Skip to main content
← Back to Arcana Readings

Legal

Privacy Policy

How Arcana Readings collects, uses, stores, and protects data across the Tarot Reading app and beta website.

App
Tarot Reading
Effective
August 1, 2026
iOS
com.havrylash.tarot
Android
com.havrylash.tarot

1. Summary

This Privacy Policy explains how Havrulash Vladyslav, operating under the Arcana Readings brand, handles personal data when you use the Tarot Reading mobile application (the “App”), the Arcana Readings website at app.arcanareadings.com, and the beta waitlist (together, the “Services”).

  • The App does not require an account. There is no sign-up, password, or social login.
  • The website collects your email address only if you choose to join the beta waitlist.
  • We do not sell your personal data, and we do not use it for cross-app or cross-site advertising tracking.
  • We do not run advertising SDKs and we do not collect the Advertising Identifier (IDFA or GAID).
  • Your identity in the App is a random identifier generated on your device the first time you open the App.
  • The profile details you enter and the questions you ask are sent to our AI provider, OpenAI, so the App can generate a personalised reading. They are not used to train AI models by default through the API.

2. Who we are

Havrulash Vladyslav, operating Arcana Readings (“we”, “us”), is the controller of the personal data described in this policy.

For any privacy question, request, or complaint, email gavrulash@icloud.com.

3. How you are identified in the App

When you first launch the App, it generates two random identifiers on your device and stores them in the App’s local storage:

IdentifierFormatPurpose
Anonymous app IDguest_<random UUID>Links your readings, journal, Crystals balance, and profile to one App installation on our backend.
Commerce and messaging IDRandom UUID v4Used as the user ID for our paywall provider, Superwall, and as the external ID for our push provider, OneSignal, so purchases and notifications reach the correct installation.

These identifiers are created by the App, not read from your device. They are not the IDFA, Android Advertising ID, phone number, or a hardware serial number. They are not linked to your real-world identity unless you enter identifying information yourself, such as your real name.

Because there is no account, these identifiers live only on the device where they were created. If you delete and reinstall the App, a new identifier is generated and your previous readings, journal entries, and Crystals balance are no longer reachable from the new installation.

4. What data we collect

4.1 Data you provide directly in the App

DataWhere you provide itRequired?
First name or nicknameOnboarding, My ProfileOptional — you may skip it or use any name.
Date of birthOnboarding, My ProfileUsed to derive your zodiac sign and personalise readings.
GenderOnboarding, My ProfileOptional.
Relationship statusOnboarding, My ProfileOptional.
Occupation categoryOnboarding, My ProfileOptional.
Preferred reading languageOnboarding, My ProfileDefaults to English.
Your question for a spreadTarot Reading flowOptional.
Your messages to an AI tarot readerAsk a Tarot Reader chatOnly if you use chat.
Notes added to a saved readingReading JournalOptional.

Please do not enter special-category information, such as health conditions, sexual life, religious or political beliefs, criminal history, or the personal data of other identifiable people into free-text fields. If you do, you are asking us and our AI provider to process it to respond to you.

4.2 Data generated by your use of the App

DataDetail
Reading recordsTopic, spread, drawn cards and orientation, position meanings, AI-generated interpretation, timestamps, prompt version, and model name.
Daily card and Yes-or-No recordsCard drawn, orientation, day key, and device time zone.
Horoscope recordsZodiac sign, period, profile snapshot used, and AI-generated text.
Reading JournalSaved readings and your notes.
Chat recordsThread status, your and the reader’s message text, turn count, token counts, and timestamps.
Crystals ledgerBalance and every credit or debit with a reason code, including daily reward, AI reading, AI chat, purchase, refund, or adjustment.
Daily reward streakLast claim date and streak day.
Notification preferenceWhether push is enabled and the push subscription state.
Device time zoneIANA time zone name, such as Europe/Kyiv, used so the daily card and reminder follow your local day.

4.3 Purchase data

Purchases are made through the Apple App Store and Google Play. We never receive your payment card, bank details, or billing address — those remain with Apple and Google. Through our paywall provider and store server notifications, we receive:

  • Store transaction ID and original transaction ID, product ID, store, and production or sandbox environment.
  • Purchase, renewal, cancellation, billing-issue, refund, and expiration events with timestamps.
  • Current subscription status and expiry, and an opaque server-derived entitlement key used to restore Premium on a new installation without copying other App data.

