TAROT AURA Terms of Use

Privacy Policy

Effective date: 28 July 2026 · Last updated: 29 July 2026

This Privacy Policy explains what personal data the Tarot Aura mobile application and the website tarotaura.app (together, the “Service”) collect, why we collect it, who we share it with, how long we keep it, and what rights you have. It applies to all users worldwide.

Read this first

Tarot Aura is an entertainment application for users aged 18 and over. The text of your question is sent to a third-party artificial-intelligence provider (Google) to generate a reading, and a copy of your question and of the generated reading is kept in our service logs for up to 90 days. Please do not enter other people’s names or contact details, health information, financial account data or any other sensitive personal information into your questions. See section 5. Questions you submit and AI processing.

At a glance

1. Who we are

The controller of your personal data is Eva Soft, a trading name of a sole trader established in Poland (“we”, “us”, “our”). Full legal and registration details are available on request.

Contact for any privacy matter, including exercising your rights: support@tarotaura.app. We aim to answer within 30 days.

We process personal data in accordance with the EU General Data Protection Regulation (GDPR), the Polish Personal Data Protection Act of 10 May 2018, and other applicable data-protection laws.

2. Who may use the Service

The Service is intended solely for users who are 18 years of age or older. We do not knowingly collect personal data from anyone under 18. If we learn that we have collected such data, we will delete it. See section 13. Children.

3. What data we collect

3.1 Account data

DataWhen we get it
Anonymous account identifierAlways — an anonymous account is created on first launch
E-mail addressOnly if you sign in with Google
Display name and profile picture URLOnly if you sign in with Google

Signing in with Google is optional and serves to keep your reading history across devices and reinstalls. We receive this data from Google as part of the sign-in flow; we never receive your Google password.

3.2 Content you create

The text of the questions you ask, the cards drawn, the category you choose, the text of the readings generated for you, and their dates. This is stored under your account so that your reading history works.

3.3 Service logs

Each time a reading is generated, our servers record a log entry containing: your account identifier, the timestamp, the type of reading, the AI model used, your subscription tier and whether the tier claimed by the app matched the one verified on the server, the latency, the outcome and any error code, the interface language, the category, the number of tokens processed, and a copy of your question text and of the generated reading text.

These logs exist to prevent fraud and abuse of paid features, to investigate support complaints, and to account for AI-model usage. Retention periods are in section 9.

3.4 Purchase data

If you buy a subscription, we receive from Google Play and RevenueCat the fact and status of your purchase, the product purchased, its expiry and renewal state, and the store country. We never receive your card number, bank details or billing address. Payment is processed by Google Play, which acts as the seller.

3.5 Usage, device and diagnostic data

The text of your questions and readings is not sent to analytics or crash-reporting systems. The data in this section is collected only with your consent — see section 6.

3.6 Data stored only on your device

Your theme and language preferences, local usage counters and a local cache of your reading history are stored on your device and are not transmitted to us. They are removed when you uninstall the app.

3.7 Fonts and configuration

The app downloads fonts from Google Fonts and configuration values from Firebase Remote Config at runtime. As with any network request, this discloses your IP address to the provider.

4. Why we use your data and legal bases

PurposeData usedLegal basis (GDPR Art. 6)
Creating and maintaining your accountAccount dataPerformance of a contract
Generating readings and keeping your historyQuestions, readings, account dataPerformance of a contract
Providing paid features and managing subscriptionsPurchase data, account dataPerformance of a contract
Preventing fraud and abuse of paid featuresService logsLegitimate interests
Investigating support requests and complaintsService logs, account dataLegitimate interests
Keeping the Service secure and stableCrash and diagnostic dataYour consent (collected only if you allow diagnostics)
Understanding how the Service is used and improving itProduct events, technical attributesYour consent (collected only if you allow analytics)
Complying with accounting and legal obligationsPurchase recordsLegal obligation

Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms. You may object to such processing at any time — see 11. Your rights.

5. Questions you submit and AI processing

To generate a reading, the Service sends the text of your question, the cards drawn, the category and your interface language to Google’s Gemini generative-AI service, which processes them on our behalf and returns generated text. Google processes this data as our service provider under its own terms.

Readings are produced automatically by a language model. They are not reviewed by a human before you see them, they are provided for entertainment only, and they may be inaccurate. This processing does not produce legal or similarly significant effects for you within the meaning of GDPR Article 22.

Please do not submit personal data about other people, or sensitive information about yourself — such as health conditions, sexual life, religious or political beliefs, financial account data or government identifiers. You are responsible for what you type into your questions.

