1. Who controls your data
The controller is [PLACEHOLDER: legal name], with an address at [PLACEHOLDER: legal address]. Privacy questions and requests can be sent to [PLACEHOLDER: privacy mailbox]@tarotjournalapp.com.
Tarot Journal has no user accounts. That limits what we can identify about you and means most journal data is controlled directly on your iPhone.
2. What the app keeps on your device
The app stores readings locally using Apple’s on-device data frameworks. A saved reading can include its date, question, spread, language, topic, drawn cards and orientations, generated meanings and synthesis, reflection questions, premium continuity and advice, your journal note, a selected reflection question, reminder dates, your follow-up note and completion date.
The app also stores daily cards and reveal state, the generated daily sentence, collection reveal state, locally calculated portrait statistics, cached generated portrait text, and preferences such as your greeting name, language, grammatical-form preference, reversed-card setting, reminder time, onboarding state and notification choices.
A randomly generated device identifier is stored in Keychain and mirrored in app preferences. It is used for rate limits and purchase-related services. Because Keychain items can survive deletion and reinstall, deleting the app may not remove this identifier.
Current code does not sync the journal with iCloud or another journal database. Local daily and follow-up notifications are scheduled through iOS; there is no remote push-notification server in the reviewed implementation.
3. What leaves the device
| Feature | Sent to the Cloudflare proxy | Forwarded to the AI provider |
|---|---|---|
| Reading | Device identifier, local date, premium status, question, 1–3 card names, positions and orientations, short/full depth, language, optional grammatical gender, and for a full premium reading up to three recent question themes. | Question, cards, response language, grammatical gender when set, and recent themes when used. The device identifier, local date and premium flag are not put into the provider prompt. |
| Daily card sentence | Device identifier, language, local date, premium status and, for premium only, up to three recent question themes. | The deterministic card name, language, free/premium tier and premium recent themes. The device identifier and date are not put into the provider prompt. |
| Generated period portrait | A request identifier, device identifier, local date, premium status, language, optional grammatical gender, the 7- or 30-day period, counts and aggregates for the current and previous periods, and bounded evidence from readings: dates, questions, topics, cards, journal notes and follow-up notes. Up to 24 current-period and 12 previous-period entries are accepted; question text is limited to 300 characters and combined note plus follow-up text to 800 characters per entry. | Language, grammatical gender when set, period dates, aggregates, derived card summaries and the bounded evidence. The device identifier, request identifier, premium flag and request local date are not put into the provider prompt. |
Your greeting name and notification schedule are not included in those generation requests. One-day and three-day portraits are calculated locally and do not request generated portrait text.
4. Why we process data
- To save and display your journal, daily card, collection and preferences on your device.
- To generate readings, personalized daily sentences and eligible premium period portraits.
- To enforce service limits, protect the service from abuse and monitor reliability.
- To process, restore and understand subscriptions and paywall performance.
- To schedule notifications you choose and respond to support or legal requests.
5. Service-side storage and logs
The proxy does not store reading or portrait request bodies in Cloudflare KV. KV stores rate-limit counters under keys that include the lowercased device identifier and the server’s UTC date for 24 hours. Operational generation-budget counters are stored for 48 hours and contain no user content.
For premium daily-card generation, KV caches the returned card name, generated sentence, language, local date and personalization flag under a key containing the lowercased device identifier, date and card. That cache and its generation counter expire after 48 hours. The free daily cache is shared by date, card and language and does not include a device identifier.
Worker application logs record technical fields such as endpoint, Cloudflare request ID, requested and detected language, model and provider, token counts, latency, retries, validation results and prompt version. Production configuration does not enable rejected model-output diagnostics, and application logs do not deliberately include the device identifier, questions, cards, notes or prompt text.
[OWNER ACTION: confirm and insert the Cloudflare Observability log retention period configured for the production account.]
6. Processors and recipients
Cloudflare
Cloudflare hosts the proxy, Pages website, KV counters and daily cache. It necessarily processes request payloads in transit, plus network and security metadata such as IP address and request headers.
Anthropic
Anthropic receives the provider-prompt data described above and returns generated text. The app does not send Anthropic your greeting name or device identifier. Anthropic’s own retention and security terms apply.