4.4 Data collected by service-provider SDKs

The SDKs embedded in the App collect limited technical data on our behalf:

  • Superwall for paywalls, purchase orchestration, and paywall analytics: App version, OS version, device model and locale, vendor device identifier, paywall impressions and interactions, and purchase and restore events.
  • OneSignal for push notifications: the push token issued by Apple or Google, OneSignal device ID, device model, OS version, App version, language, notification delivery and open events, and, depending on settings, a country derived from the request IP address. Location tracking is disabled in the App build configuration.
  • Convex for our backend: standard server request metadata, including IP address and user agent, used to operate and secure the service.

We do not embed advertising, attribution, or cross-app tracking SDKs.

4.5 Website and beta waitlist data

If you voluntarily join the beta waitlist, we collect the email address you submit, the form location used to submit it, and the submission time. The website sends this information through a server-side Vercel Function to our private Telegram bot chat so we can manage beta invitations and product updates.

Vercel may process ordinary technical request data, such as IP address, user agent, request time, and security logs, to host and protect the website and its server function. We do not use the waitlist email for unrelated advertising and do not place the Telegram bot token in the browser.

4.6 Data stored only on your device

The onboarding completion flag, animation preference, favourite spreads, pending-reading state, cached chat, and, for free users, a local reading journal of up to five entries are stored in local App storage and removed when you uninstall the App.

4.7 Data we do not collect

The App does not collect an email address for an account. Across the Services, we do not intentionally collect phone numbers, postal addresses, contacts, photos, camera or microphone data, precise or coarse GPS location, health data, browsing history, biometric data, or advertising identifiers. The website collects an email address only when you submit the beta waitlist form.

5. Why we use your data and our legal bases

PurposeData usedLegal basis under GDPR Article 6
Provide readings, horoscopes, chat, journal, and daily cardProfile, questions, drawn cards, chat messages, and identifiersPerformance of a contract, Article 6(1)(b).
Personalise reading text to your profileName, date of birth, gender, relationship status, occupation, and languagePerformance of a contract, Article 6(1)(b).
Operate the Crystals economy, daily rewards, and Premium entitlementsLedger, purchase and subscription data, and identifiersPerformance of a contract, Article 6(1)(b).
Deliver and schedule push notifications you enabledPush token, external ID, time zone, and Premium flagConsent, Article 6(1)(a), which you can withdraw at any time.
Manage the voluntary beta waitlist and send beta updatesEmail address, form source, and submission timeConsent, Article 6(1)(a), which you can withdraw at any time.
Prevent abuse of rewards, restores, purchases, and website formsEntitlement key, ledger, transaction IDs, and request metadataLegitimate interests, Article 6(1)(f).
Diagnose failures and keep the Services reliableError messages, HTTP statuses, provider response IDs, and request metadataLegitimate interests, Article 6(1)(f).
Comply with tax, accounting, and legal obligationsPurchase recordsLegal obligation, Article 6(1)(c).

We do not use your data for profiling with legal or similarly significant effects, and we do not make automated decisions about you in that sense. AI-generated readings are entertainment content, not decisions about you.

6. AI processing

Readings, horoscope personalisation, and tarot-reader chat are generated by OpenAI models called from our backend. We send:

  • Your profile fields, including name, date of birth, gender, relationship status, occupation, and preferred language.
  • The spread, drawn cards, and their positions.
  • Your typed question or chat message.
  • A pseudonymous user reference used for abuse monitoring and request correlation.

We do not send your push token, device identifiers, IP address, purchase history, or Reading Journal history to the AI provider.

Training: we use OpenAI’s API. Data submitted through the API is not used to train OpenAI models by default, and we have not opted into a training-data sharing programme.

Provider retention: chat generations are sent with server-side storage disabled. Provider-side conversation state used to keep a chat coherent is deleted when you delete chat history in the App. Reading and horoscope generations may be retained for a limited abuse-monitoring period under the provider’s applicable API data-retention policy.

We do not use the AI provider for advertising, and we do not sell AI inputs or outputs.

7. Who we share data with

We do not sell personal data or share it for cross-context behavioural advertising. We share data only with the service providers and recipients below, as needed to provide the Services or for their own store operations under their published policies.

ProviderRoleDataRegionPolicy
Convex, Inc.Backend, database, and server functionsServer-side App data described above.United StatesConvex Privacy Policy
OpenAI, L.L.C.AI text generationProfile fields, questions, chat messages, cards, and pseudonymous user reference.United StatesOpenAI Privacy Policy
Superwall, Inc.Paywalls, purchase orchestration, and purchase analyticsCommerce user ID, device and App metadata, and purchase events.United StatesSuperwall Privacy Policy
OneSignal, Inc.Push notification deliveryPush token, external ID, device metadata, tarot_premium_active tag, and delivery events.United StatesOneSignal Privacy Policy
Vercel Inc.Website hosting and server-side waitlist functionSubmitted email and ordinary technical request metadata.United States and globalVercel Privacy Policy
TelegramDelivery of beta waitlist notifications to our private bot chatSubmitted email, form source, and submission time.GlobalTelegram Privacy Policy
Apple Inc.App distribution, in-app purchases, receipts, and server notificationsPurchase and subscription events.United States and globalApple Privacy Policy
Google LLCApp distribution, Google Play Billing, and server notificationsPurchase and subscription events.United States and globalGoogle Privacy Policy

We may also disclose data where legally required, to establish or defend legal claims, or as part of a merger or acquisition. Where required, we will notify you, and the recipient will remain subject to applicable privacy obligations.

