PRIVACY POLICY

1. Privacy at a Glance

General Information

The following notes provide a simple overview of what happens to your personal data when you use our app "Tarot to GO" or visit our website (https://www.tarottogo.app/). Personal data is any data that can be used to personally identify you.

Responsible Party (Data Controller)

Damon BaslerKampstraße 2020357 HamburgGermanyEmail: tarottogo@sezaba.dePhone: +4915156940462Website: https://www.tarottogo.app/

Version and Effective Date

This privacy policy is version 1.2 and is effective as of 6 August 2026. The current version is always available at https://www.tarottogo.app/privacy.


2. Data Processing in the "Tarot to GO" App

a) Anonymous Account Without Registration

Tarot to GO has no login and no sign-up. The first time you open the app, an anonymous user account is created automatically with our backend provider Supabase. This account is identified only by a randomly generated user ID (UUID). We do not ask for an email address, a phone number, or a password, and the user ID is not connected to your name, your email address, or a device identifier unless you enter a name into your profile yourself.

  • Processed Data: Randomly generated user ID (UUID), account creation and last-access timestamps, access tokens for your session.
  • Purpose: Enabling app features that store your content and make it available again after restarting the app.
  • Legal Basis: Art. 6(1)(b) GDPR (Performance of a contract / Provision of app features).

b) Profile Data

You may optionally maintain a profile in the app.

  • Processed Data: The name you enter (free text — a pseudonym or nickname is sufficient), your selected focus ("Clarity", "Daily ritual", "Curiosity" or "Growth"), a profile picture you upload, your daily-reminder setting, your chosen card deck style, and your premium status.
  • Purpose: Personalizing the app and displaying your profile.
  • Legal Basis: Art. 6(1)(b) GDPR (Performance of a contract / Provision of app features).
  • Note: Profile pictures are stored in a non-public storage area that only your own account can access. Every entry in your profile is voluntary; the app is fully usable without a name and without a profile picture.

c) Readings, Journal, Card Collection and Card of the Day

So that your readings remain available after restarting the app, after reinstalling it, and on a new device, this content is not stored solely on your device but is saved to our backend (Supabase) under your anonymous user ID.

  • Processed Data: The topic you selected (love, career, friendship, growth, decision, energy), the drawn cards and their orientation, the free-text notes and journal entries you write yourself, how often you have drawn each card, and the dates on which you opened your card of the day.
  • Purpose: Saving, displaying and synchronizing your readings, your journal and your card collection.
  • Legal Basis: Art. 6(1)(b) GDPR (Performance of a contract / Provision of app features).
  • Note: Access is protected at database level by row-level security, so that this content can only be read and modified by your own account. Please avoid entering particularly sensitive information (for example about your health) into free-text notes.

d) Camera Access and Card Recognition

So that you can photograph a physical tarot spread and have it recognized, the app requires access to your mobile device's camera. Recognition does not take place on your device: the photo is transmitted for this purpose to a service function operated by us (Supabase Edge Function) and from there to the service provider OpenRouter (OpenRouter, Inc., USA), which forwards it to an AI vision model for evaluation. By default this is the model "GPT-4o mini" operated by OpenAI (OpenAI, L.L.C., USA).

  • Processed Data: The photo of your card spread, and the names of the recognized tarot cards returned in response.
  • Purpose: Automatically recognizing the tarot cards visible in the photo.
  • Legal Basis: Art. 6(1)(a) GDPR (Consent, granted by permitting camera access and by deliberately starting the recognition process). You may withdraw this consent at any time with effect for the future by revoking the camera permission in your device settings and no longer using the recognition feature.
  • Storage: We do not store the photo. It is processed only for the duration of the recognition request and is saved neither in our database nor in our storage area. Only the recognized card names become part of your reading. Storage by the aforementioned service providers is governed by their respective terms and privacy policies.
  • International Data Transfer: OpenRouter and OpenAI process data in the USA. The transfer is based on the Standard Contractual Clauses (SCC) of the European Commission.

e) Storage on Your Device

The app stores a small amount of data locally on your device using the "Capacitor Preferences" component.

  • Processed Data: The access token for your anonymous session (so that you are not assigned a new account on every start) and the time you set for your daily reminder.
  • Purpose: Preserving your session and your settings between app starts.
  • Legal Basis: Art. 6(1)(b) GDPR (Performance of a contract / Provision of app features).
  • Note: This data remains on your device and is deleted when you uninstall the app.

f) Daily Reminder (Notifications)

If you activate the daily reminder, the app schedules a notification at the time you choose.