6. Analytics and diagnostics

We use two analytics systems: Google Analytics for Firebase, and PostHog, which we host ourselves on infrastructure under our own control. We also use Firebase Crashlytics for crash reporting. These systems receive product events and technical attributes as described in section 3.5.

Analytics and crash reporting are off by default. On first launch the app shows a privacy screen where you can separately allow or decline analytics and diagnostics; nothing is collected until you decide. You can change your decision at any time in Settings → Privacy and data, and it takes effect immediately. Your choice is stored on your device, so after reinstalling the app you will be asked again. You can also write to support@tarotaura.app at any time to have the analytics data already associated with your account deleted.

We do not use analytics data for advertising, and we do not combine it with data from other services to build advertising profiles.

7. Who we share data with

We do not sell personal data, and we do not “share” it for cross-context behavioural advertising as those terms are defined under United States privacy laws. We disclose data only to the service providers listed below, each of which processes it on our instructions and only to the extent needed:

RecipientWhat it receivesPurpose
Google (Firebase Authentication, Firestore, Cloud Functions, Remote Config)Account data, questions, readings, service logsHosting and core app functionality
Google (Gemini)Question text, cards, category, languageGenerating readings
Google (Analytics for Firebase, Crashlytics)Product events, technical attributes, crash reportsAnalytics and diagnostics
Google PlayPurchase and billing dataSelling and processing subscriptions
RevenueCat, Inc.Account identifier, subscription statusManaging subscription entitlements
Cloudflare, Inc.Archived service logs; website trafficStorage and website delivery

We may also disclose data where we are legally required to do so, or where it is necessary to establish, exercise or defend legal claims. If the Service is ever transferred to another owner, data may be transferred with it; we will give notice before that takes effect.

8. International transfers

We are established in Poland, within the European Economic Area. Our service providers may process data in the EEA, the United States and other countries. Where data is transferred outside the EEA, it is protected by an adequacy decision of the European Commission, by the EU Standard Contractual Clauses, or by another lawful transfer mechanism. You may request further information at support@tarotaura.app.

9. How long we keep data

DataRetention period
Account and profile dataUntil you delete your account
Your questions and readings (history)Until you delete them, or until you delete your account
Service logs, including copies of question and reading text90 days, then deleted automatically
Archived copies of service logsUp to 12 months from creation
Usage counters90 days
Analytics dataUp to 14 months
Crash reports90 days
Purchase recordsAs required by Polish accounting and tax law — as a rule, five years from the end of the year in which the tax became payable

10. Security

Data is transmitted over encrypted connections (TLS) and stored on managed infrastructure to which access is restricted. Administrative tools require authentication and are limited to an explicit list of administrators. We keep audit logs of AI-generation requests.

No method of transmission or storage is completely secure. While we take reasonable and appropriate measures, we cannot guarantee absolute security, and you use the Service at your own risk. If a personal-data breach is likely to result in a high risk to your rights, we will notify you and the competent supervisory authority as required by law.

11. Your rights

Depending on where you live, you may have the right to:

To exercise any of these rights, write to support@tarotaura.app from the e-mail address associated with your account, or include your account identifier if you use an anonymous account. We may ask for information needed to verify your identity — this protects you from someone else accessing or deleting your data. We respond within 30 days; where a request is complex we may extend that period and will tell you why.

If you believe we have handled your data unlawfully, you may lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO) in Warsaw, Poland, or with the supervisory authority of your own country of residence in the EEA or the United Kingdom.

12. Deleting your account and data

You can delete individual readings from within the app at any time.

To delete your entire account together with your reading history you can either use Settings → Delete account inside the app, or, if you have already uninstalled it, the web form at tarotaura.app/delete-account. Both paths delete the same data: your account, profile, reading history and usage counters are erased immediately, and service logs are anonymised — your identifier is removed and the question and reading text is erased. Your identifier is removed from analytics within 30 days; backup archives of service logs are deleted on the schedule set out in section 9. Records we must keep by law, such as records of purchases, are retained in anonymised form for the required period and are not used for any other purpose. You can also write to support@tarotaura.app instead.

Deleting your account does not cancel a subscription. Subscriptions are managed by Google Play and must be cancelled there, in the Play Store, under Subscriptions.

13. Children

The Service is not directed to, and may not be used by, anyone under 18. We do not knowingly collect personal data from children. If you believe a minor has provided us with personal data, write to support@tarotaura.app and we will delete it promptly.

14. Changes to this policy

We may update this policy as the Service evolves. The current version is always available at tarotaura.app/privacy with its effective date at the top. If we make a material change, we will give notice in the app or by other reasonable means before it takes effect. Continued use of the Service after a change takes effect means you accept the updated policy.

15. Contact

Questions, requests or complaints about privacy: support@tarotaura.app.