Privacy Policy
Last updated: August 2, 2026
TarotPro limits collection to data used to run readings, protect the service, support optional accounts, and measure product reliability.
Operator and privacy contact
TarotPro is an independently operated online service. The independent operator is the controller of the personal data described in this Privacy Policy. Privacy requests can be sent to [email protected]. The governing law is stated in the Terms.
Reading requests and generated results
A reading request can contain the spread, intent, source page, random seed, selected card indices, a request ID, and an optional question. The Worker validates those fields, resolves identity and access, checks quota/verification eligibility, and rejects supported high-risk categories before reserving a successful reading quota. When AI is enabled, it sends an eligible question and fixed card context to the configured AI provider to prepare the result. Do not enter names, contact details, account numbers, health records, or other sensitive personal information.
The application does not write an anonymous reading to the long-term readings table. The exact cards, generated summary,
advice, and provider metadata may be held only to finish and safely replay the same request: in a request-specific Cloudflare Durable
Object until database finalization succeeds, and in the quota claim response cache for no more than 10 minutes. Both copies are
automatically cleared. Generated text can indirectly reflect the substance of a question and is treated as user content during that
short window. A configured AI provider processes the request under that provider's own terms and data practices.
Cookies and browser storage
The API sets a signed, pseudonymous tarotpro_visitor cookie to apply quotas and bind retries. In production it is HttpOnly, Secure,
SameSite=Lax, scoped to the site, and configured for a one-year maximum age. JavaScript cannot read this cookie. Clearing it does not
remove server records already created.
TarotPro does not store questions or reading results in custom local storage. If you sign in for a protected spread, a short-lived question and mode draft may be kept in session storage solely to restore that spread after the authentication redirect. TarotPro accepts it for no more than 15 minutes, consumes it on return, deletes invalid or expired data when next checked, and does not share it across browser sessions. The Supabase authentication client persists and refreshes the browser session in browser storage. The Worker validates the bearer token, uses the resolved user ID for access and quota accounting, and does not send the token, account ID, or email address to the AI provider.
Login is enabled only for Three Card, Love, and three-card Yes/No access. Saved readings, account deletion, and email follow-up remain disabled; their existing dormant screens or code are not authorization to activate them without a separately reviewed lifecycle.
Abuse prevention and Turnstile
Cloudflare necessarily receives network request data while serving the site. The Worker converts the connecting IP address into a secret-keyed, UTC-day-specific hash for daily and per-minute abuse controls; application code does not persist the full IP address. Higher-risk requests may receive a Cloudflare Turnstile challenge. Only then does the Worker send the Turnstile token and connecting IP to Cloudflare's verification service. Hashes are pseudonymous security data, not anonymous data.
Analytics
Google Analytics 4 and Cloudflare Web Analytics load only in a production build with a syntactically valid configured identifier. Product events use an allowlist of coarse fields such as tool, spread, intent, card count, source route, viewport class, quota remaining, and offer ID. The analytics client rejects free text, raw questions, email, cookie values, visitor or IP hashes, complete URLs, and other unapproved fields. The analytics providers may process ordinary browser and connection data under their own policies.
Accounts and email
Account sign-in uses whichever production method is configured, such as Google or an email one-time code. Guest one-card readings do not require an account or email address. Saved readings and email follow-up are disabled and require a separate reviewed release before their related data is collected.
Affiliate links
Sponsored links are absent when no approved destination is configured. If enabled, the redirect service records an opaque click ID, offer ID, destination host, request trace ID, and time. It does not store the tarot question, full destination URL, raw IP address, raw user agent, cookie value, or full referrer query as affiliate-click data. If an optional CTA cannot be prepared, the reading still succeeds without it; the redirect remains unavailable unless its destination passes the server allowlist.
Server logs, access, and retention
Structured application logs contain a trace ID, event category, route or fixed product context, and error category. Logging code excludes raw questions, prompts, model output, email, IP addresses, cookies, bearer tokens, and secrets. Database access is restricted to the server service role, except that authenticated users may access only their own saved readings under row-level security.
The database cleanup runs every five minutes in bounded batches. It clears complete replay results after 10 minutes, expires result-free claim metadata after 24 hours, removes minute-level IP admission data after 48 hours, removes visitor/IP daily quota detail and identity links after 7 days, and keeps content-free daily AI budget totals for 90 days. Claim expiry releases visitor and IP reservations; a provider attempt already made remains counted in the aggregate AI budget.
Cloudflare log retention is configured outside this repository. The launch target is the shortest period that supports incident investigation and no more than 14 days, but that external setting must be verified before launch; this policy does not claim that an unverified account setting is already active.