Legal
Privacy Policy
How Arcana Readings collects, uses, stores, and protects data across the Tarot Reading app and beta website.
- App
- Tarot Reading
- Effective
- August 1, 2026
- iOS
- com.havrylash.tarot
- Android
- com.havrylash.tarot
1. Summary
This Privacy Policy explains how Havrulash Vladyslav, operating under the Arcana Readings brand, handles personal data when you use the Tarot Reading mobile application (the “App”), the Arcana Readings website at app.arcanareadings.com, and the beta waitlist (together, the “Services”).
- The App does not require an account. There is no sign-up, password, or social login.
- The website collects your email address only if you choose to join the beta waitlist.
- We do not sell your personal data, and we do not use it for cross-app or cross-site advertising tracking.
- We do not run advertising SDKs and we do not collect the Advertising Identifier (IDFA or GAID).
- Your identity in the App is a random identifier generated on your device the first time you open the App.
- The profile details you enter and the questions you ask are sent to our AI provider, OpenAI, so the App can generate a personalised reading. They are not used to train AI models by default through the API.
2. Who we are
Havrulash Vladyslav, operating Arcana Readings (“we”, “us”), is the controller of the personal data described in this policy.
For any privacy question, request, or complaint, email gavrulash@icloud.com.
3. How you are identified in the App
When you first launch the App, it generates two random identifiers on your device and stores them in the App’s local storage:
| Identifier | Format | Purpose |
|---|---|---|
| Anonymous app ID | guest_<random UUID> | Links your readings, journal, Crystals balance, and profile to one App installation on our backend. |
| Commerce and messaging ID | Random UUID v4 | Used as the user ID for our paywall provider, Superwall, and as the external ID for our push provider, OneSignal, so purchases and notifications reach the correct installation. |
These identifiers are created by the App, not read from your device. They are not the IDFA, Android Advertising ID, phone number, or a hardware serial number. They are not linked to your real-world identity unless you enter identifying information yourself, such as your real name.
Because there is no account, these identifiers live only on the device where they were created. If you delete and reinstall the App, a new identifier is generated and your previous readings, journal entries, and Crystals balance are no longer reachable from the new installation.
4. What data we collect
4.1 Data you provide directly in the App
| Data | Where you provide it | Required? |
|---|---|---|
| First name or nickname | Onboarding, My Profile | Optional — you may skip it or use any name. |
| Date of birth | Onboarding, My Profile | Used to derive your zodiac sign and personalise readings. |
| Gender | Onboarding, My Profile | Optional. |
| Relationship status | Onboarding, My Profile | Optional. |
| Occupation category | Onboarding, My Profile | Optional. |
| Preferred reading language | Onboarding, My Profile | Defaults to English. |
| Your question for a spread | Tarot Reading flow | Optional. |
| Your messages to an AI tarot reader | Ask a Tarot Reader chat | Only if you use chat. |
| Notes added to a saved reading | Reading Journal | Optional. |
Please do not enter special-category information, such as health conditions, sexual life, religious or political beliefs, criminal history, or the personal data of other identifiable people into free-text fields. If you do, you are asking us and our AI provider to process it to respond to you.
4.2 Data generated by your use of the App
| Data | Detail |
|---|---|
| Reading records | Topic, spread, drawn cards and orientation, position meanings, AI-generated interpretation, timestamps, prompt version, and model name. |
| Daily card and Yes-or-No records | Card drawn, orientation, day key, and device time zone. |
| Horoscope records | Zodiac sign, period, profile snapshot used, and AI-generated text. |
| Reading Journal | Saved readings and your notes. |
| Chat records | Thread status, your and the reader’s message text, turn count, token counts, and timestamps. |
| Crystals ledger | Balance and every credit or debit with a reason code, including daily reward, AI reading, AI chat, purchase, refund, or adjustment. |
| Daily reward streak | Last claim date and streak day. |
| Notification preference | Whether push is enabled and the push subscription state. |
| Device time zone | IANA time zone name, such as Europe/Kyiv, used so the daily card and reminder follow your local day. |
4.3 Purchase data
Purchases are made through the Apple App Store and Google Play. We never receive your payment card, bank details, or billing address — those remain with Apple and Google. Through our paywall provider and store server notifications, we receive:
- Store transaction ID and original transaction ID, product ID, store, and production or sandbox environment.
- Purchase, renewal, cancellation, billing-issue, refund, and expiration events with timestamps.
- Current subscription status and expiry, and an opaque server-derived entitlement key used to restore Premium on a new installation without copying other App data.
4.4 Data collected by service-provider SDKs
The SDKs embedded in the App collect limited technical data on our behalf:
- Superwall for paywalls, purchase orchestration, and paywall analytics: App version, OS version, device model and locale, vendor device identifier, paywall impressions and interactions, and purchase and restore events.