8. International transfers

Some providers process data in the United States and other countries. If you use the Services from the European Economic Area, the United Kingdom, or Switzerland, your data may be transferred outside your country. Where applicable, we rely on recognised safeguards such as the European Commission’s Standard Contractual Clauses and the UK Addendum, together with providers’ technical and organisational safeguards. You may request more information by emailing gavrulash@icloud.com.

9. How long we keep data

DataRetention
Profile, Crystals balance and ledger, and App identifiersUntil you request deletion or the installation has been inactive for 24 months.
Readings and AI interpretationsUntil you request deletion or the installation has been inactive for 24 months.
Reading Journal entries and notesUntil you delete the entry in the App or request full deletion.
Chat threads and messagesUntil you delete chat history in the App or request full deletion.
Personalised horoscope readingsAutomatically expire and are purged after the period they cover.
Shared non-personal horoscope forecastsAutomatically purged after the period they cover; these contain no user data.
Purchase, subscription, and entitlement recordsFor the life of the entitlement plus the period required by tax and accounting law, typically seven years.
Sanitised commerce webhook audit recordsAutomatically purged; raw webhook bodies are not stored.
Push delivery jobsKept for a short operational window, then purged.
Beta waitlist emailUntil the beta programme ends, you withdraw consent, or you request deletion.
Website security and function logsAccording to Vercel’s applicable operational and security retention periods.
Data stored only on your deviceUntil you delete it in the App or uninstall the App.

10. Your rights

Depending on where you live, you may have the right to access your data, obtain a portable copy, correct or delete it, restrict or object to processing, and withdraw consent at any time. Withdrawal does not affect processing already completed.

How to exercise App-data rights. Because there is no account, we cannot identify App records from your name or email alone. Email gavrulash@icloud.com from the device you use and include the anonymous App identifier available to you, if possible. If you cannot locate it, contact us for instructions. We may need to verify that the request relates to the installation whose data you want to access or delete.

How to leave the beta waitlist. Email gavrulash@icloud.com from the address you submitted and ask us to remove it.

We respond within 30 days, extendable by a further 60 days for complex requests where the law permits and with notice.

EEA and UK: you may lodge a complaint with your local supervisory authority. California: we do not sell or share personal information as those terms are defined, do not use sensitive personal information to infer characteristics, and will not discriminate against you for exercising your rights. Other applicable US state laws: access, correction, deletion, portability, opt-out, and appeal rights apply where required by law. You can make a request using the support email above.

11. Children

Tarot Reading is not directed at children. You must be at least 16 years old, or the age of digital consent in your country if higher, to use the Services. We do not knowingly collect personal data from children below the applicable age. If you believe a child has provided personal data, email gavrulash@icloud.com and we will take appropriate steps to delete it.

12. Push notifications

Push notifications are optional and the App works without them. On iOS, we request system permission only after you turn notifications on; on Android, we request the POST_NOTIFICATIONS permission in the same way. We may send a daily card reminder and product messages related to features you use. You can turn push off in Settings → Notifications inside the App or in your operating-system settings. We attach one tag, tarot_premium_active, to the push profile so Premium and non-Premium users receive the appropriate message.

13. Security

Data is transmitted over TLS and stored on providers’ protected infrastructure. Secrets, including AI provider keys, store credentials, push credentials, Telegram bot token, and webhook secrets, are held as server-side environment variables and are not shipped in the App or website browser bundle. Store webhooks are signature-verified with a short acceptance window, and raw webhook bodies are not persisted. Access to production data is limited to people who need it to operate the Services.

No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant regulator where required by law.

14. Not professional advice

Readings, horoscopes, and AI reader messages are provided for entertainment and personal reflection only. They are not medical, psychological, legal, financial, or safety advice, and they are not predictions of fact. See our Terms of Use for the full disclaimer.

15. Changes to this policy

We may update this policy as the Services or applicable law changes. We will post the updated version here with a new effective date. Material changes will be announced in the App or through another appropriate channel before they take effect where required. If consent is legally required for a new use, we will ask for it.

16. Contact

Havrulash Vladyslav Arcana Readings

gavrulash@icloud.com