot be linked back to you.

7. Your rights

Under the GDPR, you have the following rights regarding your personal data:

  • Access (Art. 15) -- request a copy of all personal data we hold about you.
  • Rectification (Art. 16) -- correct inaccurate data. You can update most data directly in the app.
  • Erasure (Art. 17) -- request deletion of your data. You can delete your account directly in the app, which removes all personal data.
  • Restriction (Art. 18) -- request that we limit processing of your data in certain circumstances.
  • Data portability (Art. 20) -- receive your data in a structured, machine-readable format.
  • Objection (Art. 21) -- object to processing based on legitimate interest. We will stop unless we demonstrate compelling grounds.
  • Withdraw consent (Art. 7(3)) -- where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

To exercise any of these rights, email us at hello@tarotink.app. We will respond within 30 days.

If you believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection supervisory authority. In Germany, this is your state's Landesdatenschutzbeauftragter.

8. Cookies and device storage

Website (tarotink.com)

Our website uses cookies in the following categories:

  • Strictly necessary -- cookie consent preferences, theme selection. These do not require consent under TDDDG Section 25.
  • Analytics -- PostHog analytics cookies to understand how visitors use the site. Only set with your consent.

You can manage your cookie preferences at any time using the "Cookie Settings" link in the website footer.

Mobile app

The mobile app stores authentication tokens and user preferences on your device using secure storage (Expo SecureStore). These are strictly necessary for the app to function and do not require consent. Analytics identifiers are only stored with your consent.

9. Children

Tarot Ink is not intended for children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has provided us with personal data, please contact us and we will delete it promptly.

10. Changes to this policy

We may update this privacy policy from time to time. If we make material changes, we will notify you through the app or by email at least 30 days before the changes take effect. The "Last updated" date at the top of this page indicates when the policy was most recently revised. Continued use of the service after the effective date constitutes acceptance of the updated policy.

11. Contact

For any questions about this privacy policy or how we handle your data: