TAROT AURA
Terms of Use
This Privacy Policy explains what personal data the Tarot Aura mobile application and the website tarotaura.app (together, the “Service”) collect, why we collect it, who we share it with, how long we keep it, and what rights you have. It applies to all users worldwide.
Tarot Aura is an entertainment application for users aged 18 and over. The text of your question is sent to a third-party artificial-intelligence provider (Google) to generate a reading, and a copy of your question and of the generated reading is kept in our service logs for up to 90 days. Please do not enter other people’s names or contact details, health information, financial account data or any other sensitive personal information into your questions. See section 5. Questions you submit and AI processing.
The controller of your personal data is Eva Soft, a trading name of a sole trader established in Poland (“we”, “us”, “our”). Full legal and registration details are available on request.
Contact for any privacy matter, including exercising your rights: support@tarotaura.app. We aim to answer within 30 days.
We process personal data in accordance with the EU General Data Protection Regulation (GDPR), the Polish Personal Data Protection Act of 10 May 2018, and other applicable data-protection laws.
The Service is intended solely for users who are 18 years of age or older. We do not knowingly collect personal data from anyone under 18. If we learn that we have collected such data, we will delete it. See section 13. Children.
| Data | When we get it |
|---|---|
| Anonymous account identifier | Always — an anonymous account is created on first launch |
| E-mail address | Only if you sign in with Google |
| Display name and profile picture URL | Only if you sign in with Google |
Signing in with Google is optional and serves to keep your reading history across devices and reinstalls. We receive this data from Google as part of the sign-in flow; we never receive your Google password.
The text of the questions you ask, the cards drawn, the category you choose, the text of the readings generated for you, and their dates. This is stored under your account so that your reading history works.
Each time a reading is generated, our servers record a log entry containing: your account identifier, the timestamp, the type of reading, the AI model used, your subscription tier and whether the tier claimed by the app matched the one verified on the server, the latency, the outcome and any error code, the interface language, the category, the number of tokens processed, and a copy of your question text and of the generated reading text.
These logs exist to prevent fraud and abuse of paid features, to investigate support complaints, and to account for AI-model usage. Retention periods are in section 9.
If you buy a subscription, we receive from Google Play and RevenueCat the fact and status of your purchase, the product purchased, its expiry and renewal state, and the store country. We never receive your card number, bank details or billing address. Payment is processed by Google Play, which acts as the seller.
The text of your questions and readings is not sent to analytics or crash-reporting systems. The data in this section is collected only with your consent — see section 6.
Your theme and language preferences, local usage counters and a local cache of your reading history are stored on your device and are not transmitted to us. They are removed when you uninstall the app.
The app downloads fonts from Google Fonts and configuration values from Firebase Remote Config at runtime. As with any network request, this discloses your IP address to the provider.
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Creating and maintaining your account | Account data | Performance of a contract |
| Generating readings and keeping your history | Questions, readings, account data | Performance of a contract |
| Providing paid features and managing subscriptions | Purchase data, account data | Performance of a contract |
| Preventing fraud and abuse of paid features | Service logs | Legitimate interests |
| Investigating support requests and complaints | Service logs, account data | Legitimate interests |
| Keeping the Service secure and stable | Crash and diagnostic data | Your consent (collected only if you allow diagnostics) |
| Understanding how the Service is used and improving it | Product events, technical attributes | Your consent (collected only if you allow analytics) |
| Complying with accounting and legal obligations | Purchase records | Legal obligation |
Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms. You may object to such processing at any time — see 11. Your rights.
To generate a reading, the Service sends the text of your question, the cards drawn, the category and your interface language to Google’s Gemini generative-AI service, which processes them on our behalf and returns generated text. Google processes this data as our service provider under its own terms.
Readings are produced automatically by a language model. They are not reviewed by a human before you see them, they are provided for entertainment only, and they may be inaccurate. This processing does not produce legal or similarly significant effects for you within the meaning of GDPR Article 22.
Please do not submit personal data about other people, or sensitive information about yourself — such as health conditions, sexual life, religious or political beliefs, financial account data or government identifiers. You are responsible for what you type into your questions.
We use two analytics systems: Google Analytics for Firebase, and PostHog, which we host ourselves on infrastructure under our own control. We also use Firebase Crashlytics for crash reporting. These systems receive product events and technical attributes as described in section 3.5.