[OWNER ACTION: verify the production Anthropic API data-retention setting and replace this note with the current retention period before publication.]
Adapty
The app activates Adapty in observer mode, identifies the installation with the persistent device identifier, reports verified StoreKit transactions, fetches the paywall_main flow and records when that paywall is shown. Adapty does not receive journal text from the reviewed integration.
Apple
Apple provides the App Store, StoreKit subscription processing, Keychain and local notification frameworks. Purchases can include the device identifier as an App Account Token. Apple processes purchase and device data under its own terms and privacy policy.
Telegram operational alerts
If configured, the proxy sends Telegram operational alerts containing only the event type, route, UTC time, Worker version, budget counts, failure count, and provider status or error type. Those alerts do not contain the device identifier, IP address, questions, cards, themes, notes or generated text.
7. International transfers
Cloudflare, Anthropic, Adapty, Apple and Telegram may process data outside your country, including in the United States. Where GDPR or similar law applies, transfers must rely on an approved mechanism such as an adequacy decision or Standard Contractual Clauses, together with supplementary safeguards where required.
[OWNER ACTION: confirm the controller’s processor agreements, transfer locations and transfer mechanisms.]
8. Legal bases under GDPR
- Contract: processing needed to provide the app, generation features and subscriptions you request.
- Legitimate interests: proportionate security, rate limiting, debugging and service reliability.
- Consent: optional local notifications and any other processing presented as optional and consent-based. You can withdraw consent through iOS or app settings.
- Legal obligation: tax, accounting, consumer-protection and lawful-request duties where applicable.
You may type information about health, beliefs, sexuality or other special-category matters into a question or note. Such content should be sent for generation only on the basis of your explicit consent.
[OWNER ACTION — COMPLIANCE BLOCKER: the reviewed code did not establish an explicit-consent step for sending special-category data. Add and document that consent before relying on this legal basis or launching the affected processing.]
9. Retention and deletion
- On-device journal and preferences: kept until you edit or delete them, reset them where the app offers that control, or delete the app. The Keychain device identifier may survive reinstall.
- Cloudflare KV: reading and portrait counters expire after 24 hours; daily response caches and counters expire after 48 hours; operational alert deduplication records last from 2 hours to 48 hours, and upstream-failure state lasts 10 minutes.
- Generated portrait cache: stored on the device until replaced or the app’s local data is removed.
- Provider and platform records: retained under each processor’s current terms and the controller’s account settings.
Because Anthropic does not receive an account ID or device identifier in the prompt, a particular provider request may not be linkable back to you for deletion. You may still contact us; we will assess and pass on a deletion request where identification and deletion are technically and legally available. We cannot promise removal of records that a processor cannot identify or must retain by law.
10. Your rights without an account
Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, receive portable data, withdraw consent and complain to a supervisory authority. There is no account dashboard: make a request using the privacy contact above. We may ask for enough information to locate a server-side record and verify that it relates to your device without collecting more than necessary.
For local journal data, the developer cannot remotely access, export or delete it. Use the app’s controls where available or delete the app. Current code does not include a journal export feature.
11. Advertising, selling and tracking
The reviewed app contains no advertising SDK, does not request Apple’s tracking permission, and does not implement cross-app advertising tracking. We do not sell journal data. Adapty’s subscription analytics are described above.
[OWNER CONFIRMATION REQUIRED: confirm the business does not sell or share personal data for cross-context behavioural advertising in any channel outside the reviewed code.]
12. Children
Tarot Journal is not directed to children under [PLACEHOLDER: minimum age]. We do not knowingly collect a child’s personal data. If you believe a child has sent data through the service, contact us so we can assess the request.
13. Security
We use measures such as HTTPS, provider credentials held in the proxy rather than the app, bounded request fields and short-lived service counters. No system is completely secure; avoid putting information into a question or note that you do not want processed as described here.
14. Changes
We may update this policy when the app, processors or law changes. The date at the top will identify the latest version. Where required, we will provide additional notice or request renewed consent.
15. Contact
[PLACEHOLDER: legal name]
[PLACEHOLDER: legal address]
[PLACEHOLDER: privacy mailbox]@tarotjournalapp.com