Privacy & Security

Privacy Policy

Last updated: December 2024

🥺

1. A Message (to the Hackers)

"Dear hackers, please don't hack my site *sobs* :((( begging, pleading, praying here 😭

I'm just a tiny, weak, fragile little tarot website... please don't hack me *crying* 🙏🙏🙏"

2. Legal Basis for Data Processing

We collect and process your data based on the following legal grounds:

  • Your Consent: When you create an account or use our services, you consent to our data practices
  • Service Delivery: Processing necessary to provide Tarot AI readings and fulfill your requests
  • Legitimate Interests: Security measures, fraud prevention, and service improvement
  • Legal Obligations: Compliance with applicable laws and regulations

3. Information We Collect

When using DNA Tarot, we may collect:

  • Account Information: Email, display name when you register
  • Device Information: Anonymous identifier to save reading history
  • Reading Data: Questions, reading results (stored encrypted)
  • Payment Information: Processed via third-party payment gateways (we do not store your card)
  • AI Interaction History: Questions and AI responses stored for your Journaling features

4. How Data Is Collected

Your information is collected through various methods:

  • Direct Input: Information you provide when registering, asking Tarot questions, or contacting us
  • Automatic Collection: Cookies, server logs, device identifiers, and browsing behavior
  • Payment Partners: Transaction data from our secure payment gateways
  • In-App Interactions: Your activity within our platform such as readings, favorites, and preferences

5. How We Use Information

  • Provide and improve Tarot AI services
  • Save reading history for you to review
  • Process payments and orders
  • Send important account notifications

6. Third-Party Sharing

We may share limited data with trusted partners:

  • Payment Processors: Transaction details necessary to complete purchases (card info is NOT stored by us)
  • Analytics Services: Anonymized usage data to improve our platform (e.g., page views, session duration)
  • Hosting Providers: Our infrastructure partners who may have system-level access under strict agreements
  • AI Partners (OpenAI): Question content is sent to OpenAI for processing. We do not share your personal identifiers.

🔒 We NEVER sell your personal information to third parties. Ever.

7. Data Retention Period

We retain your data responsibly:

  • Account data is kept while your account remains active
  • Upon deletion request, data is removed or anonymized within 30 days
  • Payment transaction records are NOT stored on our servers
  • Server logs are automatically purged after 90 days

8. Children's Privacy

DNA Tarot is not intended for children under 13 years of age (or 16 in certain jurisdictions).

We do not knowingly collect personal information from children. If we discover that a child has provided us with personal data, we will delete it immediately.

Parents or guardians who believe their child has submitted information to us should contact us at dnab2d2@gmail.com.

9. Data Security Measures

We implement comprehensive security practices:

  • All passwords are hashed using industry-standard algorithms
  • Sensitive data (Tarot questions, readings) is encrypted at rest
  • Access to user data is strictly limited to authorized personnel only
  • We monitor access logs and employ anomaly detection systems
  • Regular security audits and vulnerability assessments are conducted
  • AI Chat history is strictly private; only the account owner has access rights

10. International Data Transfers

DNA Tarot uses cloud infrastructure providers (such as Vercel, Supabase, and similar services) whose servers may be located outside of Vietnam.

By using our services, you acknowledge that your data may be transferred to and processed in countries with different data protection laws.

We ensure that appropriate safeguards are in place to protect your information regardless of where it is stored.

11. Community Content

If you participate in our community features:

  • You are solely responsible for content you post publicly
  • Do not share sensitive personal information of yourself or others
  • DNA Tarot reserves the right to remove content that violates our guidelines
  • Content you share may be visible to other users and should be treated as public

12. Cookies

Cookies are like the website's 'memory'. They help us recognize you when you return, for example keeping you logged in or remembering items you placed in your cart.

If you disable Cookies, the website will become 'forgetful' and some convenient features may not work anymore.

13. Policy Updates

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements.

When we make significant changes, we will notify you via email or a prominent notice on our platform.

The updated policy becomes effective immediately upon posting. Your continued use of DNA Tarot after changes indicates your acceptance of the new policy.

14. Contact & Privacy Inquiries

If you have any questions about this policy, want to exercise your data rights, or have privacy concerns, please contact us:

dnab2d2@gmail.com