Analytics and crash reporting are off by default. On first launch the app shows a privacy screen where you can separately allow or decline analytics and diagnostics; nothing is collected until you decide. You can change your decision at any time in Settings → Privacy and data, and it takes effect immediately. Your choice is stored on your device, so after reinstalling the app you will be asked again. You can also write to support@tarotaura.app at any time to have the analytics data already associated with your account deleted.
We do not use analytics data for advertising, and we do not combine it with data from other services to build advertising profiles.
We do not sell personal data, and we do not “share” it for cross-context behavioural advertising as those terms are defined under United States privacy laws. We disclose data only to the service providers listed below, each of which processes it on our instructions and only to the extent needed:
| Recipient | What it receives | Purpose |
|---|---|---|
| Google (Firebase Authentication, Firestore, Cloud Functions, Remote Config) | Account data, questions, readings, service logs | Hosting and core app functionality |
| Google (Gemini) | Question text, cards, category, language | Generating readings |
| Google (Analytics for Firebase, Crashlytics) | Product events, technical attributes, crash reports | Analytics and diagnostics |
| Google Play | Purchase and billing data | Selling and processing subscriptions |
| RevenueCat, Inc. | Account identifier, subscription status | Managing subscription entitlements |
| Cloudflare, Inc. | Archived service logs; website traffic | Storage and website delivery |
We may also disclose data where we are legally required to do so, or where it is necessary to establish, exercise or defend legal claims. If the Service is ever transferred to another owner, data may be transferred with it; we will give notice before that takes effect.
We are established in Poland, within the European Economic Area. Our service providers may process data in the EEA, the United States and other countries. Where data is transferred outside the EEA, it is protected by an adequacy decision of the European Commission, by the EU Standard Contractual Clauses, or by another lawful transfer mechanism. You may request further information at support@tarotaura.app.
| Data | Retention period |
|---|---|
| Account and profile data | Until you delete your account |
| Your questions and readings (history) | Until you delete them, or until you delete your account |
| Service logs, including copies of question and reading text | 90 days, then deleted automatically |
| Archived copies of service logs | Up to 12 months from creation |
| Usage counters | 90 days |
| Analytics data | Up to 14 months |
| Crash reports | 90 days |
| Purchase records | As required by Polish accounting and tax law — as a rule, five years from the end of the year in which the tax became payable |
Data is transmitted over encrypted connections (TLS) and stored on managed infrastructure to which access is restricted. Administrative tools require authentication and are limited to an explicit list of administrators. We keep audit logs of AI-generation requests.
No method of transmission or storage is completely secure. While we take reasonable and appropriate measures, we cannot guarantee absolute security, and you use the Service at your own risk. If a personal-data breach is likely to result in a high risk to your rights, we will notify you and the competent supervisory authority as required by law.
Depending on where you live, you may have the right to:
To exercise any of these rights, write to support@tarotaura.app from the e-mail address associated with your account, or include your account identifier if you use an anonymous account. We may ask for information needed to verify your identity — this protects you from someone else accessing or deleting your data. We respond within 30 days; where a request is complex we may extend that period and will tell you why.
If you believe we have handled your data unlawfully, you may lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO) in Warsaw, Poland, or with the supervisory authority of your own country of residence in the EEA or the United Kingdom.
You can delete individual readings from within the app at any time.
To delete your entire account together with your reading history you can either use Settings → Delete account inside the app, or, if you have already uninstalled it, the web form at tarotaura.app/delete-account. Both paths delete the same data: your account, profile, reading history and usage counters are erased immediately, and service logs are anonymised — your identifier is removed and the question and reading text is erased. Your identifier is removed from analytics within 30 days; backup archives of service logs are deleted on the schedule set out in section 9. Records we must keep by law, such as records of purchases, are retained in anonymised form for the required period and are not used for any other purpose. You can also write to support@tarotaura.app instead.
Deleting your account does not cancel a subscription. Subscriptions are managed by Google Play and must be cancelled there, in the Play Store, under Subscriptions.
The Service is not directed to, and may not be used by, anyone under 18. We do not knowingly collect personal data from children. If you believe a minor has provided us with personal data, write to support@tarotaura.app and we will delete it promptly.
We may update this policy as the Service evolves. The current version is always available at tarotaura.app/privacy with its effective date at the top. If we make a material change, we will give notice in the app or by other reasonable means before it takes effect. Continued use of the Service after a change takes effect means you accept the updated policy.
Questions, requests or complaints about privacy: support@tarotaura.app.