- OneSignal for push notifications: the push token issued by Apple or Google, OneSignal device ID, device model, OS version, App version, language, notification delivery and open events, and, depending on settings, a country derived from the request IP address. Location tracking is disabled in the App build configuration.
- Convex for our backend: standard server request metadata, including IP address and user agent, used to operate and secure the service.
We do not embed advertising, attribution, or cross-app tracking SDKs.
4.5 Website and beta waitlist data
If you voluntarily join the beta waitlist, we collect the email address you submit, the form location used to submit it, and the submission time. The website sends this information through a server-side Vercel Function to our private Telegram bot chat so we can manage beta invitations and product updates.
Vercel may process ordinary technical request data, such as IP address, user agent, request time, and security logs, to host and protect the website and its server function. We do not use the waitlist email for unrelated advertising and do not place the Telegram bot token in the browser.
4.6 Data stored only on your device
The onboarding completion flag, animation preference, favourite spreads, pending-reading state, cached chat, and, for free users, a local reading journal of up to five entries are stored in local App storage and removed when you uninstall the App.
4.7 Data we do not collect
The App does not collect an email address for an account. Across the Services, we do not intentionally collect phone numbers, postal addresses, contacts, photos, camera or microphone data, precise or coarse GPS location, health data, browsing history, biometric data, or advertising identifiers. The website collects an email address only when you submit the beta waitlist form.
5. Why we use your data and our legal bases
| Purpose | Data used | Legal basis under GDPR Article 6 |
|---|---|---|
| Provide readings, horoscopes, chat, journal, and daily card | Profile, questions, drawn cards, chat messages, and identifiers | Performance of a contract, Article 6(1)(b). |
| Personalise reading text to your profile | Name, date of birth, gender, relationship status, occupation, and language | Performance of a contract, Article 6(1)(b). |
| Operate the Crystals economy, daily rewards, and Premium entitlements | Ledger, purchase and subscription data, and identifiers | Performance of a contract, Article 6(1)(b). |
| Deliver and schedule push notifications you enabled | Push token, external ID, time zone, and Premium flag | Consent, Article 6(1)(a), which you can withdraw at any time. |
| Manage the voluntary beta waitlist and send beta updates | Email address, form source, and submission time | Consent, Article 6(1)(a), which you can withdraw at any time. |
| Prevent abuse of rewards, restores, purchases, and website forms | Entitlement key, ledger, transaction IDs, and request metadata | Legitimate interests, Article 6(1)(f). |
| Diagnose failures and keep the Services reliable | Error messages, HTTP statuses, provider response IDs, and request metadata | Legitimate interests, Article 6(1)(f). |
| Comply with tax, accounting, and legal obligations | Purchase records | Legal obligation, Article 6(1)(c). |
We do not use your data for profiling with legal or similarly significant effects, and we do not make automated decisions about you in that sense. AI-generated readings are entertainment content, not decisions about you.
6. AI processing
Readings, horoscope personalisation, and tarot-reader chat are generated by OpenAI models called from our backend. We send:
- Your profile fields, including name, date of birth, gender, relationship status, occupation, and preferred language.
- The spread, drawn cards, and their positions.
- Your typed question or chat message.
- A pseudonymous user reference used for abuse monitoring and request correlation.
We do not send your push token, device identifiers, IP address, purchase history, or Reading Journal history to the AI provider.
Training: we use OpenAI’s API. Data submitted through the API is not used to train OpenAI models by default, and we have not opted into a training-data sharing programme.
Provider retention: chat generations are sent with server-side storage disabled. Provider-side conversation state used to keep a chat coherent is deleted when you delete chat history in the App. Reading and horoscope generations may be retained for a limited abuse-monitoring period under the provider’s applicable API data-retention policy.
We do not use the AI provider for advertising, and we do not sell AI inputs or outputs.
7. Who we share data with
We do not sell personal data or share it for cross-context behavioural advertising. We share data only with the service providers and recipients below, as needed to provide the Services or for their own store operations under their published policies.
| Provider | Role | Data | Region | Policy |
|---|---|---|---|---|
| Convex, Inc. | Backend, database, and server functions | Server-side App data described above. | United States | Convex Privacy Policy |
| OpenAI, L.L.C. | AI text generation | Profile fields, questions, chat messages, cards, and pseudonymous user reference. | United States | OpenAI Privacy Policy |
| Superwall, Inc. | Paywalls, purchase orchestration, and purchase analytics | Commerce user ID, device and App metadata, and purchase events. | United States | Superwall Privacy Policy |
| OneSignal, Inc. | Push notification delivery | Push token, external ID, device metadata, tarot_premium_active tag, and delivery events. | United States | OneSignal Privacy Policy |
| Vercel Inc. | Website hosting and server-side waitlist function | Submitted email and ordinary technical request metadata. | United States and global | Vercel Privacy Policy |
| Telegram | Delivery of beta waitlist notifications to our private bot chat | Submitted email, form source, and submission time. | Global | Telegram Privacy Policy |
| Apple Inc. | App distribution, in-app purchases, receipts, and server notifications | Purchase and subscription events. | United States and global | Apple Privacy Policy |
| Google LLC | App distribution, Google Play Billing, and server notifications | Purchase and subscription events. | United States and global | Google Privacy Policy |
We may also disclose data where legally required, to establish or defend legal claims, or as part of a merger or acquisition. Where required, we will notify you, and the recipient will remain subject to applicable privacy obligations.