  • Processed Data: The reminder time, and the notification permission you granted in the operating system.
  • Purpose: Reminding you about your card of the day.
  • Legal Basis: Art. 6(1)(a) GDPR (Consent, granted by activating the reminder and permitting notifications). You may withdraw this consent at any time by deactivating the reminder.
  • Note: These are purely local notifications generated by your device itself. We operate no push service, we receive no device token, and no data leaves your device for this purpose.

g) In-App Purchases & Subscriptions (RevenueCat / Apple App Store / Google Play Store)

To manage in-app purchases and subscriptions, we use the service RevenueCat (RevenueCat, Inc., 123 10th Street, San Francisco, CA 94103, USA) alongside the native payment systems of the Apple App Store and Google Play Store.

  • Processed Data: Your anonymous user ID (UUID), which is passed to RevenueCat as the "App User ID", transaction and receipt data, the purchased product, purchase history, subscription and entitlement status, price and currency, and the device and app metadata collected by the RevenueCat SDK. We do not collect or process direct payment information (such as credit card details); these are handled exclusively by Apple or Google.
  • Purpose: Management, verification, and provision of digital content and subscriptions, and making a purchase available across devices and platforms under the same profile.
  • Legal Basis: Art. 6(1)(b) GDPR (Performance of a contract).
  • Synchronization: RevenueCat notifies our backend of changes to your subscription status through an automated interface (webhook), so that your premium status is current in the app. In doing so we briefly store the event ID and your user ID in order to recognize duplicate notifications.
  • International Data Transfer: Data transfer to the USA is based on the Standard Contractual Clauses (SCC) of the European Commission.

h) Over-the-Air Updates (Capgo)

So that improvements to the app can reach you without waiting for an app store review, the app checks for an updated app bundle using the service Capgo (Digital Shift OÜ, Estonia).

  • Processed Data: Technical update metadata such as the app version, the bundle version, the platform, and the IP address transmitted when the request is made.
  • Purpose: Delivering updates and being able to withdraw a faulty update.
  • Legal Basis: Art. 6(1)(f) GDPR (Legitimate interest in a functioning, up-to-date and secure app).

i) Advertising Measurement (Meta App Events)

To measure the effectiveness of our advertising, optimize the delivery of our ads, and understand which campaigns lead to app installs and purchases, we use "Meta App Events", a function of the Facebook SDK provided by Meta Platforms Ireland Ltd. (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland).

  • Processed Data: Standard app events and their parameters — app install, app launch, viewing a card, searching, completing onboarding, starting a purchase, purchase, and subscription — together with the value and currency of a purchase, technical device and app information, and, only if you consent (see below), your device's advertising identifier (on iOS the IDFA).
  • Purpose: Measuring and optimizing advertising, building advertising audiences, and attributing app installs and purchases to advertising campaigns.
  • Legal Basis: Art. 6(1)(a) GDPR (Consent). On iOS we ask for your consent through the operating system's App Tracking Transparency dialog before your advertising identifier is used. If you decline, no advertising identifier is read and Meta receives only aggregated event data.
  • Withdrawal: You may withdraw this consent at any time with effect for the future — on iOS under Settings > Privacy & Security > Tracking, and on Android under Settings > Privacy > Ads. You can additionally limit ad personalization directly in Meta's settings.
  • International Data Transfer: Meta may process data in the USA. The transfer is based on the Standard Contractual Clauses (SCC) of the European Commission and/or the EU-U.S. Data Privacy Framework.

3. Data Collection on the Website (https://www.tarottogo.app/)

Web Hosting via Vercel

Our website is hosted by Vercel Inc. (440 N Barranca Avenue #4133, Covina, CA 91723, USA). When you visit our website, Vercel automatically collects server log files (e.g., IP address, requested files, browser type, timestamp of access).

  • Purpose: Ensuring technical stability, performance, and security of the website.
  • Legal Basis: Art. 6(1)(f) GDPR (Legitimate interest in providing a secure online offering).
  • International Data Transfer: Vercel processes data in compliance with EU Standard Contractual Clauses (SCC) and/or the EU-U.S. Data Privacy Framework.

No Consent-Requiring Cookies; Vercel Web Analytics

Our website does not set cookies that require consent and does not use advertising, marketing or social-media trackers. We use Vercel Web Analytics to measure use of our website in aggregate and improve our offering. Vercel Web Analytics does not use cookies and does not store a persistent visitor identifier in the browser. Therefore, no cookie banner is required for this service.

