Privacy Policy
Tarot CoachTerms of Service
Privacy PolicyThis Privacy Policy explains how Tarot Coach ("we", "us", "our") collects, uses, stores, and shares personal data when you use the Tarot Coach mobile application and related services (the "Service"). By using the Service, you consent to the collection and processing of your personal data as described in this Policy.

All data collected is used solely to provide and improve the entertainment experience. We do not use your data for purposes beyond operating the Service.


Data controller: Tarot Coach. Contact: support@tarotcoach.app.


This Policy is designed to comply with applicable data protection laws in your jurisdiction, including the General Data Protection Regulation (GDPR) where applicable, and other relevant privacy and data protection legislation.
1. Information We CollectData You Provide:

• Account Data: email, password (stored as a hash), profile data you provide (name, date of birth, optional profile photo, optional phone number). • Chat and Messages: message content, timestamps, and attachments you send (including chat with AI coaches). • Tarot Inputs: questions you type, selected spreads/cards, and related context you provide. Questions and context you enter for tarot readings are used solely to generate entertainment content. • Social Features: posts, comments, reactions, and related metadata if social feed features are available to you.


Data Collected Automatically:


• Anonymous Usage: if you use the Service without registration, you may be identified by an app-specific device identifier stored locally. We may store reading history and usage counters tied to that identifier. • Purchase and Subscription Data: subscription status, entitlement state, purchase validation signals, and transaction identifiers required to unlock premium features. • Tokens and Transactions: token balance changes, consumption, and transaction history inside the Service. • Push Notification Data: device push token (for example, Expo push token) if you enable notifications. You can disable notifications in your device settings. • Device and Technical Data: device type, OS version, app version, language, time zone, and approximate usage analytics.
2. How We Use Your DataWe use your data to: operate the Service; create and maintain accounts; provide tarot readings, AI chat responses, and personalized entertainment content; store your history and preferences; manage tokens and entitlements; validate subscriptions and purchases; deliver notifications you enable; facilitate community features; detect fraud, abuse, and security incidents; moderate content and enforce rules; debug issues and improve stability and performance; comply with legal obligations.

We do not sell your personal data.
3. Data MinimizationWe collect only the minimum data necessary to provide the Service. You can use core features of the app with minimal personal data. Registration is optional for basic functionality.
4. Legal Bases for ProcessingWe process your personal data under the following legal bases, as recognized by applicable data protection laws (including GDPR for EEA/UK users):

Consent: by using the Service and accepting this Policy, you consent to the processing of your personal data as described herein. You may withdraw consent at any time (see Section 11). Contract: to provide the Service (account, purchases, tokens, core features). Legitimate Interests: security, fraud prevention, moderation, analytics, and improving reliability. Legal Obligation: where we must retain or disclose information to comply with applicable law.


Your personal data is processed in accordance with the data protection laws applicable in your jurisdiction.
5. AI-Generated Content and Data ProcessingSome content is generated by artificial intelligence. Your prompts (questions), selected context, and certain profile signals (such as date of birth or zodiac-related inputs) may be transmitted to our AI provider to generate responses.

Data sent to AI providers is used only to generate your reading or response. We minimize personal data sent to AI — only the content of your question and necessary context. We do not send direct identifiers (such as your email) to AI providers.


Important: do not include sensitive personal data in prompts (for example: medical records, exact addresses, IDs, payment details). AI output may be inaccurate or incomplete and is provided for entertainment and personal reflection only.
6. Sharing and Third-Party ServicesWe share data with service providers only as needed to operate the Service:

Supabase — authentication, database, file storage, and real-time infrastructure. OpenAI — AI content generation for readings and chat. Expo / React Native tooling — app infrastructure and push delivery. RevenueCat — purchase validation and subscription state management. Apple App Store / Google Play — payment processing and subscription administration.


We may also share data if required by law, to protect users, to enforce policies, or to respond to valid legal requests from courts or government authorities.
7. Subscriptions and PurchasesSubscriptions and in-app purchases are processed by Apple or Google. Your subscription is managed through your Apple ID / Google account. We do not store your payment card details.

We use RevenueCat to validate purchases and subscription entitlements and to keep your premium access in sync across devices. RevenueCat receives only anonymized purchase validation data.


Refunds and billing disputes are handled by Apple/Google under their rules. We cannot directly issue refunds for app store purchases.
8. Data Storage and SecurityWe use reasonable administrative, technical, and organizational safeguards designed to protect your data (HTTPS, access controls, hashed passwords, and security monitoring). No system is 100% secure; you use the Service at your own risk.

If we become aware of a security incident affecting your data, we will take reasonable steps to investigate and, where required, notify affected users and/or authorities.
9. Data RetentionWe keep personal data only for as long as needed to provide the Service and for legitimate business or legal purposes.

Account data: retained while your account is active. Anonymous usage: may be retained for a limited period for product functionality and fraud prevention. Messages and attachments: retained until you delete them (if the Service supports deletion) or until account deletion, subject to legal retention needs.


When you delete your account, we will delete or anonymize associated personal data within a reasonable time, except where retention is required by law or necessary to resolve disputes, enforce agreements, or prevent fraud.
10. Cookies and Local StorageThe mobile app uses local storage to store preferences and session data. The web version (if used) may use cookies for session management. We do not use third-party advertising cookies for behavioral advertising.
11. Your RightsDepending on the data protection laws applicable in your jurisdiction, you may have the following rights:

Access / Portability: request a copy of your personal data. Rectification: correct inaccurate data. Erasure: request deletion of your data. You can delete your account in the app settings. Restriction: request restriction of processing in certain circumstances. Object: object to processing based on legitimate interests. Withdraw Consent: withdraw consent at any time where processing is based on consent. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.


To exercise your rights, contact support@tarotcoach.app. We respond within 30 days.


Right to complain: if you believe your data protection rights have been violated, you have the right to file a complaint with the competent data protection authority in your country of residence.
12. International Data TransfersOur providers may process data in countries other than your country of residence (including the United States). Where applicable, we rely on appropriate safeguards for international transfers (such as contractual protections and vendor security measures).
13. Children's PrivacyThe Service is not intended for children under 16 years old (or the minimum age required by your jurisdiction). We do not knowingly collect personal data from children. If we learn we have collected data from a child under the applicable age, we will delete it promptly. If you believe a child has provided us with personal data, contact support@tarotcoach.app.
14. Changes to This PolicyWe may update this Privacy Policy from time to time. We will post the updated version in the Service and update the "Last updated" date. Material changes may be notified via the app or email where appropriate.
15. ContactContact us at support@tarotcoach.app for privacy questions, requests, or complaints.
Last updated: March 2026
© 2026 Tarot CoachTerms of Service