8. International transfers
Some providers process data in the United States and other countries. If you use the Services from the European Economic Area, the United Kingdom, or Switzerland, your data may be transferred outside your country. Where applicable, we rely on recognised safeguards such as the European Commission’s Standard Contractual Clauses and the UK Addendum, together with providers’ technical and organisational safeguards. You may request more information by emailing gavrulash@icloud.com.
9. How long we keep data
| Data | Retention |
|---|---|
| Profile, Crystals balance and ledger, and App identifiers | Until you request deletion or the installation has been inactive for 24 months. |
| Readings and AI interpretations | Until you request deletion or the installation has been inactive for 24 months. |
| Reading Journal entries and notes | Until you delete the entry in the App or request full deletion. |
| Chat threads and messages | Until you delete chat history in the App or request full deletion. |
| Personalised horoscope readings | Automatically expire and are purged after the period they cover. |
| Shared non-personal horoscope forecasts | Automatically purged after the period they cover; these contain no user data. |
| Purchase, subscription, and entitlement records | For the life of the entitlement plus the period required by tax and accounting law, typically seven years. |
| Sanitised commerce webhook audit records | Automatically purged; raw webhook bodies are not stored. |
| Push delivery jobs | Kept for a short operational window, then purged. |
| Beta waitlist email | Until the beta programme ends, you withdraw consent, or you request deletion. |
| Website security and function logs | According to Vercel’s applicable operational and security retention periods. |
| Data stored only on your device | Until you delete it in the App or uninstall the App. |
10. Your rights
Depending on where you live, you may have the right to access your data, obtain a portable copy, correct or delete it, restrict or object to processing, and withdraw consent at any time. Withdrawal does not affect processing already completed.
How to exercise App-data rights. Because there is no account, we cannot identify App records from your name or email alone. Email gavrulash@icloud.com from the device you use and include the anonymous App identifier available to you, if possible. If you cannot locate it, contact us for instructions. We may need to verify that the request relates to the installation whose data you want to access or delete.
How to leave the beta waitlist. Email gavrulash@icloud.com from the address you submitted and ask us to remove it.
We respond within 30 days, extendable by a further 60 days for complex requests where the law permits and with notice.
EEA and UK: you may lodge a complaint with your local supervisory authority. California: we do not sell or share personal information as those terms are defined, do not use sensitive personal information to infer characteristics, and will not discriminate against you for exercising your rights. Other applicable US state laws: access, correction, deletion, portability, opt-out, and appeal rights apply where required by law. You can make a request using the support email above.
11. Children
Tarot Reading is not directed at children. You must be at least 16 years old, or the age of digital consent in your country if higher, to use the Services. We do not knowingly collect personal data from children below the applicable age. If you believe a child has provided personal data, email gavrulash@icloud.com and we will take appropriate steps to delete it.
12. Push notifications
Push notifications are optional and the App works without them. On iOS, we request system permission only after you turn notifications on; on Android, we request the POST_NOTIFICATIONS permission in the same way. We may send a daily card reminder and product messages related to features you use. You can turn push off in Settings → Notifications inside the App or in your operating-system settings. We attach one tag, tarot_premium_active, to the push profile so Premium and non-Premium users receive the appropriate message.
13. Security
Data is transmitted over TLS and stored on providers’ protected infrastructure. Secrets, including AI provider keys, store credentials, push credentials, Telegram bot token, and webhook secrets, are held as server-side environment variables and are not shipped in the App or website browser bundle. Store webhooks are signature-verified with a short acceptance window, and raw webhook bodies are not persisted. Access to production data is limited to people who need it to operate the Services.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant regulator where required by law.
14. Not professional advice
Readings, horoscopes, and AI reader messages are provided for entertainment and personal reflection only. They are not medical, psychological, legal, financial, or safety advice, and they are not predictions of fact. See our Terms of Use for the full disclaimer.
15. Changes to this policy
We may update this policy as the Services or applicable law changes. We will post the updated version here with a new effective date. Material changes will be announced in the App or through another appropriate channel before they take effect where required. If consent is legally required for a new use, we will ask for it.
16. Contact
Havrulash Vladyslav Arcana Readings