  • Processed Data: Timestamp and requested URL or route, referring website, filtered URL parameters, approximate geographic information, browser, operating system, device type and analytics script version. Vercel derives a daily visitor identifier from technical request data; the hash used for this purpose is discarded after 24 hours and does not allow recognition across different days or websites. We do not intentionally send names, email addresses or other direct identifiers to Vercel Web Analytics.
  • Purpose: Aggregate audience measurement, identifying frequently used content, and improving the website technically and editorially.
  • Legal Basis: Art. 6(1)(f) GDPR (Legitimate interest in privacy-preserving performance measurement and improvement of our online offering).
  • Retention: Analytics data is stored in accordance with our Vercel plan and contractual settings and is then deleted or aggregated.

Further information: https://vercel.com/docs/analytics/privacy-policy

Fonts

The font used on the website is delivered from our own server. No connection to Google servers is established when you visit the site, and no data is transmitted to Google in this context.


4. What We Do Not Collect

To state it explicitly, we do not process the following:

  • No advertising IDs and no cross-app tracking unless you have given your explicit consent for advertising measurement (see section 2 i); if you do not consent, no advertising ID is used.
  • No analytics or attribution services in the app or on the website beyond the purposes described above.
  • No location data, no contacts, no calendar, and no access to your photo library beyond the photo you deliberately take or select for card recognition.
  • No email addresses, no phone numbers, and no passwords — the app has no registration.
  • No sale of personal data to third parties.

5. Recipients and International Transfers

Personal data is passed only to the following processors and service providers:

  • Supabase (Supabase, Inc., USA) — backend: anonymous authentication, database, storage.
  • RevenueCat (RevenueCat, Inc., USA) — subscription and entitlement management.
  • Apple (Apple Inc. / Apple Distribution International Ltd.) and Google (Google LLC / Google Ireland Ltd.) — processing of payment for in-app purchases.
  • OpenRouter (OpenRouter, Inc., USA) and the AI model provider used, by default OpenAI (OpenAI, L.L.C., USA) — card recognition from your photo.
  • Capgo (Digital Shift OÜ, Estonia) — delivery of app updates.
  • Vercel (Vercel Inc., USA) — hosting of the website and Vercel Web Analytics.
  • Meta (Meta Platforms Ireland Ltd., Ireland; may also process data via Meta Platforms, Inc., USA) — measurement and optimization of advertising (app events), only with your consent.

Where these providers process data outside the European Economic Area, the transfer is based on the Standard Contractual Clauses (SCC) of the European Commission and/or the EU-U.S. Data Privacy Framework.


6. Retention Periods and Deletion

Retention

We store the data described above for as long as your account exists, because it is the content of the app itself — your journal, your collection, your profile. We deliberately set no automatic expiry, so that your journal does not disappear unexpectedly. Technical log data is deleted or anonymized by the respective provider after a short period. Records of processed subscription notifications are kept only for as long as is necessary to detect duplicate messages.

Deleting Your Account

You can permanently delete your account and all associated data yourself at any time in the app under Settings via "Delete profile". This process deletes:

  • your customer record at RevenueCat, including the purchase history stored there;
  • your profile picture in our storage area;
  • the records of processed subscription notifications relating to you;
  • your user account, and with it your profile, all readings and notes, your card collection, and your card-of-the-day history.

Alternatively, you may contact us using the details given in the imprint.

Important: Deletion Does Not Cancel Your Subscription

Deleting your Tarot to GO account does not cancel an active subscription concluded through the Apple App Store or Google Play Store, and does not trigger a refund. Only the respective store can do that. Please cancel your subscription before deleting your account, in the subscription settings of your Apple Account or your Google Play account.


7. Your Rights

You have the right at any time to:

  • Request information about your stored data (Art. 15 GDPR).
  • Request the correction of incorrect data (Art. 16 GDPR).
  • Request the erasure of your data (Art. 17 GDPR).
  • Request restriction of data processing (Art. 18 GDPR).
  • Request data portability (Art. 20 GDPR).
  • Object to processing (Art. 21 GDPR).
  • Withdraw consent you have given, at any time with effect for the future (Art. 7(3) GDPR).

To exercise these rights, you may contact us at any time at the address specified in the Imprint. You also have the right to lodge a complaint with the competent data protection supervisory authority (Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit).

Please note: Because the app deliberately holds no login and no personal identifiers, we are generally unable to assign an enquiry to a specific account without further information. To exercise your rights, please provide us with your user ID, which you can find in the app under Settings.


8. Children

Tarot to GO is not directed at children. The app is intended for persons aged 16 and over. We do not knowingly collect data from children under 16. If you become aware that a child has provided us with data, please contact us — we will delete it.


9. Changes to This Privacy Policy

We will amend this privacy policy whenever changes to the app or to the legal situation make it necessary. The current version, together with its version number and effective date, is always available at https://www.tarottogo.app/privacy. In the event of material changes we will additionally point them out in the app.


10. Further Information